next up previous contents
Next: Unfied2 IDS Event IP6 Up: Unified2 File Format Previous: Unified2 Packet   Contents

Unfied2 IDS Event

    sensor id               4 bytes
    event id                4 bytes
    event second            4 bytes
    event microsecond       4 bytes
    signature id            4 bytes
    generator id            4 bytes
    signature revision      4 bytes
    classification id       4 bytes
    priority id             4 bytes
    ip source               4 bytes
    ip destination          4 bytes
    source port/icmp type   2 bytes
    dest. port/icmp code    2 bytes
    protocol                1 byte
    impact flag             1 byte
    impact                  1 byte
    blocked                 1 byte

Unified2 IDS Event is logged for IPv4 Events without VLAN or MPLS tagging.



Eugene Misnik 2013-05-08