Available fields depend on the source record and can include address, network, provider, organization, location, hostname, or related context. Store the raw response, query, and returned timestamps before normalizing fields into a SIEM or case-management schema.Do not implement a risk score by counting whichever boolean or location fields happen to be present. Define explicit evidence and event context for each investigation.