(SHA256=a3f79e422ce726c93a4a038a97cdeec33f0fb54d74b7c9b2bc97690feb6893a1)
NOTES:
| ||||||
ElementID | Name | Data Type | Semantics | Units | Range | Date |
---|---|---|---|---|---|---|
Description | ||||||
0 | Reserved | |||||
Reserved as per section 4 of [RFC7012]. | ||||||
1-11 | Unassigned | |||||
12 | obsoleteReverseOctetTotalCount | unsigned64 | totalCounter | |||
13 | obsoleteReversePacketTotalCount | unsigned64 | totalCounter | |||
14 | initialTCPFlags | unsigned16 | flags | |||
Reversible as reverseInitialTCPFlags (ElementID 16398). TCP flags on the initial packet in the forward direction of the flow. | ||||||
15 | unionTCPFlags | unsigned16 | flags | |||
Reversible as reverseUnionTCPFlags (ElementID 16399). Union of TCP flags of all packets other than the initial packet in the forward direction of the flow. | ||||||
16 | obsoleteReverseInitialTCPFlags | unsigned8 | flags | |||
17 | obsoleteReverseUnionTCPFlags | unsigned8 | flags | |||
18 | payload | octetArray | ||||
Reversible as reversePayload (ElementID 16402). Initial bytes of flow payload in the forward direction. | ||||||
19 | obsoleteReversePayload | octetArray | ||||
20 | obsoleteReverseTcpSequenceNumber | unsigned32 | ||||
21 | reverseFlowDeltaMilliseconds | unsigned32 | quantity | milliseconds | ||
Difference between the times of the first packet in forward direction and the first packet in the reverse direction, measured in milliseconds. | ||||||
22-28 | Unassigned | |||||
29 | obsoleteReverseVlanId | unsigned16 | identifier | |||
30 | silkFlowtypeId | unsigned8 | identifier | |||
A value typically assigned by SiLK identifying the direction and related properties of the flow record. The flowtype may also be represented by a silkFlowtypeName (CERT/938) or by the pair silkClassName (CERT/939) and silkTypeName (CERT/940). Prior to 2022-05-26, this element was named "silkFlowType". | ||||||
31 | silkSensorId | unsigned16 | identifier | |||
A value typically assigned by SiLK identifying the sensor where the flow record was collected. The sensor may also be represented by a silkSensorName (CERT/941). Prior to 2022-05-26, this element was named "silkFlowSensor". | ||||||
32 | silkTCPState | unsigned8 | flags | |||
Aspects of a flow record assigned by the SiLK rwflowpack tool. | ||||||
33 | silkAppLabel | unsigned16 | identifier | |||
Application label, defined as the primary well-known port associated with a given application. | ||||||
34 | Unassigned | |||||
35 | payloadEntropy | unsigned8 | ||||
Reversible as reversePayloadEntropy (ElementID 16419). The Shannon Entropy value for the payload, converted from a floating point (range 0.0 to 8.0) to an 8-bit unsigned integer. Generally, numbers above 230 are compressed or encrypted, numbers centered around 140 are English text, and very low value may indicate zero-padding of packets (e.g. TLS). | ||||||
36 | osName | string | ||||
Reversible as reverseOsName (ElementID 16420). p0f OS Name for the forward flow based on the SYN packet and p0f SYN Fingerprints. | ||||||
37 | osVersion | string | ||||
Reversible as reverseOsVersion (ElementID 16421). p0f OS Version for the forward flow based on the SYN packet and p0f SYN Fingerprints. | ||||||
38 | firstPacketBanner | octetArray | ||||
Reversible as reverseFirstPacketBanner (ElementID 16422). IP and transport headers for first packet in forward direction to be used for external OS Fingerprinters. | ||||||
39 | secondPacketBanner | octetArray | ||||
Reversible as reverseSecondPacketBanner (ElementID 16423). IP and transport headers for first packet in forward direction to be used for external OS Fingerprinters. | ||||||
40 | flowAttributes | unsigned16 | flags | |||
Reversible as reverseFlowAttributes (ElementID 16424). Bits indicating miscellaneous flow attributes for the forward direction of the flow: Bit 1 (Least significant bit): All packets in the forward direction had the same size. For TCP flows, only packets having payload are considered (to avoid TCP handshakes and teardowns). Bit 2: At least one packet in the forward direction was received out-of-sequence. Bit 3: Host may be MP_CAPABLE (MPTCP-capable). For TCP flows, this bit will be set if a packet in the flow was seen that had the MP_CAPABLE TCP option or attempted an MP_JOIN operation. Bit 4: The flow contains packets that were fragmented. | ||||||
41 | reverseFlowDeltaMicroseconds | unsigned64 | quantity | microseconds | ||
Difference between the times of the first packet in forward direction and the first packet in the reverse direction, measured in microseconds. | ||||||
42 | reverseFlowDeltaNanoseconds | unsigned64 | quantity | nanoseconds | ||
Difference between the times of the first packet in forward direction and the first packet in the reverse direction, measured in nanoseconds. | ||||||
43-99 | Unassigned | |||||
100 | yafExpiredFragmentCount | unsigned32 | totalCounter | packets | ||
Total number of packet fragments that have been expired since yaf start time. Prior to YAF 3.0, this element was named "expiredFragmentCount". | ||||||
101 | yafAssembledFragmentCount | unsigned32 | totalCounter | packets | ||
Total number of packets that been assembled from a series of fragments since yaf start time. Prior to YAF 3.0, this element was named "assembledFragmentCount". | ||||||
102 | yafMeanFlowRate | unsigned32 | flows | |||
The mean flow rate of the yaf flow sensor since yaf start time, rounded to the nearest integer. Prior to YAF 3.0, this element was named "meanFlowRate". | ||||||
103 | yafMeanPacketRate | unsigned32 | packets | |||
The mean packet rate of the yaf flow sensor since yaf start time, rounded to the nearest integer. Prior to YAF 3.0, this element was named "meanPacketRate". | ||||||
104 | yafFlowTableFlushEventCount | unsigned32 | totalCounter | flows | ||
Total number of times the yaf flow table has been flushed since yaf start time. Prior to YAF 3.0, this element was named "flowTableFlushEventCount". | ||||||
105 | yafFlowTablePeakCount | unsigned32 | flows | |||
The maximum number of flows in the yaf flow table at any one time since yaf start time. Prior to YAF 3.0, this element was named "flowTablePeakCount". | ||||||
106 | yafFlowKeyHash | unsigned32 | identifier | |||
The 32 bit hash of the 5-tuple and VLAN that is used as they key to YAF's internal flow table. | ||||||
107 | osFingerprint | string | ||||
Reversible as reverseOsFingerprint (ElementID 16491). p0f OS Fingerprint for the forward flow based on the SYN packet and p0f SYN fingerprints. Prior to YAF 3.0, this element was named "osFingerPrint". | ||||||
108-109 | Unassigned | |||||
110 | httpServerString | string | ||||
HTTP Server Response-header field. Contains information about the software used to handle the HTTP Request. | ||||||
111 | httpUserAgent | string | ||||
HTTP User-Agent Request-header field. Contains information about the user agent originating the request. | ||||||
