Welcome to the community !
I think the fields corresponding to what you are looking for are probably mapped as follow:
User_name == Source_User
Service_name == Application
Client_addr == Source IP
The best thing to do is to create a view and link each component to have this information on the same page. This will also help you do the drilldown easely.
I have create a view and link each of the component to the Windows Event ID back and it is a match . Thank you very much and I really appreciate your advices on this matters. Hope that I will get something valuable out of this Event logs data. Thanks again.