Try using below as reference:
select "collectorId" as 'Event Collector ID',"qidEventId" as 'Event ID',QIDNAME(qid) as 'Event Name',logsourcename(logSourceId) as 'Log Source',"eventCount" as 'Event Count',"startTime" as 'Start Time',categoryname(category) as 'Low Level Category',"sourceIP" as 'Source IP',"sourcePort" as 'Source Port',"destinationIP" as 'Destination IP',"destinationPort" as 'Destination Port',"userName" as 'Username',"magnitude" as 'Magnitude' from events
To get the event ID: "qidEventId" as 'Event ID'
------------------------------
Namit Maurya
------------------------------
Original Message:
Sent: Mon February 28, 2022 09:27 PM
From: Dan Zerkle
Subject: How to fetch Event ID from AQL?
For some strange reason, all my attempts to get the Event ID field from AQL are failing. I've tried every combination of spaces and upper/lower case I can think of, but just get "N/A". It works fine when I build a search with the GUI. It shows up on the GUI display of the event.
This is for a custom DSM for a syslog LEEF log source. So, I used the DSM editor to just have a LEEF expression of $eventid$. It maps events just fine.
I.e., everything is fine except for AQL. How do I get the Event ID with AQL?
Also, there's no mention of Event ID at Event, flow, and simarc fields for AQL queries - IBM Documentation
------------------------------
Dan Zerkle
------------------------------