1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
|
00474{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"radius_false_positive.pcapng","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":64,"tick-resolution":1000,"reader-thread-count":1,"flow-scan-interval":10000,"generic-max-idle-time":600000,"icmp-max-idle-time":120000,"udp-max-idle-time":180000,"tcp-max-idle-time":7560000,"max-packets-per-flow-to-send":3,"max-packets-per-flow-to-process":32,"global_ts_msec":0}
00560{"daemon_event_id":4,"daemon_event_name":"status","thread_id":0,"packet_id":1,"source":"radius_false_positive.pcapng","alias":"nDPId-test","packets-captured":1,"packets-processed":0,"total-skipped-flows":0,"total-l4-data-len":0,"total-not-detected-flows":0,"total-guessed-flows":0,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":0,"total-idle-flows":0,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"total-events-serialized":2,"global_ts_msec":1638897892722}
00639{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_packets_processed":1,"flow_first_seen":1638897892722,"flow_last_seen":1638897892722,"flow_idle_time":180000,"flow_min_l4_payload_len":1230,"flow_max_l4_payload_len":1230,"flow_tot_l4_payload_len":1230,"flow_avg_l4_payload_len":1230,"midstream":0,"thread_ts_msec":1638897892722,"l3_proto":"ip6","src_ip":"2bc6:b5ac:cb3b:676b::18","dst_ip":"3dba:3762:c186:e122:89b0:5170:a86c:ecff","src_port":443,"dst_port":53129,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":3}
02138{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_last_seen":1638897892722,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":1292,"pkt_type":34525,"pkt_l3_offset":14,"pkt_l4_offset":54,"pkt_len":1292,"pkt_l4_len":1238,"thread_ts_msec":1638897892722,"pkt":"AAAAAAAAAAUAHNVSht1ohf3HBNYRNyvGtazLO2drAAAAAAAAABg9ujdiwYbhIomwUXCobOz\/AbvPiQTW\/+II9QTO5\/6moMoBfKc4frxprVfBsxdaQAED2QEABgCgAQJbUkVKAAcAAABTVEsAOAAAAFNOTwBsAAAAUFJPRmwBAABTQ0ZH8wEAAFJSRUr3AQAAU1RUTP8BAABDUlT\/GwIAADVoRFFcZEfiQgn1oXI2ORzyXhwGYKf\/Flu1\/kK\/l4UH4q9DCId2Xb2zn9efGujSc\/F0aNOeHZb6KAjEeRC9dXjLQIA3XVxkxqhCJrs95QV3gGPSLgjsQQ873Rxpmhq\/VDe1SdA9fAVAXfMUX1s0Z5mAWpV6sSbDkPHYULs7X0KVe+fR2Ai5noT8neP+HJa14zskJKzRF7WTWAfIPB94k7XcyneleZDZy\/LsPNPpKzumkgJT693IGvFFGpwQ7o47hVb2V37u8BaJMyzZuDr4CIc8F1YA1joFN7OPyOLc3a+gm+fEb18FG1gS\/ZrcntqavJ3HLz5Vi8zFgzSja7rxlz5ZT0Fgr\/\/hUJDycGNBHRHMai1MLz1CKo55ez2Vq+oMFJFtHL8m7Yk0AZ6oTphvz\/47C32mJ\/BonrdxqQzXuP2SrkxlJp8ughvQJBkM+kPiZ+nnveyN+ypLny4LxyWPno4oScYJJSbW2FdJTZlTQ0ZHBgAAAEFFQUQIAAAAU0NJRBgAAABQVUJTOwAAAEtFWFM\/AAAAT0JJVEcAAABFWFBZTwAAAEFFU0dDQzIwYXTY6XlRVYYUrxtElpX4jCAAAK5TCWYobSWz756zKFc0+OhHde7JrmIR8db7Z6FsadZoQzI1NVZwm2DcDowaV9aKYgAAAAANAAAAcj3bAAAAAAAC1l9bpELMSn4CHk1io2ZOe6cCwpjjNUiKNMcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA="}
