Field TypeTypeValueAvailabilityDescription
assetAssignments    
assignments    
@id    
@ingesttimestamp    
@rawstring    
@timestamp    
@timestamp.nanos    
@timezone    
category    Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch
groupAssignments    
#category    
#repo    
#severity    
message    Message of the alert or event
orgId    Organization ID
severity    Severity of the event
subCategory    Subcategory of the event
timestamp    Timestamp in milliseconds of the event
user    User who runs the query
userAssignments    
userId    User ID