1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
|
00477{"daemon_event_id":1,"daemon_event_name":"init","thread_id":0,"packet_id":0,"source":"wireguard.pcap","alias":"nDPId-test","max-flows-per-thread":2048,"max-idle-flows-per-thread":256,"tick-resolution":1000,"reader-thread-count":1,"idle-scan-period":10000,"generic-max-idle-time":600000,"icmp-max-idle-time":30000,"udp-max-idle-time":180000,"tcp-max-idle-time":7440000,"tcp-max-post-end-flow-time":120000,"max-packets-per-flow-to-send":15,"max-packets-per-flow-to-process":255}
00494{"flow_event_id":1,"flow_event_name":"new","thread_id":0,"packet_id":1,"source":"wireguard.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":1,"flow_first_seen":1563973554628,"flow_last_seen":0,"flow_min_l4_payload_len":800,"flow_max_l4_payload_len":800,"flow_tot_l4_payload_len":800,"flow_avg_l4_payload_len":800,"midstream":0,"l3_proto":"ip4","src_ip":"139.162.192.157","dst_ip":"192.168.0.14","src_port":51820,"dst_port":36116,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
01487{"flow_id":1,"flow_packet_id":1,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":1,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":628757,"pkt_caplen":842,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":842,"pkt_l4_len":808,"pkt":"OCxKuzMdABAY3q0FCABFAAM8FXkAADURYEKLosCdwKgADspsjRQDKLH1BAAAAL5AaY1rAAAAAAAAANUJ2VrXQI01RZfJr8PEwgZEhNNcu6x03VWSZ67dhAHHTWKcRpBFkk8NVHd\/C4D4pz\/puWqoUUxKuxxH6YlcxuxAvZFB0Na5O4CW6jEyMIx3UMKSHboRTInUKfs0ifRWz\/ah3LYVezBxxWAse8HA4hp9J+12MZT8TmyygIwyCCaeEvoUQjFc6leSZrAZpKnPNseLUtXq9seSkA+QHufBd5P\/nAxkid4Fwq057VLJqJcJvFJRIdSNrsUBNHlMd2O226LQDMo6+sXnZNRhM\/0lY6T99lZ2rtutA5g+LROCm\/BZLu+Ww0aOhZ9T5CPKvl1MXzbqDpHjEWohQohUG62HCabsLz2Pl6HJpafmxv\/xXmUvqTxvWO5iYVSI4YH0rzZVN3aVdPUxgXYG+W8rSU+st0bg\/OnAMZWFzotivj2mfqRsGMWV3egRFwhvlfe7Fuv0OvGM3s9ZvinFAlmQZqUDOt74G5zoedU\/69v6LWqjWqMgwmKLQ\/lMwt2MnS6hiTwk\/iqPpTIM8RYnxG13RvjKDr4JXT\/U7OnZL63BA8kKbkL5zeTL+gL4bvPs8T4bLqWJpX+KPgKK5qcCbrRIXtRaFjvffCmBHmxiams\/n7B6m2DssFWcjX1Ev1oBu1UMKN6t2aeneW6ZYl4Q+afpKmmTZbh75sYoA8rPXxM4Q6E\/CvQ8xKFJuG12US4vfj96Tg+HLqjTKQn0aT3tP\/WRrjoWHz5nOKAwY2ssdZ\/sOQ7Z4I975oMYqMkolPHC\/IQyZ00spefKrUv00QdKXcsmU90gzx2i\/XncJUiW6+cRr5y\/xIasdRDvxOeWrnEuyr4eneiO5Pi37MXP8f2E65R6K8EWKkhOt2QxypTL9OYJAB3d80dQUxikTgyJwcF9uQEqgJNA\/GZhO2rBxL\/P3ze0It5qd4umjz9rSz1Tj4x9V7iRrPWik7ncKTUF\/OLBOu3ao3EyUG8u2N+GMLh6DNMnc3AMj260R63yyZIj87BZpn+95duhzSfs8I4u6YbCy54JPpusEK7oluD\/Hy2\/DI77VPA2QYc="}
00588{"flow_id":1,"flow_packet_id":2,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":2,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":628780,"pkt_caplen":186,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":186,"pkt_l4_len":152,"pkt":"OCxKuzMdABAY3q0FCABFAACsFXoAADURYtGLosCdwKgADspsjRQAmIUlBAAAAL5AaY1sAAAAAAAAAApaAsrtXpH1hJEWMIaMon2Jp07DYKtFnos9KJ2dxNXsnPOlMw8teGIqqtQyAhfCvZKfSoj8FKmPC1PCtu8qqniK567s\/wF6cALr5IJXHXdFnmr1I94kKjzDU62XCT24xGedWrUZRek84+e2Fsx1lJJ6NR9cFgw9VnO9J77GX8hL"}
