Protocol field name: eventlog
Versions: 1.0.0 to 4.6.0
Back to Display Filter Reference
| Field name | Description | Type | Versions |
|---|---|---|---|
| eventlog | Backupfilename | Character string | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Unknown2 | Label | 1.0.0 to 4.6.0 |
| eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Unknown0 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Unknown1 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Backupfilename | Character string | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | CbBufSize | Unsigned integer (32 bits) | 4.4.0 to 4.6.0 |
| eventlog | CbBytesNeeded | Signed integer (32 bits) | 4.4.0 to 4.6.0 |
| eventlog | DwInfoLevel | Unsigned integer (32 bits) | 4.4.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 4.4.0 to 4.6.0 |
| eventlog | LpBuffer | Unsigned integer (8 bits) | 4.4.0 to 4.6.0 |
| eventlog | CbBufSize | Unsigned integer (32 bits) | 1.0.0 to 4.2.14 |
| eventlog | CbBytesNeeded | Signed integer (32 bits) | 1.0.0 to 4.2.14 |
| eventlog | DwInfoLevel | Unsigned integer (32 bits) | 1.0.0 to 4.2.14 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.2.14 |
| eventlog | LpBuffer | Unsigned integer (8 bits) | 1.0.0 to 4.2.14 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Number | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Oldest | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Logname | Character string | 1.0.0 to 4.6.0 |
| eventlog | Unknown0 | Label | 1.0.0 to 4.6.0 |
| eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Logname | Label | 1.0.0 to 1.2.18 |
| eventlog | MajorVersion | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | MinorVersion | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | Module | Character string | 1.4.0 to 4.6.0 |
| eventlog | RegModuleName | Character string | 1.4.0 to 4.6.0 |
| eventlog | Servername | Label | 1.0.0 to 1.2.18 |
| eventlog | Unknown0 | Label | 1.0.0 to 4.6.0 |
| eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 1.2.18 |
| eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 1.2.18 |
| eventlog | Unknown0 | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Unknown1 | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Data | Unsigned integer (8 bits) | 1.0.0 to 4.6.0 |
| eventlog | Flags | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Number Of Bytes | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Offset | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Real Size | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Sent Size | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Closing Record Number | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Computer Name | Character string | 1.0.0 to 4.6.0 |
| eventlog | Data Length | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Data Offset | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Event Category | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Event Id | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Event Type | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Num Of Strings | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Raw Data | Character string | 1.0.0 to 4.6.0 |
| eventlog | Record Number | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Reserved | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Reserved Flags | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Sid Length | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Sid Offset | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Size | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Source Name | Character string | 1.0.0 to 4.6.0 |
| eventlog | Stringoffset | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Strings | Character string | 1.0.0 to 4.6.0 |
| eventlog | Time Generated | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Time Written | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.0.0 to 4.6.0 |
| eventlog | Logname | Character string | 1.0.0 to 4.6.0 |
| eventlog | Servername | Character string | 1.0.0 to 4.6.0 |
| eventlog | Unknown0 | Label | 1.0.0 to 4.6.0 |
| eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Computer Name | Character string | 1.4.0 to 4.6.0 |
| eventlog | Data Length | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | Event Category | Unsigned integer (16 bits) | 1.4.0 to 4.6.0 |
| eventlog | Event Id | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | Handle | Byte sequence | 1.4.0 to 4.6.0 |
| eventlog | Num Of Strings | Unsigned integer (16 bits) | 1.4.0 to 4.6.0 |
| eventlog | Time | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | Type | Unsigned integer (32 bits) | 1.4.0 to 4.6.0 |
| eventlog | EVENTLOG AUDIT FAILURE | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG AUDIT SUCCESS | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG ERROR TYPE | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG INFORMATION TYPE | Boolean | 1.0.0 to 4.6.0 |
| eventlog | Eventlog Success | Boolean | 1.0.0 to 2.2.1 |
| eventlog | EVENTLOG WARNING TYPE | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG BACKWARDS READ | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG FORWARDS READ | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG SEEK READ | Boolean | 1.0.0 to 4.6.0 |
| eventlog | EVENTLOG SEQUENTIAL READ | Boolean | 1.0.0 to 4.6.0 |
| eventlog | Operation | Unsigned integer (16 bits) | 1.0.0 to 4.6.0 |
| eventlog | Record | Label | 1.0.0 to 4.6.0 |
| eventlog | Computer Name | Character string | 1.0.0 to 4.6.0 |
| eventlog | Record Length | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |
| eventlog | Source Name | Character string | 1.0.0 to 4.6.0 |
| eventlog | string | Character string | 1.0.0 to 4.6.0 |
| eventlog | NT Error | Unsigned integer (32 bits) | 1.0.0 to 4.6.0 |