> ## Documentation Index
> Fetch the complete documentation index at: https://docs.infrawatch.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Protocols S–Z

> Protocol-specific service search fields in Protocols S–Z

Protocol-specific service search fields in Protocols S–Z.

Dataset: `services`

<ResponseField name="s7comm" type="object">
  <Expandable title="Fields">
    <ResponseField name="destination_tsap" type="uint32">
      TSAP destination that completed setup communication. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="firmware_version" type="string">
      Firmware version from SZL module identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="hardware_version" type="string">
      Hardware version from SZL module identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="location" type="string">
      Installation location from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="module_id" type="string">
      Module identifier string from SZL module identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="module_name" type="string">
      Module name from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="module_type" type="string">
      Module type from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="plant_id" type="string">
      Plant identifier from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="serial_number" type="string">
      Device serial number from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="system_name" type="string">
      System name from component identification records. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="sbc_3cx" type="object">
  <Expandable title="Fields">
    <ResponseField name="initial_opcode" type="InitialOpcode">
      Initial control opcode observed from the server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="sccp" type="object">
  <Expandable title="Fields">
    <ResponseField name="protocol_version" type="uint32">
      Protocol version if present in the register-ack payload. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="response_type" type="ResponseType">
      Response type from the SCCP server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="seven_days_to_die" type="object">
  <Expandable title="Fields">
    <ResponseField name="app_id" type="uint32">
      Steam app ID. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="game_description" type="string">
      Source game description. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="game_directory" type="string">
      Source game directory. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="game_host" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="game_id" type="uint64">
      Optional full 64-bit Source game ID from the EDF tail. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="game_mode" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="game_name" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="game_type" type="string">
      7DTD metadata fields parsed from the keywords string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="keywords" type="string">
      Raw Source keywords string, which carries the 7DTD metadata blob. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="level_name" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="map_name" type="string">
      Active map or level name from the A2S INFO response. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="max_players" type="uint32">
      Maximum player slots. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="operating_system" type="string">
      Server operating system (linux/windows/macos). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="platform" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="play_group" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="players" type="uint32">
      Current player count. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="private_server" type="bool">
      Whether the server is private/passworded. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="secure" type="bool">
      Whether VAC is enabled. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="server_description" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_login_confirmation_text" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_name" type="string">
      Source server name from the A2S INFO response. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_type" type="string">
      Server type (dedicated/listen/proxy). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_version" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_website_url" type="string">
      Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Reported server build/version from A2S INFO. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="sip" type="object">
  <Expandable title="Fields">
    <ResponseField name="allow_methods" type="repeated string">
      List of allow methods. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="code" type="uint32">
      Code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="server" type="string">
      Server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="status" type="string">
      Status. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="supported_extensions" type="repeated string">
      List of supported extensions. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Version. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="slp" type="object">
  <Expandable title="Fields">
    <ResponseField name="error_code" type="uint32">
      SLP response error code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="function_id" type="uint32">
      SLP function identifier in the response. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="function_name" type="string">
      Human-readable SLP function name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="language_tag" type="string">
      Language tag from response headers. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="service_urls" type="repeated string">
      Service URLs returned by the responder. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="url_count" type="uint32">
      Number of URLs returned for service replies. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="xid" type="uint32">
      Transaction identifier. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="smb" type="object">
  <Expandable title="Fields">
    <ResponseField name="anonymous" type="bool">
      Whether anonymous session access succeeded. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="authentication_mode" type="string">
      Authentication mode (anonymous, required, unknown). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="capabilities" type="repeated string">
      Protocol capabilities. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="dialect" type="string">
      Negotiated dialect label. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_dns_computer" type="string">
      NTLM DNS computer name from challenge metadata. Friendly label: `NTLM DNS Computer`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_dns_domain" type="string">
      NTLM DNS domain name from challenge metadata. Friendly label: `NTLM DNS Domain`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_dns_tree" type="string">
      NTLM DNS forest/tree name from challenge metadata. Friendly label: `NTLM DNS Tree`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_netbios_computer" type="string">
      NTLM NetBIOS computer name from challenge metadata. Friendly label: `NTLM NetBIOS Computer`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_netbios_domain" type="string">
      NTLM NetBIOS domain name from challenge metadata. Friendly label: `NTLM NetBIOS Domain`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ntlm_target_name" type="string">
      NTLM target name from challenge metadata. Friendly label: `NTLM Target Name`. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="os" type="string">
      Native operating system hint. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="signing_enabled" type="bool">
      Whether message signing is enabled. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="signing_required" type="bool">
      Whether message signing is required. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="smb_version" type="uint32">
      Preferred SMB major version (1 or 2). Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="software" type="string">
      Native software hint. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="supports_smb1" type="bool">
      Whether SMB1 was observed. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="supports_smb2" type="bool">
      Whether SMB2+ was observed. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="shares" type="object">
      <Expandable title="Fields">
        <ResponseField name="comment" type="string">
          Share comment. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="is_special" type="bool">
          Whether share is special. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="is_temporary" type="bool">
          Whether share is temporary. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="kind" type="string">
          Share kind (disk, ipc, printer, device, unknown). Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="name" type="string">
          Share name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="entries" type="object">
          <Expandable title="Fields">
            <ResponseField name="is_directory" type="bool">
              Whether entry is a directory. Operators: `:` `=` `!=`.
            </ResponseField>

