(SHA256=a33ab076322caf27f50a6345f51790e9bca168d9f238b4645601228e55953c11)
NOTES:
| ||||||
ElementID | Name | Data Type | Semantics | Units | Range | Date |
---|---|---|---|---|---|---|
Description | ||||||
0 | Reserved | |||||
Reserved as per section 4 of [RFC7012]. | ||||||
1-11 | Unassigned | |||||
12 | obsoleteReverseOctetTotalCount | unsigned64 | totalCounter | |||
13 | obsoleteReversePacketTotalCount | unsigned64 | totalCounter | |||
14 | initialTCPFlags | unsigned16 | flags | |||
Reversible as reverseInitialTCPFlags (ElementID 16398). TCP flags on the initial packet in the forward direction of the flow. | ||||||
15 | unionTCPFlags | unsigned16 | flags | |||
Reversible as reverseUnionTCPFlags (ElementID 16399). Union of TCP flags of all packets other than the initial packet in the forward direction of the flow. | ||||||
16 | obsoleteReverseInitialTCPFlags | unsigned8 | flags | |||
17 | obsoleteReverseUnionTCPFlags | unsigned8 | flags | |||
18 | payload | octetArray | ||||
Reversible as reversePayload (ElementID 16402). Initial bytes of flow payload in the forward direction. | ||||||
19 | obsoleteReversePayload | octetArray | ||||
20 | obsoleteReverseTcpSequenceNumber | unsigned32 | ||||
21 | reverseFlowDeltaMilliseconds | unsigned32 | quantity | milliseconds | ||
Difference in milliseconds between the times of the first packet in forward direction and the first packet in the reverse direction. | ||||||
22-28 | Unassigned | |||||
29 | obsoleteReverseVlanId | unsigned16 | identifier | |||
30 | silkFlowType | unsigned8 | identifier | |||
The type of flow as assigned by the SiLK rwflowpack tool. | ||||||
31 | silkFlowSensor | unsigned16 | identifier | |||
The sensor where a flow was collected as assigned by the SiLK rwflowpack tool. | ||||||
32 | silkTCPState | unsigned8 | flags | |||
Aspects of a flow record assigned by the SiLK rwflowpack tool. | ||||||
33 | silkAppLabel | unsigned16 | identifier | |||
Application label, defined as the primary well-known port associated with a given application. | ||||||
34 | Unassigned | |||||
35 | payloadEntropy | unsigned8 | ||||
Reversible as reversePayloadEntropy (ElementID 16419). The Shannon Entropy value for the payload, converted from a floating point (range 0.0 to 8.0) to an 8-bit unsigned integer. Generally, numbers above 230 are compressed or encrypted, numbers centered around 140 are English text, and very low value may indicate zero-padding of packets (e.g. TLS). | ||||||
36 | osName | string | ||||
Reversible as reverseOsName (ElementID 16420). p0f OS Name for the forward flow based on the SYN packet and p0f SYN Fingerprints. | ||||||
37 | osVersion | string | ||||
Reversible as reverseOsVersion (ElementID 16421). p0f OS Version for the forward flow based on the SYN packet and p0f SYN Fingerprints. | ||||||
38 | firstPacketBanner | octetArray | ||||
Reversible as reverseFirstPacketBanner (ElementID 16422). IP and transport headers for first packet in forward direction to be used for external OS Fingerprinters. | ||||||
39 | secondPacketBanner | octetArray | ||||
Reversible as reverseSecondPacketBanner (ElementID 16423). IP and transport headers for first packet in forward direction to be used for external OS Fingerprinters. | ||||||
40 | flowAttributes | unsigned16 | flags | |||
Reversible as reverseFlowAttributes (ElementID 16424). Miscellaneous flow attributes for the forward direction of the flow. | ||||||
41-99 | Unassigned | |||||
100 | yafExpiredFragmentCount | unsigned32 | totalCounter | packets | ||
Total number of packet fragments that have been expired since yaf start time. This element previously was named "expiredFragmentCount". | ||||||
101 | yafAssembledFragmentCount | unsigned32 | totalCounter | packets | ||
Total number of packets that been assembled from a series of fragments since yaf start time. This element previously was named "assembledFragmentCount". | ||||||
102 | yafMeanFlowRate | unsigned32 | flows | |||
The mean flow rate of the yaf flow sensor since yaf start time, rounded to the nearest integer. This element previously was named "meanFlowRate". | ||||||
103 | yafMeanPacketRate | unsigned32 | packets | |||
The mean packet rate of the yaf flow sensor since yaf start time, rounded to the nearest integer. This element previously was named "meanPacketRate". | ||||||
104 | yafFlowTableFlushEventCount | unsigned32 | totalCounter | flows | ||
Total number of times the yaf flow table has been flushed since yaf start time. This element previously was named "flowTableFlushEventCount". | ||||||
105 | yafFlowTablePeakCount | unsigned32 | flows | |||
The maximum number of flows in the yaf flow table at any one time since yaf start time. This element previously was named "flowTablePeakCount". | ||||||
106 | yafFlowKeyHash | unsigned32 | identifier | |||
The 32 bit hash of the 5-tuple and VLAN that is used as they key to YAF's internal flow table. | ||||||
107 | osFingerprint | string | ||||
Reversible as reverseOsFingerprint (ElementID 16491). p0f OS Fingerprint for the forward flow based on the SYN packet and p0f SYN fingerprints. This element previously was named "osFingerPrint". | ||||||
108-109 | Unassigned | |||||
110 | httpServerString | string | ||||
HTTP Server Response-header field. Contains information about the software used to handle the HTTP Request. | ||||||
111 | httpUserAgent | string | ||||
HTTP User-Agent Request-header field. Contains information about the user agent originating the request. | ||||||
112 | httpGet | string | ||||
HTTP Method Command. Retrieves information identified by the following Request-URI. | ||||||
113 | httpConnection | string | ||||
HTTP Connection header fields. Contains options that are desired for a particular connection. | ||||||
114 | httpVersion | string | ||||
HTTP Version Number. | ||||||
115 | httpReferer | string | ||||
HTTP Referer request-header field. Address (URI) of the resource which the Request-URI was obtained. | ||||||
116 | httpLocation | string | ||||
HTTP Location response-header field. Used to redirect the recipient to a location to complete a request or identify a new resource. | ||||||
117 | httpHost | string | ||||
HTTP Host Request-header. The Internet host and port number of the resource being requested. | ||||||
118 | httpContentLength | string | ||||
HTTP Content-Length header. Indicates the size of the entity-body. | ||||||
119 | httpAge | string | ||||
HTTP Age response-header. Argument is the sender's estimate of the time elapsed since the response. | ||||||
120 | httpAccept | string | ||||
HTTP Accept request-header field. Used to specify certain media types that are acceptable for the response. | ||||||
121 | httpAcceptLanguage | string | ||||
HTTP Accept-Language Request-Header field. Restricts the set of natural languages that preferred. | ||||||
122 | httpContentType | string | ||||
HTTP Content Type entity-header field. Indicates the media type of the entity-body. | ||||||
123 | httpResponse | string | ||||
