1
_time
3
Channel
5
Computer
7
EventChannel
9
EventCode
11
EventData_Xml
13
EventDescription
15
EventID
17
EventRecordID
19
Guid
21
Keywords
23
Level
25
Name
27
NewThreadId
29
Opcode
31
ProcessID
33
RecordID
35
RecordNumber
37
RuleName
39
SecurityID
41
SourceImage
43
SourceProcessGuid
45
SourceProcessId
47
StartAddress
49
StartFunction
51
StartModule
53
SystemTime
55
System_Props_Xml
57
TargetImage
59
TargetProcessGuid
61
TargetProcessId
63
Task
65
ThreadID
67
TimeCreated
69
UserID
71
UtcTime
73
Version
75
action
77
date_hour
79
date_mday
81
date_minute
83
date_month
85
date_second
87
date_wday
89
date_year
91
date_zone
93
dest
95
dvc_nt_host
97
event_id
99
eventtype
101
host
103
id
105
index
107
linecount
109
os
111
parent_process_exec
113
parent_process_guid
115
parent_process_id
117
parent_process_name
119
parent_process_path
121
process_exec
123
process_guid
125
process_id
127
process_name
129
process_path
131
punct
133
signature
135
signature_id
137
source
139
sourcetype
141
splunk_server
143
src_address
145
src_function
147
src_module
149
tag
151
tag::eventtype
153
timeendpos
155
timestartpos
157
user_id
159
vendor_product
161
not set