            <ResponseField name="name" type="string">
              Entry name. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>

            <ResponseField name="read_only" type="bool">
              Whether entry is read-only. Operators: `:` `=` `!=`.
            </ResponseField>

            <ResponseField name="size_bytes" type="uint64">
              Entry size in bytes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
            </ResponseField>
          </Expandable>
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="smpp" type="object">
  <Expandable title="Fields">
    <ResponseField name="command_status" type="uint32">
      SMPP command status from the response header. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="interface_version" type="uint32">
      Interface version from optional TLV, if present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="response_type" type="ResponseType">
      Response type observed from the server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="system_id" type="string">
      System ID returned by bind responses, if present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="smtp" type="object">
  <Expandable title="Fields">
    <ResponseField name="auth_mechanisms" type="repeated string">
      Authentication mechanisms derived from AUTH capability. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="capabilities" type="repeated string">
      EHLO capability lines, normalized and deduped. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="greeting" type="string">
      Server greeting line as received (CRLF preserved when present). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="greeting_code" type="uint32">
      Parsed SMTP reply code from greeting, when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="greeting_message" type="string">
      Greeting text after the SMTP reply code. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="max_message_bytes" type="uint64">
      Maximum advertised message size parsed from SIZE capability. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="software" type="string">
      Optional software hint extracted from greeting text (e.g. Postfix, Exim). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="starttls_accepted" type="bool">
      True when STARTTLS reply indicates acceptance. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="starttls_reply" type="string">
      STARTTLS command reply line. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="starttls_supported" type="bool">
      True when STARTTLS is advertised in capabilities. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="used_implicit_tls" type="bool">
      True when scan connected with implicit TLS (usually port 465). Operators: `:` `=` `!=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="snmp" type="object">
  <Expandable title="Fields">
    <ResponseField name="observed_versions" type="repeated string">
      List of observed versions. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="engine_metadata" type="object">
      <Expandable title="Fields">
        <ResponseField name="boots_counter" type="uint32">
          Boots counter. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="engine_id_hex" type="string">
          Engine ID hex. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="engine_uptime_seconds" type="uint32">
          Engine uptime seconds in seconds. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="enterprise_name" type="string">
          Enterprise name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="enterprise_number" type="uint32">
          Enterprise number. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="id_layout" type="string">
          ID layout. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="probe_descriptor" type="string">
          Probe descriptor. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="uses_rfc3411_layout" type="bool">
          Whether uses rfc3411 layout. Operators: `:` `=` `!=`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="snpp" type="object">
  <Expandable title="Fields">
    <ResponseField name="banner" type="string">
      Greeting banner line observed from the service. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="socks" type="object">
  <Expandable title="Fields">
    <ResponseField name="auth_required" type="bool">
      Whether auth required. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="version" type="uint32">
      Version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="spotify_connect" type="object">
  <Expandable title="Fields">
    <ResponseField name="active_user" type="string">
      Active user. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="brand_display_name" type="string">
      Brand display name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="client_id" type="string">
      Client ID. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="device_id" type="string">
      Device ID. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="device_type" type="string">
      Device type. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="library_version" type="string">
      Library version. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="model_display_name" type="string">
      Model display name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="remote_name" type="string">
      Remote name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="scope" type="string">
      Scope. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Version. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="ssdp" type="object">
  <Expandable title="Fields">
    <ResponseField name="boot_id" type="uint32">
      Boot ID from BOOTID.UPNP.ORG when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="cache_max_age_seconds" type="uint32">
      Cache lifetime parsed from CACHE-CONTROL max-age. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="config_id" type="uint32">
      Config ID from CONFIGID.UPNP.ORG when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="location" type="string">
      Device description URL from the LOCATION header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="search_target" type="string">
      Search target from the ST header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server" type="string">
      Software and UPnP stack hint from the SERVER header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="status_code" type="uint32">
      HTTP status code from the M-SEARCH response. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="status_line" type="string">
      HTTP status line from the responder. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="unique_service_name" type="string">
      Unique service name from the USN header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="ssh" type="object">
  <Expandable title="Fields">
    <ResponseField name="client_id" type="string">
      Client ID. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_id" type="string">
      Server ID. Included in overview projections. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="algorithm_selection" type="object">
      <Expandable title="Fields">
        <ResponseField name="host_key_algorithm" type="string">
          Host key algorithm. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="kex_algorithm" type="string">
          Kex algorithm. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="client_to_server_alg_group" type="object">
          <Expandable title="Fields">
            <ResponseField name="cipher" type="string">
              Cipher. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>

            <ResponseField name="compression" type="string">
              Compression. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>

            <ResponseField name="mac" type="string">
              Mac. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>
          </Expandable>
        </ResponseField>

        <ResponseField name="server_to_client_alg_group" type="object">
          <Expandable title="Fields">
            <ResponseField name="cipher" type="string">
              Cipher. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>

            <ResponseField name="compression" type="string">
              Compression. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>

