aboutsummaryrefslogtreecommitdiff
path: root/test/results/zoom.pcap.out
diff options
context:
space:
mode:
authorToni Uhlig <matzeton@googlemail.com>2021-04-09 14:33:34 +0200
committerToni Uhlig <matzeton@googlemail.com>2021-04-09 14:43:28 +0200
commitba586e1ecf848937a612cf35bed6275578dad088 (patch)
tree954884ee118dcb05ff17a61165ecaf853b37a387 /test/results/zoom.pcap.out
parent4e583cd4dedd6467f300eea5947a4f6bb2c036f2 (diff)
nDPId-test: mimic full nDPId lifecycle
* generate DAEMON_EVENT_INIT as well as DAEMON_EVENT_SHUTDOWN * process remaining flows before shutdown (and generate events) Signed-off-by: Toni Uhlig <matzeton@googlemail.com>
Diffstat (limited to 'test/results/zoom.pcap.out')
-rw-r--r--test/results/zoom.pcap.out39
1 files changed, 39 insertions, 0 deletions
diff --git a/test/results/zoom.pcap.out b/test/results/zoom.pcap.out
index bfa2599c2..aeb342de1 100644
--- a/test/results/zoom.pcap.out
+++ b/test/results/zoom.pcap.out
@@ -1,3 +1,4 @@
+00381{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"zoom.pcap","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":256,"tick-resolution":1000,"reader-thread-count":1,"idle-scan-period":10000,"max-idle-time":600000,"tcp-max-post-end-flow-time":60000,"max-packets-per-flow-to-send":15,"max-packets-per-flow-to-process":255}
00474{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"zoom.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1569520466080,"flow_last_seen":0,"flow_tot_l4_data_len":231,"flow_min_l4_data_len":231,"flow_max_l4_data_len":231,"flow_avg_l4_data_len":231,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"172.217.21.72","src_port":54854,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
00692{"flow_id":1,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"zoom.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1569520466,"pkt_ts_usec":80774,"pkt_caplen":265,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":265,"pkt_l4_len":231,"pkt":"EBMx8Tl2KDc3AG3ICABFAAD7AABAAEAGtb7AqAF1rNkVSNZGAbt9MLg2pduNV4AYEAjbcQAAAQEICiWcznNwmChtFgMBAMIBAAC+AwE5BEH329R9hgOe6JDNh5Do5\/IyBg\/qLeMPj9mOGNz+swAAEgAvADMANQA5wAnACsATwBRWAAEAAIP\/AQABAAAAAB0AGwAAGHd3dy5nb29nbGV0YWdtYW5hZ2VyLmNvbQAXAAAABQAFAQAAAAAzdAAAABIAAAAQADAALgJoMgVoMi0xNgVoMi0xNQVoMi0xNAhzcGR5LzMuMQZzcGR5LzMIaHR0cC8xLjEACwACAQAACgAKAAgAHQAXABgAGQ=="}
00802{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":1,"source":"zoom.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1569520466080,"flow_last_seen":0,"flow_tot_l4_data_len":231,"flow_min_l4_data_len":231,"flow_max_l4_data_len":231,"flow_avg_l4_data_len":231,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"172.217.21.72","src_port":54854,"dst_port":443,"l4_proto":"tcp","ndpi": {"flow_risk": {"7":"Obsolete TLS version (< 1.1)"},"proto":"TLS.Google","breed":"Unrated","category":"Web"},"tls": {"version":"TLSv1","client_requested_server_name":"www.googletagmanager.com","ja3":"d78489b860c8bf7838a6ff0b4d131541","ja3s":"","unsafe_cipher":0,"cipher":"TLS_NULL_WITH_NULL_NULL","alpn":"h2,h2-16,h2-15,h2-14,spdy\/3.1,spdy\/3,http\/1.1"}}
@@ -323,3 +324,41 @@
00466{"flow_id":32,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":689,"source":"zoom.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1569520473,"pkt_ts_usec":157959,"pkt_caplen":99,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":99,"pkt_l4_len":65,"pkt":"EBMx8Tl2KDc3AG3ICABFAABV25wAAEARzxzAqAF1bV6gY+zMImEAQdYuBSIBAPuQCRAAAAAAAAAAAACAyAAGAQAEAuE3edfn7BLaAAAJEAAAAAUAAAC1gcoAAgEABAIBAAAA"}
00411{"flow_id":33,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":693,"source":"zoom.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1569520473,"pkt_ts_usec":170187,"pkt_caplen":57,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":57,"pkt_l4_len":23,"pkt":"EBMx8Tl2KDc3AG3ICABFAAArmBYAAEAREs3AqAF1bV6gY\/EjImEAFxFSBQoGAAAAAAAAAAAAAAAA"}
00414{"flow_id":33,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1569520473,"pkt_ts_usec":198709,"pkt_caplen":60,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":60,"pkt_l4_len":23,"pkt":"KDc3AG3IEBMx8Tl2CABFAAArvZdAADURuEttXqBjwKgBdSJh8SMAFxFSBQoGAAAAAAAAAAAAAAAAAAAA"}
+00455{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":17,"flow_packet_id":2,"flow_first_seen":1569520469423,"flow_last_seen":1569520469433,"flow_tot_l4_data_len":72,"flow_min_l4_data_len":36,"flow_max_l4_data_len":36,"flow_avg_l4_data_len":36,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"162.255.38.14","l4_proto":"icmp","flow_datalink":1,"flow_max_packets":15}
