1
_time
3
ActivityID
5
Caller_Domain
7
Caller_User_Name
9
Channel
11
Computer
13
Error_Code
15
EventCode
17
EventData_Xml
19
EventID
21
EventRecordID
23
Guid
25
Keywords
27
Level
29
Logon_ID
31
Name
33
Opcode
35
PrivilegeList
37
ProcessID
39
RecordNumber
41
SubjectDomainName
43
SubjectLogonId
45
SubjectUserName
47
SubjectUserSid
49
SystemTime
51
System_Props_Xml
53
Task
55
ThreadID
57
Version
59
action
61
app
63
date_hour
65
date_mday
67
date_minute
69
date_month
71
date_second
73
date_wday
75
date_year
77
date_zone
79
dest
81
dvc
83
dvc_nt_host
85
event_id
87
eventtype
89
host
91
id
93
index
95
linecount
97
name
99
product
101
punct
103
session_id
105
signature
107
signature_id
109
source
111
sourcetype
113
splunk_server
115
src_nt_domain
117
src_user
119
status
121
subject
123
ta_windows_action
125
tag
127
tag::action
129
tag::eventtype
131
timeendpos
133
timestartpos
135
vendor
137
vendor_product
139
not set