            <ResponseField name="mac" type="string">
              Mac. Operators: `:` `=` `!=` `=~` `:~`.
            </ResponseField>
          </Expandable>
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="endpoint_id" type="object">
      <Expandable title="Fields">
        <ResponseField name="protocol_version" type="string">
          Protocol version. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="software_version" type="string">
          Software version. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="kex_init" type="object">
      <Expandable title="Fields">
        <ResponseField name="compression_algorithms_client_to_server" type="repeated string">
          List of compression algorithms client to server. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="compression_algorithms_server_to_client" type="repeated string">
          List of compression algorithms server to client. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="encryption_algorithms_client_to_server" type="repeated string">
          List of encryption algorithms client to server. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="encryption_algorithms_server_to_client" type="repeated string">
          List of encryption algorithms server to client. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="kex_algorithms" type="repeated string">
          List of kex algorithms. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="mac_algorithms_client_to_server" type="repeated string">
          List of mac algorithms client to server. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="mac_algorithms_server_to_client" type="repeated string">
          List of mac algorithms server to client. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_host_key_algorithms" type="repeated string">
          List of server host key algorithms. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="kex_init_message" type="object">
      <Expandable title="Fields">
        <ResponseField name="client_to_server_ciphers" type="repeated string">
          List of client to server ciphers. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="client_to_server_compression" type="repeated string">
          List of client to server compression. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="client_to_server_languages" type="repeated string">
          List of client to server languages. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="client_to_server_macs" type="repeated string">
          List of client to server macs. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="first_kex_follows" type="bool">
          Whether first kex follows. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="host_key_algorithms" type="repeated string">
          List of host key algorithms. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="kex_algorithms" type="repeated string">
          List of kex algorithms. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_to_client_ciphers" type="repeated string">
          List of server to client ciphers. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_to_client_compression" type="repeated string">
          List of server to client compression. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_to_client_languages" type="repeated string">
          List of server to client languages. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_to_client_macs" type="repeated string">
          List of server to client macs. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="ssrp" type="object">
  <Expandable title="Fields">
    <ResponseField name="instance_count" type="uint32">
      Number of parsed instances. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="message_type" type="uint32">
      SSRP message type from response header. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="instances" type="object">
      <Expandable title="Fields">
        <ResponseField name="clustered" type="bool">
          Whether the instance reports clustering enabled. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="instance_name" type="string">
          SQL instance name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="named_pipe" type="string">
          SQL instance named pipe endpoint. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="server_name" type="string">
          SQL host/server name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="tcp_port" type="uint32">
          SQL instance TCP listener port. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="version" type="string">
          SQL instance version string. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="steam_ihs" type="object">
  <Expandable title="Fields">
    <ResponseField name="broadcasting_active" type="bool">
      Whether broadcasting is active. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="client_id" type="string">
      Steam client identifier from the broadcast header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="connect_port" type="uint32">
      Reported remote connection port. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="enabled_services" type="uint32">
      Enabled service bitmask. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="euniverse" type="int32">
      Reported Steam universe. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="games_running" type="bool">
      Whether games are currently running. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="hostname" type="string">
      Reported device hostname. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="instance_id" type="string">
      Steam instance identifier from the broadcast header. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ip_addresses" type="repeated string">
      Reported private or LAN addresses. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="is_64bit" type="bool">
      Whether the remote device reports a 64-bit OS. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="mac_addresses" type="repeated string">
      Reported MAC addresses. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="message_type" type="string">
      Normalized broadcast message type. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="min_version" type="int32">
      Minimum supported Steam IHS protocol version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="os_type" type="int32">
      Reported operating system type. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="public_ip_address" type="string">