112 | httpGet | string | ||||
HTTP Method Command. Retrieves information identified by the following Request-URI. | ||||||
113 | httpConnection | string | ||||
HTTP Connection header fields. Contains options that are desired for a particular connection. | ||||||
114 | httpVersion | string | ||||
HTTP Version Number. | ||||||
115 | httpReferer | string | ||||
HTTP Referer request-header field. Address (URI) of the resource which the Request-URI was obtained. | ||||||
116 | httpLocation | string | ||||
HTTP Location response-header field. Used to redirect the recipient to a location to complete a request or identify a new resource. | ||||||
117 | httpHost | string | ||||
HTTP Host Request-header. The Internet host and port number of the resource being requested. | ||||||
118 | httpContentLength | string | ||||
HTTP Content-Length header. Indicates the size of the entity-body. | ||||||
119 | httpAge | string | ||||
HTTP Age response-header. Argument is the sender's estimate of the time elapsed since the response. | ||||||
120 | httpAccept | string | ||||
HTTP Accept request-header field. Used to specify certain media types that are acceptable for the response. | ||||||
121 | httpAcceptLanguage | string | ||||
HTTP Accept-Language Request-Header field. Restricts the set of natural languages that preferred. | ||||||
122 | httpContentType | string | ||||
HTTP Content Type entity-header field. Indicates the media type of the entity-body. | ||||||
123 | httpResponse | string | ||||
HTTP Response Status Code. Usually a three-digit number followed by text. | ||||||
124 | pop3TextMessage | string | ||||
POP3 Command and Replies. Contains any command or reply message found in POP3 payload data. | ||||||
125 | ircTextMessage | string | ||||
IRC Chat or Join Message. This field contains any IRC Command and the following arguments. | ||||||
126 | tftpFilename | string | ||||
TFTP Name of File being transferred. | ||||||
127 | tftpMode | string | ||||
Contains the mode of transfer. (netascii, octet, mail) | ||||||
128 | slpVersion | unsigned8 | ||||
SLP Version Number. | ||||||
129 | slpMessageType | unsigned8 | 1-11 | |||
SLP Message Type. This value should be between 1 and 11 and describes the type of SLP message. | ||||||
130 | slpString | string | ||||
Contains the text elements found in an SLP Service Request. | ||||||
131 | ftpReturn | string | ||||
FTP Commands or Replies. | ||||||
132 | ftpUser | string | ||||
FTP User Command Argument. This command will normally be the first command transmitted by the user. | ||||||
133 | ftpPass | string | ||||
FTP Password Command Argument. This command must be preceded by the user name command, and is usually required to complete authentication. | ||||||
134 | ftpType | string | ||||
FTP Data Representation Type. | ||||||
135 | ftpRespCode | string | ||||
FTP Reply. This consists of a three digit number followed by some text. | ||||||
136 | imapCapability | string | ||||
IMAP Capability Command and Response. Captures the listing of capabilities that the server supports. | ||||||
137 | imapLogin | string | ||||
IMAP Login Command. Arguments are user name and password. | ||||||
138 | imapStartTLS | string | ||||
IMAP STARTTLS Command. Captures this command only as no arguments or responses are related. | ||||||
139 | imapAuthenticate | string | ||||
IMAP Authenticate Command. Captures the authentication mechanism name of the server following this command. | ||||||
140 | imapCommand | string | ||||
Captures a variety of IMAP Commands and their arguments. | ||||||
141 | imapExists | string | ||||
IMAP Exists Response. Reports the number of messages in the mailbox. | ||||||
142 | imapRecent | string | ||||
IMAP Recent Response. Reports the number of message with the Recent flag set. | ||||||
143 | rtspURL | string | ||||
RTSP URL. Captures the address of the network resources requested. | ||||||
144 | rtspVersion | string | ||||
RTSP Version Number. | ||||||
145 | rtspReturnCode | string | ||||
RTSP Status-Line. Captures the RTSP Protocol version, numeric status code, and the textual phrase associated with the numeric code. | ||||||
146 | rtspContentLength | string | ||||
RTSP Content-Length Header Field. Contains the length of the content of the method. | ||||||
147 | rtspCommand | string | ||||
RTSP Command. Captures the method to be performed and the Request-URI associated with the method. | ||||||
148 | rtspContentType | string | ||||
RTSP Content Type. | ||||||
149 | rtspTransport | string | ||||
RTSP Transport request header field. Captures the transport protocol used and the parameters that follow. | ||||||
150 | rtspCSeq | string | ||||
RTSP CSeq field. Contains the sequence number for an RTSP request-response pair. | ||||||
151 | rtspLocation | string | ||||
RTSP Location header field. | ||||||
152 | rtspPacketsReceived | string | ||||
RTSP User Agent field. Contains information about the user agent originating the request. | ||||||
153 | rtspUserAgent | string | ||||
RTSP User Agent field. Contains information about the user agent originating the request. | ||||||
154 | rtspJitter | string | ||||
RTSP Jitter Value. | ||||||
155 | sipInvite | string | ||||
SIP Invite Method. Contains the SIP address and SIP Version Number. | ||||||
156 | sipCommand | string | ||||
SIP Command. Contains a SIP Method, SIP address, and SIP Version Number. | ||||||
157 | sipVia | string | ||||
SIP Via contains the SIP Version Number and the address the sender is expecting to receive responses. | ||||||
158 | sipMaxForwards | string | ||||
SIP Max Forwards contains the limit of number of hops a request can make on the way to its destination. | ||||||
159 | sipAddress | string | ||||
SIP Address contains the argument of the To, From, or Contact Header Fields. | ||||||
160 | sipContentLength | string | ||||
SIP Content Length header field. Contains the byte count of the message byte. | ||||||
161 | sipUserAgent | string | ||||
SIP User Agent Header Field. Contains information about the User Agent Client originating the request. | ||||||
162 | smtpHello | string | ||||
SMTP Hello or Extend Hello command. Captures the command and the domain name of the SMTP client. | ||||||
163 | smtpFrom | string | ||||
SMTP Mail Command. Contains the reverse-path of the sender mailbox. | ||||||
164 | smtpTo | string | ||||
The SMTP Recipient (RCPT) Command. Captures the command and the forward-path of the recipient of the mail data. | ||||||
165 | smtpContentType | string | ||||
SMTP Content Type Header Field. | ||||||
166 | smtpSubject | string | ||||
SMTP Subject. Contains the subject of the mail data. | ||||||
167 | smtpFilename | string | ||||
SMTP Filename. Contains the name of the file attached to the mail message. | ||||||
168 | smtpContentDisposition | string | ||||
SMTP Content-Disposition Header field. | ||||||
169 | smtpResponse | string | ||||
