1
2
3
4
5
6
7
|
flow_datalink,l3_proto,src_ip,dst_ip,l4_proto,src_port,dst_port,flow_state,flow_src_packets_processed,flow_dst_packets_processed,flow_first_seen,flow_src_last_pkt_time,flow_dst_last_pkt_time,flow_src_min_l4_payload_len,flow_dst_min_l4_payload_len,flow_src_max_l4_payload_len,flow_dst_max_l4_payload_len,flow_src_tot_l4_payload_len,flow_dst_tot_l4_payload_len,midstream,iat_min,iat_avg,iat_max,iat_stddev,iat_var,iat_ent,iat_data,pktlen_min,pktlen_avg,pktlen_max,pktlen_stddev,pktlen_var,pktlen_ent,pktlen_data,bins_c_to_s,bins_s_to_c,directions,entropies,proto,proto_id,encrypted,breed,category,confidence_id,confidence,risks
1,ip4,10.64.0.127,10.64.0.72,tcp,51056,4880,finished,21,11,1395235022714729,1395235117238521,1395235110214979,0,0,54,24,206,168,0,159,5871743.5,19038629,6792435.0,46137172033536.0,3.9,"159,255,14777,15032,334,333,217948,3286106,3504126,208187,10280253,10488398,202638,18835935,19038629,211109,3164637,3375690,204865,18603800,18610247,8174306,8385603,202657,7510419,7713129,211316,16164069,16375351,215494,6808240",40,52.4,94,10.8,117.4,5.0,"52,52,40,56,56,64,64,40,56,56,40,56,56,40,94,56,40,56,56,40,56,40,56,56,40,56,56,40,56,56,40,56","20,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","11,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,1,0,0,1,0,0,1,0,0,1,0,0,1,0,1,0,0,1,0,0,1,0,0,1,0,0","4.208755016,4.863714218,4.222574711,3.791955471,4.174042225,3.548727512,3.967243671,4.222574711,3.791955471,3.968184710,4.222574711,3.685983658,4.089133739,4.172574520,4.796797752,4.036043644,4.222574711,3.791955471,4.000329494,4.172574997,4.253843784,4.222574711,3.685983658,4.066899776,4.172574997,4.047204494,3.896756172,4.222574711,4.017705441,3.883275986,4.222574711,4.031185627",HiSLIP,372,0,Acceptable,IoT-Scada,6,DPI,""
1,ip4,10.64.0.127,10.64.0.72,tcp,51054,4880,finished,19,13,1395234992935199,1395235156211826,1395235186226505,0,0,54,24,158,155,0,159,11502191.0,30221196,11630422.0,135266715041792.0,4.1,"159,254,14789,15069,362,340,217930,13272901,13259574,13350289,13554941,221344,22465609,22686937,200535,2983558,3184145,214299,30221196,30007213,24848210,24848481,210992,6444733,6655718,200686,18636258,18641456,30200438,29994794,30014723",40,51.8,94,10.7,114.4,5.0,"52,52,40,56,56,64,64,40,56,40,56,56,40,56,56,40,94,56,40,46,52,56,56,40,56,56,40,56,40,46,52,46","18,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","13,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,1,0,1,0,0,1,0,0,1,0,0,1,0,1,0,0,1,0,0,1,0,1,0,1,0,1","4.247216702,4.748329163,4.272574425,3.863384008,4.102613926,3.548727512,3.935993671,4.272574425,4.289557934,4.272574425,3.827669859,4.000329018,4.172574997,4.004225254,4.036043644,4.272574425,4.877751827,4.036043644,4.222574711,4.130999565,4.359120846,4.053419590,3.932470322,4.222574711,4.053419590,4.036043644,4.222574711,4.182415009,4.222574711,4.087521076,4.359120846,4.130999565",HiSLIP,372,0,Acceptable,IoT-Scada,6,DPI,""