      Reported public IP address. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="remoteplay_active" type="bool">
      Whether Remote Play is active. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="screen_locked" type="bool">
      Whether the screen is currently locked. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="steam_deck" type="bool">
      Whether the device identifies as a Steam Deck. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="steam_version" type="uint64">
      Reported Steam client build/version identifier. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="supported_services" type="uint32">
      Supported service bitmask. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="timestamp" type="string">
      Reported device timestamp in RFC3339 format. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="int32">
      Reported Steam IHS protocol version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="vr_active" type="bool">
      Whether VR streaming is active. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="users" type="object">
      <Expandable title="Fields">
        <ResponseField name="steam_id" type="string">
          SteamID encoded as a decimal string. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="stomp" type="object">
  <Expandable title="Fields">
    <ResponseField name="content_type" type="string">
      Content-Type header value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="error_message" type="string">
      Error body when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="frame_command" type="string">
      STOMP frame command (e.g. CONNECTED, ERROR). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="heart_beat" type="string">
      Heart-beat header value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="protocol_version" type="string">
      Negotiated STOMP protocol version. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server" type="string">
      Server header value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="stun" type="object">
  <Expandable title="Fields">
    <ResponseField name="attribute_count" type="uint32">
      Count of parsed STUN attributes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="fingerprint_present" type="bool">
      True when FINGERPRINT attribute is present. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="message_class" type="string">
      STUN message class (success, error, request, indication). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="message_integrity_present" type="bool">
      True when MESSAGE-INTEGRITY attribute is present. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="method" type="uint32">
      STUN method number. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="realm" type="string">
      REALM attribute value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="software" type="string">
      SOFTWARE attribute value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="alternate_server" type="object">
      <Expandable title="Fields">
        <ResponseField name="ip" type="string">
          IP address extracted from STUN attributes. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="port" type="uint32">
          Port extracted from STUN attributes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="error" type="object">
      <Expandable title="Fields">
        <ResponseField name="code" type="uint32">
          Numeric STUN error code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="reason" type="string">
          Human-readable STUN error reason phrase. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="mapped_address" type="object">
      <Expandable title="Fields">
        <ResponseField name="ip" type="string">
          IP address extracted from STUN attributes. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="port" type="uint32">
          Port extracted from STUN attributes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="xor_mapped_address" type="object">
      <Expandable title="Fields">
        <ResponseField name="ip" type="string">
          IP address extracted from STUN attributes. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="port" type="uint32">
          Port extracted from STUN attributes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="sunray_utrcmd" type="object">
  <Expandable title="Fields">
    <ResponseField name="daemon_name" type="string">
      Reported daemon name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="error_code" type="uint32">
      Parsed protocol error code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="message" type="string">
      Normalized textual message. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="remote" type="bool">
      Whether the daemon reported a remote-side error path. Operators: `:` `=` `!=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="svnserve" type="object">
  <Expandable title="Fields">
    <ResponseField name="auth_mechanisms" type="repeated string">
      Supported authentication mechanisms. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="capabilities" type="repeated string">
      Supported server capabilities. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="max_protocol_version" type="uint32">
      Maximum protocol version advertised by the server. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="min_protocol_version" type="uint32">
      Minimum protocol version advertised by the server. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="tacacs_plus" type="object">
  <Expandable title="Fields">
    <ResponseField name="authen_status" type="uint32">
      Authentication status from AUTHEN/REPLY packets. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="authen_status_name" type="string">
      Human-readable authentication status. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="body_encrypted" type="bool">
      True when the server indicated encrypted body semantics. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="body_length" type="uint32">
      TACACS+ body length from the header. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="flags" type="uint32">
      TACACS+ flags byte. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="packet_type" type="string">
      TACACS+ packet type (authentication/authorization/accounting). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="sequence_number" type="uint32">
