1
_time
3
Channel
5
Computer
7
Contents
9
CreationUtcTime
11
EventChannel
13
EventCode
15
EventData_Xml
17
EventDescription
19
EventID
21
EventRecordID
23
Guid
25
Hash
27
IMPHASH
29
Image
31
Keywords
33
Level
35
MD5
37
Name
39
Opcode
41
ProcessGuid
43
ProcessID
45
ProcessId
47
RecordID
49
RecordNumber
51
RuleName
53
SHA256
55
SecurityID
57
SystemTime
59
System_Props_Xml
61
TargetFilename
63
Task
65
ThreadID
67
TimeCreated
69
UserID
71
UtcTime
73
Version
75
action
77
date_hour
79
date_mday
81
date_minute
83
date_month
85
date_second
87
date_wday
89
date_year
91
date_zone
93
dest
95
dvc_nt_host
97
event_id
99
eventtype
101
file_create_time
103
file_hash
105
file_name
107
file_path
109
host
111
id
113
index
115
linecount
117
os
119
process_exec
121
process_guid
123
process_id
125
process_name
127
process_path
129
punct
131
signature
133
signature_id
135
source
137
sourcetype
139
splunk_server
141
tag
143
tag::eventtype
145
timeendpos
147
timestartpos
149
user_id
151
vendor_product
153
not set