SMTP Replies. Consists of a three digit number followed by text. | ||||||
170 | smtpEnhanced | string | ||||
Enhanced SMTP. Contains the ESMTP command with the following argument. | ||||||
171 | sshVersion | string | ||||
SSH Version Number | ||||||
172 | nntpResponse | string | ||||
NNTP Reply. This consists of a three digit status code and text message. | ||||||
173 | nntpCommand | string | ||||
NNTP Command. Contains an NNTP Command and following argument(s). | ||||||
174 | dnsQueryResponse | unsigned8 | ||||
DNS Query/Response header field. This corresponds with the DNS header one bit field, QR. If the message is a query (0), or a response (1). | ||||||
175 | dnsRRType | unsigned16 | ||||
DNS Query/Response Type. This corresponds with the QTYPE field in the DNS Question Section or the TYPE field in the DNS Resource Record Section. This field determines the type of records in the DNS DPI subTemplateList dnsDetailRecordList (CERT/431). Prior to YAF 3.0, this element was named "dnsQRType". | ||||||
176 | dnsAuthoritative | unsigned8 | ||||
DNS Authoritative header field. This corresponds with the DNS header one bit field, AA. This bit is only valid in responses (when dnsQueryResponse is 1), and specifies that the responding name server is an authority for the domain name in the question section. | ||||||
177 | dnsResponseCode | unsigned8 | ||||
DNS NXDomain or Response Code (RCODE). This corresponds with the DNS RCODE header field. This field will be set to 3 for a Name Error, 2 for a Server Failure, 1 for a Format Error, and 0 for No Error. See [dns-parameters] for other valid values. Prior to YAF 3.0, this element was named "dnsNXDomain". | ||||||
178 | dnsSection | unsigned8 | ||||
DNS Resource Record Section Field. This field will be set to 0 if the information is from the Question Section, 1 for the Answer Section, 2 for the Name Server Section, and 3 for the Additional Section. Prior to YAF 3.0, this element was named "dnsRRSection". | ||||||
179 | dnsName | string | ||||
A DNS Query or Response Name. This field corresponds with the QNAME field in the DNS Question Section or the NAME field in the DNS Resource Record Section. Prior to YAF 3.0, this element was named "dnsQName". | ||||||
180 | dnsCNAME | string | ||||
A domain-name which specificies the canonical or primary name for the owner. Prior to YAF 3.0, this element was named "dnsCName". | ||||||
181 | dnsMXPreference | unsigned16 | ||||
Corresponds to the DNS MX Preference field. | ||||||
182 | dnsMXExchange | string | ||||
Corresponds to the DNS MX Exchange field. | ||||||
183 | dnsNSDName | string | ||||
An authoritative name server domain-name. | ||||||
184 | dnsPTRDName | string | ||||
Corresponds to DNS PTR PTRDNAME Field. | ||||||
185 | sslCipher | unsigned32 | ||||
sslCipher is a CipherSuite suggested by the client in the ClientHello Message. | ||||||
186 | sslClientVersion | unsigned8 | ||||
sslClientVersion is the version it supports contained in the initial ClientHello message. | ||||||
187 | sslServerCipher | unsigned32 | ||||
sslServerCipher is the CipherSuite chosen by the server in the ServerHello message. | ||||||
188 | sslCompressionMethod | unsigned8 | ||||
sslCompressionMethod is the compression method chosen by the server in the ServerHello message. | ||||||
189 | sslCertVersion | unsigned8 | ||||
The Certificate Version. This is the value contained in the certificate v1(0), v2(1), v3(2). | ||||||
190 | sslCertSignature | octetArray | ||||
The signature contained in a SSL certificate. This is typically the hashing algorithm identifier. | ||||||
191 | sslCertIssuerCountryName | string | ||||
Country name {id-at 6} of the issuer of an SSL certificate. | ||||||
192 | sslCertIssuerOrgName | string | ||||
Organization name {id-at 10} of the issuer of an SSL certificate. | ||||||
193 | sslCertIssuerOrgUnitName | string | ||||
Organizational unit name {id-at 11} of the issuer of an SSL certificate. | ||||||
194 | sslCertIssuerZipCode | string | ||||
Postal or zip code {id-at 17} of the issuer of an SSL certificate. | ||||||
195 | sslCertIssuerState | string | ||||
State or providence name {id-at 8} of the issuer of an SSL certificate. | ||||||
196 | sslCertIssuerCommonName | string | ||||
Common name {id-at 3} of the issuer of an SSL certificate. | ||||||
197 | sslCertIssuerLocalityName | string | ||||
Locality name {id-at 7} of the issuer of an SSL certificate. | ||||||
198 | sslCertIssuerStreetAddress | string | ||||
Street address {id-at 9} of the issuer of an SSL certificate. | ||||||
199 | dnsTTL | unsigned32 | ||||
DNS Time To Live. This is an unsigned integer that specifies the time interval, in seconds, that the resource record may be cached for. This will contain a value of zero for DNS Queries. | ||||||
200 | sslCertSubjectCountryName | string | ||||
Country name {id-at 6} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubCountryName". | ||||||
201 | sslCertSubjectOrgName | string | ||||
Organization name {id-at 10} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubOrgName". | ||||||
202 | sslCertSubjectOrgUnitName | string | ||||
Organizational unit name {id-at 11} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubOrgUnitName". | ||||||
203 | sslCertSubjectZipCode | string | ||||
Postal or zip code {id-at 17} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubZipCode". | ||||||
204 | sslCertSubjectState | string | ||||
State or providence name {id-at 8} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubState". | ||||||
205 | sslCertSubjectCommonName | string | ||||
Common name {id-at 3} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubCommonName". | ||||||
206 | sslCertSubjectLocalityName | string | ||||
Locality name {id-at 7} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubLocalityName". | ||||||
207 | sslCertSubjectStreetAddress | string | ||||
Street address {id-at 9} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubStreetAddress". | ||||||
208 | dnsTXTData | string | ||||
Corresponds to DNS TXT TXT-DATA field. | ||||||
209 | dnsSOASerial | unsigned32 | ||||
Corresponds to DNS SOA SERIAL Field. | ||||||
210 | dnsSOARefresh | unsigned32 | ||||
Corresponds to DNS SOA REFRESH Field. | ||||||
211 | dnsSOARetry | unsigned32 | ||||
Corresponds to DNS SOA RETRY Field. | ||||||
212 | dnsSOAExpire | unsigned32 | ||||
Corresponds to DNS SOA EXPIRE Field. | ||||||
213 | dnsSOAMinimum | unsigned32 | ||||
Corresponds to DNS SOA MINIMUM Field. | ||||||
214 | dnsSOAMName | string | ||||
Corresponds to DNS SOA MNAME Field. | ||||||
215 | dnsSOARName | string | ||||
Corresponds to DNS SOA RNAME Field. | ||||||
216 | dnsSRVPriority | unsigned16 | ||||
Corresponds to the Priority Field in the DNS SRV Resource Record. | ||||||
217 | dnsSRVWeight | unsigned16 | ||||
Corresponds to the Weight Field in the DNS SRV Resource Record. | ||||||
218 | dnsSRVPort | unsigned16 | ||||
Corresponds to the Port Field in the DNS SRV Resource Record. | ||||||