      TACACS+ sequence number. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="server_message" type="string">
      Server message from AUTHEN/REPLY when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version_major" type="uint32">
      TACACS+ major version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="version_minor" type="uint32">
      TACACS+ minor version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="teamspeak" type="object">
  <Expandable title="Fields">
    <ResponseField name="build" type="string">
      Build or release identifier reported by the query interface. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="generation" type="string">
      TeamSpeak major generation, such as "2" or "3". Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="interface_variant" type="string">
      Interface variant used to identify the service, such as "serverquery", "tcpquery", or "voice". Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="platform" type="string">
      Platform or operating system string reported by the server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_name" type="string">
      Server name advertised by TeamSpeak 2 voice discovery. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Server version reported by the query interface or inferred from a fixed voice-protocol signature. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="telnet" type="object">
  <Expandable title="Fields">
    <ResponseField name="do_option_codes" type="repeated uint32">
      List of do option codes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="do_option_names" type="repeated string">
      List of do option names. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="dont_option_codes" type="repeated uint32">
      List of dont option codes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="dont_option_names" type="repeated string">
      List of dont option names. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="has_starttls_option" type="bool">
      True when START\_TLS option (46) was observed. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="iac_command_count" type="uint32">
      Number of iac command count. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="negotiation_seen" type="bool">
      Whether negotiation seen. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="pre_auth_text" type="string">
      Printable text emitted before authentication (banner/prompts). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="will_option_codes" type="repeated uint32">
      List of will option codes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="will_option_names" type="repeated string">
      List of will option names. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="wont_option_codes" type="repeated uint32">
      List of wont option codes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="wont_option_names" type="repeated string">
      List of wont option names. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="subnegotiations" type="object">
      <Expandable title="Fields">
        <ResponseField name="option_code" type="uint32">
          Option code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="option_name" type="string">
          Option name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="tftp" type="object">
  <Expandable title="Fields">
    <ResponseField name="block_number" type="uint32">
      Block number from DATA/ACK packets when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="data_size" type="uint32">
      DATA payload size in bytes. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="error_code" type="uint32">
      TFTP error code from ERROR packets when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="error_message" type="string">
      TFTP error message from ERROR packets. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="option_acknowledged" type="bool">
      True when an OACK packet was observed. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="response_opcode" type="uint32">
      First response opcode. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="response_opcode_name" type="string">
      Symbolic response opcode label. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_tid" type="uint32">
      Source UDP port used by the responder for transfer traffic. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="transfer_mode" type="string">
      Transfer mode echoed from the request. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="options" type="object">
      <Expandable title="Fields">
        <ResponseField name="name" type="string">
          Option key name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="value" type="string">
          Option value. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="tns" type="object">
  <Expandable title="Fields">
    <ResponseField name="error_code" type="uint32">
      Listener error code when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="error_message" type="string">
      Listener error details when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="listener_version" type="string">
      Listener version string when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="packet_type" type="uint32">
      TNS packet type value from the response header. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="packet_type_name" type="string">
      Human-readable TNS packet type. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="vsnnum" type="string">
      Raw VSNNUM value when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="turn" type="object">
  <Expandable title="Fields">
    <ResponseField name="error_code" type="uint32">
      ERROR-CODE attribute if provided. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="realm" type="string">
      REALM attribute if provided. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="software" type="string">
      SOFTWARE attribute if provided. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="ubiquiti_ndp" type="object">
  <Expandable title="Fields">
    <ResponseField name="command" type="uint32">
      Ubiquiti discovery response command value. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="config_status" type="string">
      Adoption/configuration status when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="essid" type="string">
      Wireless ESSID when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="firmware" type="string">
      Firmware string when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="hostname" type="string">
