Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

DescriptionField NameField Value
Any field containing a source IP addressip_src_ipaddrOctets (xxx.xxx.xxx.xxx)
Any field containing a destination IP addressip_dst_ipaddrOctets (xxx.xxx.xxx.xxx)
Any field containing a source portip_src_portInteger
Any field containing a destination portip_dst_portInteger
Any field containing a protocolprotoprotocol

String as a protocol, all caps.

So if protocol = 6, value should be TCP

TimestamptstimestampEpoch timestamp (timestamp comes from sensor, not parser)
Message Typesource.typeyaf|snort|bro|etc...
Timestampstart_timeEpoch timestamp
Timestampend_timeEpoch timestamp