1
_time
3
ActivityID
5
Attributes
7
Channel
9
Computer
11
Disposition
13
Error_Code
15
EventCode
17
EventData_Xml
19
EventID
21
EventRecordID
23
Guid
25
Keywords
27
Level
29
Name
31
Opcode
33
ProcessID
35
RecordNumber
37
RequestId
39
Requester
41
Subject
43
SubjectKeyIdentifier
45
SystemTime
47
System_Props_Xml
49
Task
51
ThreadID
53
Version
55
action
57
app
59
date_hour
61
date_mday
63
date_minute
65
date_month
67
date_second
69
date_wday
71
date_year
73
date_zone
75
dest
77
dvc
79
dvc_nt_host
81
event_id
83
eventtype
85
host
87
id
89
index
91
linecount
93
name
95
product
97
punct
99
signature
101
signature_id
103
source
105
sourcetype
107
splunk_server
109
status
111
subject
113
ta_windows_action
115
tag
117
tag::action
119
tag::eventtype
121
timeendpos
123
timestartpos
125
vendor
127
vendor_product
129
not set