      Device hostname when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ip_addresses" type="repeated string">
      Observed interface IP addresses. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="mac_addresses" type="repeated string">
      Observed MAC addresses. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="management_port" type="uint32">
      Management port when advertised. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="model" type="string">
      Model string when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="product" type="string">
      Product string when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="protocol_version" type="uint32">
      Ubiquiti discovery protocol version (1 or 2). Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="software_version" type="string">
      Software version when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="uptime_seconds" type="uint32">
      Uptime in seconds when present. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="unitronics_pcom" type="object">
  <Expandable title="Fields">
    <ResponseField name="hardware_version" type="string">
      PLC hardware revision. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="model" type="string">
      Human-readable PLC model when recognized. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="model_code" type="string">
      Raw PLC model code returned by the device. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="os_build" type="uint32">
      PLC operating system build number. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="os_version" type="string">
      PLC operating system version in major.minor form. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="plc_name" type="string">
      PLC name configured on the controller. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="plc_unique_id" type="uint64">
      PLC unique identifier. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="uid_master" type="uint32">
      Unit ID of the PCOM master PLC. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="vatsim_fsd" type="object">
  <Expandable title="Fields">
    <ResponseField name="callsigns" type="repeated string">
      Callsigns observed in position/update traffic. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="recipient" type="string">
      Recipient identifier from the \$DI greeting. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="saw_position_updates" type="bool">
      True when position/update traffic was also observed. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="sender" type="string">
      Sender identifier from the \$DI greeting. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Advertised FSD version string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="vmware_authd" type="object">
  <Expandable title="Fields">
    <ResponseField name="features" type="repeated string">
      Supported feature flags from the banner tail. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="greeting_code" type="uint32">
      Greeting status code. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="greeting_text" type="string">
      Greeting text after the numeric status code. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="mks_display_protocol" type="string">
      Advertised MKS display protocol, when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_daemon_protocol" type="string">
      Advertised server daemon protocol, when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="ssl_required" type="bool">
      True when the banner requires SSL/TLS. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Authentication daemon version string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="vnc" type="object">
  <Expandable title="Fields">
    <ResponseField name="security_type_ids" type="repeated uint32">
      Security types as raw numeric IDs. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="security_types" type="repeated string">
      Security types decoded to labels. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="vendor" type="string">
      Best-effort implementation/vendor family hint. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Raw banner version string from the server (e.g. "003.008"). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="weblogic_t3" type="object">
  <Expandable title="Fields">
    <ResponseField name="public_url" type="string">
      Advertised public T3 endpoint, when included in the handshake. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="response_type" type="ResponseType">
      First T3 response type observed from the server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_version" type="string">
      Parsed server version when the response exposes a trustworthy version string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="whois" type="object">
  <Expandable title="Fields">
    <ResponseField name="referral_server" type="string">
      Referral WHOIS server endpoint if present in response metadata. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="winaqms_data_server" type="object">
  <Expandable title="Fields">
    <ResponseField name="product_name" type="string">
      Product name extracted from the banner. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="prompt_present" type="bool">
      Whether the session exposed the interactive prompt. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Version string from the WinAQMS data server greeting. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="world_of_warcraft" type="object">
  <Expandable title="Fields">
    <ResponseField name="connection_direction" type="string">
      Direction of the connection banner. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="protocol_version" type="string">
      Reported connection protocol version, e.g. "V2". Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="ws_discovery" type="object">
  <Expandable title="Fields">
    <ResponseField name="action" type="string">
      SOAP action from the response header when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="fault_reason" type="string">
      SOAP fault reason when present. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="soap_fault" type="bool">
      True when the response body is a SOAP fault. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="matches" type="object">
      <Expandable title="Fields">
        <ResponseField name="message_id" type="string">