+00484{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":9,"flow_packet_id":2,"flow_first_seen":1569520469036,"flow_last_seen":1569520469072,"flow_tot_l4_data_len":137,"flow_min_l4_data_len":31,"flow_max_l4_data_len":106,"flow_avg_l4_data_len":68,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":65394,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00474{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":18,"flow_packet_id":1,"flow_first_seen":1569520469797,"flow_last_seen":0,"flow_tot_l4_data_len":287,"flow_min_l4_data_len":287,"flow_max_l4_data_len":287,"flow_avg_l4_data_len":287,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.0.1","dst_ip":"255.255.255.255","src_port":68,"dst_port":67,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00441{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":10,"flow_packet_id":1,"flow_first_seen":1569520469072,"flow_last_seen":0,"flow_tot_l4_data_len":36,"flow_min_l4_data_len":36,"flow_max_l4_data_len":36,"flow_avg_l4_data_len":36,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","l4_proto":"icmp","flow_datalink":1,"flow_max_packets":15}
+00505{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":11,"flow_packet_id":2,"flow_first_seen":1569520469081,"flow_last_seen":1569520469116,"flow_tot_l4_data_len":40,"flow_min_l4_data_len":20,"flow_max_l4_data_len":20,"flow_avg_l4_data_len":20,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"13.225.84.182","src_port":54798,"dst_port":443,"l4_proto":"tcp","ndpi": {"proto":"TLS","breed":"Safe","category":"Web"}}
+00485{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":11,"flow_packet_id":2,"flow_first_seen":1569520469081,"flow_last_seen":1569520469116,"flow_tot_l4_data_len":40,"flow_min_l4_data_len":20,"flow_max_l4_data_len":20,"flow_avg_l4_data_len":20,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"13.225.84.182","src_port":54798,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00484{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":29,"flow_packet_id":2,"flow_first_seen":1569520471147,"flow_last_seen":1569520471188,"flow_tot_l4_data_len":108,"flow_min_l4_data_len":46,"flow_max_l4_data_len":62,"flow_avg_l4_data_len":54,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":51185,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00489{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":4,"flow_first_seen":1569520466080,"flow_last_seen":1569520472536,"flow_tot_l4_data_len":924,"flow_min_l4_data_len":231,"flow_max_l4_data_len":231,"flow_avg_l4_data_len":231,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"172.217.21.72","src_port":54854,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00484{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":6,"flow_packet_id":3,"flow_first_seen":1569520468399,"flow_last_seen":1569520468399,"flow_tot_l4_data_len":228,"flow_min_l4_data_len":76,"flow_max_l4_data_len":76,"flow_avg_l4_data_len":76,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.255","src_port":137,"dst_port":137,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00489{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":33,"flow_packet_id":8,"flow_first_seen":1569520473084,"flow_last_seen":1569520473198,"flow_tot_l4_data_len":382,"flow_min_l4_data_len":21,"flow_max_l4_data_len":117,"flow_avg_l4_data_len":47,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"109.94.160.99","src_port":61731,"dst_port":8801,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00529{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":15,"flow_packet_id":6,"flow_first_seen":1569520469340,"flow_last_seen":1569520469435,"flow_tot_l4_data_len":748,"flow_min_l4_data_len":32,"flow_max_l4_data_len":295,"flow_avg_l4_data_len":124,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"104.199.65.42","src_port":53867,"dst_port":80,"l4_proto":"tcp","ndpi": {"proto":"HTTP.Google","breed":"Unrated","category":"Web"},"http": {}}
+00488{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":15,"flow_packet_id":6,"flow_first_seen":1569520469340,"flow_last_seen":1569520469435,"flow_tot_l4_data_len":748,"flow_min_l4_data_len":32,"flow_max_l4_data_len":295,"flow_avg_l4_data_len":124,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"104.199.65.42","src_port":53867,"dst_port":80,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00491{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":8,"flow_packet_id":18,"flow_first_seen":1569520468959,"flow_last_seen":1569520469430,"flow_tot_l4_data_len":7695,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":427,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"52.202.62.238","src_port":54864,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00493{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":19,"flow_packet_id":30,"flow_first_seen":1569520469950,"flow_last_seen":1569520470454,"flow_tot_l4_data_len":17921,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