219 | dnsSRVTarget | string | ||||
Corresponds to the Target Field in the DNS SRV Resource Record. | ||||||
220 | httpCookie | string | ||||
HTTP Cookie Header Field. | ||||||
221 | httpSetCookie | string | ||||
HTTP Set Cookie Header Field. | ||||||
222 | smtpSize | string | ||||
SMTP Size Header Field. Contains the size in bytes of the mail data. | ||||||
223 | mysqlUsername | string | ||||
The username seen when authenticating to a MySQL server. | ||||||
224 | mysqlCommandCode | unsigned8 | 0-28 | |||
MySQL Command Code. This number should be between 0 and 28. | ||||||
225 | mysqlCommandText | string | ||||
MySQL Command Text. For example, this can be a SELECT, INSERT, DELETE statement. | ||||||
226 | dnsId | unsigned16 | ||||
DNS Transaction ID. This identifier is used by the requester to match up replies to outstanding queries. Prior to YAF 3.0, this element was named "dnsID". | ||||||
227 | dnsAlgorithm | unsigned8 | ||||
Deprecated in favor of dnsDNSKEYAlgorithm (CERT/423), dnsDSAlgorithm (CERT/433), dnsNSEC3Algorithm (CERT/435), dnsNSEC3PARAMAlgorithm (CERT/441), and dnsRRSIGAlgorithm (CERT/447). The Hash Algorithm field in various DNSSEC records. | ||||||
228 | dnsKeyTag | unsigned16 | ||||
Deprecated in favor of dnsDSKeyTag (CERT/434) and dnsRRSIGKeyTag (CERT/448). The Key Tag field in the DS RR. | ||||||
229 | dnsRRSIGSigner | string | ||||
The Signer's Name field in the DNS RRSIG RR. Prior to YAF 3.0, this element was named "dnsSigner". | ||||||
230 | dnsRRSIGSignature | octetArray | ||||
The Signature field in the DNS RRSIG RR. Contains the cryptographic signature that covers the dnsName (CERT/179) field. Prior to YAF 3.0, this element was named "dnsSignature". | ||||||
231 | dnsDSDigest | octetArray | ||||
The Digest field of the DNS DS RR. Prior to YAF 3.0, this element was named "dnsDigest". | ||||||
232 | dnsDNSKEYPublicKey | octetArray | ||||
DNSSEC uses public key cryptography to sign and authenticate DNS resource record sets. This field holds the public key. The format depends on the algorithm of the key. Prior to YAF 3.0, this element was named "dnsPublicKey". | ||||||
233 | dnsSalt | octetArray | ||||
Deprecated in favor of dnsNSEC3Salt (CERT/439) and dnsNSEC3PARAMSalt (CERT/444). The Salt Field in the DNSSEC NSEC3 or NSEC3PARAM RR. | ||||||
234 | dnsHashData | octetArray | ||||
Deprecated in favor of dnsNSEC3NextHashedOwnerName (CERT/438) and dnsNSECNextDomainName (CERT/445). The Next Hashed Owner Name in the DNSSEC NSEC3 RR and Next Domain Name field in the DNSNSEC RR. | ||||||
235 | dnsIterations | unsigned16 | ||||
Deprecated in favor of dnsNSEC3Iterations (CERT/437) and dnsNSEC3PARAMIterations (CERT/443). The Iterations field in the DNSSEC NSEC3 or NSEC3PARAM RR. | ||||||
236 | dnsRRSIGSignatureExpiration | unsigned32 | ||||
The Signature Expiration field in a DNS RRSIG RR. The Expiration and Inception fields specify a validity period for the signature. Prior to YAF 3.0, this element was named "dnsSignatureExpiration". | ||||||
237 | dnsRRSIGSignatureInception | unsigned32 | ||||
The Signature Inception field in a RRSIG RR. The Expiration and Inception fields specify a validity period for the signature. Prior to YAF 3.0, this element was named "dnsSignatureInception". | ||||||
238 | dnsDSDigestType | unsigned8 | ||||
The Digest Type field in a DNS DS RR which identifes the algorithm used to construct the digest. Prior to YAF 3.0, this element was named "dnsDigestType". | ||||||
239 | dnsRRSIGLabels | unsigned8 | ||||
The Labels field in a DNS RRSIG RR. Specifies the number of labels in the original RRSIG resource record owner name. Prior to YAF 3.0, this element was named "dnsLabels". | ||||||
240 | dnsRRSIGTypeCovered | unsigned16 | ||||
The Type Covered field in a DNS RRSIG RR. Prior to YAF 3.0, this element was named "dnsTypeCovered". | ||||||
241 | dnsDNSKEYFlags | unsigned16 | flags | |||
The Flags field in the DNS DNSKEY Resource Record. Certain bits determine if the key is a zone key or should be used for a secure entry point. Prior to YAF 3.0, this element was named "dnsFlags". | ||||||
242 | dhcpFingerprint | string | ||||
Reversible as reverseDhcpFingerprint (ElementID 16626). The DHCP fingerprint. This will be the description of the OS. Prior to YAF 3.0, this element was named "dhcpFingerPrint". | ||||||
243 | dhcpVendorCode | string | ||||
Reversible as reverseDhcpVendorCode (ElementID 16627). The DHCP vendor class ID found in Option 60 of the DHCP packet. This field may help further identify the operating system of the sender. | ||||||
244 | sslCertSerialNumber | octetArray | ||||
The Serial Number from the X.509 certificate. | ||||||
245 | sslObjectType | unsigned8 | ||||
The type of the value contained in the sslObjectValue (CERT/246) in a subrecord of an sslIssuerFieldList (CERT/426), sslSubjectFieldList (CERT/427), or sslExtensionFieldList (CERT/428). For the sslIssuerFieldList (CERT/426) and sslSubjectFieldList (CERT/427) subTemplateLists, YAF only parses objects that are members of the id-at arc {joint-iso-ccitt(2) ds(5) 4}, pkcs-9 {iso(1) member-body (2) us(840) rsadsi(113459) pkcs(1) 9}, and LDAP dc 0.9.2342.19200300.100.1.25. This field will not contain the full object identfier, it will just contain the member id. For example, for an issuer common name, sslObjectType will contain 3. Below is a list of common objects in an X.509 RelativeDistinguishedName Sequence for X.509 Certificates: pkcs-9-emailAddress {pkcs-9 1} id-at-commonName {id-at 3} id-at-countryName {id-at 6} id-at-localityName {id-at 7} id-at-stateOrProvinceName {id-at 8} id-at-streetAddress {id-at 9} id-at-organizationName {id-at 10} id-at-organizationalUnitName {id-at 11} id-at-title {id-at 12} id-at-postalCode {id-at 17} 0.9.2342.19200300.100.1.25 {dc 25} id-at-name {id-at 41} | ||||||
246 | sslObjectValue | octetArray | ||||
The bit string value associated with an sslObjectType (CERT/245) in a subrecord of an sslIssuerFieldList (CERT/426), sslSubjectFieldList (CERT/427), or sslExtensionFieldList (CERT/428). | ||||||
247 | sslCertValidityNotBefore | string | ||||
The notBefore field in the Validity Sequence of the X.509 Certificate. | ||||||
248 | sslCertValidityNotAfter | string | ||||
The notAfter field in the Validity Sequence of the X.509 Certificate. | ||||||
249 | sslPublicKeyAlgorithm | octetArray | ||||
The algorithm, encoded in ASN.1, in the SubjectPublicKeyInfo Sequence of the X.509 Certificate. | ||||||
250 | sslPublicKeyLength | unsigned16 | ||||
The length of the public key in the X.509 Certificate. | ||||||
251 | smtpDate | string | ||||
SMTP Date Field. | ||||||
252 | httpAuthorization | string | ||||
HTTP Authorization Header Field. | ||||||
253 | httpVia | string | ||||
HTTP Via Header Field. | ||||||
254 | httpXForwardedFor | string | ||||
HTTP X-Forwarded-For Header Field. Prior to YAF 3.0, this element was named "httpX-Forwarded-For". | ||||||
