1
_time
3
Channel
5
Computer
7
EventChannel
9
EventCode
11
EventData_Xml
13
EventDescription
15
EventID
17
EventRecordID
19
EventType
21
Guid
23
Image
25
Keywords
27
Level
29
Name
31
Opcode
33
ProcessGuid
35
ProcessID
37
ProcessId
39
RecordID
41
RecordNumber
43
RuleName
45
SecurityID
47
SystemTime
49
System_Props_Xml
51
TargetObject
53
Task
55
ThreadID
57
TimeCreated
59
UserID
61
UtcTime
63
Version
65
action
67
date_hour
69
date_mday
71
date_minute
73
date_month
75
date_second
77
date_wday
79
date_year
81
date_zone
83
dest
85
dvc_nt_host
87
event_id
89
eventtype
91
host
93
id
95
index
97
linecount
99
object_category
101
object_path
103
process_exec
105
process_guid
107
process_id
109
process_name
111
process_path
113
punct
115
registry_hive
117
registry_key_name
119
registry_path
121
severity_id
123
signature
125
signature_id
127
source
129
sourcetype
131
splunk_server
133
status
135
tag
137
tag::eventtype
139
tag::object_category
141
timeendpos
143
timestartpos
145
user_id
147
vendor_product
149
not set