HTTP Response Status Code. Usually a three-digit number followed by text. | ||||||
124 | pop3TextMessage | string | ||||
POP3 Command and Replies. Contains any command or reply message found in POP3 payload data. | ||||||
125 | ircTextMessage | string | ||||
IRC Chat or Join Message. This field contains any IRC Command and the following arguments. | ||||||
126 | tftpFilename | string | ||||
TFTP Name of File being transferred. | ||||||
127 | tftpMode | string | ||||
Contains the mode of transfer. (netascii, octet, mail) | ||||||
128 | slpVersion | unsigned8 | ||||
SLP Version Number. | ||||||
129 | slpMessageType | unsigned8 | 1-11 | |||
SLP Message Type. This value should be between 1 and 11 and describes the type of SLP message. | ||||||
130 | slpString | string | ||||
Contains the text elements found in an SLP Service Request. | ||||||
131 | ftpReturn | string | ||||
FTP Commands or Replies. | ||||||
132 | ftpUser | string | ||||
FTP User Command Argument. This command will normally be the first command transmitted by the user. | ||||||
133 | ftpPass | string | ||||
FTP Password Command Argument. This command must be preceded by the user name command, and is usually required to complete authentication. | ||||||
134 | ftpType | string | ||||
FTP Data Representation Type. | ||||||
135 | ftpRespCode | string | ||||
FTP Reply. This consists of a three digit number followed by some text. | ||||||
136 | imapCapability | string | ||||
IMAP Capability Command and Response. Captures the listing of capabilities that the server supports. | ||||||
137 | imapLogin | string | ||||
IMAP Login Command. Arguments are user name and password. | ||||||
138 | imapStartTLS | string | ||||
IMAP STARTTLS Command. Captures this command only as no arguments or responses are related. | ||||||
139 | imapAuthenticate | string | ||||
IMAP Authenticate Command. Captures the authentication mechanism name of the server following this command. | ||||||
140 | imapCommand | string | ||||
Captures a variety of IMAP Commands and their arguments. | ||||||
141 | imapExists | string | ||||
IMAP Exists Response. Reports the number of messages in the mailbox. | ||||||
142 | imapRecent | string | ||||
IMAP Recent Response. Reports the number of message with the Recent flag set. | ||||||
143 | rtspURL | string | ||||
RTSP URL. Captures the address of the network resources requested. | ||||||
144 | rtspVersion | string | ||||
RTSP Version Number. | ||||||
145 | rtspReturnCode | string | ||||
RTSP Status-Line. Captures the RTSP Protocol version, numeric status code, and the textual phrase associated with the numeric code. | ||||||
146 | rtspContentLength | string | ||||
RTSP Content-Length Header Field. Contains the length of the content of the method. | ||||||
147 | rtspCommand | string | ||||
RTSP Command. Captures the method to be performed and the Request-URI associated with the method. | ||||||
148 | rtspContentType | string | ||||
RTSP Content Type. | ||||||
149 | rtspTransport | string | ||||
RTSP Transport request header field. Captures the transport protocol used and the parameters that follow. | ||||||
150 | rtspCSeq | string | ||||
RTSP CSeq field. Contains the sequence number for an RTSP request-response pair. | ||||||
151 | rtspLocation | string | ||||
RTSP Location header field. | ||||||
152 | rtspPacketsReceived | string | ||||
RTSP User Agent field. Contains information about the user agent originating the request. | ||||||
153 | rtspUserAgent | string | ||||
RTSP User Agent field. Contains information about the user agent originating the request. | ||||||
154 | rtspJitter | string | ||||
RTSP Jitter Value. | ||||||
155 | sipInvite | string | ||||
SIP Invite Method. Contains the SIP address and SIP Version Number. | ||||||
156 | sipCommand | string | ||||
SIP Command. Contains a SIP Method, SIP address, and SIP Version Number. | ||||||
157 | sipVia | string | ||||
SIP Via contains the SIP Version Number and the address the sender is expecting to receive responses. | ||||||
158 | sipMaxForwards | string | ||||
SIP Max Forwards contains the limit of number of hops a request can make on the way to its destination. | ||||||
159 | sipAddress | string | ||||
SIP Address contains the argument of the To, From, or Contact Header Fields. | ||||||
160 | sipContentLength | string | ||||
SIP Content Length header field. Contains the byte count of the message byte. | ||||||
161 | sipUserAgent | string | ||||
SIP User Agent Header Field. Contains information about the User Agent Client originating the request. | ||||||
162 | smtpHello | string | ||||
SMTP Hello or Extend Hello command. Captures the command and the domain name of the SMTP client. | ||||||
163 | smtpFrom | string | ||||
SMTP Mail Command. Contains the reverse-path of the sender mailbox. | ||||||
164 | smtpTo | string | ||||
The SMTP Recipient (RCPT) Command. Captures the command and the forward-path of the recipient of the mail data. | ||||||
165 | smtpContentType | string | ||||
SMTP Content Type Header Field. | ||||||
166 | smtpSubject | string | ||||
SMTP Subject. Contains the subject of the mail data. | ||||||
167 | smtpFilename | string | ||||
SMTP Filename. Contains the name of the file attached to the mail message. | ||||||
168 | smtpContentDisposition | string | ||||
SMTP Content-Disposition Header field. | ||||||
169 | smtpResponse | string | ||||
SMTP Replies. Consists of a three digit number followed by text. | ||||||
170 | smtpEnhanced | string | ||||
Enhanced SMTP. Contains the ESMTP command with the following argument. | ||||||
171 | sshVersion | string | ||||
SSH Version Number | ||||||
172 | nntpResponse | string | ||||
NNTP Reply. This consists of a three digit status code and text message. | ||||||
173 | nntpCommand | string | ||||
NNTP Command. Contains an NNTP Command and following argument(s). | ||||||
174 | dnsQueryResponse | unsigned8 | ||||
DNS Query/Response header field. This corresponds with the DNS header one bit field, QR. If the message is a query (0), or a response (1). | ||||||
175 | dnsRRType | unsigned16 | ||||
DNS Query/Response Type. This corresponds with the QTYPE field in the DNS Question Section or the TYPE field in the DNS Resource Record Section. This field determines the type of records in the DNS DPI subTemplateList. This element previously was named "dnsQRType". | ||||||
176 | dnsAuthoritative | unsigned8 | ||||
DNS Authoritative header field. This corresponds with the DNS header one bit field, AA. This bit is only valid in responses (when dnsQueryResponse is 1), and specifies that the responding name server is an authority for the domain name in the question section. | ||||||
177 | dnsResponseCode | unsigned8 | ||||
DNS NXDomain or Response Code (RCODE). This corresponds with the DNS RCODE header field. This field will be set to 3 for a Name Error, 2 for a Server Failure, 1 for a Format Error, and 0 for No Error. See [dns-parameters] for other valid values. This element previously was named "dnsNXDomain". | ||||||
