|
|
@ -148,23 +148,17 @@ Examples
|
|
|
|
|
|
|
|
|
|
|
|
"anomaly": {
|
|
|
|
"anomaly": {
|
|
|
|
"type": "packet",
|
|
|
|
"type": "packet",
|
|
|
|
"event": "decoder.udp.pkt_too_small"
|
|
|
|
"event": "decoder.icmpv4.unknown_type"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
{
|
|
|
|
|
|
|
|
"timestamp": "2016-01-17T13:26:30.841742-0800",
|
|
|
|
|
|
|
|
"flow_id": 1848021463489450,
|
|
|
|
|
|
|
|
"pcap_cnt": 1393890,
|
|
|
|
|
|
|
|
"event_type": "anomaly",
|
|
|
|
|
|
|
|
"src_ip": "192.168.81.128",
|
|
|
|
|
|
|
|
"src_port": 50105,
|
|
|
|
|
|
|
|
"dest_ip": "31.148.99.125",
|
|
|
|
|
|
|
|
"dest_port": 80,
|
|
|
|
|
|
|
|
"proto": "TCP",
|
|
|
|
|
|
|
|
"anomaly": {
|
|
|
|
"anomaly": {
|
|
|
|
"type": "stream",
|
|
|
|
"type": "packet",
|
|
|
|
"event": "stream.reassembly_seq_gap"
|
|
|
|
"event": "decoder.udp.pkt_too_small"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
"anomaly": {
|
|
|
|
|
|
|
|
"type": "packet",
|
|
|
|
|
|
|
|
"event": "decoder.ipv4.wrong_ip_version"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
{
|
|
|
|
{
|
|
|
|