1,ip4,10.64.0.127,10.64.0.72,tcp,51055,4880,finished,19,13,1395235022698475,1395235189368494,1395235189368700,0,0,26,41,195,208,0,172,10752911.0,30224299,11913816.0,141939022233600.0,4.0,"245,363,15354,15637,202654,30224299,30021867,21890463,21890725,221333,2690180,2911516,172,434,30016519,30016515,22101315,22101636,211148,5004629,5215774,205595,30216128,30010867,15065087,15272489,6292463,6085327,219281,2500471,2719758",40,55.1,81,11.5,131.2,5.0,"52,52,40,63,56,40,46,52,66,69,40,66,56,81,40,46,52,66,69,40,66,69,40,46,52,56,46,66,69,40,66,56","19,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","12,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,1,0,0,1,0,0,1,1,0,1,0,0,1,0,0,1,0,1,0,0,1,0,1,0,0,1","4.247216702,4.772274017,4.153702736,4.327305794,3.946276665,4.153702736,4.071110249,4.188837051,4.350000858,4.564953327,4.203702450,4.496242523,4.204648972,5.077324390,4.203702450,4.071110249,4.219791889,4.496243000,4.644472599,4.153702259,4.489754677,4.615487099,4.203702450,4.011221409,4.282197952,4.140867233,4.071110249,4.406847000,4.650129795,4.203702450,4.397905827,4.182415009",HiSLIP,372,0,Acceptable,IoT-Scada,6,DPI,""
1,ip4,10.64.0.127,10.64.0.72,tcp,51053,4880,finished,18,14,1395234992923478,1395235216038558,1395235216038493,0,0,26,63,123,228,0,181,14394519.0,30237001,13485121.0,181848479105024.0,4.1,"244,360,10820,11109,202661,4710669,4913387,218770,8156706,8375451,205,492,7975375,7975670,215748,30237001,30021528,30014758,30014761,29999078,29999082,21560664,21560964,181,468,30013098,30013102,30014666,30014661,29999203,29999213",40,54.9,103,14.0,195.0,5.0,"52,52,40,63,56,40,62,103,40,66,56,81,40,66,69,40,46,52,46,52,46,52,66,56,81,40,46,52,46,52,46,52","18,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","11,3,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0","0,1,0,0,1,0,0,1,0,0,1,1,0,0,1,0,1,0,1,0,1,0,0,1,1,0,1,0,1,0,1,0","4.208755016,4.825252533,4.272574425,4.371034145,4.066899776,4.272574425,4.273222923,5.284747601,4.051712990,4.490328312,4.289557934,5.102015972,4.172574520,4.544446468,4.669953823,4.101713181,3.885338783,4.203743458,3.928816795,4.203743458,3.928816795,4.203743458,4.355523586,4.253843784,5.102015972,4.222574711,4.130999565,4.349692822,4.130999565,4.349692822,4.087521076,4.349692822",HiSLIP,372,0,Acceptable,IoT-Scada,6,DPI,""
timestamp,json_lines,json_bytes,flow_src_total_bytes,flow_dst_total_bytes,flow_new_count,flow_end_count,flow_idle_count,flow_update_count,flow_analyse_count,flow_guessed_count,flow_detected_count,flow_detection_update_count,flow_not_detected_count,flow_risky_count,packet_count,packet_flow_count,init_count,reconnect_count,shutdown_count,status_count,error_unknown_datalink,error_unknown_l3_protocol,error_unsupported_datalink,error_packet_too_short,error_packet_type_unknown,error_packet_header_invalid,error_ip4_packet_too_short,error_ip4_size_smaller_than_header,error_ip4_l4_payload_detection,error_ip6_packet_too_short,error_ip6_size_smaller_than_header,error_ip6_l4_payload_detection,error_tcp_packet_too_short,error_udp_packet_too_short,error_capture_size_smaller_than_packet,error_max_flows_to_track,error_flow_memory_alloc,flow_state_info,flow_state_finished,flow_breed_safe_count,flow_breed_acceptable_count,flow_breed_fun_count,flow_breed_unsafe_count,flow_breed_potentially_dangerous_count,flow_breed_tracker_ads_count,flow_breed_dangerous_count