02150{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":2,"flow_last_seen":1638897892751,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":1292,"pkt_type":34525,"pkt_l3_offset":14,"pkt_l4_offset":54,"pkt_len":1292,"pkt_l4_len":1238,"thread_ts_msec":1638897892751,"pkt":"AAAAAAAAAAUAHNVSht1ohf3HBNYRNyvGtazLO2drAAAAAAAAABg9ujdiwYbhIomwUXCobOz\/AbvPiQTWXcUENlLj0f+6+Jgr1PUqO1anUCJ2f97tXf2Z8dBl2WTNukYCx1qDOvW8l6pBbA\/QzGs9GCu+xmb0GpSAkHyfZJ2yzr+NsYf988AiiEM8Mw9vmVCFpA4j3zmgSbUMUqgIFl\/ckMyhcXVUAjUruKWcZMMMomSxBL0vpnp1XovZUE8pJR53GIvlrl+aH1JwTdTEvoURGDfXj7HymZzIuiSpGYcRD4vDvqxyXwPsD4kklWrCDS5cMNSnSoB8eE1CrkyDZbEac8d6Z9X9O9hVutHpXHdc8gBWr725a+RbAoF\/nPg5l47cpx3KLC5AygsRsFUsycadOOJsrJqf+9lTAUvzlDtUj+J25fiK8TqR0Htv0gjY+Jf2ES1obpMcjsWCiXC6C0982Lwh98CIWpY1gYbDsiQa6EEuHVALLYQUT42cGlDbewsfp4Tjx+NbNHC0NZc0UCj102HBZbyY5AOE9r7wfqiQaj2v1GD0l19oUj5P0xtAFB0SNmmD5d08q+OoF+ZBA0E6SCA8jehYueJJlNRt2O31FJ1PeCVRpXT8NS7VE4tXMJ8ZArjTuP5NIrSPPhiEXOHrCn7C8kPSZZB1pxxVhkM4fCfMQWma2EIEU+REEtViwMip2cC0g0V4nnW\/YfK+57akB9Uu+0UaHviwxWuzhAxGMdVzbjXnwSWJNac8i6mybugAVsdsQkGBl70YyNWbeahKe2D3y1P1bYLnJrYbOkYRBF+Acbl4FGuz\/nCgMU7SEMmI0+\/U7iLhf8TNIcHbgmGN3xWUp8MMU9z3FDMAHi7oQ7vcqn2oU94rkkS4y8axIrx2QwCkDJN+5S2PReVaFfu1ihdUnHLmPXcZnAO8wWRnGVr5ewQO2snzrfhV6kqHoNqKp3sFYCKZ0h+VYPxDLQBix8ZW6P\/vNI9cAHY6sTfoSrJh69tT4CbgMvKAE\/sDmImL3P9qv\/1IhHstTBm1LX4GOfYYS3rPAwVQ4pUO6qOTB\/jrOTmqyO8ggnJnicgTHfMyrt\/YUwgZmzOkC+28uYLM3BRiFyBEWOfbvNmWpIppEHAM4TQ0LASWi29RTMAA6yhmP48DyvIzh6MvPkc0C7ttlJFR5dXsueCqSPXJSa6RHS4Ghz3UQkk\/bW1yQQQsHLm1zJ0CZlvZsfILcijdRrY9oJzL3OU10dq2OTOj0EwYIjYZjoMNzWrVQoyWC\/hUYzb6TZHFiQ0v1S83RquW6dw1uqUaQxnSA6gjTt36ObS8o0yGINds3ce3lWwTO8wJp\/1VtDvWP4mJz0R1RdgPl7H3Qc\/OIu\/Uiz172qtXeu\/a6zn7juIxWvjrSwDhsEYK4AndiRVwqXJA+\/U7JrGg\/1Z+sEaWCLNPlGxx1qPQc\/lXR7j8\/6rGoy9j+Sp2Y0lmI790AsfFUJVXzf8\/sNql\/iXQyYk27jdTY1xFLuqEW+0sJDJplhnhSo2HCLraX8NwZK089VGLFoARqXLlZelV4DNWO6zmal7a5naaLGht\/dyC7GGpM9macDSuMEKqgE9PYIHiWZZiwe0n1VqYdrMTEbEA3PMydAo+v0ArxApe\/wf93uRzNVvGy\/z5z3Li6zsJTZIl4sCmgnO9Hg9luCpGiq\/3VXjdOqOdtq2C1KUdQUsQ0qfvDVjcB41LwFOcvnc="}
00510{"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_packet_id":3,"flow_last_seen":1638897892751,"flow_idle_time":180000,"pkt_oversize":false,"pkt_caplen":85,"pkt_type":34525,"pkt_l3_offset":14,"pkt_l4_offset":54,"pkt_len":85,"pkt_l4_len":31,"thread_ts_msec":1638897892751,"pkt":"AAAAAAAAAAUAHNVSht1gBf3HAB8RNyvGtazLO2drAAAAAAAAABg9ujdiwYbhIomwUXCobOz\/AbvPiQAfGG4AA72ZrkYpyvqLS4TIp3bivr3zq\/PFuA=="}
