|
2201 | 2201 | "id": "679408454713142279", |
2202 | 2202 | "seq_num": "724" |
2203 | 2203 | } |
| 2204 | + }, |
| 2205 | + { |
| 2206 | + "json": { |
| 2207 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2208 | + "vendor": "Gigamon", |
| 2209 | + "version": "6.5.00", |
| 2210 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2211 | + "dst_mac": "00:90:7f:3e:02:d0", |
| 2212 | + "src_mac": "e0:f8:47:21:c9:d6", |
| 2213 | + "src_ip": "172.16.133.96", |
| 2214 | + "dst_ip": "172.16.133.134", |
| 2215 | + "protocol": "6", |
| 2216 | + "src_port": "53512", |
| 2217 | + "dst_port": "80", |
| 2218 | + "device_inbound_interface": "0", |
| 2219 | + "http_rtt": "2", |
| 2220 | + "http_server": "g-pixel.invitemedia.com", |
| 2221 | + "http_referer": "http:\\/\\/pixel.invitemedia.com\\/data_sync?partner_id=419", |
| 2222 | + "http_uri": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999", |
| 2223 | + "http_uri_path": "\\/BurstingPipe\\/adServer.bs", |
| 2224 | + "http_host": "bs.serving-sys.com", |
| 2225 | + "http_uri_raw": "\\/BurstingPipe\\/adServer.bs?cn=rsb&c=28&pli=6283423&PluID=0&w=600&h=300&ncu=$$http:\\/\\/adclick.g.doubleclick.net\\/aclk?sa=L&ai=BbjDYCjItUfTZNtD56AGYzIHoAYjCzaoDAAAAEAEg5IOJAzgAWKi3js5KYMmG7YiEpOwPsgEWd3d3LmJhcnN0b29sc3BvcnRzLmNvbboBCWdmcF9pbWFnZcgBCdoBHmh0dHA6Ly93d3cuYmFyc3Rvb2xzcG9ydHMuY29tL8ACAuACAOoCGy81NzI0OTA1Ni82MDB4MzAwX1N1cGVycGFnZfgCgtIegAMBkAOkA5gDpAOoAwHgBAGgBhY&num=0&sig=AOD64_3ys4vfsF0cKFXmFwXWDhecLGNUFA&client=ca-pub-8984096390091816&adurl=$$&ord=1291673978&z=9999", |
| 2226 | + "http_set_cookie": "S_6283423=1070476434893147863", |
| 2227 | + "http_server_agent": "Jetty(7.3.1.v20110307)", |
| 2228 | + "http_code": "200", |
| 2229 | + "http_content_encoding": "gzip", |
| 2230 | + "http_content_type": "image\\/gif", |
| 2231 | + "http_method": "GET", |
| 2232 | + "http_version": "1.1", |
| 2233 | + "http_user_agent": "Mozilla\\/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit\\/534.57.2 (KHTML, like Gecko) Version\\/5.1.7 Safari\\/534.57.2", |
| 2234 | + "http_file_type": "GIF (v89a)", |
| 2235 | + "app_id": "67", |
| 2236 | + "tcp_flags": "19", |
| 2237 | + "src_bytes": "702", |
| 2238 | + "dst_bytes": "1261", |
| 2239 | + "src_packets": "5", |
| 2240 | + "dst_packets": "4", |
| 2241 | + "start_time": "2025:01:27 21:31:31.807", |
| 2242 | + "end_time": "2025:01:27 21:31:31.863", |
| 2243 | + "flow_start_sec": "2025:01:27 21:31:30", |
| 2244 | + "flow_end_sec": "2025:01:27 21:31:30", |
| 2245 | + "intf_name": "0", |
| 2246 | + "egress_intf_id": "0", |
| 2247 | + "app_name": "http", |
| 2248 | + "id": "6470375316427636737", |
| 2249 | + "seq_num": "187452" |
| 2250 | + } |
| 2251 | + }, |
| 2252 | + { |
| 2253 | + "json": { |
| 2254 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2255 | + "vendor": "Gigamon", |
| 2256 | + "version": "6.5.00", |
| 2257 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2258 | + "dst_mac": "b4:0c:25:e0:40:11", |
| 2259 | + "src_mac": "4c:32:75:97:66:cf", |
| 2260 | + "src_ip": "10.155.24.73", |
| 2261 | + "dst_ip": "10.155.24.35", |
| 2262 | + "protocol": "6", |
| 2263 | + "src_port": "64631", |
| 2264 | + "dst_port": "443", |