":597,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"52.202.62.196","src_port":54865,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00493{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":21,"flow_packet_id":33,"flow_first_seen":1569520470022,"flow_last_seen":1569520470628,"flow_tot_l4_data_len":20585,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":623,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"52.202.62.236","src_port":54866,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00488{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":13,"flow_packet_id":6,"flow_first_seen":1569520469221,"flow_last_seen":1569520469399,"flow_tot_l4_data_len":276,"flow_min_l4_data_len":40,"flow_max_l4_data_len":52,"flow_avg_l4_data_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"162.255.38.14","src_port":23903,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00488{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":12,"flow_packet_id":6,"flow_first_seen":1569520469189,"flow_last_seen":1569520469375,"flow_tot_l4_data_len":276,"flow_min_l4_data_len":40,"flow_max_l4_data_len":52,"flow_avg_l4_data_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"162.255.37.14","src_port":23903,"dst_port":3478,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00488{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":14,"flow_packet_id":6,"flow_first_seen":1569520469253,"flow_last_seen":1569520469433,"flow_tot_l4_data_len":276,"flow_min_l4_data_len":40,"flow_max_l4_data_len":52,"flow_avg_l4_data_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"162.255.38.14","src_port":23903,"dst_port":3479,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00471{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":2,"flow_packet_id":1,"flow_first_seen":1569520466209,"flow_last_seen":0,"flow_tot_l4_data_len":53,"flow_min_l4_data_len":53,"flow_max_l4_data_len":53,"flow_avg_l4_data_len":53,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"224.0.0.251","src_port":5353,"dst_port":5353,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00476{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":22,"flow_packet_id":1,"flow_first_seen":1569520470666,"flow_last_seen":0,"flow_tot_l4_data_len":52,"flow_min_l4_data_len":52,"flow_max_l4_data_len":52,"flow_avg_l4_data_len":52,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.255","src_port":57621,"dst_port":57621,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00492{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":3,"flow_packet_id":20,"flow_first_seen":1569520466316,"flow_last_seen":1569520471572,"flow_tot_l4_data_len":3585,"flow_min_l4_data_len":32,"flow_max_l4_data_len":1258,"flow_avg_l4_data_len":179,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"167.99.215.164","src_port":54863,"dst_port":4434,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00484{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":24,"flow_packet_id":2,"flow_first_seen":1569520470742,"flow_last_seen":1569520470776,"flow_tot_l4_data_len":104,"flow_min_l4_data_len":44,"flow_max_l4_data_len":60,"flow_avg_l4_data_len":52,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":58063,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00492{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":25,"flow_packet_id":29,"flow_first_seen":1569520470742,"flow_last_seen":1569520471166,"flow_tot_l4_data_len":8664,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":298,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"213.19.144.105","src_port":54867,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00492{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":26,"flow_packet_id":30,"flow_first_seen":1569520470755,"flow_last_seen":1569520471166,"flow_tot_l4_data_len":8688,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":289,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"213.19.144.104","src_port":54868,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00482{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":7,"flow_packet_id":2,"flow_first_seen":1569520468922,"flow_last_seen":1569520468958,"flow_tot_l4_data_len":90,"flow_min_l4_data_len":37,"flow_max_l4_data_len":53,"flow_avg_l4_data_len":45,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":64352,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00497{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":31,"flow_packet_id":185,"flow_first_seen":1569520471748,"flow_last_seen":1569520473190,"flow_tot_l4_data_len":185945,"flow_min_l4_data_len":21,"flow_max_l4_data_len":1037,"flow_avg_l4_data_len":1005,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"109.94.160.99","src_port":58327,"dst