00654{"flow_event_id":8,"flow_event_name":"not-detected","thread_id":0,"packet_id":10,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_packets_processed":10,"flow_first_seen":1638897892722,"flow_last_seen":1638897893066,"flow_idle_time":180000,"flow_min_l4_payload_len":20,"flow_max_l4_payload_len":1230,"flow_tot_l4_payload_len":6859,"flow_avg_l4_payload_len":685,"midstream":0,"thread_ts_msec":1638897893066,"l3_proto":"ip6","src_ip":"2bc6:b5ac:cb3b:676b::18","dst_ip":"3dba:3762:c186:e122:89b0:5170:a86c:ecff","src_port":443,"dst_port":53129,"l4_proto":"udp","ndpi": {"proto":"Unknown","breed":"Unrated"}}
00639{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":10,"source":"radius_false_positive.pcapng","alias":"nDPId-test","flow_id":1,"flow_state":"info","flow_packets_processed":10,"flow_first_seen":1638897892722,"flow_last_seen":1638897893066,"flow_idle_time":180000,"flow_min_l4_payload_len":20,"flow_max_l4_payload_len":1230,"flow_tot_l4_payload_len":6859,"flow_avg_l4_payload_len":685,"midstream":0,"thread_ts_msec":1638897893066,"l3_proto":"ip6","src_ip":"2bc6:b5ac:cb3b:676b::18","dst_ip":"3dba:3762:c186:e122:89b0:5170:a86c:ecff","src_port":443,"dst_port":53129,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":3}
00568{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":10,"source":"radius_false_positive.pcapng","alias":"nDPId-test","packets-captured":10,"packets-processed":10,"total-skipped-flows":0,"total-l4-data-len":6859,"total-not-detected-flows":1,"total-guessed-flows":0,"total-detected-flows":0,"total-detection-updates":0,"total-updates":0,"current-active-flows":0,"total-active-flows":1,"total-idle-flows":1,"total-compressions":0,"total-compression-diff":0,"current-compression-diff":0,"total-events-serialized":9,"global_ts_msec":1638897893066}
~~~~~~~~~~~~~~~~~~~~ SUMMARY ~~~~~~~~~~~~~~~~~~~~
~~ packets captured/processed: 10/10
~~ skipped flows.............: 0
~~ total layer4 data length..: 6859 bytes
~~ total detected protocols..: 0
~~ total active/idle flows...: 1/1
~~ total timeout flows.......: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ total memory allocated....: 5178707 bytes
~~ total memory freed........: 5178707 bytes
~~ total allocations/frees...: 113035/113035
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~ json string min len.......: 479 chars
~~ json string max len.......: 2155 chars
~~ json string avg len.......: 1303 chars
|