255 | httpExpires | string | ||||
HTTP Expires Header Field. | ||||||
256 | httpRefresh | string | ||||
HTTP Refresh Header Field. | ||||||
257 | httpIMEI | string | ||||
HTTP International Mobile Station Equipment Identity ID. | ||||||
258 | httpIMSI | string | ||||
HTTP International Mobile Subscriber Identity | ||||||
259 | httpMSISDN | string | ||||
HTTP MSISDN number, a telephone number for the SIM card in a mobile/cellular phone. | ||||||
260 | httpSubscriber | string | ||||
HTTP Mobile Subscriber Information. | ||||||
261 | httpAcceptCharset | string | ||||
HTTP Accept Charset Header Field. | ||||||
262 | httpAcceptEncoding | string | ||||
HTTP Accept Encoding Header Field. | ||||||
263 | httpAllow | string | ||||
HTTP Allow Header Field. | ||||||
264 | httpDate | string | ||||
HTTP Date Header Field. | ||||||
265 | httpExpect | string | ||||
HTTP Expect Header Field. | ||||||
266 | httpFrom | string | ||||
HTTP From Header Field. | ||||||
267 | httpProxyAuthentication | string | ||||
HTTP Proxy Authentication Field. | ||||||
268 | httpUpgrade | string | ||||
HTTP Upgrade Header Field. | ||||||
269 | httpWarning | string | ||||
HTTP Warning Header Field. | ||||||
270 | httpDNT | string | ||||
HTTP DNT Header Field. | ||||||
271 | httpXForwardedProto | string | ||||
HTTP X-Forwarded-Proto Header Field. Prior to YAF 3.0, this element was named "httpX-Forwarded-Proto". | ||||||
272 | httpXForwardedHost | string | ||||
HTTP X-Forwarded-Host Header Field. Prior to YAF 3.0, this element was named "httpX-Forwarded-Host". | ||||||
273 | httpXForwardedServer | string | ||||
HTTP X-Forwarded-Server Header Field. Prior to YAF 3.0, this element was named "httpX-Forwarded-Server". | ||||||
274 | httpXDeviceId | string | ||||
HTTP X-Device ID Header Field. Prior to YAF 3.0, this element was named "httpX-DeviceID". | ||||||
275 | httpXProfile | string | ||||
HTTP X-Profile Header Field. Prior to YAF 3.0, this element was named "httpX-Profile". | ||||||
276 | httpLastModified | string | ||||
HTTP Last Modified Header Field. | ||||||
277 | httpContentEncoding | string | ||||
HTTP Content Encoding Header Field. | ||||||
278 | httpContentLanguage | string | ||||
HTTP Content Language Header Field. | ||||||
279 | httpContentLocation | string | ||||
HTTP Content Location Header Field. | ||||||
280 | httpXUaCompatible | string | ||||
HTTP X-UA-Compatible Header Field. Prior to YAF 3.0, this element was named "httpX-UA-Compatible". | ||||||
281 | dnp3SourceAddress | unsigned16 | ||||
The DNP3 Source Address found in the Data Link Layer of the DNP Header. | ||||||
282 | dnp3DestinationAddress | unsigned16 | ||||
The DNP3 Destination Address found in the Data Link Layer of the DNP Header. | ||||||
283 | dnp3Function | unsigned8 | ||||
The DNP3 Function Code found in the first byte of the Application Layer. | ||||||
284 | dnp3ObjectData | octetArray | ||||
The pattern captured from the DNP3 regular expression. | ||||||
285 | modbusData | octetArray | ||||
Data associated with the Modbus protocol, a widely used network messaging protocol used in industrial manufacturing. | ||||||
286 | enipData | octetArray | ||||
Data associated with EtherNet/IP (ENIP), a protocol used in industrial automation applications. Prior to YAF 3.0, this element was named "ethernetIPData". | ||||||
287 | rtpPayloadType | unsigned8 | ||||
Reversible as reverseRtpPayloadType (ElementID 16671). The payload type in the RTP header of the first payload in the forward direction. | ||||||
288 | sslRecordVersion | unsigned16 | ||||
sslRecordVersion is the version of ssl or tls that was used in the flow. | ||||||
289 | mptcpInitialDataSequenceNumber | unsigned64 | ||||
The initial data sequence number found in the MPTCP Data Sequence Signal (DSS) Option of a flow. (See Multipath TCP, [RFC8684].) | ||||||
290 | mptcpReceiverToken | unsigned32 | identifier | |||
The token used to identify an MPTCP connection over multiple subflows. This value is found in the MP_JOIN TCP Option for the initial SYN of a subflow. | ||||||
291 | mptcpMaximumSegmentSize | unsigned16 | ||||
The maximum segment size reported in the Maximum Segment Size TCP Option captured from an MPTCP flow. | ||||||
292 | mptcpAddressId | unsigned8 | identifier | |||
The address identifier of the subflow found in the SYN/ACK of an MP_JOIN operation captured from an MPTCP flow. Prior to YAF 3.0, this element was named "mptcpAddressID". | ||||||
293 | mptcpFlags | unsigned8 | flags | |||
Various MPTCP Values: Bit 1: Priority was changed during the life of the subflow (MP_PRIO was seen). Bit 2: Subflow has priority at setup (backup flag was not set at initialization). Bit 3: Subflow failed. (MP_FAIL option was seen). Bit 4: Subflow experienced fast close. (MP_FASTCLOSE options was seen). | ||||||
294 | sslServerName | string | ||||
The server name from the SSL/TLS Client Hello. This is typically the name of the server that the client is connecting to. | ||||||
295 | sslCertificateHash | octetArray | ||||
The hash of the X.509 certificate. | ||||||
296 | sslBinaryCertificate | octetArray | ||||
A binary dump of the full X.509 certificate. Prior to YAF 3.0, this element was named "sslCertificate". | ||||||
297 | dhcpOption | unsigned8 | ||||
The list of requested parameters found in DHCP Option 55. | ||||||
298 | sslCertificateSHA1 | octetArray | ||||
The SHA1 hash of a complete SSL certificate. | ||||||
299 | sslCertificateMD5 | octetArray | ||||
The MD5 hash of a complete SSL certificate. | ||||||
300 | ndpiL7Protocol | unsigned16 | identifier | |||
The protocol as determined by analysis with nDPI, the ntop-maintained superset of the OpenDPI library. Prior to YAF 3.0, this element was named "nDPIL7Protocol". | ||||||
301 | ndpiL7SubProtocol | unsigned16 | identifier | |||
The subprotocol as determined by analysis with nDPI, the ntop-maintained superset of the OpenDPI library. Prior to YAF 3.0, this element was named "nDPIL7SubProtocol". | ||||||
302 | dnsA | ipv4Address | ||||
An IPv4 address that specifies an address for a DNS host name. Prior to YAF 3.0, this element was named "rrIPv4". | ||||||
303 | dnsAAAA | ipv6Address | ||||
An IPv6 address that specifies an address for a DNS host name. Prior to YAF 3.0, this element was named "rrIPv6". | ||||||
304 | dnsDNSKEYProtocol | unsigned8 | ||||
The Protocol field from a DNS DNSKEY Resource Record. Prior to YAF 3.0, this element was named "DNSKEY_protocolIdentifier". | ||||||
305 | pipelineDNSARecord | subTemplateList | list | |||
Element holding an entire DNS A record, which is a subTemplateList when emitted from YAF. This is used in Analysis Pipeline for fast flux. Prior to YAF 3.0, this element was named "DNS_A_Record". | ||||||
306 | pipelineDNSAAAARecord | subTemplateList | list | |||
Element holding an entire DNS AAAA record, which is a subTemplateList when emitted from YAF. This is used in Analysis Pipeline for fast flux. Prior to YAF 3.0, this element was named "DNS_AAAA_Record". | ||||||
