next up previous contents
Next: Unfied2 IDS Event Up: Unified2 File Format Previous: Serial Unified2 Header   Contents

Unified2 Packet

    sensor id               4 bytes
    event id                4 bytes
    event seconds           4 bytes
    event microseconds      4 bytes
    linktype                4 bytes
    packet length           4 bytes
    packet data             <variable length>

A Unified2 Packet is provided with each Unified2 Event record. This packet is the `alerting' packet that caused a given event.

Unified2 Packet records contain contain a copy of the packet that caused an alert (Packet Data) and is packet length octets long.



Eugene Misnik 2013-05-08