178 | dnsSection | unsigned8 | ||||
DNS Resource Record Section Field. This field will be set to 0 if the information is from the Question Section, 1 for the Answer Section, 2 for the Name Server Section, and 3 for the Additional Section. This element previously was named "dnsRRSection". | ||||||
179 | dnsName | string | ||||
A DNS Query or Response Name. This field corresponds with the QNAME field in the DNS Question Section or the NAME field in the DNS Resource Record Section. This element previously was named "dnsQName". | ||||||
180 | dnsCNAME | string | ||||
A domain-name which specificies the canonical or primary name for the owner. This element previously was named "dnsCName". | ||||||
181 | dnsMXPreference | unsigned16 | ||||
Corresponds to the DNS MX Preference field. | ||||||
182 | dnsMXExchange | string | ||||
Corresponds to the DNS MX Exchange field. | ||||||
183 | dnsNSDName | string | ||||
An authoritative name server domain-name. | ||||||
184 | dnsPTRDName | string | ||||
Corresponds to DNS PTR PTRDNAME Field. | ||||||
185 | sslCipher | unsigned32 | ||||
sslCipher is a CipherSuite suggested by the client in the ClientHello Message. | ||||||
186 | sslClientVersion | unsigned8 | ||||
sslClientVersion is the version it supports contained in the initial ClientHello message. | ||||||
187 | sslServerCipher | unsigned32 | ||||
sslServerCipher is the CipherSuite chosen by the server in the ServerHello message. | ||||||
188 | sslCompressionMethod | unsigned8 | ||||
sslCompressionMethod is the compression method chosen by the server in the ServerHello message. | ||||||
189 | sslCertVersion | unsigned8 | ||||
The Certificate Version. This is the value contained in the certificate v1(0), v2(1), v3(2). | ||||||
190 | sslCertSignature | octetArray | ||||
The signature contained in a SSL certificate. This is typically the hashing algorithm identifier. | ||||||
191 | sslCertIssuerCountryName | string | ||||
Country name {id-at 6} of the issuer of an SSL certificate. | ||||||
192 | sslCertIssuerOrgName | string | ||||
Organization name {id-at 10} of the issuer of an SSL certificate. | ||||||
193 | sslCertIssuerOrgUnitName | string | ||||
Organizational unit name {id-at 11} of the issuer of an SSL certificate. | ||||||
194 | sslCertIssuerZipCode | string | ||||
Postal or zip code {id-at 17} of the issuer of an SSL certificate. | ||||||
195 | sslCertIssuerState | string | ||||
State or providence name {id-at 8} of the issuer of an SSL certificate. | ||||||
196 | sslCertIssuerCommonName | string | ||||
Common name {id-at 3} of the issuer of an SSL certificate. | ||||||
197 | sslCertIssuerLocalityName | string | ||||
Locality name {id-at 7} of the issuer of an SSL certificate. | ||||||
198 | sslCertIssuerStreetAddress | string | ||||
Street address {id-at 9} of the issuer of an SSL certificate. | ||||||
199 | dnsTTL | unsigned32 | ||||
DNS Time To Live. This is an unsigned integer that specifies the time interval, in seconds, that the resource record may be cached for. This will contain a value of zero for DNS Queries. | ||||||
200 | sslCertSubjectCountryName | string | ||||
Country name {id-at 6} of the subject of an SSL certificate. This element previously was named "sslCertSubCountryName". | ||||||
201 | sslCertSubjectOrgName | string | ||||
Organization name {id-at 10} of the subject of an SSL certificate. This element previously was named "sslCertSubOrgName". | ||||||
202 | sslCertSubjectOrgUnitName | string | ||||
Organizational unit name {id-at 11} of the subject of an SSL certificate. This element previously was named "sslCertSubOrgUnitName". | ||||||
203 | sslCertSubjectZipCode | string | ||||
Postal or zip code {id-at 17} of the subject of an SSL certificate. This element previously was named "sslCertSubZipCode". | ||||||
204 | sslCertSubjectState | string | ||||
State or providence name {id-at 8} of the subject of an SSL certificate. This element previously was named "sslCertSubState". | ||||||
205 | sslCertSubjectCommonName | string | ||||
Common name {id-at 3} of the subject of an SSL certificate. This element previously was named "sslCertSubCommonName". | ||||||
206 | sslCertSubjectLocalityName | string | ||||
Locality name {id-at 7} of the subject of an SSL certificate. This element previously was named "sslCertSubLocalityName". | ||||||
207 | sslCertSubjectStreetAddress | string | ||||
Street address {id-at 9} of the subject of an SSL certificate. This element previously was named "sslCertSubStreetAddress". | ||||||
208 | dnsTXTData | string | ||||
Corresponds to DNS TXT TXT-DATA field. | ||||||
209 | dnsSOASerial | unsigned32 | ||||
Corresponds to DNS SOA SERIAL Field. | ||||||
210 | dnsSOARefresh | unsigned32 | ||||
Corresponds to DNS SOA REFRESH Field. | ||||||
211 | dnsSOARetry | unsigned32 | ||||
Corresponds to DNS SOA RETRY Field. | ||||||
212 | dnsSOAExpire | unsigned32 | ||||
Corresponds to DNS SOA EXPIRE Field. | ||||||
213 | dnsSOAMinimum | unsigned32 | ||||
Corresponds to DNS SOA MINIMUM Field. | ||||||
214 | dnsSOAMName | string | ||||
Corresponds to DNS SOA MNAME Field. | ||||||
215 | dnsSOARName | string | ||||
Corresponds to DNS SOA RNAME Field. | ||||||
216 | dnsSRVPriority | unsigned16 | ||||
Corresponds to the Priority Field in the DNS SRV Resource Record. | ||||||
217 | dnsSRVWeight | unsigned16 | ||||
Corresponds to the Weight Field in the DNS SRV Resource Record. | ||||||
218 | dnsSRVPort | unsigned16 | ||||
Corresponds to the Port Field in the DNS SRV Resource Record. | ||||||
219 | dnsSRVTarget | string | ||||
Corresponds to the Target Field in the DNS SRV Resource Record. | ||||||
220 | httpCookie | string | ||||
HTTP Cookie Header Field. | ||||||
221 | httpSetCookie | string | ||||
HTTP Set Cookie Header Field. | ||||||
222 | smtpSize | string | ||||
SMTP Size Header Field. Contains the size in bytes of the mail data. | ||||||
223 | mysqlUsername | string | ||||
The username seen when authenticating to a MySQL server. | ||||||
224 | mysqlCommandCode | unsigned8 | 0-28 | |||
MySQL Command Code. This number should be between 0 and 28. | ||||||
225 | mysqlCommandText | string | ||||
MySQL Command Text. For example, this can be a SELECT, INSERT, DELETE statement. | ||||||
226 | dnsId | unsigned16 | ||||
DNS Transaction ID. This identifier is used by the requester to match up replies to outstanding queries. This element previously was named "dnsID". | ||||||
227 | dnsAlgorithm | unsigned8 | ||||
Deprecated in favor of ID 6871/423 dnsDNSKEYAlgorithm, 6871/433 dnsDSAlgorithm, 6871/435 dnsNSEC3Algorithm, 6871/441 dnsNSEC3PARAMAlgorithm, and 6871/447 dnsRRSIGAlgorithm. The Hash Algorithm field in various DNSSEC records. | ||||||
228 | dnsKeyTag | unsigned16 | ||||
Deprecated in favor of 6871/434 dnsDSKeyTag and 6871/448 dnsRRSIGKeyTag. The Key Tag field in the DS RR. | ||||||
229 | dnsRRSIGSigner | string | ||||
The Signer's Name field in the DNS RRSIG RR. This element previously was named "dnsSigner". | ||||||
