Event storage structure
Overview
You can check the structure in which sent event logs are stored in BigQuery, the detailed structure of the attributes JSON field, and how logs that violate the transmission rules are isolated.
Table structure
Sent event logs are stored in the t_raw_event_log table of each company's BigQuery dataset.
Table column structure
Storage location
| Item | Format |
|---|---|
| Table | t_raw_event_log |
| Partitioning | Daily partitions based on dateTime |
Column definitions
| Column name | Data type | Description | Example |
|---|---|---|---|
userId | STRING | Value sent as the required attribute userId | 100001 |
identifierProvider | STRING | Value sent as the required attribute identifierProvider | hive |
deviceId | STRING | Value sent as the required attribute deviceId | 100000 |
appId | STRING | Value sent as the required attribute appId | "com.com2us.game.ios" |
appIdGroup | STRING | Value converted from the required attribute appId to the app name in Project Settings > App ID | com.com2us.game |
dateTime | TIMESTAMP | Value of the required attribute eventTime converted to UTC | 2026-07-20T05:01:01Z |
eventName | STRING | Value sent as the required attribute eventName | asset_drop |
checksum | STRING | Hash value generated for each event | HW2FTEB56TEEWER |
bigqueryRegistTimestamp | TIMESTAMP | UTC time when the event was stored in BigQuery | 2026-07-20T05:02:01Z |
attributes | JSON | JSON field that stores custom attributes and automatically collected attributes | See below |
Example of attributes
{
"hiveAttributes": {
"dataSource": "custom_server",
"geoIpCountry": "KR"
},
"eventAttributes": {
"eventTime": "2026-07-20T14:01:01+09:00",
"level": 10,
"character_name": "AA",
"stage_id": "stage_101"
}
}
Table structure notes & tips
- The same event can be stored more than once because of resending or other causes, so we recommend that you also use a deduplication query based on
checksumwhen you query the data. - Event logs that violate the transmission rules are stored in the rescue table, not in this table. For details, see Data isolation.
attributes details
Note
The attributes column is of JSON type and is divided into two areas: hiveAttributes and eventAttributes.
Example of attributes
{
"hiveAttributes": {
"dataSource": "custom_server",
"geoIpCountry": "KR"
},
"eventAttributes": {
"eventTime": "2026-07-20T14:01:01+09:00",
"level": 10,
"character_name": "AA"
}
}
hiveAttributes
This is the area that the pipeline processes and stores automatically.
| Attribute name | Data type | Description | Example |
|---|---|---|---|
dataSource | STRING | Sender of the event log. See the dataSource details below | custom_server |
geoIpCountry | STRING | Country code that the pipeline determined based on the IP (ISO 3166 alpha-2) | KR |
dataSource details
dataSource indicates the sender of the event log, and one of the following values is set automatically.
| Value | Description |
|---|---|
airbridge | Events collected through Airbridge |
appsflyer | Events collected through Appsflyer |
adjust | Events collected through Adjust |
singular | Events collected through Singular |
hive_server | Events collected automatically through Hive authentication, billing, and so on |
hive_sdk | Events, such as funnels, that the Hive SDK collects automatically |
custom_server | Custom events that the customer sends from a server |
custom_sdk | Custom events that the customer sends through the event log sending feature of the Hive Axyl SDK |
custom_sdk_mig | Custom events that the customer sends to the legacy version of Analytics through the event log sending feature of the Hive SDK |
custom_server_mig | Custom events that the customer sends from a server to the legacy version of Analytics |
custom_except | Events sent with eventAttribute and hiveAttribute generated as an exceptional case during event conversion |
eventAttributes
This is the area that stores the attributes you sent and the attributes the SDK collected automatically.
| Attribute name | Data type | Description |
|---|---|---|
eventTime | STRING | Original eventTime value sent as a required attribute |
| (custom attributes) | Number/text | Custom attributes that you sent directly |
| (automatically collected attributes) | Varies by attribute | Client information that the SDK collected automatically (when sent from the client) |
attributes notes & tips
hiveAttributesis not an area where the developer sets values directly; the pipeline fills it automatically. Values other thandataSourceandgeoIpCountryare not stored.- Custom attributes and attributes that the SDK collects automatically are both stored together in
eventAttributes. When you query them, you must distinguish them by attribute name. - You can use the
dataSourcevalue to query event logs separately by transmission path (such as SDK or server).
Data isolation
Warning
Event logs that do not follow the transmission rules are not stored in the normal table (t_raw_event_log). Instead, they are stored separately in the isolation table (t_raw_event_log_rescue). Because the isolation table also keeps the original JSON, you can identify the cause of the isolation, fix it, and resend the event log.
Isolation reasons
| Error reason | Description | How to handle |
|---|---|---|
| Missing required attribute | Any of the seven required attributes (userId, identifierProvider, deviceId, appId, eventTime, eventName, appIdGroup) is missing or empty | Resend with the missing required attributes included |
| Reserved word used | attributes, eventAttributes, or hiveAttributes is used as an attribute name (case-insensitive) | Change the attribute name to a different name |
| Disallowed attribute value | The attribute value is a JSON object ({}) or a JSON array ([]) | Change the attribute value to a string or a number |
| eventTime format error | eventTime is not in RFC 3339 format or cannot be parsed | Change it to RFC 3339 format (including the time zone) |
| eventTime out of range | eventTime is outside the range of 31 days in the past to 31 days in the future relative to the current time | Check the eventTime value and change it to fall within the valid range |
| JSON parsing failure | The sent message is not in valid JSON format | Validate the JSON format and resend |
Isolation table structure
Isolated event logs are stored in the t_raw_event_log_rescue table with the following structure.
| Column name | Data type | Description |
|---|---|---|
userId | STRING | userId as sent (when it can be parsed) |
identifierProvider | STRING | identifierProvider as sent |
deviceId | STRING | deviceId as sent |
appIdGroup | STRING | appIdGroup as sent |
dateTime | STRING | Original eventTime value as sent (stored as a string as is, not TIMESTAMP) |
eventName | STRING | eventName as sent |
bigqueryRegistTimestamp | TIMESTAMP | Time when the log was stored in BigQuery |
checksum | STRING | Hash value |
rawData | STRING | Entire original JSON as sent |
errorReason | STRING | Isolation reason code |
errorStackTrace | STRING | Isolation details (such as missing field names) |
Learn more
- Send event attributes — Detailed rules for required, automatically collected, and custom attributes
- Send event logs — How to send through Hive Axyl, Fluentd, and HTTP