Analytics data feed
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
This feature is only available for Knox Guard Edition customers.
The Analytics data feed policy allows you to retrieve data for a large number of devices, without having to directly call the Knox Guard server using the Knox Guard API. This allows you to consistently receive large amounts of data, without having to worry about timeouts or system stability.
While you must have Knox Guard Edition devices to use this feature, analytics data is available for all devices in your tenant.
Prerequisites
To use this feature, you must have:
- Knox Guard Edition devices.
- Access to the Knox API Portal. You can apply for access to the Knox API service by contacting your Samsung representative, or by creating a support ticket.
- For sub admins, the appropriate role permissions:
- Analytics Data Feed
- Allow access to Knox Cloud APIs portal
How to retrieve data using the Analytics data feed
Setting up your analytics data feed requires a few key steps:
- Generate your Knox Guard client identifier and key pair.
- Configure your analytics data feed settings on the Knox Guard console.
- Generate your SFTP access token.
- Retrieve data using an SFTP call.
- Decrypt the downloaded files.
Generate your Knox Guard client identifier and key pair
Knox Guard uses Knox Cloud Authentication, our legacy authentication scheme. Before you can retrieve or decrypt analytics data, you’ll need to generate your client identifier and key pair from the Knox API Portal. This is the same method you use to generate your REST API key for the Knox Guard API, with a few small differences.
For more information on how to generate these values, see the Knox Guard developer guide.
Configure your Analytics data feed settings
Next, define the data you’d like to retrieve by configuring your data feed settings on the Knox Guard console:
-
Navigate to the Policies page.
-
Under KNOX GUARD EDITION, click ANALYTICS DATA FEED. The Analytics data feed page opens.
-
Enter a Configuration name.
-
Review the Data collection frequency field. Data is available every 12 hours, and reports are ready for download at UTC 00:00 and 12:00.
Your first report is ready for download at UTC 00:00 or 12:00, 24 hours after you enable this policy.
-
In the IP range allowlist field, enter the IP address or a range of IP addresses where you’ll download the data from. IPv4 addresses and CIDR ranges are accepted.
-
Select a Public key to encrypt the configuration file with. This is the public key you previously generated in step 1.
-
Review the Data category field. You can only receive device list data.
-
Click SAVE.
Once you save your configuration, a success notification containing SFTP Server IP and SFTP Port information displays on the Knox Guard console. Save this — you’ll need these details to connect to the SFTP server later.
It’ll take roughly 24 hours before the first data report is ready for retrieval. After 24 hours, new data is available at the intervals configured using the policy, and is stored for 15 days.
Retrieve and decrypt data
Once you set your data feed configuration settings, it’ll take roughly 24 hours before the first data report is ready for retrieval. After 24 hours, new data is available at the intervals configured using the policy, and is stored for 15 days.
You can then retrieve these reports using an SFTP call. Specifically, you’ll need to:
- Generate your SFTP access token.
- Retrieve the data using an SFTP call.
- Decrypt the downloaded files.
The Knox Guard developer guide walks you through each of these steps while also providing sample code and additional tips where necessary. To learn more, see the Set up analytics data feed tutorial.
Types of data you can retrieve
Currently, the analytics data feed policy supports the retrieval of device list data. This contains all the information available on the Knox Guard device table, and through the Get device info endpoint of the Knox Guard API.
The following table describes each field returned in the device list CSV file.