230 | dnsRRSIGSignature | octetArray | ||||
The Signature field in the DNS RRSIG RR. Contains the cryptographic signature that covers the dnsName (6871/179) field. This element previously was named "dnsSignature". | ||||||
231 | dnsDSDigest | octetArray | ||||
The Digest field of the DNS DS RR. This element previously was named "dnsDigest". | ||||||
232 | dnsDNSKEYPublicKey | octetArray | ||||
DNSSEC uses public key cryptography to sign and authenticate DNS resource record sets. This field holds the public key. The format depends on the algorithm of the key. This element previously was named "dnsPublicKey". | ||||||
233 | dnsSalt | octetArray | ||||
Deprecated in favor of 6871/439 dnsNSEC3Salt and 6871/444 dnsNSEC3PARAMSalt. The Salt Field in the DNSSEC NSEC3 or NSEC3PARAM RR. | ||||||
234 | dnsHashData | octetArray | ||||
Deprecated in favor of 6871/438 dnsNSEC3NextHashedOwnerName and 6871/445 dnsNSECNextDomainName. The Next Hashed Owner Name in the DNSSEC NSEC3 RR and Next Domain Name field in the DNSNSEC RR. | ||||||
235 | dnsIterations | unsigned16 | ||||
Deprecated in favor of 6871/437 dnsNSEC3Iterations and 6871/443 dnsNSEC3PARAMIterations. The Iterations field in the DNSSEC NSEC3 or NSEC3PARAM RR. | ||||||
236 | dnsRRSIGSignatureExpiration | unsigned32 | ||||
The Signature Expiration field in a DNS RRSIG RR. The Expiration and Inception fields specify a validity period for the signature. This element previously was named "dnsSignatureExpiration". | ||||||
237 | dnsRRSIGSignatureInception | unsigned32 | ||||
The Signature Inception field in a RRSIG RR. The Expiration and Inception fields specify a validity period for the signature. This element previously was named "dnsSignatureInception". | ||||||
238 | dnsDSDigestType | unsigned8 | ||||
The Digest Type field in a DNS DS RR which identifes the algorithm used to construct the digest. This element previously was named "dnsDigestType". | ||||||
239 | dnsRRSIGLabels | unsigned8 | ||||
The Labels field in a DNS RRSIG RR. Specifies the number of labels in the original RRSIG resource record owner name. This element previously was named "dnsLabels". | ||||||
240 | dnsRRSIGTypeCovered | unsigned16 | ||||
The Type Covered field in a DNS RRSIG RR. This element previously was named "dnsTypeCovered". | ||||||
241 | dnsDNSKEYFlags | unsigned16 | flags | |||
The Flags field in the DNS DNSKEY Resource Record. Certain bits determine if the key is a zone key or should be used for a secure entry point. This element previously was named "dnsFlags". | ||||||
242 | dhcpFingerprint | string | ||||
Reversible as reverseDhcpFingerprint (ElementID 16626). The DHCP fingerprint. This will be the description of the OS. This element previously was named "dhcpFingerPrint". | ||||||
243 | dhcpVendorCode | string | ||||
Reversible as reverseDhcpVendorCode (ElementID 16627). The DHCP vendor class ID found in Option 60 of the DHCP packet. This field may help further identify the operating system of the sender. | ||||||
244 | sslCertSerialNumber | octetArray | ||||
The Serial Number from the X.509 certificate. | ||||||
245 | sslObjectType | unsigned8 | ||||
For the Issuer and Subject subTemplateLists, yaf only parses objects that are members of the id-at arc {joint-iso-ccitt(2) ds(5) 4}, pkcs-9 {iso(1) member-body (2) us(840) rsadsi(113459) pkcs(1) 9}, and LDAP dc 0.9.2342.19200300.100.1.25. This field will not contain the full object identfier, it will just contain the member id. For example, for an issuer common name, sslObjectType will contain 3. Below is a list of common objects in an X.509 RelativeDistinguishedName Sequence for X.509 Certificates: pkcs-9-emailAddress {pkcs-9 1} id-at-commonName {id-at 3} id-at-countryName {id-at 6} id-at-localityName {id-at 7} id-at-stateOrProvinceName {id-at 8} id-at-streetAddress {id-at 9} id-at-organizationName {id-at 10} id-at-organizationalUnitName {id-at 11} id-at-title {id-at 12} id-at-postalCode {id-at 17} 0.9.2342.19200300.100.1.25 {dc 25} id-at-name {id-at 41} | ||||||
246 | sslObjectValue | octetArray | ||||
The bit strings associated with sslObjectType. | ||||||
247 | sslCertValidityNotBefore | string | ||||
The notBefore field in the Validity Sequence of the X.509 Certificate. | ||||||
248 | sslCertValidityNotAfter | string | ||||
The notAfter field in the Validity Sequence of the X.509 Certificate. | ||||||
249 | sslPublicKeyAlgorithm | octetArray | ||||
The algorithm, encoded in ASN.1, in the SubjectPublicKeyInfo Sequence of the X.509 Certificate. | ||||||
250 | sslPublicKeyLength | unsigned16 | ||||
The length of the public key in the X.509 Certificate. | ||||||
251 | smtpDate | string | ||||
SMTP Date Field. | ||||||
252 | httpAuthorization | string | ||||
HTTP Authorization Header Field. | ||||||
253 | httpVia | string | ||||
HTTP Via Header Field. | ||||||
254 | httpXForwardedFor | string | ||||
HTTP X-Forwarded-For Header Field. This element previously was named "httpX-Forwarded-For". | ||||||
255 | httpExpires | string | ||||
HTTP Expires Header Field. | ||||||
256 | httpRefresh | string | ||||
HTTP Refresh Header Field. | ||||||
257 | httpIMEI | string | ||||
HTTP International Mobile Station Equipment Identity ID. | ||||||
258 | httpIMSI | string | ||||
HTTP International Mobile Subscriber Identity | ||||||
259 | httpMSISDN | string | ||||
HTTP MSISDN number, a telephone number for the SIM card in a mobile/cellular phone. | ||||||
260 | httpSubscriber | string | ||||
HTTP Mobile Subscriber Information. | ||||||
261 | httpAcceptCharset | string | ||||
HTTP Accept Charset Header Field. | ||||||
262 | httpAcceptEncoding | string | ||||
HTTP Accept Encoding Header Field. | ||||||
263 | httpAllow | string | ||||
HTTP Allow Header Field. | ||||||
264 | httpDate | string | ||||
HTTP Date Header Field. | ||||||
265 | httpExpect | string | ||||
HTTP Expect Header Field. | ||||||
266 | httpFrom | string | ||||
HTTP From Header Field. | ||||||
267 | httpProxyAuthentication | string | ||||
HTTP Proxy Authentication Field. | ||||||
268 | httpUpgrade | string | ||||
HTTP Upgrade Header Field. | ||||||
269 | httpWarning | string | ||||
HTTP Warning Header Field. | ||||||
270 | httpDNT | string | ||||
HTTP DNT Header Field. | ||||||
271 | httpXForwardedProto | string | ||||
HTTP X-Forwarded-Proto Header Field. This element previously was named "httpX-Forwarded-Proto". | ||||||
272 | httpXForwardedHost | string | ||||
HTTP X-Forwarded-Host Header Field. This element previously was named "httpX-Forwarded-Host". | ||||||
273 | httpXForwardedServer | string | ||||
HTTP X-Forwarded-Server Header Field. This element previously was named "httpX-Forwarded-Server". | ||||||
274 | httpXDeviceId | string | ||||
HTTP X-Device ID Header Field. This element previously was named "httpX-DeviceID". | ||||||
275 | httpXProfile | string | ||||
HTTP X-Profile Header Field. This element previously was named "httpX-Profile". | ||||||
276 | httpLastModified | string | ||||
HTTP Last Modified Header Field. | ||||||