307 | pipelineDNSResourceRecord | subTemplateList | list | |||
Element holding an entire DNS resource record, which is a subTemplateList when emitted from YAF. This is used in Analysis Pipeline. Prior to YAF 3.0, this element was named "DNS_RESOURCE_RECORD". | ||||||
308 | sslCertIssuerTitle | string | ||||
Title {id-at 12} of the issuer of an SSL certificate. | ||||||
309 | sslCertSubjectTitle | string | ||||
Title {id-at 12} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubTitle". | ||||||
310 | sslCertIssuerName | string | ||||
Name {id-at 41} of the issuer of an SSL certificate. | ||||||
311 | sslCertSubjectName | string | ||||
Name {id-at 41} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubName". | ||||||
312 | sslCertIssuerEmailAddress | string | ||||
Email address {pkcs-9 1} of the issuer of an SSL certificate. | ||||||
313 | sslCertSubjectEmailAddress | string | ||||
Email address {pkcs-9 1} of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubEmailAddress". | ||||||
314 | sslCertIssuerDomainComponent | string | ||||
LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the issuer of an SSL certificate. | ||||||
315 | sslCertSubjectDomainComponent | string | ||||
LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the subject of an SSL certificate. Prior to YAF 3.0, this element was named "sslCertSubDomainComponent". | ||||||
316 | sslCertExtSubjectKeyIdent | octetArray | ||||
SSL extension value holding the subject key identifer, {id-ce 14} subjectKeyIdentifier. | ||||||
317 | sslCertExtKeyUsage | octetArray | ||||
SSL extension value holding the key usage, {id-ce 15} keyUsage. | ||||||
318 | sslCertExtPrivKeyUsagePeriod | octetArray | ||||
SSL extension value holding the usage period for the private key, {id-ce 16} privateKeyUsagePeriod. | ||||||
319 | sslCertExtSubjectAltName | octetArray | ||||
SSL extension value holding the subject's alternative names, {id-ce 17} subjectAltName. | ||||||
320 | sslCertExtIssuerAltName | octetArray | ||||
SSL extension value holding the issuer's alternative names, {id-ce 18} issuerAltName. | ||||||
321 | sslCertExtCertIssuer | octetArray | ||||
SSL extension value holding the certificate issuer associated with an entry in an indirect CRL, {id-ce 29} certificateIssuer. | ||||||
322 | sslCertExtCrlDistribution | octetArray | ||||
SSL extension value holding the certificate revocation list (CRL) distribution points, {id-ce 31} crlDistributionPoints. | ||||||
323 | sslCertExtCertPolicies | octetArray | ||||
SSL extension value holding the certificate policies, {id-ce 32} certificatePolicies. | ||||||
324 | sslCertExtAuthorityKeyIdent | octetArray | ||||
SSL extension value holding the authority key identifier, {id-ce 35} authorityKeyIdentifier. | ||||||
325 | sslCertExtExtendedKeyUsage | octetArray | ||||
SSL extension value holding the extended key usage {id-ce 37}, extKeyUage. | ||||||
326 | smtpStartTLS | unsigned8 | ||||
Element indicating whether or not the SMTP session sent the START TLS command. | ||||||
327 | smtpKey | string | ||||
SMTP Header key string. | ||||||
328 | smtpValue | string | ||||
SMTP Header value string. | ||||||
329 | smtpURL | string | ||||
Element for URLs captured in the SMTP message body | ||||||
330 | smtpMessageSize | unsigned32 | ||||
Element containing the value of the SMTP message size. | ||||||
331 | smtpResponseList | basicList | ||||
A basicList of smtpResponse (CERT/169) elements. | ||||||
332 | smtpToList | basicList | ||||
A basicList of smtpTo (CERT/164) elements. | ||||||
333 | smtpFromList | basicList | ||||
A basicList of smtpFrom (CERT/163) elements. | ||||||
334 | smtpFilenameList | basicList | ||||
A basicList of smtpFilename (CERT/167) elements. | ||||||
335 | smtpURLList | basicList | ||||
A basicList of smtpURL (CERT/329) elements. | ||||||
336 | smtpMessageList | subTemplateList | list | |||
A subTemplateList holding email data in smtpMessage templates. | ||||||
337 | smtpHeaderList | subTemplateList | list | |||
A subTemplateList holding smtpKey (CERT/327), smtpValue (CERT/328) pairs describing email headers. | ||||||
338 | httpServerStringList | basicList | ||||
A basicList of httpServerString (CERT/110) elements. | ||||||
339 | httpUserAgentList | basicList | ||||
A basicList of httpUserAgent (CERT/111) elements. | ||||||
340 | httpGetList | basicList | ||||
A basicList of httpGet (CERT/112) elements. | ||||||
341 | httpConnectionList | basicList | ||||
A basicList of httpConnection (CERT/113) elements. | ||||||
342 | httpVersionList | basicList | ||||
A basicList of httpVersion (CERT/114) elements. | ||||||
343 | httpRefererList | basicList | ||||
A basicList of httpReferer (CERT/115) elements. | ||||||
344 | httpLocationList | basicList | ||||
A basicList of httpLocation (CERT/116) elements. | ||||||
345 | httpHostList | basicList | ||||
A basicList of httpHost (CERT/117) elements. | ||||||
346 | httpContentLengthList | basicList | ||||
A basicList of httpContentLength (CERT/118) elements. | ||||||
347 | httpAgeList | basicList | ||||
A basicList of httpAge (CERT/119) elements. | ||||||
348 | httpAcceptList | basicList | ||||
A basicList of httpAccept (CERT/120) elements. | ||||||
349 | httpAcceptLanguageList | basicList | ||||
A basicList of httpAcceptLanguage (CERT/121) elements. | ||||||
350 | httpContentTypeList | basicList | ||||
A basicList of httpContentType (CERT/122) elements. | ||||||
351 | httpResponseList | basicList | ||||
A basicList of httpResponse (CERT/123) elements. | ||||||
352 | pop3TextMessageList | basicList | ||||
A basicList of pop3TextMessage (CERT/124) elements. | ||||||
353 | ircTextMessageList | basicList | ||||
A basicList of ircTextMessage (CERT/125) elements. | ||||||
354 | slpStringList | basicList | ||||
A basicList of slpString (CERT/130) elements. | ||||||
355 | ftpReturnList | basicList | ||||
A basicList of ftpReturn (CERT/131) elements. | ||||||
356 | ftpUserList | basicList | ||||
A basicList of ftpUser (CERT/132) elements. | ||||||
357 | ftpPassList | basicList | ||||
A basicList of ftpPass (CERT/133) elements. | ||||||
358 | ftpTypeList | basicList | ||||
A basicList of ftpType (CERT/134) elements. | ||||||
359 | ftpRespCodeList | basicList | ||||
A basicList of ftpRespCode (CERT/135) elements. | ||||||
360 | imapCapabilityList | basicList | ||||
A basicList of imapCapability (CERT/136) elements. | ||||||
361 | imapLoginList | basicList | ||||
A basicList of imapLogin (CERT/137) elements. | ||||||
362 | imapStartTLSList | basicList | ||||
A basicList of imapStartTLS (CERT/138) elements. | ||||||
363 | imapAuthenticateList | basicList | ||||
A basicList of imapAuthenticate (CERT/139) elements. | ||||||
364 | imapCommandList | basicList | ||||
A basicList of imapCommand (CERT/140) elements. | ||||||
365 | imapExistsList | basicList | ||||
