1
_time
3
ActivityID
5
AppCorrelationID
7
AttributeLDAPDisplayName
9
AttributeSyntaxOID
11
AttributeValue
13
Caller_Domain
15
Caller_User_Name
17
Channel
19
Computer
21
DSName
23
DSType
25
Error_Code
27
EventCode
29
EventData_Xml
31
EventID
33
EventRecordID
35
Guid
37
Keywords
39
Level
41
Logon_ID
43
Name
45
ObjectClass
47
ObjectDN
49
ObjectGUID
51
OpCorrelationID
53
Opcode
55
OperationType
57
ProcessID
59
RecordNumber
61
SubjectDomainName
63
SubjectLogonId
65
SubjectUserName
67
SubjectUserSid
69
SystemTime
71
System_Props_Xml
73
Task
75
ThreadID
77
Version
79
action
81
app
83
date_hour
85
date_mday
87
date_minute
89
date_month
91
date_second
93
date_wday
95
date_year
97
date_zone
99
dest
101
dvc
103
dvc_nt_host
105
event_id
107
eventtype
109
host
111
id
113
index
115
linecount
117
name
119
product
121
punct
123
session_id
125
signature
127
signature_id
129
source
131
sourcetype
133
splunk_server
135
src_nt_domain
137
src_user
139
status
141
subject
143
ta_windows_action
145
tag
147
tag::action
149
tag::eventtype
151
timeendpos
153
timestartpos
155
vendor
157
vendor_product
159
not set