277 | httpContentEncoding | string | ||||
HTTP Content Encoding Header Field. | ||||||
278 | httpContentLanguage | string | ||||
HTTP Content Language Header Field. | ||||||
279 | httpContentLocation | string | ||||
HTTP Content Location Header Field. | ||||||
280 | httpXUaCompatible | string | ||||
HTTP X-UA-Compatible Header Field. This element previously was named "httpX-UA-Compatible". | ||||||
281 | dnp3SourceAddress | unsigned16 | ||||
The DNP3 Source Address found in the Data Link Layer of the DNP Header. | ||||||
282 | dnp3DestinationAddress | unsigned16 | ||||
The DNP3 Destination Address found in the Data Link Layer of the DNP Header. | ||||||
283 | dnp3Function | unsigned8 | ||||
The DNP3 Function Code found in the first byte of the Application Layer. | ||||||
284 | dnp3ObjectData | octetArray | ||||
The pattern captured from the DNP3 regular expression. | ||||||
285 | modbusData | octetArray | ||||
Data associated with the Modbus protocol, a widely used network messaging protocol used in industrial manufacturing. | ||||||
286 | enipData | octetArray | ||||
Data associated with EtherNet/IP (ENIP), a protocol used in industrial automation applications. This element previously was named "ethernetIPData". | ||||||
287 | rtpPayloadType | unsigned8 | ||||
Reversible as reverseRtpPayloadType (ElementID 16671). The payload type in the RTP header of the first payload in the forward direction. | ||||||
288 | sslRecordVersion | unsigned16 | ||||
sslRecordVersion is the version of ssl or tls that was used in the flow. | ||||||
289 | mptcpInitialDataSequenceNumber | unsigned64 | ||||
The initial data sequence number found in the MPTCP Data Sequence Signal (DSS) Option of a flow. (See Multipath TCP, [RFC8684].) | ||||||
290 | mptcpReceiverToken | unsigned32 | identifier | |||
The token used to identify an MPTCP connection over multiple subflows. This value is found in the MP_JOIN TCP Option for the initial SYN of a subflow. | ||||||
291 | mptcpMaximumSegmentSize | unsigned16 | ||||
The maximum segment size reported in the Maximum Segment Size TCP Option captured from an MPTCP flow. | ||||||
292 | mptcpAddressId | unsigned8 | identifier | |||
The address identifier of the subflow found in the SYN/ACK of an MP_JOIN operation captured from an MPTCP flow. This element previously was named "mptcpAddressID". | ||||||
293 | mptcpFlags | unsigned8 | flags | |||
Various MPTCP Values: Bit 1: Priority was changed during the life of the subflow (MP_PRIO was seen). Bit 2: Subflow has priority at setup (backup flag was not set at initialization). Bit 3: Subflow failed. (MP_FAIL option was seen). Bit 4: Subflow experienced fast close. (MP_FASTCLOSE options was seen). | ||||||
294 | sslServerName | string | ||||
The server name from the SSL/TLS Client Hello. This is typically the name of the server that the client is connecting to. | ||||||
295 | sslCertificateHash | octetArray | ||||
The hash of the X.509 certificate. | ||||||
296 | sslBinaryCertificate | octetArray | ||||
A binary dump of the full X.509 certificate. This element previously was named "sslCertificate". | ||||||
297 | dhcpOption | unsigned8 | ||||
The list of requested parameters found in DHCP Option 55. | ||||||
298 | sslCertificateSHA1 | octetArray | ||||
The SHA1 hash of a complete SSL certificate. | ||||||
299 | sslCertificateMD5 | octetArray | ||||
The MD5 hash of a complete SSL certificate. | ||||||
300 | ndpiL7Protocol | unsigned16 | identifier | |||
The protocol as determined by analysis with nDPI, the ntop-maintained superset of the OpenDPI library. This element previously was named "nDPIL7Protocol". | ||||||
301 | ndpiL7SubProtocol | unsigned16 | identifier | |||
The subprotocol as determined by analysis with nDPI, the ntop-maintained superset of the OpenDPI library. This element previously was named "nDPIL7SubProtocol". | ||||||
302 | dnsA | ipv4Address | ||||
An IPv4 address that specifies an address for a DNS host name. This element previously was named "rrIPv4". | ||||||
303 | dnsAAAA | ipv6Address | ||||
An IPv6 address that specifies an address for a DNS host name. This element previously was named "rrIPv6". | ||||||
304 | dnsDNSKEYProtocol | unsigned8 | ||||
The Protocol field from a DNS DNSKEY Resource Record. This element previously was named "DNSKEY_protocolIdentifier" and "dnsKeyProtocolIdentifier". | ||||||
305 | pipelineDNSARecord | subTemplateList | list | |||
Element holding an entire DNS A record, which is a sub template list when emitted from YAF. This is used in Analysis Pipeline for fast flux. This element previously was named "DNS_A_Record". | ||||||
306 | pipelineDNSAAAARecord | subTemplateList | list | |||
Element holding an entire DNS AAAA record, which is a sub template list when emitted from YAF. This is used in Analysis Pipeline for fast flux. This element previously was named "DNS_AAAA_Record". | ||||||
307 | pipelineDNSResourceRecord | subTemplateList | list | |||
Element holding an entire DNS resource record, which is a sub template list when emitted from YAF. This is used in Analysis Pipeline. This element previously was named "DNS_RESOURCE_RECORD". | ||||||
308 | sslCertIssuerTitle | string | ||||
Title {id-at 12} of the issuer of an SSL certificate. | ||||||
309 | sslCertSubjectTitle | string | ||||
Title {id-at 12} of the subject of an SSL certificate. This element previously was named "sslCertSubTitle". | ||||||
310 | sslCertIssuerName | string | ||||
Name {id-at 41} of the issuer of an SSL certificate. | ||||||
311 | sslCertSubjectName | string | ||||
Name {id-at 41} of the subject of an SSL certificate. This element previously was named "sslCertSubName". | ||||||
312 | sslCertIssuerEmailAddress | string | ||||
Email address {pkcs-9 1} of the issuer of an SSL certificate. | ||||||
313 | sslCertSubjectEmailAddress | string | ||||
Email address {pkcs-9 1} of the subject of an SSL certificate. This element previously was named "sslCertSubEmailAddress". | ||||||
314 | sslCertIssuerDomainComponent | string | ||||
LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the issuer of an SSL certificate. | ||||||
315 | sslCertSubjectDomainComponent | string | ||||
LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the subject of an SSL certificate. This element previously was named "sslCertSubDomainComponent". | ||||||
316 | sslCertExtSubjectKeyIdent | octetArray | ||||
SSL extension value holding the subject key identifer, {id-ce 14} subjectKeyIdentifier. | ||||||
317 | sslCertExtKeyUsage | octetArray | ||||
SSL extension value holding the key usage, {id-ce 15} keyUsage. | ||||||
318 | sslCertExtPrivKeyUsagePeriod | octetArray | ||||
SSL extension value holding the usage period for the private key, {id-ce 16} privateKeyUsagePeriod. | ||||||
319 | sslCertExtSubjectAltName | octetArray | ||||
SSL extension value holding the subject's alternative names, {id-ce 17} subjectAltName. | ||||||
320 | sslCertExtIssuerAltName | octetArray | ||||
SSL extension value holding the issuer's alternative names, {id-ce 18} issuerAltName. | ||||||