00524{"flow_id":1,"flow_packet_id":3,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":3,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":628915,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"ABAY3q0FOCxKuzMdCABFAAB8LYcAAEARP\/TAqAAOi6LAnY0UymwAaNyeBAAAAG2mYV5wAAAAAAAAAAo35XrmOHswcilnP2QelKUcrUyMt+9zQAFDeYSUJyyw9BNkc7uq5jhjxm51P1MBuT08PEWRrzriFSk+BrqayZkHU3Oi+bUZJb76bMmarQhF"}
00765{"flow_id":1,"flow_packet_id":4,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":4,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":642219,"pkt_caplen":314,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":314,"pkt_l4_len":280,"pkt":"ABAY3q0FOCxKuzMdCABFAAEsLY4AAEARPz3AqAAOi6LAnY0UymwBGEmaBAAAAG2mYV5xAAAAAAAAAN5Ok0twWoOc3RX\/pBAmM5A4ttcyiSnr6WlIZ3rw0bHvyhJ8D0gFIaNhxkibunbxRgGXjlWZ99hJmuC6tQZVIrGyeoMJlogcU2ClZA6z15\/EtpzcXY3I+CEXh+Z9iqr2KZVCGuC0MXTHXbARADST6kVD8xHIEc4v0mzYC7k51yygUmbpSItW\/AA444wfSuDNmUbiY4K6LA3k\/CPu2j6keZRenRNezN\/II1ww58lLjPExI9BPRB1+PF7znwM0R3fflSkyQ5tURRe9xKq9gD77tIEtmEPJinN8ZwbFdxDLT4hg5tE5HwK3DHMsaD5svhmlGUYurJQySzz\/oUE7ajjVW1A="}
00539{"flow_event_id":5,"flow_event_name":"detected","thread_id":0,"packet_id":4,"source":"wireguard.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":4,"flow_first_seen":1563973554628,"flow_last_seen":1563973554642,"flow_min_l4_payload_len":96,"flow_max_l4_payload_len":800,"flow_tot_l4_payload_len":1312,"flow_avg_l4_payload_len":328,"midstream":0,"l3_proto":"ip4","src_ip":"139.162.192.157","dst_ip":"192.168.0.14","src_port":51820,"dst_port":36116,"l4_proto":"udp","ndpi": {"proto":"WireGuard","breed":"Acceptable","category":"VPN"}}
00525{"flow_id":1,"flow_packet_id":5,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":5,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":711201,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"OCxKuzMdABAY3q0FCABFAAB8FcIAADURYrmLosCdwKgADspsjRQAaAbHBAAAAL5AaY1tAAAAAAAAAPpGK9K5H5VHV22UlCuzckhifHXG0mCPbNY7tJ3Ehp5q9DbTenVPM\/dETy5WTx4iR6yiQjK\/qZpSgBD1KbJ+XOoBt2B9Juw3RjALxSawFkyQ"}
00785{"flow_id":1,"flow_packet_id":6,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":6,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":734641,"pkt_caplen":330,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":330,"pkt_l4_len":296,"pkt":"OCxKuzMdABAY3q0FCABFAAE8FcgAADURYfOLosCdwKgADspsjRQBKLKwBAAAAL5AaY1uAAAAAAAAAA7P3gsnfqyHSkxVvk7ZUFfTs5uId8MR1z\/P++3DU89F58u2KSBC89E+TMwoo5vdIMJsT+b7A709MaciSbaelRStCwO5ZHba2yhLzuruktuPjiNIsswqDnfibWXsnF+j4ERJh\/qJKXlzotU8KGVfs3A\/MVxVeJz4RCiD9OutpTiyTZH5LA9aw3ADvoaPd3eDEzJlPLuKOab0J9G0siyGPuaN2cX4sA5O942yloPoD+JsBf\/I39eYbc2nNxpH8g9awDhFPsYLC2g8MqV3gZYHPKs8UajcENjPNY+h3kSsFkuQY4BIfZQ+mgr+5rf4E0AshweBq\/HM2Ka\/WmNJdKPdtd4HzfWy+F5vIZKbjE+7T2oM"}
