Data Source: Windows Event Log Application 17135

Data source object for Windows Event Log Application 17135

Property Value
Source XmlWinEventLog:Application
Sourcetype XmlWinEventLog
Separator EventCode
+ Fields

            1
            CategoryString
          
            3
            Channel
          
            5
            Computer
          
            7
            Error_Code
          
            9
            EventCode
          
            11
            EventData_Xml
          
            13
            EventID
          
            15
            EventRecordID
          
            17
            Image_File_Name
          
            19
            Keywords
          
            21
            Level
          
            23
            Name
          
            25
            Opcode
          
            27
            ProcessID
          
            29
            Qualifiers
          
            31
            RecordNumber
          
            33
            RenderingInfo_Xml
          
            35
            SourceName
          
            37
            SubStatus
          
            39
            SystemTime
          
            41
            System_Props_Xml
          
            43
            Task
          
            45
            TaskCategory
          
            47
            ThreadID
          
            49
            Version
          
            51
            _bkt
          
            53
            _cd
          
            55
            _eventtype_color
          
            57
            _indextime
          
            59
            _raw
          
            61
            _serial
          
            63
            _si
          
            65
            _sourcetype
          
            67
            _subsecond
          
            69
            _time
          
            71
            action
          
            73
            category
          
            75
            date_hour
          
            77
            date_mday
          
            79
            date_minute
          
            81
            date_month
          
            83
            date_second
          
            85
            date_wday
          
            87
            date_year
          
            89
            date_zone
          
            91
            dest
          
            93
            dvc
          
            95
            dvc_nt_host
          
            97
            event_id
          
            99
            eventtype
          
            101
            host
          
            103
            id
          
            105
            index
          
            107
            linecount
          
            109
            name
          
            111
            parent_process
          
            113
            process_name
          
            115
            punct
          
            117
            result
          
            119
            service
          
            121
            service_id
          
            123
            service_name
          
            125
            severity
          
            127
            severity_id
          
            129
            signature
          
            131
            signature_id
          
            133
            source
          
            135
            sourcetype
          
            137
            splunk_server
          
            139
            splunk_server_group
          
            141
            status
          
            143
            subject
          
            145
            tag
          
            147
            tag::action
          
            149
            tag::eventtype
          
            151
            timeendpos
          
            153
            timestartpos
          
            155
            user_group_id
          
            157
            user_id
          
            159
            vendor_product
          
            161
            
          
...
not set
1<Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='MSSQLSERVER'/><EventID Qualifiers='16384'>17135</EventID><Version>0</Version><Level>4</Level><Task>2</Task><Opcode>0</Opcode><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime='2025-02-10T16:38:42.6969829Z'/><EventRecordID>16509</EventRecordID><Correlation/><Execution ProcessID='0' ThreadID='0'/><Channel>Application</Channel><Computer>ar-win-2.attackrange.local</Computer><Security/></System><EventData><Data>sp_add_sysadmin</Data><Binary>EF4200000A00000009000000610072002D00770069006E002D0032000000070000006D00610073007400650072000000</Binary></EventData></Event>

Source: GitHub | Version: 1