A basicList of imapExists (CERT/141) elements. | ||||||
366 | imapRecentList | basicList | ||||
A basicList of imapRecent (CERT/142) elements. | ||||||
367 | rtspURLList | basicList | ||||
A basicList of rtspURL (CERT/143) elements. | ||||||
368 | rtspVersionList | basicList | ||||
A basicList of rtspVersion (CERT/144) elements. | ||||||
369 | rtspReturnCodeList | basicList | ||||
A basicList of rtspReturnCode (CERT/145) elements. | ||||||
370 | rtspContentLengthList | basicList | ||||
A basicList of rtspContentLength (CERT/146) elements. | ||||||
371 | rtspCommandList | basicList | ||||
A basicList of rtspCommand (CERT/147) elements. | ||||||
372 | rtspContentTypeList | basicList | ||||
A basicList of rtspContentType (CERT/148) elements. | ||||||
373 | rtspTransportList | basicList | ||||
A basicList of rtspTransport (CERT/149) elements. | ||||||
374 | rtspCSeqList | basicList | ||||
A basicList of rtspCSeq (CERT/150) elements. | ||||||
375 | rtspLocationList | basicList | ||||
A basicList of rtspLocation (CERT/151) elements. | ||||||
376 | rtspPacketsReceivedList | basicList | ||||
A basicList of rtspPacketsReceived (CERT/152) elements. | ||||||
377 | rtspUserAgentList | basicList | ||||
A basicList of rtspUserAgent (CERT/153) elements. | ||||||
378 | rtspJitterList | basicList | ||||
A basicList of rtspJitter (CERT/154) elements. | ||||||
379 | sipInviteList | basicList | ||||
A basicList of sipInvite (CERT/155) elements. | ||||||
380 | sipCommandList | basicList | ||||
A basicList of sipCommand (CERT/156) elements. | ||||||
381 | sipViaList | basicList | ||||
A basicList of sipVia (CERT/157) elements. | ||||||
382 | sipMaxForwardsList | basicList | ||||
A basicList of sipMaxForwards (CERT/158) elements. | ||||||
383 | sipAddressList | basicList | ||||
A basicList of sipAddress (CERT/159) elements. | ||||||
384 | sipContentLengthList | basicList | ||||
A basicList of sipContentLength (CERT/160) elements. | ||||||
385 | sipUserAgentList | basicList | ||||
A basicList of sipUserAgent (CERT/161) elements. | ||||||
386 | sshVersionList | basicList | ||||
A basicList of sshVersion (CERT/171) elements. | ||||||
387 | nntpResponseList | basicList | ||||
A basicList of nntpResponse (CERT/172) elements. | ||||||
388 | nntpCommandList | basicList | ||||
A basicList of nntpCommand (CERT/173) elements. | ||||||
389 | sslCipherList | basicList | ||||
A basicList of sslCipher (CERT/185) elements. | ||||||
390 | httpCookieList | basicList | ||||
A basicList of httpCookie (CERT/220) elements. | ||||||
391 | httpSetCookieList | basicList | ||||
A basicList of httpSetCookie (CERT/221) elements. | ||||||
392 | httpAuthorizationList | basicList | ||||
A basicList of httpAuthorization (CERT/252) elements. | ||||||
393 | httpViaList | basicList | ||||
A basicList of httpVia (CERT/253) elements. | ||||||
394 | httpXForwardedForList | basicList | ||||
A basicList of httpXForwardedFor (CERT/254) elements. | ||||||
395 | httpExpiresList | basicList | ||||
A basicList of httpExpires (CERT/255) elements. | ||||||
396 | httpRefreshList | basicList | ||||
A basicList of httpRefresh (CERT/256) elements. | ||||||
397 | httpIMEIList | basicList | ||||
A basicList of httpIMEI (CERT/257) elements. | ||||||
398 | httpIMSIList | basicList | ||||
A basicList of httpIMSI (CERT/258) elements. | ||||||
399 | httpMSISDNList | basicList | ||||
A basicList of httpMSISDN (CERT/259) elements. | ||||||
400 | httpSubscriberList | basicList | ||||
A basicList of httpSubscriber (CERT/260) elements. | ||||||
401 | httpAcceptCharsetList | basicList | ||||
A basicList of httpAcceptCharset (CERT/261) elements. | ||||||
402 | httpAllowList | basicList | ||||
A basicList of httpAllow (CERT/263) elements. | ||||||
403 | httpDateList | basicList | ||||
A basicList of httpDate (CERT/264) elements. | ||||||
404 | httpExpectList | basicList | ||||
A basicList of httpExpect (CERT/265) elements. | ||||||
405 | httpFromList | basicList | ||||
A basicList of httpFrom (CERT/266) elements. | ||||||
406 | httpProxyAuthenticationList | basicList | ||||
A basicList of httpProxyAuthentication (CERT/267) elements. | ||||||
407 | httpUpgradeList | basicList | ||||
A basicList of httpUpgrade (CERT/268) elements. | ||||||
408 | httpWarningList | basicList | ||||
A basicList of httpWarning (CERT/269) elements. | ||||||
409 | httpDNTList | basicList | ||||
A basicList of httpDNT (CERT/270) elements. | ||||||
410 | httpXForwardedProtoList | basicList | ||||
A basicList of httpXForwardedProto (CERT/271) elements. | ||||||
411 | httpXForwardedHostList | basicList | ||||
A basicList of httpXForwardedHost (CERT/272) elements. | ||||||
412 | httpXForwardedServerList | basicList | ||||
A basicList of httpXForwardedServer (CERT/273) elements. | ||||||
413 | httpXDeviceIdList | basicList | ||||
A basicList of httpXDeviceId (CERT/274) elements. | ||||||
414 | httpXProfileList | basicList | ||||
A basicList of httpXProfile (CERT/275) elements. | ||||||
415 | httpLastModifiedList | basicList | ||||
A basicList of httpLastModified (CERT/276) elements. | ||||||
416 | httpContentEncodingList | basicList | ||||
A basicList of httpContentEncoding (CERT/277) elements. | ||||||
417 | httpContentLanguageList | basicList | ||||
A basicList of httpContentLanguage (CERT/278) elements. | ||||||
418 | httpContentLocationList | basicList | ||||
A basicList of httpContentLocation (CERT/279) elements. | ||||||
419 | httpXUaCompatibleList | basicList | ||||
A basicList of httpXUaCompatible (CERT/280) elements. | ||||||
420 | modbusDataList | basicList | ||||
A basicList of modbusData (CERT/285) elements. | ||||||
421 | enipDataList | basicList | ||||
A basicList of enipData (CERT/286) elements. | ||||||
422 | dhcpOptionList | basicList | ||||
Reversible as reverseDhcpOptionList (ElementID 16806). A basicList of dhcpOption (CERT/297) elements. | ||||||
423 | dnsDNSKEYAlgorithm | unsigned8 | ||||
The cryptographic algorithm used for the public key in a DNS DNSKEY RR. | ||||||
424 | mysqlCommandTextCodeList | subTemplateList | ||||
A subTemplateList of mysqlCommandText (CERT/225) mysqlCommandCode (CERT/224) pairs. | ||||||
425 | sslCertList | subTemplateList | ||||
A subTemplateList of yaf_ssl_cert templates. | ||||||
426 | sslIssuerFieldList | subTemplateList | ||||
A subTemplateList containing pairs of sslObjectValue (CERT/246) and sslObjectType (CERT/245) values describing the issuer of an X.509 certificate. | ||||||
427 | sslSubjectFieldList | subTemplateList | ||||
A subTemplateList containing pairs of sslObjectValue (CERT/246) and sslObjectType (CERT/245) values describing the subject of an X.509 certificate. | ||||||
428 | sslExtensionFieldList | subTemplateList | ||||
A subTemplateList containing pairs of sslObjectValue (CERT/246) and sslObjectType (CERT/245) values describing some of the extensions present on an X.509 certificate. | ||||||
429 | sslBinaryCertificateList | basicList | ||||