| Field | Type | Description |
|---|---|---|
objectId |
string | The Unique ID generated by Knox Guard when the device is registered. |
deviceUid |
string | IMEI or serial number used to uniquely identify a device. |
approveId |
string | The billing approval ID used by a financial institution’s unique billing system to approve a loan payment. |
approveComment |
string | Comment specified when the device was accepted into Knox Guard. |
createDate |
integer | Datetime the device was created, in Unix timestamp format. |
modifiedDate |
integer | Datetime the device was last modified, in Unix timestamp format. |
firstEnrolled |
integer | Datetime Knox Guard first activated on the device, in Unix timestamp format. Only returned for devices that have already activated Knox Guard. |
status |
string | The device’s current status. |
isDeviceSupportHotp |
boolean | Whether the device supports HMAC-based one time password (HOTP). |
isOfflineLocked |
boolean | Whether the device is locked by the Offline device lock. |
isDeviceOffline |
boolean | Whether the device is offline and not connected to a network. Offline devices can’t receive policies from Knox Guard. |
simControlEnabled |
boolean | Whether SIM control settings are configured for the device. Displays only to tenants or users with SIM control permissions. |
simControlApplied |
boolean | Whether the SIM control policy is applied to the device. Displays only to tenants or users with SIM control permissions. |
simControlPolicyId |
string | ID of the SIM control policy assigned to the device. Only returned if SIM control settings are configured for the device. |
lastSeen |
integer | Datetime the device was last connected to the Knox Guard server, in Unix timestamp format. Displays only to tenants or users with last seen permissions. |
relockTimestamp |
integer | Datetime the relock timestamp is configured to trigger on the device, in Unix timestamp format. Displays only to PAYG tenants. |
appliedRelockTimestamp |
integer | Relock timestamp currently applied to the device, in Unix timestamp format. When this time is reached, the device locks and displays a customized message. Displays only to PAYG tenants. |
latestRelockApplied |
boolean | Whether the latest configured relock timestamp is applied to the device. Displays only to PAYG tenants. |
autoLockTarget |
boolean | Whether auto lock is enabled for the device. |
isRelockReminderTarget |
boolean | Whether relock reminders are configured for the device. Displays only to tenants or users with relock reminder permissions. |
isRelockReminderApplied |
boolean | Whether relock reminders are turned on for the device. Displays only to tenants or users with relock reminder permissions. |
isFactoryResetBlockTarget |
boolean | Whether the device is configured to block factory resets. Displays only to tenants or users with the Block or unblock factory reset permission. |
isFactoryResetBlockApplied |
boolean | Whether factory reset is blocked on the device. Displays only to tenants or users with the Block or unblock factory reset permission. |
isOfflineLockTarget |
boolean | Whether the Offline device lock policy is configured for the device. |
isOfflineLockApplied |
boolean | Whether the Offline device lock policy is applied to the device. |
isEnrollmentNoticeTarget |
boolean | Whether the enrollment notice policy is enabled on the device. |
isFunctionRestrictionsTarget |
boolean | Whether function restrictions are configured for the device. Displays only to tenants with a Knox Guard Advanced license. |
isFunctionRestrictionsApplied |
boolean | Whether function restrictions are applied to the device. Displays only to tenants with a Knox Guard Advanced license. |
isForceAutoDownloadTarget |
boolean | Whether the Firmware auto download over Wi-Fi policy is configured for the device. Displays only to tenants or users with the Firmware auto download over Wi-Fi permission. |
isForceAutoDownloadApplied |
boolean | Whether the Firmware auto download over Wi-Fi policy is applied to the device. Displays only to tenants or users with the Firmware auto download over Wi-Fi permission. |
hsModeApplied |
boolean | Whether Hardened Security mode is applied to the device. Displays only to tenants with the Device Financing domain. |
isWallpaperRestrictionsTarget |
boolean | Whether wallpaper restrictions are configured for the device. Displays only to tenants or users with a Knox Guard Advanced license. |
isWallpaperRestrictionsApplied |
boolean | Whether wallpaper restrictions are applied to the device. Displays only to tenants or users with a Knox Guard Advanced license. |
isOutgoingCallRestrictionsTarget |
boolean | Whether the customer has enabled outgoing call controls on the device. Displays only to tenants with a Knox Guard Advanced license. |
isOutgoingCallRestrictionsApplied |
boolean | Whether outgoing call controls are applied to the device. Displays only to tenants with a Knox Guard Advanced license. |
outgoingCallRestrictions |
object | If outgoing call controls are configured for the device, returns the configured settings. Displays only to tenants with a Knox Guard Advanced license. |
outgoingCallRestrictions > allowList |
array of strings | Array of strings containing the phone numbers on the allowlist currently applied to the device. Maximum 10 items. |
outgoingCallRestrictions > message |
string | Notification message displayed on devices with outgoing call restrictions. |
outgoingCallRestrictions > alwaysShow |
boolean | Whether the notification message is persistent or dismissible. If set to true, the message permanently displays in the device’s notification panel. |
outgoingCallRestrictions > showOnReboot |
boolean | Whether the notification message displays when the device reboots. |
isKge |
boolean | Whether the device is classified as a Knox Guard Edition device. Displays only to tenants or users with the Knox Guard Edition permission. |
fullModel |
string | Full device SKU information. |
offlineLock |
object | If the Offline device lock policy is enabled for the device, returns details about the configured settings. |
offlineLock > warningMessage |
string | The warning message that displays before the device locks. This is a one-time, full screen notification. |