321 | sslCertExtCertIssuer | octetArray | ||||
SSL extension value holding the certificate issuer associated with an entry in an indirect CRL, {id-ce 29} certificateIssuer. | ||||||
322 | sslCertExtCrlDistribution | octetArray | ||||
SSL extension value holding the certificate revocation list (CRL) distribution points, {id-ce 31} crlDistributionPoints. | ||||||
323 | sslCertExtCertPolicies | octetArray | ||||
SSL extension value holding the certificate policies, {id-ce 32} certificatePolicies. | ||||||
324 | sslCertExtAuthorityKeyIdent | octetArray | ||||
SSL extension value holding the authority key identifier, {id-ce 35} authorityKeyIdentifier. | ||||||
325 | sslCertExtExtendedKeyUsage | octetArray | ||||
SSL extension value holding the extended key usage {id-ce 37}, extKeyUage. | ||||||
326 | smtpStartTLS | unsigned8 | ||||
Element indicating whether or not the SMTP session sent the START TLS command. | ||||||
327 | smtpKey | string | ||||
SMTP Header key string. | ||||||
328 | smtpValue | string | ||||
SMTP Header value string. | ||||||
329 | smtpURL | string | ||||
Element for URLs captured in the SMTP message body | ||||||
330 | smtpMessageSize | unsigned32 | ||||
Element containing the value of the SMTP message size. | ||||||
331 | smtpResponseList | basicList | ||||
A basicList of smtpResponse (CERT/169) elements. | ||||||
332 | smtpToList | basicList | ||||
A basicList of smtpTo (CERT/164) elements. | ||||||
333 | smtpFromList | basicList | ||||
A basicList of smtpFrom (CERT/163) elements. | ||||||
334 | smtpFilenameList | basicList | ||||
A basicList of smtpFilename (CERT/167) elements. | ||||||
335 | smtpURLList | basicList | ||||
A basicList of smtpURL (CERT/329) elements. | ||||||
336 | smtpMessageList | subTemplateList | list | |||
A sub template list holding email data in smtpMessage templates. | ||||||
337 | smtpHeaderList | subTemplateList | list | |||
A sub template list holding email header data in smtpHeader templates. | ||||||
338 | httpServerStringList | basicList | ||||
A basicList of httpServerString (CERT/110) elements. | ||||||
339 | httpUserAgentList | basicList | ||||
A basicList of httpUserAgent (CERT/111) elements. | ||||||
340 | httpGetList | basicList | ||||
A basicList of httpGet (CERT/112) elements. | ||||||
341 | httpConnectionList | basicList | ||||
A basicList of httpConnection (CERT/113) elements. | ||||||
342 | httpVersionList | basicList | ||||
A basicList of httpVersion (CERT/114) elements. | ||||||
343 | httpRefererList | basicList | ||||
A basicList of httpReferer (CERT/115) elements. | ||||||
344 | httpLocationList | basicList | ||||
A basicList of httpLocation (CERT/116) elements. | ||||||
345 | httpHostList | basicList | ||||
A basicList of httpHost (CERT/117) elements. | ||||||
346 | httpContentLengthList | basicList | ||||
A basicList of httpContentLength (CERT/118) elements. | ||||||
347 | httpAgeList | basicList | ||||
A basicList of httpAge (CERT/119) elements. | ||||||
348 | httpAcceptList | basicList | ||||
A basicList of httpAccept (CERT/120) elements. | ||||||
349 | httpAcceptLanguageList | basicList | ||||
A basicList of httpAcceptLanguage (CERT/121) elements. | ||||||
350 | httpContentTypeList | basicList | ||||
A basicList of httpContentType (CERT/122) elements. | ||||||
351 | httpResponseList | basicList | ||||
A basicList of httpResponse (CERT/123) elements. | ||||||
352 | pop3TextMessageList | basicList | ||||
A basicList of pop3TextMessage (CERT/124) elements. | ||||||
353 | ircTextMessageList | basicList | ||||
A basicList of ircTextMessage (CERT/125) elements. | ||||||
354 | slpStringList | basicList | ||||
A basicList of slpString (CERT/130) elements. | ||||||
355 | ftpReturnList | basicList | ||||
A basicList of ftpReturn (CERT/131) elements. | ||||||
356 | ftpUserList | basicList | ||||
A basicList of ftpUser (CERT/132) elements. | ||||||
357 | ftpPassList | basicList | ||||
A basicList of ftpPass (CERT/133) elements. | ||||||
358 | ftpTypeList | basicList | ||||
A basicList of ftpType (CERT/134) elements. | ||||||
359 | ftpRespCodeList | basicList | ||||
A basicList of ftpRespCode (CERT/135) elements. | ||||||
360 | imapCapabilityList | basicList | ||||
A basicList of imapCapability (CERT/136) elements. | ||||||
361 | imapLoginList | basicList | ||||
A basicList of imapLogin (CERT/137) elements. | ||||||
362 | imapStartTLSList | basicList | ||||
A basicList of imapStartTLS (CERT/138) elements. | ||||||
363 | imapAuthenticateList | basicList | ||||
A basicList of imapAuthenticate (CERT/139) elements. | ||||||
364 | imapCommandList | basicList | ||||
A basicList of imapCommand (CERT/140) elements. | ||||||
365 | imapExistsList | basicList | ||||
A basicList of imapExists (CERT/141) elements. | ||||||
366 | imapRecentList | basicList | ||||
A basicList of imapRecent (CERT/142) elements. | ||||||
367 | rtspURLList | basicList | ||||
A basicList of rtspURL (CERT/143) elements. | ||||||
368 | rtspVersionList | basicList | ||||
A basicList of rtspVersion (CERT/144) elements. | ||||||
369 | rtspReturnCodeList | basicList | ||||
A basicList of rtspReturnCode (CERT/145) elements. | ||||||
370 | rtspContentLengthList | basicList | ||||
A basicList of rtspContentLength (CERT/146) elements. | ||||||
371 | rtspCommandList | basicList | ||||
A basicList of rtspCommand (CERT/147) elements. | ||||||
372 | rtspContentTypeList | basicList | ||||
A basicList of rtspContentType (CERT/148) elements. | ||||||
373 | rtspTransportList | basicList | ||||
A basicList of rtspTransport (CERT/149) elements. | ||||||
374 | rtspCSeqList | basicList | ||||
A basicList of rtspCSeq (CERT/150) elements. | ||||||
375 | rtspLocationList | basicList | ||||
A basicList of rtspLocation (CERT/151) elements. | ||||||
376 | rtspPacketsReceivedList | basicList | ||||
A basicList of rtspPacketsReceived (CERT/152) elements. | ||||||
377 | rtspUserAgentList | basicList | ||||
A basicList of rtspUserAgent (CERT/153) elements. | ||||||
378 | rtspJitterList | basicList | ||||
A basicList of rtspJitter (CERT/154) elements. | ||||||
379 | sipInviteList | basicList | ||||
A basicList of sipInvite (CERT/155) elements. | ||||||
380 | sipCommandList | basicList | ||||
A basicList of sipCommand (CERT/156) elements. | ||||||
381 | sipViaList | basicList | ||||
A basicList of sipVia (CERT/157) elements. | ||||||
382 | sipMaxForwardsList | basicList | ||||
A basicList of sipMaxForwards (CERT/158) elements. | ||||||
383 | sipAddressList | basicList | ||||
A basicList of sipAddress (CERT/159) elements. | ||||||
384 | sipContentLengthList | basicList | ||||
A basicList of sipContentLength (CERT/160) elements. | ||||||
385 | sipUserAgentList | basicList | ||||
A basicList of sipUserAgent (CERT/161) elements. | ||||||
386 | sshVersionList | basicList | ||||
A basicList of sshVersion (CERT/171) elements. | ||||||
387 | nntpResponseList | basicList | ||||
A basicList of nntpResponse (CERT/172) elements. | ||||||
