1
_time
3
ActorContextId
5
Actor{}.ID
7
Actor{}.Type
9
AzureActiveDirectoryEventType
11
CreationTime
13
ExtendedProperties{}.Name
15
ExtendedProperties{}.Value
17
Id
19
InterSystemsId
21
IntraSystemId
23
ModifiedProperties{}.Name
25
ModifiedProperties{}.NewValue
27
ModifiedProperties{}.OldValue
29
ObjectId
31
Operation
33
OrganizationId
35
RecordType
37
ResultStatus
39
SupportTicketId
41
TargetContextId
43
Target{}.ID
45
Target{}.Type
47
UserId
49
UserKey
51
UserType
53
Version
55
Workload
57
action
59
additionalDetails
61
app
63
authentication_service
65
change_type
67
command
69
dataset_name
71
date_hour
73
date_mday
75
date_minute
77
date_month
79
date_second
81
date_wday
83
date_year
85
date_zone
87
dest
89
dest_name
91
dvc
93
event_type
95
eventtype
97
extendedAuditEventCategory
99
host
101
index
103
linecount
105
object_attrs
107
object_category
109
punct
111
record_type
113
signature
115
source
117
sourcetype
119
splunk_server
121
src_user
123
status
125
tag
127
tag::eventtype
129
timeendpos
131
timestartpos
133
user
135
user_agent
137
user_agent_change
139
user_id
141
user_type
143
vendor_account
145
vendor_product
147
not set