|
8 | 8 | "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
9 | 9 | "dst_mac": "01:00:5e:00:00:fb", |
10 | 10 | "src_mac": "00:50:56:8d:89:41", |
11 | | - "src_ip": "10.114.82.101", |
12 | | - "dst_ip": "224.0.0.251", |
| 11 | + "src_ip": "89.160.20.112", |
| 12 | + "dst_ip": "89.160.20.113", |
13 | 13 | "protocol": "17", |
14 | 14 | "src_port": "5353", |
15 | 15 | "dst_port": "5353", |
|
1044 | 1044 | "dns_qdcount": "4", |
1045 | 1045 | "dns_transaction_id": "0", |
1046 | 1046 | "dns_name": "3.a.2.3.7.1.5.5.e.2.1.6.e.4.7.e.0.8.0.2.1.0.0.0.0.0.0.0.b.a.c.f. ip6.arpa", |
| 1047 | + "dns_message_type": "QUERY", |
| 1048 | + "dns_tunneling": "1", |
1047 | 1049 | "dns_host": "pnstrex-83631.local", |
1048 | 1050 | "dns_host_addr": "10.114.82.162", |
1049 | 1051 | "dns_host_type": "PTR", |
|
1099 | 1101 | "egress_intf_id": "0", |
1100 | 1102 | "sys_up_time_first": "1890478091", |
1101 | 1103 | "sys_up_time_last": "2158913547", |
| 1104 | + "http_rtt": "2", |
| 1105 | + "http_server": "g-pixel.invitemedia.com", |
| 1106 | + "http_referer": "http:\\/\\/pixel.invitemedia.com\\/data_sync?partner_id=419", |
| 1107 | + "http_uri": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999", |
| 1108 | + "http_uri_path": "\\/BurstingPipe\\/adServer.bs", |
| 1109 | + "http_host": "bs.serving-sys.com", |
| 1110 | + "http_uri_raw": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999", |
| 1111 | + "http_set_cookie": "S_6283423=1070476434893147863", |
| 1112 | + "http_server_agent": "Jetty(7.3.1.v20110307)", |
| 1113 | + "http_code": "200", |
| 1114 | + "http_content_encoding": "gzip", |
| 1115 | + "http_content_type": "image\\/gif", |
| 1116 | + "http_method": "GET", |
| 1117 | + "http_version": "1.1", |
| 1118 | + "http_user_agent": "Mozilla\\/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit\\/534.57.2 (KHTML, like Gecko) Version\\/5.1.7 Safari\\/534.57.2", |
| 1119 | + "http_file_type": "GIF (v89a)", |
1102 | 1120 | "end_reason": "1", |
1103 | 1121 | "app_name": "https", |
1104 | 1122 | "id": "679408454713104391", |
|
2081 | 2099 | "dst_packets": "3", |
2082 | 2100 | "start_time": "2023:12:13 15:25:36.669", |
2083 | 2101 | "end_time": "2023:12:13 15:25:38.253", |
| 2102 | + "flow_start_sec": "2023:12:13 15:25:21", |
| 2103 | + "flow_end_sec": "2023:12:13 15:25:40", |
2084 | 2104 | "intf_name": "0", |
2085 | 2105 | "egress_intf_id": "0", |
2086 | 2106 | "sys_up_time_first": "1624860683", |
|
2097 | 2117 | "vendor": "Gigamon", |
2098 | 2118 | "version": "6.5.00", |
2099 | 2119 | "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
2100 | | - "dns_qdcount": "0", |
2101 | | - "dns_ancount": "27", |
2102 | | - "dns_transaction_id": "0", |
2103 | | - "dns_name": "sys" |
| 2120 | + "smb_version": "1", |
| 2121 | + "smb_command_string": "negotiate", |
| 2122 | + "smb_path": "\\/\\/11.1.0.37:445\\/sharefile", |
| 2123 | + "smb_host": "user1", |
| 2124 | + "smb_filename": "testfile", |
| 2125 | + "app_id": "3855", |
| 2126 | + "tcp_flags": "0", |
| 2127 | + "src_bytes": "1036", |
| 2128 | + "dst_bytes": "0", |
| 2129 | + "src_packets": "4", |
| 2130 | + "dst_packets": "0", |
| 2131 | + "app_name": "mailslot" |
2104 | 2132 | } |
2105 | 2133 | }, |
2106 | 2134 | { |
|
2117 | 2145 | "src_port": "41529", |
2118 | 2146 | "dst_port": "9080", |
2119 | 2147 | "device_inbound_interface": "0", |
2120 | | - "ssl_cipher_suite_id": "49200", |
| 2148 | + "ssl_common_name": "*.zoom.us", |
| 2149 | + "ssl_issuer": "Go Daddy Secure Certificate Authority - G2", |
| 2150 | + "ssl_cipher_suite_id": "49199", |
| 2151 | + "ssl_protocol_version": "771", |
| 2152 | + "ssl_certificate_subject_cn": "*.zoom.us", |
| 2153 | + "ssl_ext_sig_algorithm_scheme": "1537", |
| 2154 | + "ssl_ext_sig_algorithm_hash": "6", |
| 2155 | + "ssl_ext_sig_algorithm_sig": "1", |
| 2156 | + "ssl_validity_not_before": "2025-05-26 04:32:14", |
| 2157 | + "ssl_validity_not_after": "2026-05-26 04:32:14", |
2121 | 2158 | "app_id": "4962", |
2122 | 2159 | "ip_version": "4", |
2123 | 2160 | "src_bytes": "1533", |
|
2142 | 2179 | "vendor": "Gigamon", |
2143 | 2180 | "version": "6.5.00", |
2144 | 2181 | "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
2145 | | - "dns_qdcount": "1", |
2146 | | - "dns_ancount": "30", |
2147 | | - "dns_transaction_id": "0", |
2148 | | - "dns_name": "_tms_cluster._tcp.local", |
2149 | | - "dns_host": "duo-test-cluster._tms_cluster._tcp.local", |
2150 | | - "dns_host_type": "PTR" |
| 2182 | + "tcp_loss_count": "1380", |
| 2183 | + "tcp_rtt": "0.000015", |
| 2184 | + "tcp_rtt_app": "0.000026", |
| 2185 | + "tcp_retransmission_bytes": "155", |
| 2186 | + "tcp_flag_reset": "1", |
| 2187 | + "tcp_wrong_crc": "4296", |
| 2188 | + "ip_wrong_crc": "5199", |
| 2189 | + "app_id": "15" |
2151 | 2190 | } |
2152 | 2191 | }, |
2153 | 2192 | { |
|
2156 | 2195 | "vendor": "Gigamon", |
2157 | 2196 | "version": "6.5.00", |
2158 | 2197 | "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
2159 | | - "dns_qdcount": "2", |
2160 | | - "dns_ancount": "40", |
2161 | | - "dns_transaction_id": "0", |
2162 | | - "dns_name": "_tcn_Suki-Cluster._tcp.local", |
2163 | | - "dns_host": "eqaHCT._tms" |
| 2198 | + "snmp_version": "2c", |
| 2199 | + "app_id": "190" |
2164 | 2200 | } |
2165 | 2201 | }, |
2166 | 2202 | { |
|
2204 | 2240 | } |
2205 | 2241 | ] |
2206 | 2242 | } |
| 2243 | + |
0 commit comments