Field TypeTypeAvailabilityDescription
assetAssignments   
assignments   
@id   
@ingesttimestamp   
@rawstring   
@timestamp   
@timestamp.nanos   
@timezone   
category   Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch
groupAssignments   
#category   
#repo   
#severity   
message   Message of the alert or event
orgId   Organization ID
severity   Severity of the event
subCategory   Subcategory of the event
timestamp   Timestamp in milliseconds of the event
user   User who runs the query
userAssignments   
userId   User ID