Skip to main content

OpenTelemetry Tracing Reference

All backend spans are created via the OpenTelemetry SDK using otel.Tracer(observability.TracerName). Traces are exported to Tempo via OTLP gRPC (port 4317) and can be visualized in Grafana Explore using the Tempo datasource.

Auth Middleware​

SpanAttributesSource
auth.validate_tokenauth.validapi/auth_middleware.go
auth.resolve_accessauth.subject_id, auth.subject_type, auth.is_super_adminapi/auth_middleware.go
auth.check_permissionauth.permission_checked, auth.subject_id, auth.subject_type, auth.is_super_admin, auth.permitted, auth.client_idapi/auth_middleware.go

HTTP Middleware​

SpanAttributesSource
otelhttp (auto-instrumented)request_id, method, path, statusobservability/middleware.go

Credential API​

SpanAttributesSource
api.CreateCredential—api/credential_handler.go
api.ListCredentials—api/credential_handler.go
api.GetCredential—api/credential_handler.go
api.UpdateCredential—api/credential_handler.go
api.DeleteCredential—api/credential_handler.go
api.TestCredential—api/credential_handler.go

Healthcheck API​

SpanAttributesSource
healthcheck.score.host—api/healthcheck_handler.go
healthcheck.score.environment—api/healthcheck_handler.go
healthcheck.score.client—api/healthcheck_handler.go
healthcheck.trigger—api/healthcheck_handler.go

Metric API​

SpanAttributesSource
api.ListMetricNamesproxima.host_idapi/metric_handler.go
api.QueryMetricsproxima.host_id, proxima.metric_name, proxima.derivativeapi/metric_handler.go
api.ListMetricSeriesproxima.host_id, proxima.metric_nameapi/metric_handler.go
api.QueryLatestMetricsproxima.host_count, proxima.metric_countapi/metric_handler.go
api.QueryProcessMetricsproxima.host_id, proxima.pid, proxima.process_nameapi/metric_handler.go
api.QueryContainerMetricsproxima.host_id, proxima.container_idapi/metric_handler.go
api.QueryContainerLatestMetricsproxima.host_idapi/metric_handler.go

Aggregate Metric API​

SpanAttributesSource
api.ListMetricNamesByEnvironment—api/aggregate_metric_handler.go
api.QueryMetricsByEnvironment—api/aggregate_metric_handler.go
api.ListMetricSeriesByEnvironment—api/aggregate_metric_handler.go
api.ListMetricNamesByClient—api/aggregate_metric_handler.go
api.QueryMetricsByClient—api/aggregate_metric_handler.go
api.ListMetricSeriesByClient—api/aggregate_metric_handler.go

Search API​

SpanAttributesSource
api.Search—api/search_handler.go
api.SearchCount—api/search_handler.go
api.SearchFields—api/search_handler.go
api.SearchValues—api/search_handler.go
api.SearchValidate—api/search_handler.go
api.SearchAggregate—api/search_handler.go

Logs API​

SpanAttributesSource
logs.query—api/logs_handler.go
logs.proxy—api/logs_handler.go

Saved Search API​

SpanAttributesSource
api.SavedSearchList—api/saved_search_handler.go
api.SavedSearchCreate—api/saved_search_handler.go
api.SavedSearchGetByID—api/saved_search_handler.go
api.SavedSearchUpdate—api/saved_search_handler.go
api.SavedSearchDelete—api/saved_search_handler.go

NATS Workers​

The span name is process.<envelope type>

Consumer spans are built as "process." + envelope.Type, so the span set is exactly the set of envelope types each consumer dispatches. There is no process.registration, process.telemetry or process.heartbeat_v2 — those name a consumer or a stream, not an envelope type, and searching Tempo for them returns nothing.

SpanAttributesSource
process.inventorymessaging.system, messaging.subject, proxima.correlation_id, proxima.agent_id, proxima.message_typeworker/events.go
process.changessameworker/events.go
process.healthchecksameworker/events.go
process.kubernetessameworker/events.go
process.connectionssameworker/events.go
process.metricsmessaging.system, messaging.subject, proxima.agent_idworker/telemetry.go
process.processessameworker/telemetry.go
process.logssameworker/telemetry.go
process.heartbeatmessaging.system, messaging.subject, proxima.agent_idworker/heartbeat_consumer.go
process.config_fetchmessaging.system, messaging.subject, proxima.host_idworker/config_fetch.go
process.config_applymessaging.system, messaging.subject, proxima.host_id, proxima.config_type, proxima.status, proxima.versionworker/config_apply.go

Worker Processing​

SpanAttributesSource
worker.HeartbeatProcessproxima.host_id, proxima.collectors_count, proxima.scanners_countworker/heartbeat.go
worker.ProcessesProcessproxima.host_id, proxima.process_countworker/processes.go
worker.MetricsProcessproxima.host_id, vm.account_id, vm.metric_countworker/metrics.go
worker.InventoryProcess—worker/inventory.go
worker.ChangesProcessproxima.host_id, proxima.scan_type, proxima.file_count, proxima.batch_seq, proxima.batch_totalworker/changes.go
worker.HealthcheckProcessproxima.host_id, proxima.run_id, proxima.scanner, proxima.environment_id, proxima.client_id, proxima.total_checks, proxima.passed, proxima.failed, proxima.findings_countworker/healthcheck.go
logs.processproxima.agent_id, vl.account_id, vl.entry_count, vl.self_logsworker/logs_worker.go

