1
_time
3
ActivityID
5
CallerProcessId
7
CallerProcessName
9
Caller_Domain
11
Caller_User_Name
13
Channel
15
Computer
17
Error_Code
19
EventCode
21
EventData_Xml
23
EventID
25
EventRecordID
27
Guid
29
Keywords
31
Level
33
Logon_ID
35
Name
37
Opcode
39
ProcessID
41
RecordNumber
43
SubjectDomainName
45
SubjectLogonId
47
SubjectUserName
49
SubjectUserSid
51
SystemTime
53
System_Props_Xml
55
TargetDomainName
57
TargetSid
59
TargetUserName
61
Target_Domain
63
Target_User_Name
65
Task
67
ThreadID
69
Version
71
action
73
app
75
date_hour
77
date_mday
79
date_minute
81
date_month
83
date_second
85
date_wday
87
date_year
89
date_zone
91
dest
93
dest_nt_domain
95
dvc
97
dvc_nt_host
99
event_id
101
eventtype
103
host
105
id
107
index
109
linecount
111
product
113
punct
115
session_id
117
signature_id
119
source
121
sourcetype
123
splunk_server
125
src_nt_domain
127
src_user
129
status
131
ta_windows_action
133
tag
135
tag::action
137
tag::eventtype
139
timeendpos
141
timestartpos
143
user
145
user_group
147
vendor
149
vendor_product
151
not set