          WS-Addressing message identifier. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="types" type="string">
          Advertised type list. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="xaddrs" type="string">
          Advertised service addresses. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="wsman" type="object">
  <Expandable title="Fields">
    <ResponseField name="auth_required" type="bool">
      True when the endpoint requires authentication. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="auth_schemes" type="repeated string">
      Authentication schemes offered in WWW-Authenticate headers. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="fault_code" type="string">
      SOAP fault code when the endpoint returned a WS-Man fault. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="fault_reason" type="string">
      SOAP fault reason when the endpoint returned a WS-Man fault. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="product_vendor" type="string">
      Product vendor reported by Identify. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="product_version" type="string">
      Product version reported by Identify. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="protocol_version" type="string">
      WS-Management protocol URI reported by Identify. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="response_type" type="WsmanResponseType">
      Classification of the first protocol-specific response. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="x11" type="object">
  <Expandable title="Fields">
    <ResponseField name="failure_reason" type="string">
      Optional failure reason text. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="major_version" type="uint32">
      X11 protocol major version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="minor_version" type="uint32">
      X11 protocol minor version. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="setup_status" type="SetupStatus">
      Setup status returned by the X11 server. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="vendor" type="string">
      Optional X11 vendor string on successful setup. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="xbmsp" type="object">
  <Expandable title="Fields">
    <ResponseField name="protocol_name" type="string">
      Protocol banner prefix, e.g. XBMSP-1.0. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="protocol_version" type="string">
      Advertised protocol version token. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_name" type="string">
      Server product name. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="server_version" type="string">
      Trailing server version or build token. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="xdmcp" type="object">
  <Expandable title="Fields">
    <ResponseField name="authentication_name" type="string">
      Authentication name selected by a Willing response. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="hostname" type="string">
      Human-readable manager hostname string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="response_type" type="ResponseType">
      Whether the manager answered Willing or Unwilling. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="status" type="string">
      Human-readable manager status string. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="xilinx_hw_server" type="object">
  <Expandable title="Fields">
    <ResponseField name="capabilities" type="repeated string">
      Advertised server capabilities. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="greeting" type="string">
      Greeting family, typically "ELocatorHello". Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="xicom_version" type="string">
      Xicom version token when advertised, e.g. "Xicom\_v1.00". Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="xmpp" type="object">
  <Expandable title="Fields">
    <ResponseField name="error" type="string">
      Stream error (for example host-unknown). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="used_implicit_tls" type="bool">
      Whether the scan used implicit TLS. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="features" type="object">
      <Expandable title="Fields">
        <ResponseField name="entity_capabilities_node" type="string">
          Entity capabilities node. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="entity_capabilities_verification" type="string">
          Entity capabilities verification string. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="sasl_mechanisms" type="repeated string">
          SASL mechanisms. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="starttls_offered" type="bool">
          Whether STARTTLS is offered. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="starttls_required" type="bool">
          Whether STARTTLS is required. Operators: `:` `=` `!=`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="stream" type="object">
      <Expandable title="Fields">
        <ResponseField name="from" type="string">
          Stream from address. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="id" type="string">
          Stream id. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="namespace" type="string">
          Stream namespace. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="to" type="string">
          Stream to address. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="version" type="string">
          Stream version. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="zeromq" type="object">
  <Expandable title="Fields">
    <ResponseField name="command" type="string">
      Command. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="mechanism" type="string">
      Mechanism. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="signature_valid" type="bool">
      Whether signature valid. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="socket_type" type="string">
      Socket type. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="zmtp_version" type="string">
      Zmtp version. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="zookeeper" type="object">
  <Expandable title="Fields">
    <ResponseField name="connection_count" type="uint32">
      Reported active client connection count. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="mode" type="string">
      Server mode (leader, follower, standalone, read-only). Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>

