1
_time
3
Level
5
callerIpAddress
7
category
9
correlationId
11
date_hour
13
date_mday
15
date_minute
17
date_month
19
date_second
21
date_wday
23
date_year
25
date_zone
27
durationMs
29
host
31
index
33
linecount
35
operationName
37
operationVersion
39
properties.activityDateTime
41
properties.activityDisplayName
43
properties.additionalDetails{}.key
45
properties.additionalDetails{}.value
47
properties.category
49
properties.correlationId
51
properties.id
53
properties.initiatedBy.user.displayName
55
properties.initiatedBy.user.id
57
properties.initiatedBy.user.ipAddress
59
properties.initiatedBy.user.userPrincipalName
61
properties.loggedByService
63
properties.operationType
65
properties.result
67
properties.resultReason
69
properties.targetResources{}.displayName
71
properties.targetResources{}.id
73
properties.targetResources{}.modifiedProperties{}.displayName
75
properties.targetResources{}.modifiedProperties{}.newValue
77
properties.targetResources{}.modifiedProperties{}.oldValue
79
properties.targetResources{}.type
81
properties.userAgent
83
punct
85
resourceId
87
resultSignature
89
source
91
sourcetype
93
splunk_server
95
tenantId
97
time
99
timeendpos
101
timestartpos
103
not set