Part 2 of 3:
"event_data": {
"properties": {
"AdapterName": {
"type": "keyword"
},
"AdapterSuffixName": {
"type": "keyword"
},
"Address": {
"type": "keyword"
},
"AddressLength": {
"type": "keyword"
},
"AuditPolicyChanges": {
"type": "keyword"
},
"Binary": {
"type": "keyword"
},
"CategoryId": {
"type": "keyword"
},
"ClientName": {
"type": "keyword"
},
"Context": {
"type": "keyword"
},
"DirtyPages": {
"type": "keyword"
},
"DnsServerList": {
"type": "keyword"
},
"ErrorCode": {
"type": "keyword"
},
"HiveName": {
"type": "keyword"
},
"HiveNameLength": {
"type": "keyword"
},
"HostName": {
"type": "keyword"
},
"IP_Name": {
"type": "keyword"
},
"Ipaddress": {
"type": "keyword"
},
"KeysUpdated": {
"type": "keyword"
},
"Name": {
"type": "keyword"
},
"QueryName": {
"type": "keyword"
},
"ReservationName": {
"type": "keyword"
},
"Sent UpdateServer": {
"type": "keyword"
},
"ServerURL": {
"type": "keyword"
},
"SubcategoryGuid": {
"type": "keyword"
},
"SubcategoryId": {
"type": "keyword"
},
"SubjectDomainName": {
"type": "keyword"
},
"SubjectLogonId": {
"type": "keyword"
},
"SubjectUserName": {
"type": "keyword"
},
"SubjectUserSid": {
"type": "keyword"
},
"TSId": {
"type": "keyword"
},
"Type": {
"type": "keyword"
},
"UserSid": {
"type": "keyword"
},
"param1": {
"type": "keyword"
},
"param10": {
"type": "keyword"
},
"param11": {
"type": "keyword"
},
"param12": {
"type": "keyword"
},
"param2": {
"type": "keyword"
},
"param3": {
"type": "keyword"
},
"param4": {
"type": "keyword"
},
"param5": {
"type": "keyword"
},
"param6": {
"type": "keyword"
},
"param7": {
"type": "keyword"
},
"param8": {
"type": "keyword"
},
"param9": {
"type": "keyword"
}
}
},
"event_id": {
"type": "long"
},
"fields": {
"type": "object"
},
"keywords": {
"type": "keyword",
"ignore_above": 1024
},
"kubernetes": {
"properties": {
"annotations": {
"type": "object"
},
"container": {
"properties": {
"image": {
"type": "keyword",
"ignore_above": 1024
},
"name": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"labels": {
"type": "object"
},
"namespace": {
"type": "keyword",
"ignore_above": 1024
},
"pod": {
"properties": {
"name": {
"type": "keyword",
"ignore_above": 1024
}
}
}
}
},
"level": {
"type": "keyword",
"ignore_above": 1024
},
"log_name": {
"type": "keyword",
"ignore_above": 1024
},
"message": {
"type": "text",
"norms": false
},
"message_error": {
"type": "keyword",
"ignore_above": 1024
},
"meta": {
"properties": {
"cloud": {
"properties": {
"availability_zone": {
"type": "keyword",
"ignore_above": 1024
},
"instance_id": {
"type": "keyword",
"ignore_above": 1024
},
"instance_name": {
"type": "keyword",
"ignore_above": 1024
},
"machine_type": {
"type": "keyword",
"ignore_above": 1024
},
"project_id": {
"type": "keyword",
"ignore_above": 1024
},
"provider": {
"type": "keyword",
"ignore_above": 1024
},
"region": {
"type": "keyword",
"ignore_above": 1024
}
}
}
}
},
"opcode": {
"type": "keyword",
"ignore_above": 1024
},
"process_id": {
"type": "long"
},
"provider_guid": {
"type": "keyword",
"ignore_above": 1024
},
"record_number": {
"type": "keyword",
"ignore_above": 1024
},
"related_activity_id": {
"type": "keyword",
"ignore_above": 1024
},
"source_name": {
"type": "keyword",
"ignore_above": 1024
},
"tags": {
"type": "keyword",
"ignore_above": 1024
},
"task": {
"type": "keyword",
"ignore_above": 1024
},
"thread_id": {
"type": "long"
},
"type": {
"type": "keyword",
"ignore_above": 1024
},
"user": {
"properties": {
"domain": {
"type": "keyword",
"ignore_above": 1024
},
"identifier": {
"type": "keyword",
"ignore_above": 1024
},
"name": {
"type": "keyword",
"ignore_above": 1024
},
"type": {
"type": "keyword",
"ignore_above": 1024
}
}
},
"user_data": {
"type": "object"
},
"version": {
"type": "long"
},
"xml": {
"type": "text",
"norms": false
}
}
},