1
_time
3
Channel
5
Computer
7
EventChannel
9
EventCode
11
EventData_Xml
13
EventDescription
15
EventID
17
EventRecordID
19
EventType
21
Guid
23
Image
25
Keywords
27
Level
29
Name
31
Opcode
33
PipeName
35
ProcessGuid
37
ProcessID
39
ProcessId
41
RecordID
43
RecordNumber
45
RuleName
47
SecurityID
49
SystemTime
51
System_Props_Xml
53
Task
55
ThreadID
57
TimeCreated
59
UserID
61
UtcTime
63
Version
65
action
67
date_hour
69
date_mday
71
date_minute
73
date_month
75
date_second
77
date_wday
79
date_year
81
date_zone
83
dest
85
dvc_nt_host
87
event_id
89
eventtype
91
host
93
id
95
index
97
linecount
99
os
101
pipe_name
103
process_exec
105
process_guid
107
process_id
109
process_name
111
process_path
113
punct
115
severity_id
117
signature
119
signature_id
121
source
123
sourcetype
125
splunk_server
127
tag
129
tag::eventtype
131
timeendpos
133
timestartpos
135
user_id
137
vendor_product
139
not set