_port":8801,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00492{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":27,"flow_packet_id":29,"flow_first_seen":1569520470769,"flow_last_seen":1569520471156,"flow_tot_l4_data_len":8670,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":298,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"213.244.140.85","src_port":54869,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00492{"flow_event_id":2,"flow_event_name":"end","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":28,"flow_packet_id":28,"flow_first_seen":1569520470776,"flow_last_seen":1569520471159,"flow_tot_l4_data_len":7582,"flow_min_l4_data_len":20,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":270,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"213.244.140.84","src_port":54870,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00484{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":23,"flow_packet_id":2,"flow_first_seen":1569520470741,"flow_last_seen":1569520470768,"flow_tot_l4_data_len":104,"flow_min_l4_data_len":44,"flow_max_l4_data_len":60,"flow_avg_l4_data_len":52,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":62563,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00510{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":2,"flow_first_seen":1569520467811,"flow_last_seen":1569520471399,"flow_tot_l4_data_len":158,"flow_min_l4_data_len":79,"flow_max_l4_data_len":79,"flow_avg_l4_data_len":79,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"62.149.152.153","src_port":54341,"dst_port":993,"l4_proto":"tcp","ndpi": {"proto":"IMAPS","breed":"Safe","category":"Email"}}
+00487{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":4,"flow_packet_id":2,"flow_first_seen":1569520467811,"flow_last_seen":1569520471399,"flow_tot_l4_data_len":158,"flow_min_l4_data_len":79,"flow_max_l4_data_len":79,"flow_avg_l4_data_len":79,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"62.149.152.153","src_port":54341,"dst_port":993,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00489{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":32,"flow_packet_id":7,"flow_first_seen":1569520471915,"flow_last_seen":1569520473157,"flow_tot_l4_data_len":387,"flow_min_l4_data_len":21,"flow_max_l4_data_len":115,"flow_avg_l4_data_len":55,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"109.94.160.99","src_port":60620,"dst_port":8801,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00480{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":5,"flow_packet_id":1,"flow_first_seen":1569520468207,"flow_last_seen":0,"flow_tot_l4_data_len":134,"flow_min_l4_data_len":134,"flow_max_l4_data_len":134,"flow_avg_l4_data_len":134,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"239.255.255.250","src_port":57025,"dst_port":1900,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00521{"flow_event_id":4,"flow_event_name":"guessed","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":16,"flow_packet_id":16,"flow_first_seen":1569520469341,"flow_last_seen":1569520469413,"flow_tot_l4_data_len":6295,"flow_min_l4_data_len":32,"flow_max_l4_data_len":1450,"flow_avg_l4_data_len":393,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"35.186.224.53","src_port":53872,"dst_port":443,"l4_proto":"tcp","ndpi": {"proto":"TLS.Google","breed":"Unrated","category":"Web"}}
+00492{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":16,"flow_packet_id":16,"flow_first_seen":1569520469341,"flow_last_seen":1569520469413,"flow_tot_l4_data_len":6295,"flow_min_l4_data_len":32,"flow_max_l4_data_len":1450,"flow_avg_l4_data_len":393,"midstream":1,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"35.186.224.53","src_port":53872,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00494{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":30,"flow_packet_id":210,"flow_first_seen":1569520471189,"flow_last_seen":1569520473190,"flow_tot_l4_data_len":64504,"flow_min_l4_data_len":32,"flow_max_l4_data_len":1472,"flow_avg_l4_data_len":307,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"109.94.160.99","src_port":54871,"dst_port":443,"l4_proto":"tcp","flow_datalink":1,"flow_max_packets":15}
+00483{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test","flow_id":20,"flow_packet_id":2,"flow_first_seen":1569520469984,"flow_last_seen":1569520470021,"flow_tot_l4_data_len":92,"flow_min_l4_data_len":38,"flow_max_l4_data_len":54,"flow_avg_l4_data_len":46,"midstream":0,"l3_proto":"ip4","src_ip":"192.168.1.117","dst_ip":"192.168.1.1","src_port":62988,"dst_port":53,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
+00125{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":700,"source":"zoom.pcap","alias":"nDPId-test"}