category
|
text
|
category_name
|
text
|
code
|
text
|
computer
|
text
|
content
|
text
|
event.event_data.binary.value
|
text
|
event.event_data.data.name
|
text
|
event.event_data.data.value
|
text
|
event.event_data.name
|
text
|
event.system.channel.value
|
text
|
event.system.computer.value
|
text
|
event.system.correlation.activity_id
|
text
|
event.system.event_id.qualifiers
|
text
|
event.system.event_id.value
|
text
|
event.system.event_record_id.value
|
text
|
event.system.execution.process_id
|
text
|
event.system.execution.thread_id
|
text
|
event.system.keywords.value
|
text
|
event.system.level.value
|
text
|
event.system.opcode.value
|
text
|
event.system.provider.event_source_name
|
text
|
event.system.provider.guid
|
text
|
event.system.provider.name
|
text
|
event.system.security.user_id
|
text
|
event.system.task.value
|
text
|
event.system.time_created.system_time
|
text
|
event.system.version.value
|
text
|
event.user_data.add_service_id.add_service_status.value
|
text
|
event.user_data.add_service_id.device_instance_id.value
|
text
|
event.user_data.add_service_id.driver_file_name.value
|
text
|
event.user_data.add_service_id.primary_service.value
|
text
|
event.user_data.add_service_id.service_name.value
|
text
|
event.user_data.add_service_id.update_service.value
|
text
|
event.user_data.audit_events_dropped.reason.value
|
text
|
event.user_data.cbs_package_change_state.client.value
|
text
|
event.user_data.cbs_package_change_state.error_code.value
|
text
|
event.user_data.cbs_package_change_state.intended_package_state.value
|
text
|
event.user_data.cbs_package_change_state.intended_package_state_textized.value
|
text
|
event.user_data.cbs_package_change_state.package_identifier.value
|
text
|
event.user_data.cbs_package_initiate_changes.client.value
|
text
|
event.user_data.cbs_package_initiate_changes.initial_package_state.value
|
text
|
event.user_data.cbs_package_initiate_changes.intended_package_state.value
|
text
|
event.user_data.cbs_package_initiate_changes.initial_package_state_textized.value
|
text
|
event.user_data.cbs_package_initiate_changes.package_identifier.value
|
text
|
event.user_data.cbs_store_corruption_repair_finish.error_code.value
|
text
|
event.user_data.cbs_store_corruption_repair_finish.repaired.value
|
text
|
event.user_data.cbs_store_corruption_repair_finish.total_corruption.value
|
text
|
event.user_data.cbs_store_corruption_repair_start.auto_triggered.value
|
text
|
event.user_data.cbs_store_corruption_repair_start.detection_only.value
|
text
|
event.user_data.cbs_update_change_state.client.value
|
text
|
event.user_data.cbs_update_change_state.error_code.value
|
text
|
event.user_data.cbs_update_change_state.package_identifier.value
|
text
|
event.user_data.cbs_update_change_state.update_name.value
|
text
|
event.user_data.data_0x8000003f.namespace.value
|
text
|
event.user_data.data_0x8000003f.provider.value
|
text
|
event.user_data.event_data.domain_name.value
|
text
|
event.user_data.event_data.domain_name_length.value
|
text
|
event.user_data.event_data.name.value
|
text
|
event.user_data.event_data.name_length.value
|
text
|
event.user_data.event_data.transport_flags.value
|
text
|
event.user_data.event_data.transport_name.value
|
text
|
event.user_data.event_data.transport_name_length.value
|
text
|
event.user_data.event_xml.address.value
|
text
|
event.user_data.event_xml.message_name.value
|
text
|
event.user_data.event_xml.reason.value
|
text
|
event.user_data.event_xml.session.value
|
text
|
event.user_data.event_xml.session_id.value
|
text
|
event.user_data.event_xml.source.value
|
text
|
event.user_data.event_xml.target_session.value
|
text
|
event.user_data.event_xml.user.value
