Display Filter Reference: Event Logger
Protocol field name: eventlog
Versions: 1.0.0 to 4.4.2
Back to Display Filter Reference
Field name | Description | Type | Versions |
---|---|---|---|
eventlog | Backupfilename | Character string | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Unknown2 | Label | 1.0.0 to 4.4.2 |
eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Unknown0 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Unknown1 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Backupfilename | Character string | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | CbBufSize | Unsigned integer (32 bits) | 4.4.0 to 4.4.2 |
eventlog | CbBytesNeeded | Signed integer (32 bits) | 4.4.0 to 4.4.2 |
eventlog | DwInfoLevel | Unsigned integer (32 bits) | 4.4.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 4.4.0 to 4.4.2 |
eventlog | LpBuffer | Unsigned integer (8 bits) | 4.4.0 to 4.4.2 |
eventlog | CbBufSize | Unsigned integer (32 bits) | 1.0.0 to 4.2.9 |
eventlog | CbBytesNeeded | Signed integer (32 bits) | 1.0.0 to 4.2.9 |
eventlog | DwInfoLevel | Unsigned integer (32 bits) | 1.0.0 to 4.2.9 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.2.9 |
eventlog | LpBuffer | Unsigned integer (8 bits) | 1.0.0 to 4.2.9 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Number | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Oldest | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Logname | Character string | 1.0.0 to 4.4.2 |
eventlog | Unknown0 | Label | 1.0.0 to 4.4.2 |
eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Logname | Label | 1.0.0 to 1.2.18 |
eventlog | MajorVersion | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | MinorVersion | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | Module | Character string | 1.4.0 to 4.4.2 |
eventlog | RegModuleName | Character string | 1.4.0 to 4.4.2 |
eventlog | Servername | Label | 1.0.0 to 1.2.18 |
eventlog | Unknown0 | Label | 1.0.0 to 4.4.2 |
eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 1.2.18 |
eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 1.2.18 |
eventlog | Unknown0 | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Unknown1 | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Data | Unsigned integer (8 bits) | 1.0.0 to 4.4.2 |
eventlog | Flags | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Number Of Bytes | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Offset | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Real Size | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Sent Size | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Closing Record Number | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Computer Name | Character string | 1.0.0 to 4.4.2 |
eventlog | Data Length | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Data Offset | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Event Category | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Event Id | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Event Type | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Num Of Strings | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Raw Data | Character string | 1.0.0 to 4.4.2 |
eventlog | Record Number | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Reserved | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Reserved Flags | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Sid Length | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Sid Offset | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Size | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Source Name | Character string | 1.0.0 to 4.4.2 |
eventlog | Stringoffset | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Strings | Character string | 1.0.0 to 4.4.2 |
eventlog | Time Generated | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Time Written | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.0.0 to 4.4.2 |
eventlog | Logname | Character string | 1.0.0 to 4.4.2 |
eventlog | Servername | Character string | 1.0.0 to 4.4.2 |
eventlog | Unknown0 | Label | 1.0.0 to 4.4.2 |
eventlog | Unknown2 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Unknown3 | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Computer Name | Character string | 1.4.0 to 4.4.2 |
eventlog | Data Length | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | Event Category | Unsigned integer (16 bits) | 1.4.0 to 4.4.2 |
eventlog | Event Id | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | Handle | Byte sequence | 1.4.0 to 4.4.2 |
eventlog | Num Of Strings | Unsigned integer (16 bits) | 1.4.0 to 4.4.2 |
eventlog | Time | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | Type | Unsigned integer (32 bits) | 1.4.0 to 4.4.2 |
eventlog | EVENTLOG AUDIT FAILURE | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG AUDIT SUCCESS | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG ERROR TYPE | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG INFORMATION TYPE | Boolean | 1.0.0 to 4.4.2 |
eventlog | Eventlog Success | Boolean | 1.0.0 to 2.2.1 |
eventlog | EVENTLOG WARNING TYPE | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG BACKWARDS READ | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG FORWARDS READ | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG SEEK READ | Boolean | 1.0.0 to 4.4.2 |
eventlog | EVENTLOG SEQUENTIAL READ | Boolean | 1.0.0 to 4.4.2 |
eventlog | Operation | Unsigned integer (16 bits) | 1.0.0 to 4.4.2 |
eventlog | Record | Label | 1.0.0 to 4.4.2 |
eventlog | Computer Name | Character string | 1.0.0 to 4.4.2 |
eventlog | Record Length | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |
eventlog | Source Name | Character string | 1.0.0 to 4.4.2 |
eventlog | string | Character string | 1.0.0 to 4.4.2 |
eventlog | NT Error | Unsigned integer (32 bits) | 1.0.0 to 4.4.2 |