| 2265 | + "device_inbound_interface": "0", |
| 2266 | + "ssl_common_name": "*.event.prod.bidr.io", |
| 2267 | + "ssl_issuer": "Amazon", |
| 2268 | + "ssl_validity_not_before": "2017-08-31 06:30:04", |
| 2269 | + "ssl_validity_not_after": "2020-08-31 06:30:04", |
| 2270 | + "ssl_cipher_suite_id": "49199", |
| 2271 | + "ssl_protocol_version": "771", |
| 2272 | + "ssl_certificate_subject_cn": "*.event.prod.bidr.io", |
| 2273 | + "ssl_ext_sig_algorithm_scheme": "1027", |
| 2274 | + "ssl_ext_sig_algorithm_hash": "4", |
| 2275 | + "ssl_ext_sig_algorithm_sig": "3", |
| 2276 | + "ip_wrong_crc": "5199", |
| 2277 | + "app_id": "1183", |
| 2278 | + "tcp_flags": "18", |
| 2279 | + "src_bytes": "2365", |
| 2280 | + "dst_bytes": "6387", |
| 2281 | + "src_packets": "11", |
| 2282 | + "dst_packets": "8", |
| 2283 | + "start_time": "2025:01:27 21:37:26.327", |
| 2284 | + "end_time": "2025:01:27 21:37:26.415", |
| 2285 | + "flow_start_sec": "2025:01:27 21:37:25", |
| 2286 | + "flow_end_sec": "2025:01:27 21:37:25", |
| 2287 | + "intf_name": "0", |
| 2288 | + "egress_intf_id": "0", |
| 2289 | + "app_name": "amazon-aws", |
| 2290 | + "id": "6470375590653329409", |
| 2291 | + "seq_num": "319260" |
| 2292 | + } |
| 2293 | + }, |
| 2294 | + { |
| 2295 | + "json": { |
| 2296 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2297 | + "vendor": "Gigamon", |
| 2298 | + "version": "6.5.00", |
| 2299 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2300 | + "dst_mac": "4c:32:75:97:66:cf", |
| 2301 | + "src_mac": "c0:94:35:1c:5e:1a", |
| 2302 | + "src_port": "443", |
| 2303 | + "dst_port": "63770", |
| 2304 | + "tcp_loss_count": "1380", |
| 2305 | + "tcp_rtt": "0.000015", |
| 2306 | + "tcp_rtt_app": "0.000026", |
| 2307 | + "tcp_retransmission_bytes": "155", |
| 2308 | + "tcp_flag_reset": "1", |
| 2309 | + "tcp_wrong_crc": "4296", |
| 2310 | + "app_id": "68", |
| 2311 | + "src_ipv6": "2a02:cf40:0000:0000:0000:0000:0000:0001", |
| 2312 | + "dst_ipv6": "2a02:cf47:ffff:ffff:ffff:ffff:ffff:0001", |
| 2313 | + "ip_version": "6", |
| 2314 | + "tcp_flags": "18", |
| 2315 | + "src_packets": "3301", |
| 2316 | + "dst_packets": "4205", |
| 2317 | + "flow_start_sec": "2025:07:28 03:12:22", |
| 2318 | + "end_reason": "2", |
| 2319 | + "app_name": "https", |
| 2320 | + "src_bytes": "307270", |
| 2321 | + "dst_bytes": "558827", |
| 2322 | + "id": "691388880983323651", |
| 2323 | + "seq_num": "52332271" |
| 2324 | + } |
| 2325 | + }, |
| 2326 | + { |
| 2327 | + "json": { |
| 2328 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2329 | + "vendor": "Gigamon", |
| 2330 | + "version": "6.5.00", |
| 2331 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2332 | + "dst_mac": "b4:0c:25:e0:40:53", |
| 2333 | + "src_mac": "00:08:e3:ff:fc:28", |
| 2334 | + "src_ip": "10.10.1.116", |
| 2335 | + "dst_ip": "10.120.10.218", |
| 2336 | + "protocol": "17", |
| 2337 | + "src_port": "61751", |
| 2338 | + "dst_port": "161", |
| 2339 | + "device_inbound_interface": "0", |
| 2340 | + "snmp_version": "2c", |
| 2341 | + "app_id": "190", |
| 2342 | + "tcp_flags": "0", |
| 2343 | + "src_bytes": "172", |
| 2344 | + "dst_bytes": "182", |
| 2345 | + "src_packets": "2", |