00593{"flow_id":1,"flow_packet_id":7,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":7,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":734739,"pkt_caplen":186,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":186,"pkt_l4_len":152,"pkt":"OCxKuzMdABAY3q0FCABFAACsFckAADURYoKLosCdwKgADspsjRQAmPsQBAAAAL5AaY1vAAAAAAAAAITu3wDVXS368ItNAaVwMwjjRLVcNvVyuKrBBn063\/VBY12\/vwBEErru4spuPmrGypdGz\/UMiwcGWV5Om9YZ\/aZEE3ZsgtATf9elbHoOLv6ksVHc3uwicicZMqOiUnBjSs\/7\/X3asoaOF+ayxeJFWuVfsTeKcXNeAn+nepd3ymgm"}
00524{"flow_id":1,"flow_packet_id":8,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":8,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":735025,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"ABAY3q0FOCxKuzMdCABFAAB8LaUAAEARP9bAqAAOi6LAnY0UymwAaFWNBAAAAG2mYV5yAAAAAAAAAPMJxgmF97YKIv3RJCYIHeMPJgeM\/RZWWn6eBSJEI9wIHK1OKYt7mfYz5CHShOmaVJQYH8+pKP0QEewtefvNyURiItsDkM8xReRe8OfW4rWl"}
00741{"flow_id":1,"flow_packet_id":9,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":9,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":735724,"pkt_caplen":298,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":298,"pkt_l4_len":264,"pkt":"ABAY3q0FOCxKuzMdCABFAAEcLaYAAEARPzXAqAAOi6LAnY0UymwBCIMOBAAAAG2mYV5zAAAAAAAAAHhCo8yDazWnyAT+lNmjxtq+IimMkzliqNoDK6v2f3Ihl8yVBvvgtrVnShoX0Y6jm2lXBqZ+fkyJDBln24epcVpvqLIrWsiQb2t0LBlhrBR5KLPvRipaU7HMslv45q6u++LAPOzeE+jew8nPfnXoo1Ir9r3ogm9ZHpzifq2YdPpGvZLGWePcY9u8o5hN+2RGPtY9ObYebSzu0\/QQ2z+odOzeHyDpCE+01xS0KNEFocG6mM2xKxmZ6rVtsLnEGFXjinzYH\/T2y1gb0pSsUjSe07JjD0tXme6v01Sle1GPsq8eZE9Qx4IISPU+VnvqCJAN7w=="}
00527{"flow_id":1,"flow_packet_id":10,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":10,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":849160,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"OCxKuzMdABAY3q0FCABFAAB8FjAAADURYkuLosCdwKgADspsjRQAaMDSBAAAAL5AaY1wAAAAAAAAAG1G7u5yBxZg2JUKp0+aYXNkdBKRCXTxTs2Qz0iIhRpWj4KCCIHEc1W9G3wlK9ux\/bfjkALMxG3HGKiCsaaIFP1Hjd6PXopXAsXn\/cKTp+mS"}
01238{"flow_id":1,"flow_packet_id":11,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":11,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":973640,"pkt_caplen":666,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":666,"pkt_l4_len":632,"pkt":"OCxKuzMdABAY3q0FCABFAAKMFqQAADURX8eLosCdwKgADspsjRQCeIrJBAAAAL5AaY1xAAAAAAAAADO1d7qpNTHdcy7vBr61XyrTj1rcjH9q1NoCUkZfktZR0EW6wfGCY1wQaucTHbXxrQPWkRhsGU778kxJdh3cW+Y1zf\/pnc0xQYqL+0qPEnolHIGhjHeoRWmcs1JHuvahR8VulSDVZq7Po5dW1ifgBpXaHhhZagCaLf2EO\/QCh4Gj2uUkExsCOvVZCl3VFejg+bku6oo2aoU7GN0pgoWrcYoY1nLyepl4A5xZ8IKkBmghRxwwLLW0Yv1uaNhIZTOcMFSgSCmvjcn6cl59gF6krbMhAWhk6zWdVpbRvxCB23YpjSYLdBgx7+1AguNrVNPNd1NnUeVZqDAEs+LHXhRgaRsIW6G0VXsP04dvicymvTNKf+xOoplPx82ZBw+qyrs2Jz7TErIrB0JBZwncsKK2KEAQEShsIFo6J4QcF0sHO02P3Zdt4ysX2ZXpZNCDxJtlXvzYYUVvBY9n+C+VszRzaoJ\/PZxy+pphFlO5gn2VGqQaJyKMejIXz4MsTKSL+FxAjwVS\/Nuj4HPCClP1gO0gyJZa3+YnbPjnDQGkAdqrBkmGZg0h2bkNJrnD9VarQCXM6eTotvAiTugbbHDUe7Uzwdr\/1t6Pzk5c\/1me2RY9Lmt7hBFzEjpRFko3xEZTe5+lJ2CpMnzqs+ZduxXY7u4Ccy2XP3RYwvMuHEzjCw58CAcYIu0iLn\/VZehTzGXlcTh4s8MjynPHL55vC\/9f7cw8nubPcMkje5xxtjbL0iuNszV7pDHms\/GpNJbxLiHDqSYqo3e676lWzduMXlesKcBhdDHehFKCx45T++x0D4gzFIv1"}
