1
_time
3
ActorContextId
5
Actor{}.ID
7
Actor{}.Type
9
AzureActiveDirectoryEventType
11
CreationTime
13
ExtendedProperties{}.Name
15
ExtendedProperties{}.Value
17
Id
19
InterSystemsId
21
IntraSystemId
23
ModifiedProperties{}.Name
25
ModifiedProperties{}.NewValue
27
ModifiedProperties{}.OldValue
29
ObjectId
31
Operation
33
OrganizationId
35
RecordType
37
ResultStatus
39
SupportTicketId
41
TargetContextId
43
Target{}.ID
45
Target{}.Type
47
UserId
49
UserKey
51
UserType
53
Version
55
Workload
57
additionalDetails
59
app
61
authentication_service
63
command
65
date_hour
67
date_mday
69
date_minute
71
date_month
73
date_second
75
date_wday
77
date_year
79
date_zone
81
dest
83
dest_name
85
dvc
87
event_type
89
extendedAuditEventCategory
91
host
93
index
95
linecount
97
object
99
punct
101
record_type
103
signature
105
source
107
sourcetype
109
splunk_server
111
status
113
timeendpos
115
timestartpos
117
user
119
user_agent
121
user_agent_change
123
user_id
125
user_type
127
vendor_account
129
vendor_product
131
not set