    <ResponseField name="node_count" type="uint32">
      Reported znode count. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
    </ResponseField>

    <ResponseField name="read_only" type="bool">
      Whether the server reports read-only mode. Operators: `:` `=` `!=`.
    </ResponseField>

    <ResponseField name="version" type="string">
      Zookeeper version from 4lw output. Operators: `:` `=` `!=` `=~` `:~`.
    </ResponseField>
  </Expandable>
</ResponseField>

<ResponseField name="valve" type="object">
  <Expandable title="Fields">
    <ResponseField name="rcon" type="object">
      <Expandable title="Fields">
        <ResponseField name="response_id" type="int32">
          RCON packet ID. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="response_size" type="uint32">
          RCON packet size field. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="response_type" type="uint32">
          RCON packet type (e.g. SERVERDATA\_RESPONSE\_VALUE=0). Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>
      </Expandable>
    </ResponseField>

    <ResponseField name="server" type="object">
      <Expandable title="Fields">
        <ResponseField name="app_id" type="uint32">
          Steam app ID. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="game_description" type="string">
          Source game description. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="game_directory" type="string">
          Source game directory. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="map" type="string">
          Active map name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="max_players" type="uint32">
          Maximum player slots. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="name" type="string">
          Source server name. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="operating_system" type="string">
          Server operating system (linux/windows/macos). Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="players" type="uint32">
          Current player count. Operators: `:` `=` `!=` `<` `<=` `>` `>=`.
        </ResponseField>

        <ResponseField name="private_server" type="bool">
          Whether server is private/passworded. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="secure" type="bool">
          Whether VAC is enabled. Operators: `:` `=` `!=`.
        </ResponseField>

        <ResponseField name="server_type" type="string">
          Server type (dedicated/listen/proxy). Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>

        <ResponseField name="version" type="string">
          Reported game/server version. Operators: `:` `=` `!=` `=~` `:~`.
        </ResponseField>
      </Expandable>
    </ResponseField>
  </Expandable>
</ResponseField>