Compliance Worker​

SpanAttributesSource
process.compliance.evaluatemessaging.system, messaging.subject, proxima.host_id, proxima.run_id, proxima.environment_id, proxima.client_idworker/compliance_consumer.go
worker.ComplianceEvaluateproxima.host_id, proxima.run_id, proxima.environment_id, proxima.client_id, proxima.framework.{slug}.controls, proxima.framework.{slug}.evaluationsworker/compliance.go

Config Sync​

SpanAttributesSource
configsync.resolveproxima.config_type, proxima.host_id, proxima.environment_id, proxima.sourceagentconfig/resolver.go
configsync.resolve_allproxima.host_id, proxima.environment_id, proxima.config_countagentconfig/resolver.go
configsync.resolve_credentialsproxima.config_type, proxima.client_id, credential_id, credential_typeagentconfig/credential_resolver.go

Search Engine​

SpanAttributesSource
search.Compileproxima.querysearch/search.go

VictoriaMetrics Client​

SpanAttributesSource
vmclient.Import—vmclient/client.go
vmclient.QueryRange—vmclient/client.go
vmclient.Query—vmclient/client.go
vmclient.LabelValues—vmclient/client.go
vmclient.Health—vmclient/client.go

VictoriaLogs Client​

SpanAttributesSource
vlclient.Insert—vlclient/client.go
vlclient.Health—vlclient/client.go

Vault Transit​

SpanAttributesSource
vault.transit.encrypt—credential/vault_transit.go
vault.transit.decrypt—credential/vault_transit.go

Store​

SpanAttributesSource
store.SavedSearchList—store/saved_search.go
store.SavedSearchGetByID—store/saved_search.go
store.SavedSearchCreate—store/saved_search.go
store.SavedSearchUpdate—store/saved_search.go
store.SavedSearchDelete—store/saved_search.go
store.SearchEntityHosts—store/search.go
store.SearchEntity—store/search.go
store.CountEntity—store/search.go
store.SearchAggregate—store/search.go
store.SearchFieldValues—store/search.go

AI Chat & MCP​

SpanAttributesSource
chat.llm_callmodelchat/llm_client.go
chat.model_route.llmmessage_previewchat/router.go
chat.context_prefetch—chat/prefetch.go
chat.encryption.encrypt—chat/encryption.go
chat.encryption.decrypt—chat/encryption.go
chat.encryption.dek_resolve—chat/encryption.go
chat.encryption.vault_encrypt—chat/encryption.go
chat.encryption.vault_decrypt—chat/encryption.go

Interactive Terminal (gRPC)​

SpanAttributesSource
TerminalGRPC.Sessionhostname, login, ...grpcserver/terminal.go
TerminalGRPC.JoinSessionsession_idgrpcserver/terminal.go
TerminalGRPC.PortForwarduser_idgrpcserver/tunnel.go
TerminalGRPC.ProxySSHuser_idgrpcserver/proxyssh.go

L1 Incident Agent & Alerts​

SpanAttributesSource
process.escalation.tickproxima.escalation.plannedworker/escalation_timer_worker.go
process.memory.draftmessaging.system, messaging.subject, proxima.alert_group_idworker/memory.go
process.alerts.ingestmessaging.system, messaging.subjectworker/alert.go
process.alerts.triagemessaging.system, messaging.subject, proxima.alert_group_idworker/triage.go
process.alerts.correlatemessaging.system, messaging.subjectworker/correlation.go

Fleet​

SpanAttributesSource
fleet.worker_tick—worker/fleet_update_worker.go

Service Desk & JSM​

SpanAttributesSource
api.ServiceDesk.GetTicket.SLA—api/service_desk_ticket_handler.go
api.ServiceDesk.GetTicket.Delivery—api/service_desk_ticket_handler.go
api.ServiceDesk.GetTicket.StatusHistory—api/service_desk_ticket_handler.go
jsm.add_attachment—jsmclient/client.go
jsm.proxy_download—jsmclient/client.go

Briefing​

SpanAttributesSource
briefing.Assemble—service/briefing_service.go
briefing.<source>(per-source child spans)service/briefing_service.go

OIDC​

SpanAttributesSource
auth.oidc_exchange(client span)auth/oidc.go
auth.oidc_verify(client span)auth/oidc.go

All span names follow the subsystem.operation naming convention. Attributes use the proxima. prefix for domain-specific values and OpenTelemetry semantic conventions (e.g., messaging.system) for infrastructure attributes.

note

This page lists the primary span subsystems. The backend instruments additional spans (e.g. Kubernetes sync, ClickHouse, email) and the agent emits its own spans that are forwarded to Tempo via the trace-ingest worker — see Agent Tracing. The authoritative source is always the *.Start(ctx, "...") calls in the backend and agent code.