388 | nntpCommandList | basicList | ||||
A basicList of nntpCommand (CERT/173) elements. | ||||||
389 | sslCipherList | basicList | ||||
A basicList of sslCipher (CERT/185) elements. | ||||||
390 | httpCookieList | basicList | ||||
A basicList of httpCookie (CERT/220) elements. | ||||||
391 | httpSetCookieList | basicList | ||||
A basicList of httpSetCookie (CERT/221) elements. | ||||||
392 | httpAuthorizationList | basicList | ||||
A basicList of httpAuthorization (CERT/252) elements. | ||||||
393 | httpViaList | basicList | ||||
A basicList of httpVia (CERT/253) elements. | ||||||
394 | httpXForwardedForList | basicList | ||||
A basicList of httpX-Forwarded-For (CERT/254) elements. This element previously was named "httpX-Forwarded-ForList". | ||||||
395 | httpExpiresList | basicList | ||||
A basicList of httpExpires (CERT/255) elements. | ||||||
396 | httpRefreshList | basicList | ||||
A basicList of httpRefresh (CERT/256) elements. | ||||||
397 | httpIMEIList | basicList | ||||
A basicList of httpIMEI (CERT/257) elements. | ||||||
398 | httpIMSIList | basicList | ||||
A basicList of httpIMSI (CERT/258) elements. | ||||||
399 | httpMSISDNList | basicList | ||||
A basicList of httpMSISDN (CERT/259) elements. | ||||||
400 | httpSubscriberList | basicList | ||||
A basicList of httpSubscriber (CERT/260) elements. | ||||||
401 | httpAcceptCharsetList | basicList | ||||
A basicList of httpAcceptCharset (CERT/261) elements. | ||||||
402 | httpAllowList | basicList | ||||
A basicList of httpAllow (CERT/263) elements. | ||||||
403 | httpDateList | basicList | ||||
A basicList of httpDate (CERT/264) elements. | ||||||
404 | httpExpectList | basicList | ||||
A basicList of httpExpect (CERT/265) elements. | ||||||
405 | httpFromList | basicList | ||||
A basicList of httpFrom (CERT/266) elements. | ||||||
406 | httpProxyAuthenticationList | basicList | ||||
A basicList of httpProxyAuthentication (CERT/267) elements. | ||||||
407 | httpUpgradeList | basicList | ||||
A basicList of httpUpgrade (CERT/268) elements. | ||||||
408 | httpWarningList | basicList | ||||
A basicList of httpWarning (CERT/269) elements. | ||||||
409 | httpDNTList | basicList | ||||
A basicList of httpDNT (CERT/270) elements. | ||||||
410 | httpXForwardedProtoList | basicList | ||||
A basicList of httpXForwardedProto (CERT/271) elements. This element previously was named "httpX-Forwarded-ProtoList". | ||||||
411 | httpXForwardedHostList | basicList | ||||
A basicList of httpXForwardedHost (CERT/272) elements. This element previously was named "httpX-Forwarded-HostList". | ||||||
412 | httpXForwardedServerList | basicList | ||||
A basicList of httpXForwardedServer (CERT/273) elements. This element previously was named "httpX-Forwarded-ServerList". | ||||||
413 | httpXDeviceIdList | basicList | ||||
A basicList of httpXDeviceId (CERT/274) elements. This element previously was named "httpX-DeviceIDList". | ||||||
414 | httpXProfileList | basicList | ||||
A basicList of httpXProfile (CERT/275) elements. This element previously was named "httpX-ProfileList". | ||||||
415 | httpLastModifiedList | basicList | ||||
A basicList of httpLastModified (CERT/276) elements. | ||||||
416 | httpContentEncodingList | basicList | ||||
A basicList of httpContentEncoding (CERT/277) elements. | ||||||
417 | httpContentLanguageList | basicList | ||||
A basicList of httpContentLanguage (CERT/278) elements. | ||||||
418 | httpContentLocationList | basicList | ||||
A basicList of httpContentLocation (CERT/279) elements. | ||||||
419 | httpXUaCompatibleList | basicList | ||||
A basicList of httpXUACompatible (CERT/280) elements. This element previously was named "httpX-UA-CompatibleList". | ||||||
420 | modbusDataList | basicList | ||||
A basicList of modbusData (CERT/285) elements. | ||||||
421 | enipDataList | basicList | ||||
A basicList of enipData (6871/286) elements. This element previously was named "ethernetIPDataList". | ||||||
422 | dhcpOptionList | basicList | ||||
Reversible as reverseDhcpOptionList (ElementID 16806). A basicList of dhcpOption (6871/297) elements. | ||||||
423 | dnsDNSKEYAlgorithm | unsigned8 | ||||
The cryptographic algorithm used for the public key in a DNS DNSKEY RR. | ||||||
424 | mysqlCommandTextCodeList | subTemplateList | ||||
A subTemplateList of mysqlCommandText mysqlCommandCode pairs. | ||||||
425 | sslCertList | subTemplateList | ||||
A subTemplateList of yaf_ssl_cert templates. | ||||||
426 | sslIssuerFieldList | subTemplateList | ||||
A subTemplateList of sslCertificate values. | ||||||
427 | sslSubjectFieldList | subTemplateList | ||||
A subTemplateList of sslCertificate values. | ||||||
428 | sslExtensionFieldList | subTemplateList | ||||
A subTemplateList of sslCertificate values. | ||||||
429 | sslBinaryCertificateList | basicList | ||||
A basicList of sslBinaryCertificate (CERT/296) elements. | ||||||
430 | dnp3RecordList | subTemplateList | ||||
A subTemplateList holding the DNP3 values | ||||||
431 | dnsDetailRecordList | subTemplateList | ||||
A subTemplateList of yaf_dns_rr templates. This element previously was named "dnsQRDetailRecordList". | ||||||
432 | yafDPIList | subTemplateList | ||||
A subTemplateList of deep packet inspection data generated by yaf. | ||||||
433 | dnsDSAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS DS RR. It holds the algorithm used by the DNS DNSKEY RR to which this DS RR refers. | ||||||
434 | dnsDSKeyTag | unsigned16 | ||||
The Key Tag field in a DNS DS RR. | ||||||
435 | dnsNSEC3Algorithm | unsigned8 | ||||
The Algorithm field in a DNS NSEC3 RR. | ||||||
436 | dnsNSEC3Flags | unsigned8 | ||||
The Flags field in a DNS NSEC3 RR. | ||||||
437 | dnsNSEC3Iterations | unsigned16 | ||||
The Iterations field in a DNS NSEC3 RR. | ||||||
438 | dnsNSEC3NextHashedOwnerName | octetArray | ||||
The Next Hashed Owner Name field in a DNS NSEC3 RR. | ||||||
439 | dnsNSEC3Salt | octetArray | ||||
The Salt field in a DNS NSEC3 RR. | ||||||
440 | dnsNSEC3TypeBitMaps | octetArray | ||||
The Type Bit Maps field in a DNS NSEC3 RR. | ||||||
441 | dnsNSEC3PARAMAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS NSEC3PARAM RR. | ||||||
442 | dnsNSEC3PARAMFlags | unsigned8 | ||||
The Flags field in a DNS NSEC3PARAM RR. | ||||||
443 | dnsNSEC3PARAMIterations | unsigned16 | ||||
The Iterations field in a DNS NSEC3PARAM RR. | ||||||
444 | dnsNSEC3PARAMSalt | octetArray | ||||
The Salt field in a DNS NSEC3PARAM RR. | ||||||
445 | dnsNSECNextDomainName | octetArray | ||||
The Next Domain Name field in a DNS NSEC RR. | ||||||
446 | dnsNSECTypeBitMaps | octetArray | ||||
The Type Bit Maps field in a DNS NSEC RR. | ||||||
447 | dnsRRSIGAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS RRSIG RR. | ||||||
448 | dnsRRSIGKeyTag | unsigned16 | ||||
The Key Tag field in a DNS RRSIG RR. | ||||||
449 | dnsRRSIGOriginalTTL | unsigned32 | ||||
The Original TTL field in a DNS RRSIG RR. | ||||||
450 | sslCertIssuerOrgNameList | basicList | ||||