| 2346 | + "dst_packets": "2", |
| 2347 | + "start_time": "2025:01:27 21:33:58.759", |
| 2348 | + "end_time": "2025:01:27 21:33:58.759", |
| 2349 | + "flow_start_sec": "2025:01:27 21:33:57", |
| 2350 | + "flow_end_sec": "2025:01:27 21:33:57", |
| 2351 | + "intf_name": "0", |
| 2352 | + "egress_intf_id": "0", |
| 2353 | + "app_name": "snmp", |
| 2354 | + "id": "6470375508803584001", |
| 2355 | + "seq_num": "213751" |
| 2356 | + } |
| 2357 | + }, |
| 2358 | + { |
| 2359 | + "json": { |
| 2360 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2361 | + "vendor": "Gigamon", |
| 2362 | + "version": "6.5.00", |
| 2363 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2364 | + "dst_mac": "ff:ff:ff:ff:ff:ff", |
| 2365 | + "src_mac": "09:00:09:00:01:12", |
| 2366 | + "src_ip": "10.2.1.23", |
| 2367 | + "dst_ip": "10.2.1.255", |
| 2368 | + "protocol": "17", |
| 2369 | + "src_port": "138", |
| 2370 | + "dst_port": "138", |
| 2371 | + "device_inbound_interface": "0", |
| 2372 | + "smb_version": "1", |
| 2373 | + "smb_command_string": "negotiate", |
| 2374 | + "smb_path": "\\/\\/11.1.0.37:445\\/sharefile", |
| 2375 | + "smb_host": "user1", |
| 2376 | + "smb_filename": "testfile", |
| 2377 | + "app_id": "3855", |
| 2378 | + "tcp_flags": "0", |
| 2379 | + "src_bytes": "38376", |
| 2380 | + "dst_bytes": "0", |
| 2381 | + "src_packets": "162", |
| 2382 | + "dst_packets": "0", |
| 2383 | + "start_time": "2025:01:27 21:30:10.463", |
| 2384 | + "end_time": "2025:01:27 21:30:44.847", |
| 2385 | + "flow_start_sec": "2025:01:27 21:30:09", |
| 2386 | + "flow_end_sec": "2025:01:27 21:30:43", |
| 2387 | + "intf_name": "0", |
| 2388 | + "egress_intf_id": "0", |
| 2389 | + "app_name": "mailslot", |
| 2390 | + "id": "6470375254073016321", |
| 2391 | + "seq_num": "76099" |
| 2392 | + } |
| 2393 | + }, |
| 2394 | + { |
| 2395 | + "json": { |
| 2396 | + "ts": "Wed Dec 13 15:25:54 2023", |
| 2397 | + "vendor": "Gigamon", |
| 2398 | + "version": "6.5.00", |
| 2399 | + "generator": "gs_apps_appInst16_423722da-33ec-1556-b24b-cda2e74a53f6", |
| 2400 | + "dst_mac": "02:01:93:9c:99:4d", |
| 2401 | + "src_mac": "02:01:93:9c:98:37", |
| 2402 | + "src_ip": "10.1.0.4", |
| 2403 | + "dst_ip": "10.1.0.4", |
| 2404 | + "protocol": "17", |
| 2405 | + "src_port": "57677", |
| 2406 | + "dst_port": "67", |
| 2407 | + "dns_qdcount": "1", |
| 2408 | + "dns_message_type": "QUERY", |
| 2409 | + "dns_tunneling": "1", |
| 2410 | + "dns_reverse_addr": "10.12.21.34", |
| 2411 | + "dns_flags": "256", |
| 2412 | + "dns_opcode": "0", |
| 2413 | + "dns_class": "1", |
| 2414 | + "dns_query": "34.21.12.61.in-addr.arpa", |
| 2415 | + "dns_query_type": "12", |
| 2416 | + "app_id": "32", |
| 2417 | + "ip_version": "4", |
| 2418 | + "src_packets": "2955", |
| 2419 | + "dst_packets": "2705", |
| 2420 | + "flow_start_sec": "2025:07:27 23:52:17", |
| 2421 | + "end_reason": "1", |
| 2422 | + "app_name": "dns", |
| 2423 | + "src_bytes": "326560", |
| 2424 | + "dst_bytes": "432901", |
| 2425 | + "id": "691388880109625347", |
| 2426 | + "seq_num": "52203185" |
| 2427 | + } |
2204 | 2428 | } |
2205 | 2429 | ] |
2206 | 2430 | } |
| 2431 | + |
0 commit comments