|
text
|
event.user_data.init_channel_publisher_enable_failure.channel_path.value
|
text
|
event.user_data.init_channel_publisher_enable_failure.error_code.value
|
text
|
event.user_data.init_channel_publisher_enable_failure.publisher_guid.value
|
text
|
event.user_data.operation_client_failure.client_machine.value
|
text
|
event.user_data.operation_client_failure.client_process_id.value
|
text
|
event.user_data.operation_client_failure.component.value
|
text
|
event.user_data.operation_client_failure.id.value
|
text
|
event.user_data.operation_client_failure.operation.value
|
text
|
event.user_data.operation_client_failure.possible_cause.value
|
text
|
event.user_data.operation_client_failure.result_code.value
|
text
|
event.user_data.operation_client_failure.user.value
|
text
|
event.user_data.operation_ess_started.namespace_name.value
|
text
|
event.user_data.operation_ess_started.possible_cause.value
|
text
|
event.user_data.operation_ess_started.processid.value
|
text
|
event.user_data.operation_ess_started.provider.value
|
text
|
event.user_data.operation_ess_started.query.value
|
text
|
event.user_data.operation_ess_started.queryid.value
|
text
|
event.user_data.operation_ess_started.user.value
|
text
|
event.user_data.operation_essto_consumer_binding.consumer.value
|
text
|
event.user_data.operation_essto_consumer_binding.ess.value
|
text
|
event.user_data.operation_essto_consumer_binding.namespace.value
|
text
|
event.user_data.operation_essto_consumer_binding.possible_cause.value
|
text
|
event.user_data.operation_started_operational.code.value
|
text
|
event.user_data.operation_started_operational.host_process.value
|
text
|
event.user_data.operation_started_operational.process_id.value
|
text
|
event.user_data.operation_started_operational.provider_name.value
|
text
|
event.user_data.operation_started_operational.provider_path.value
|
text
|
event.user_data.operation_temporary_ess_started.client_machine.value
|
text
|
event.user_data.operation_temporary_ess_started.namespace_name.value
|
text
|
event.user_data.operation_temporary_ess_started.possible_cause.value
|
text
|
event.user_data.operation_temporary_ess_started.processid.value
|
text
|
event.user_data.operation_temporary_ess_started.query.value
|
text
|
event.user_data.operation_temporary_ess_started.user.value
|
text
|
event.user_data.rm_restart_event.applications.application.value
|
text
|
event.user_data.rm_restart_event.n_applications.value
|
text
|
event.user_data.rm_restart_event.reboot_reasons.value
|
text
|
event.user_data.rm_restart_event.rm_session_id.value
|
text
|
event.user_data.rm_session_event.rm_session_id.value
|
text
|
event.user_data.rm_session_event.utcstart_time.value
|
date and time
|
event.user_data.rm_unsupported_restart_event.app_type.value
|
text
|
event.user_data.rm_unsupported_restart_event.app_version.value
|
text
|
event.user_data.rm_unsupported_restart_event.display_name.value
|
text
|
event.user_data.rm_unsupported_restart_event.full_path.value
|
text
|
event.user_data.rm_unsupported_restart_event.pid.value
|
text
|
event.user_data.rm_unsupported_restart_event.reason.value
|
text
|
event.user_data.rm_unsupported_restart_event.rm_session_id.value
|
text
|
event.user_data.rm_unsupported_restart_event.status.value
|
text
|
event.user_data.rm_unsupported_restart_event.tssession_id.value
|
text
|
event.user_data.veto_app_event.app_name.value
|
text
|
event.user_data.veto_app_event.response_time.value
|
text
|
id
|
text
|
index
|
text
|
instance_id
|
text
|
keywords
|
text
|
logfile
|
text
|
msg
|
text
|
opcode
|
text
|
pid
|
text
|
source
|
text
|
task
|
text
|
tid
|
text
|
time
|
date and time
|
type
|
text
|
user
|
text
|