,flow_breed_unrated_count,flow_breed_unknown_count,flow_category_unspecified_count,flow_category_media_count,flow_category_vpn_count,flow_category_email_count,flow_category_data_transfer_count,flow_category_web_count,flow_category_social_network_count,flow_category_download_count,flow_category_game_count,flow_category_chat_count,flow_category_voip_count,flow_category_database_count,flow_category_remote_access_count,flow_category_cloud_count,flow_category_network_count,flow_category_collaborative_count,flow_category_rpc_count,flow_category_streaming_count,flow_category_system_count,flow_category_software_update_count,flow_category_music_count,flow_category_video_count,flow_category_shopping_count,flow_category_productivity_count,flow_category_file_sharing_count,flow_category_conn_check_count,flow_category_iot_scada_count,flow_category_virt_assistant_count,flow_category_cybersecurity_count,flow_category_adult_content_count,flow_category_mining_count,flow_category_malware_count,flow_category_advertisment_count,flow_category_banned_site_count,flow_category_site_unavail_count,flow_category_allowed_site_count,flow_category_antimalware_count,flow_category_crypto_currency_count,flow_category_gambling_count,flow_category_unknown_count,flow_confidence_by_port,flow_confidence_dpi_partial,flow_confidence_dpi_partial_cache,flow_confidence_dpi_cache,flow_confidence_dpi,flow_confidence_nbpf,flow_confidence_by_ip,flow_confidence_dpi_aggressive,flow_confidence_custom_rule,flow_confidence_unknown,flow_severity_low,flow_severity_medium,flow_severity_high,flow_severity_severe,flow_severity_critical,flow_severity_emergency,flow_severity_unknown,flow_l3_ip4_count,flow_l3_ip6_count,flow_l3_other_count,flow_l4_tcp_count,flow_l4_udp_count,flow_l4_icmp_count,flow_l4_other_count,flow_active_count,flow_detected_count,flow_guessed_count,flow_not_detected_count,flow_risk_1_count,flow_risk_2_count,flow_risk_3_count,flow_risk_4_count,flow_risk_5_count,flow_risk_6_count,flow_risk_7_count,flow_risk_8_count,flow_risk_9_count,flow_risk_10_count,flow_risk_11_count,flow_risk_12_count,flow_risk_13_count,flow_risk_14_count,flow_risk_15_count,flow_risk_16_count,flow_risk_17_count,flow_risk_18_count,flow_risk_19_count,flow_risk_20_count,flow_risk_21_count,flow_risk_22_count,flow_risk_23_count,flow_risk_24_count,flow_risk_25_count,flow_risk_26_count,flow_risk_27_count,flow_risk_28_count,flow_risk_29_count,flow_risk_30_count,flow_risk_31_count,flow_risk_32_count,flow_risk_33_count,flow_risk_34_count,flow_risk_35_count,flow_risk_36_count,flow_risk_37_count,flow_risk_38_count,flow_risk_39_count,flow_risk_40_count,flow_risk_41_count,flow_risk_42_count,flow_risk_43_count,flow_risk_44_count,flow_risk_45_count,flow_risk_46_count,flow_risk_47_count,flow_risk_48_count,flow_risk_49_count,flow_risk_50_count,flow_risk_51_count,flow_risk_52_count,flow_risk_53_count,flow_risk_54_count,flow_risk_55_count,flow_risk_56_count,flow_risk_unknown_count
0,39,33090,830,1033,4,4,0,0,4,0,4,0,0,0,0,20,1,0,1,1,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,0,0,0,0,0,0,0,0,0,0,4,0,0,4,0,0,0,4,4,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0
|