A basicList of sslCertIssuerOrgName (CERT/192) elements, each holding an organization name {id-at 10} of the issuer of an SSL certificate. | ||||||
451 | sslCertIssuerOrgUnitNameList | basicList | ||||
A basicList of sslCertIssuerOrgUnitName (CERT/193) elements, each holding an organizational unit name {id-at 11} of the issuer of an SSL certificate. | ||||||
452 | sslCertIssuerCommonNameList | basicList | ||||
A basicList of sslCertIssuerCommonName (CERT/196) elements, each holding a common name {id-at 3} of the issuer of an SSL certificate. | ||||||
453 | sslCertIssuerStreetAddressList | basicList | ||||
A basicList of sslCertIssuerStreetAddress (CERT/198) elements, each holding a street address {id-at 9} of the issuer of an SSL certificate. | ||||||
454 | sslCertSubjectOrgNameList | basicList | ||||
A basicList of sslCertSubjectOrgName (CERT/201) elements, each holding an organization name {id-at 10} of the subject of an SSL certificate. | ||||||
455 | sslCertSubjectOrgUnitNameList | basicList | ||||
A basicList of sslCertSubjectOrgUnitName (CERT/202) elements, each holding an organizational unit name {id-at 11} of the subject of an SSL certificate. | ||||||
456 | sslCertSubjectCommonNameList | basicList | ||||
A basicList of sslCertSubjectCommonName (CERT/205) elements, each holding a common name {id-at 3} of the subject of an SSL certificate. | ||||||
457 | sslCertSubjectStreetAddressList | basicList | ||||
A basicList of sslCertSubjectStreetAddress (CERT/207) elements, each holding a street address {id-at 9} of the subject of an SSL certificate. | ||||||
458 | sslCertIssuerDomainComponentList | basicList | ||||
A basicList of sslCertIssuerDomainComponent (CERT/314) elements, each holding an LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the issuer of an SSL certificate. | ||||||
459 | sslCertSubjectDomainComponentList | basicList | ||||
A basicList of sslCertSubjectDomainComponent (CERT/315) elements, each holding an LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the subject of an SSL certificate. | ||||||
460 | sslCertValidityTotalDays | signed32 | ||||
The whole number of days the certificate was valid (sslCertValidityNotAfter - sslCertValidityNotBefore). | ||||||
461 | sslCertValidityDaysTimeOfUse | signed32 | ||||
The whole number of days the certificate was valid at the time it was used (flowStartMilliseconds - sslCertValidityNotBefore). | ||||||
462 | sslCertificateSHA256 | octetArray | ||||
The SHA256 hash of a complete SSL certificate. | ||||||
463-499 | Unassigned | |||||
500 | smallPacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseSmallPacketCount (ElementID 16884). The number of packets that contain less than 60 bytes of payload. | ||||||
501 | nonEmptyPacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseNonEmptyPacketCount (ElementID 16885). The number of packets that contain at least 1 byte of payload. | ||||||
502 | dataByteCount | unsigned64 | totalCounter | octets | ||
Reversible as reverseDataByteCount (ElementID 16886). Total bytes transferred as payload. | ||||||
503 | averageInterarrivalTime | unsigned64 | milliseconds | |||
Reversible as reverseAverageInterarrivalTime (ElementID 16887). Average number of milliseconds between packets. | ||||||
504 | standardDeviationInterarrivalTime | unsigned64 | milliseconds | |||
Reversible as reverseStandardDeviationInterarrivalTime (ElementID 16888). Standard deviation of the interarrival time for up to the first ten packets. | ||||||
505 | firstNonEmptyPacketSize | unsigned16 | quantity | octets | ||
Reversible as reverseFirstNonEmptyPacketSize (ElementID 16889). Payload length of the first non-empty packet. | ||||||
506 | maxPacketSize | unsigned16 | quantity | octets | ||
Reversible as reverseMaxPacketSize (ElementID 16890). The largest payload length transferred in the flow. | ||||||
507 | firstEightNonEmptyPacketDirections | unsigned8 | flags | |||
Reversible as reverseFirstEightNonEmptyPacketDirections (ElementID 16891). Represents directionality for the first 8 non-empty packets. 0 for forward direction, 1 for reverse direction. | ||||||
508 | standardDeviationPayloadLength | unsigned16 | octets | |||
Reversible as reverseStandardDeviationPayloadLength (ElementID 16892). The standard deviation of the payload length for up to the first 10 non empty packets. | ||||||
509 | tcpUrgentCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseTcpUrgentCount (ElementID 16893). The number of TCP packets that have the URGENT Flag set. | ||||||
510 | largePacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseLargePacketCount (ElementID 16894). The number of packets that contain at least 220 bytes of payload. | ||||||
511-549 | Unassigned | |||||
550 | certToolTombstoneId | unsigned32 | identifier | |||
An identifier of a tombstone record that is unique within the process that initially generates the record. This element previously was named "tombstoneId". | ||||||
551 | certToolExporterConfiguredId | unsigned16 | identifier | |||
An identifier for this process chosen by the user. This element previously was named "exporterConfiguredId". | ||||||
552 | certToolExporterUniqueId | unsigned16 | identifier | |||
A pseudo-random number to identify this exporting process. This element previously was named "exporterUniqueId". | ||||||
553 | certToolId | unsigned32 | identifier | 1-6 | ||
An identifier for each CERT tool. 1 - YAF 2 - super_mediator 3 - SiLK rwflowpack 4 - SiLK rwflowappend 5 - Mothra IPFIX Packer 6 - Analysis Pipeline | ||||||
554 | certToolTombstoneAccessList | subTemplateList | list | |||
A list containing a certToolId and the time when that tool accessed the tombstone record. This element previously was named "tombstoneAccessList". | ||||||
555-926 | Unassigned | |||||
927 | smDNSData | string | ||||
Field used by super_mediator to export DNS information. This element previously was named "dnsRName". | ||||||
928 | dnsHitCount | unsigned16 | ||||
Deprecated in favor of 6871/929 smDedupHitCount. | ||||||
929 | smDedupHitCount | unsigned64 | totalCounter | |||
The number of times the deduplicated item was seen. This element previously was named "observedDataTotalCount". | ||||||
930 | smDedupData | octetArray | ||||
A representation of data that is being deduplicated. This element previously was named "observedData". | ||||||
931 | smIpsetMatchesSrc | unsigned8 | flags | |||
Used by super_mediator to indicate that the record's source IP address matched an IPset. | ||||||
932 | smIpsetMatchesDst | unsigned8 | flags | |||
Used by super_mediator to indicate that the record's destination IP address matched an IPset. | ||||||
933-999 | Unassigned | |||||
1000 | templateName | string | ||||
Specifies a human-friendly name for an IPFIX template. | ||||||
1001 | templateDescription | string | ||||
Specifies a textual description for an IPFIX template. | ||||||
1002-16383 | Unassigned |
ID | Name | Contact URI | Last Updated |
---|---|---|---|
[Netsa_Tools] | Netsa Tools Help | mailto:netsa-help@cert.org | 2018-05-01 |