offlineLock > warningTime |
integer | Determines when warningMessage displays on devices, defined as the number of days before the device locks. For example, if set to 5, the warning message displays on the device 5 days before it’s scheduled to lock. |
offlineLock > lockMessage |
string | The message that displays when the device is locked by the Offline device lock policy. |
offlineLock > lockTime |
integer | If a device hasn’t connected to a network within the number of days set using lockTime, it locks. |
offlineLock > emailAddress |
string | Email address that displays on the lock screen so device users know who to contact to unlock their device. You must provide either an emailAddress or phoneNumber. |
offlineLock > phoneNumber |
string | Phone number that displays on the lock screen so device users know who to contact to unlock their device. |
enrollmentNotice |
object | If the enrollment notice policy is enabled for the device, returns details about the configured settings. |
enrollmentNotice > enable |
boolean | Whether enrollment notices display after Knox Guard has completed activation on the device. |
enrollmentNotice > message |
string | The message that displays when enrollment notices are enabled on the device. If rebootNotice is set to true, also displays when the device reboots. |
enrollmentNotice > phoneNumber |
string | Phone number that displays in the enrollment notice. If rebootNotice is set to true, also displays when the device reboots. |
enrollmentNotice > alwaysShow |
boolean | Whether the enrollment notice is permanent or dismissible. If set to true, the enrollment notice permanently displays. |
enrollmentNotice > rebootNotice |
object | Reboot notice settings configured for the device. |
enrollmentNotice > rebootNotice > enable |
boolean | Whether the enrollment notice displays when the device reboots. |
enrollmentNotice > simCardNotice |
object | SIM card change notification settings configured for the device. |
enrollmentNotice > simCardNotice > enable |
boolean | Whether messages for SIM card change events are enabled. |
enrollmentNotice > simCardNotice > message |
string | The message that displays when a SIM card is changed. |
enrollmentNotice > simCardNotice > phoneNumber |
string | Phone number that displays in the SIM card change message. |
customerApp |
object | If any apps are installed using the application installation policy, returns details about the app. |
customerApp > appName |
string | The name of the app. |
customerApp > versionCode |
integer | The file’s version in integer format. |
customerApp > versionName |
string | The file’s version in string format. |
customerApp > firstInstallTime |
integer | The datetime the file was first installed, in Unix timestamp format. |
customerApp > packageName |
string | The file’s package name. |
customerApp > lastUpdateTime |
integer | The datetime the app was last updated, in Unix timestamp format. |
customerAppList |
array of objects | If any apps are installed using the application installation policy, returns an array containing details about the installed apps. |
languageSettings |
object | The language used by the device’s operating system. |
languageSettings > language |
string | The language currently used by the device. |
languageSettings > country |
string | The country variant of the language used by the device. |
agentVersion |
string | The version of the Knox Guard agent installed on the device. |
imei |
string | The device’s IMEI number. |
imei2 |
string | On dual SIM devices, the device’s second IMEI number. |
serial |
string | The device’s serial number. |
model |
string | The device’s model. |
androidVersion |
string | The device’s Android operating system version. |
isSimControlLocked |
boolean | Whether the device is locked by the SIM control policy. |
isAppBlockTarget |
boolean | Whether the device is blocked from installing specific apps. Displays only to tenants with a Knox Guard Advanced license. |
blockedAppList |
array of objects | An array containing the list of apps blocked from the device. Displays only to tenants with a Knox Guard Advanced license. |
blockedAppList > packageName |
string | The package name of the blocked app. |
isAppAllowTarget |
boolean | Whether the device is restricted to using only specific apps. Displays only to tenants with a Knox Guard Advanced license. |
allowedAppList |
array of objects | If an app allowlist is applied to the device, returns an array listing the apps the device can access. Displays only to tenants with a Knox Guard Advanced license. |
allowedAppList > packageName |
string | Package name of the allowed application. |
appAccessNotification |
object | Notification settings configured for devices with app access controls. |
appAccessNotification > enable |
boolean | Whether a notification message displays on devices with app access controls. |
appAccessNotification > warningMessage |
string | The notification message that displays on devices with app access controls. |
appAccessNotification > alwaysShow |
boolean | Whether the notification message is persistent or dismissible. If set to true, the message permanently displays in the device’s notification panel. |
appAccessNotification > showOnReboot |
boolean | Whether the notification message displays when the device reboots. |
licenseExpiryDate |
integer | The datetime on which the device’s assigned Knox Guard license expires, in Unix timestamp format. |
firmwareVersion |
string | The device’s firmware or binary version. |
latestFirmwareVersion |
string | The latest firmware or binary version available for the device. |
appliedFunctionRestrictions |
object | Function restrictions applied on the device. |
appliedFunctionRestrictions > denyCameraAccess |
boolean | Whether camera access is blocked on the device. |
appliedFunctionRestrictions > degradeMemoryPerformance |
string | Whether memory performance is degraded on the device. Can be either NONE, WEAK, STRONG, or null. |
Cancel analytics data collection
If you no longer need to collect data, you can disable this policy at any time.
To cancel data collection, open the Analytics data feed policy page, then click CANCEL DATA COLLECTION at the bottom of the page.
Is this page helpful?
Thank you for your feedback!