00592{"flow_id":1,"flow_packet_id":12,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":12,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":973820,"pkt_caplen":186,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":186,"pkt_l4_len":152,"pkt":"OCxKuzMdABAY3q0FCABFAACsFqUAADURYaaLosCdwKgADspsjRQAmP2RBAAAAL5AaY1yAAAAAAAAANapKXCwC90mjFmPDaVmRo5cyhieGmyS28OW9p3OU02M0MQnXGriCnr7W+oZrfnIYuNL3BLZwxUMwv9URBU7L0bjcgXxdplFO6\/V9iWI3JOAQDjq3+wA\/B2cxPnnQMmMwzRv+YZ\/DSnYZYqB3O7lDkLWKukUjOT1YDaqyD6MQDcZ"}
00526{"flow_id":1,"flow_packet_id":13,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":13,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":974260,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"ABAY3q0FOCxKuzMdCABFAAB8LiUAAEARP1bAqAAOi6LAnY0UymwAaB+LBAAAAG2mYV50AAAAAAAAAI9tfKVIx7UlVy1HDhAUrAMjKdLduP+OEpWHLBE394laW3jJ0Lqa7HURy6krpFGEtykTq3N\/a3bbxUi+nKzrcQPN9N7PTqi9qMcJcRZfRaJH"}
00766{"flow_id":1,"flow_packet_id":14,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":14,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973554,"pkt_ts_usec":988525,"pkt_caplen":314,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":314,"pkt_l4_len":280,"pkt":"ABAY3q0FOCxKuzMdCABFAAEsLioAAEARPqHAqAAOi6LAnY0UymwBGACZBAAAAG2mYV51AAAAAAAAALRQvj6tw6QAY\/1JXhRu0\/kpg0ZD7SEgnZpAC+s8jGXziAhKpCTCH\/pk3rDPYn19TKsTuLxc1zmaU017AkbnBsHquJngTkFZUSs4A7OonKFDYfNR8NBpor3e08bbX9kpBvg5hvCfcFuilN1p\/T6Gbi7F27c\/VedFYEwOOSWRAgT933bHaR8+BsGfnNRPXDEqf0GZB2Q3fwNPouZkPRRQL29PIh6Y3f7QwNYfVcFC3cp5UvgzmnSvBJcnCk94OHMYhEzEjIXqW1oc8SvvU7RtsYPY8EWQO0s5T6PvYCWeNPCyv0ncQfWZ3DrNXptDDBcOK8yNpQjgCWPIQcRiWgbLKzw="}
00525{"flow_id":1,"flow_packet_id":15,"packet_event_id":2,"packet_event_name":"packet-flow","thread_id":0,"packet_id":15,"source":"wireguard.pcap","alias":"nDPId-test","pkt_oversize":false,"pkt_ts_sec":1563973555,"pkt_ts_usec":59830,"pkt_caplen":138,"pkt_type":2048,"pkt_l3_offset":14,"pkt_l4_offset":34,"pkt_len":138,"pkt_l4_len":104,"pkt":"OCxKuzMdABAY3q0FCABFAAB8FrAAADURYcuLosCdwKgADspsjRQAaH8xBAAAAL5AaY1zAAAAAAAAAKsmGYGKi6UV\/ABoO1rTU3erm9HJ6ajuCHhNTr+BNzOxxDMpzZpoj4pN4xXAtWKi+3K8fQ4EuV95kwtHAB1+WdN92q42fF3e2HUsuFze7Je7"}
00516{"flow_event_id":3,"flow_event_name":"idle","thread_id":0,"packet_id":2399,"source":"wireguard.pcap","alias":"nDPId-test","flow_id":1,"flow_packet_id":2399,"flow_first_seen":1563973554628,"flow_last_seen":1563973935842,"flow_min_l4_payload_len":32,"flow_max_l4_payload_len":1362,"flow_tot_l4_payload_len":633424,"flow_avg_l4_payload_len":264,"midstream":0,"l3_proto":"ip4","src_ip":"139.162.192.157","dst_ip":"192.168.0.14","src_port":51820,"dst_port":36116,"l4_proto":"udp","flow_datalink":1,"flow_max_packets":15}
00131{"daemon_event_id":3,"daemon_event_name":"shutdown","thread_id":0,"packet_id":2399,"source":"wireguard.pcap","alias":"nDPId-test"}
|