1
_time
3
action
5
app
7
awsRegion
9
aws_account_id
11
change_type
13
command
15
date_hour
17
date_mday
19
date_minute
21
date_month
23
date_second
25
date_wday
27
date_year
29
date_zone
31
direction
33
dvc
35
errorCode
37
eventCategory
39
eventID
41
eventName
43
eventSource
45
eventTime
47
eventType
49
eventVersion
51
eventtype
53
host
55
index
57
linecount
59
managementEvent
61
msg
63
object_category
65
product
67
protocol
69
protocol_code
71
punct
73
readOnly
75
recipientAccountId
77
region
79
requestID
81
responseElements.requestId
83
signature
85
source
87
sourceIPAddress
89
sourcetype
91
splunk_server
93
src
95
src_ip
97
src_ip_range
99
start_time
101
status
103
tag
105
tag::eventtype
107
timeendpos
109
timestartpos
111
user
113
userAgent
115
userIdentity.accessKeyId
117
userIdentity.accountId
119
userIdentity.arn
121
userIdentity.principalId
123
userIdentity.sessionContext.attributes.creationDate
125
userIdentity.sessionContext.attributes.mfaAuthenticated
127
userIdentity.sessionContext.sessionIssuer.accountId
129
userIdentity.sessionContext.sessionIssuer.arn
131
userIdentity.sessionContext.sessionIssuer.principalId
133
userIdentity.sessionContext.sessionIssuer.type
135
userIdentity.sessionContext.sessionIssuer.userName
137
userIdentity.type
139
userName
141
user_access_key
143
user_agent
145
user_arn
147
user_group_id
149
user_id
151
user_name
153
user_type
155
vendor
157
vendor_account
159
vendor_product
161
vendor_region
163
not set