A basicList of sslBinaryCertificate (CERT/296) elements. | ||||||
430 | dnp3RecordList | subTemplateList | ||||
A subTemplateList holding the DNP3 values dnp3ObjectData (CERT/284), dnp3SourceAddress (CERT/281), dnp3DestinationAddress (CERT/282), and dnp3Function (CERT/283). | ||||||
431 | dnsDetailRecordList | subTemplateList | ||||
A subTemplateList of yaf_dns_rr templates. The template used by this element varies depending on the type of DNS Resource Record specified in dnsRRType (CERT/175). | ||||||
432 | yafDPIList | subTemplateList | ||||
A subTemplateList of deep packet inspection data generated by YAF. The template used by this element varies depending on the type of DPI data YAF collected for the record. | ||||||
433 | dnsDSAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS DS RR. It holds the algorithm used by the DNS DNSKEY RR to which this DS RR refers. | ||||||
434 | dnsDSKeyTag | unsigned16 | ||||
The Key Tag field in a DNS DS RR. | ||||||
435 | dnsNSEC3Algorithm | unsigned8 | ||||
The Algorithm field in a DNS NSEC3 RR. | ||||||
436 | dnsNSEC3Flags | unsigned8 | ||||
The Flags field in a DNS NSEC3 RR. | ||||||
437 | dnsNSEC3Iterations | unsigned16 | ||||
The Iterations field in a DNS NSEC3 RR. | ||||||
438 | dnsNSEC3NextHashedOwnerName | octetArray | ||||
The Next Hashed Owner Name field in a DNS NSEC3 RR. | ||||||
439 | dnsNSEC3Salt | octetArray | ||||
The Salt field in a DNS NSEC3 RR. | ||||||
440 | dnsNSEC3TypeBitMaps | octetArray | ||||
The Type Bit Maps field in a DNS NSEC3 RR. | ||||||
441 | dnsNSEC3PARAMAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS NSEC3PARAM RR. | ||||||
442 | dnsNSEC3PARAMFlags | unsigned8 | ||||
The Flags field in a DNS NSEC3PARAM RR. | ||||||
443 | dnsNSEC3PARAMIterations | unsigned16 | ||||
The Iterations field in a DNS NSEC3PARAM RR. | ||||||
444 | dnsNSEC3PARAMSalt | octetArray | ||||
The Salt field in a DNS NSEC3PARAM RR. | ||||||
445 | dnsNSECNextDomainName | octetArray | ||||
The Next Domain Name field in a DNS NSEC RR. | ||||||
446 | dnsNSECTypeBitMaps | octetArray | ||||
The Type Bit Maps field in a DNS NSEC RR. | ||||||
447 | dnsRRSIGAlgorithm | unsigned8 | ||||
The Algorithm field in a DNS RRSIG RR. | ||||||
448 | dnsRRSIGKeyTag | unsigned16 | ||||
The Key Tag field in a DNS RRSIG RR. | ||||||
449 | dnsRRSIGOriginalTTL | unsigned32 | ||||
The Original TTL field in a DNS RRSIG RR. | ||||||
450 | sslCertIssuerOrgNameList | basicList | ||||
A basicList of sslCertIssuerOrgName (CERT/192) elements, each holding an organization name {id-at 10} of the issuer of an SSL certificate. | ||||||
451 | sslCertIssuerOrgUnitNameList | basicList | ||||
A basicList of sslCertIssuerOrgUnitName (CERT/193) elements, each holding an organizational unit name {id-at 11} of the issuer of an SSL certificate. | ||||||
452 | sslCertIssuerCommonNameList | basicList | ||||
A basicList of sslCertIssuerCommonName (CERT/196) elements, each holding a common name {id-at 3} of the issuer of an SSL certificate. | ||||||
453 | sslCertIssuerStreetAddressList | basicList | ||||
A basicList of sslCertIssuerStreetAddress (CERT/198) elements, each holding a street address {id-at 9} of the issuer of an SSL certificate. | ||||||
454 | sslCertSubjectOrgNameList | basicList | ||||
A basicList of sslCertSubjectOrgName (CERT/201) elements, each holding an organization name {id-at 10} of the subject of an SSL certificate. | ||||||
455 | sslCertSubjectOrgUnitNameList | basicList | ||||
A basicList of sslCertSubjectOrgUnitName (CERT/202) elements, each holding an organizational unit name {id-at 11} of the subject of an SSL certificate. | ||||||
456 | sslCertSubjectCommonNameList | basicList | ||||
A basicList of sslCertSubjectCommonName (CERT/205) elements, each holding a common name {id-at 3} of the subject of an SSL certificate. | ||||||
457 | sslCertSubjectStreetAddressList | basicList | ||||
A basicList of sslCertSubjectStreetAddress (CERT/207) elements, each holding a street address {id-at 9} of the subject of an SSL certificate. | ||||||
458 | sslCertIssuerDomainComponentList | basicList | ||||
A basicList of sslCertIssuerDomainComponent (CERT/314) elements, each holding an LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the issuer of an SSL certificate. | ||||||
459 | sslCertSubjectDomainComponentList | basicList | ||||
A basicList of sslCertSubjectDomainComponent (CERT/315) elements, each holding an LDAP dc (domainComponent), 0.9.2342.19200300.100.1.25, holding one component, a label, of the DNS name of the subject of an SSL certificate. | ||||||
460 | sslCertValidityTotalDays | signed32 | ||||
The whole number of days the certificate was valid (sslCertValidityNotAfter - sslCertValidityNotBefore). | ||||||
461 | sslCertValidityDaysTimeOfUse | signed32 | ||||
The whole number of days the certificate was valid at the time it was used (flowStartMilliseconds - sslCertValidityNotBefore). | ||||||
462 | sslCertificateSHA256 | octetArray | ||||
The SHA256 hash of a complete SSL certificate. | ||||||
463 | sslClientJA3 | octetArray | ||||
The JA3 MD5 hash of the sslClientJA3Fingerprint (CERT/464) calculated on the client-side TLS/SSL fingerprint string. | ||||||
464 | sslClientJA3Fingerprint | string | ||||
The JA3 fingerprint string enumerated from the TLS/SSL ClientHello packet. Element sslClientJA3 (CERT/463) holds the MD5 of this. | ||||||
465 | sslServerJA3S | octetArray | ||||
The JA3S MD5 hash of the sslServerJA3SFingerprint (CERT/466) calculated on the server-side TLS/SSL fingerprint string. | ||||||
466 | sslServerJA3SFingerprint | string | ||||
The JA3S fingerprint string enumerated from the TLS/SSL ServerHello packet. Element sslServerJA3S (CERT/465) holds the MD5 of this. | ||||||
467 | sshHasshVersion | string | ||||
The version of the HASSH algorithm used by sshHassh (CERT/468), sshHasshAlgorithms (CERT/469), sshServerHassh (CERT/470), and sshServerHasshAlgorithms (CERT/471). | ||||||
468 | sshHassh | octetArray | ||||
The client HASSH MD5 hash of the sshHasshAlgorithms (CERT/469) fingerprint for an SSH client. | ||||||
469 | sshHasshAlgorithms | string | ||||
The SSH client hasshAlgorithms: the concatenated name-lists of the client-to-server algorithms delimited by a semicolon. Element sshHassh (CERT/468) holds the MD5 of this. | ||||||
470 | sshServerHassh | octetArray | ||||
The server HASSH MD5 hash (hasshServer) of the sshServerHasshAlgorithms (CERT/471) fingerprint for an SSH server. | ||||||
471 | sshServerHasshAlgorithms | string | ||||
The SSH server hasshServerAlgoritms: the concatenated name-lists of the server-to-client algorithms delimited by a semicolon. Element sshServerHassh (CERT/470) holds the MD5 of this. | ||||||
472 | sshServerVersion | string | ||||
The version string from an SSH server. | ||||||
473 | sshCipher | string | ||||
The negotiated symmetric encryption algorithm used for an SSH session. | ||||||
474 | sshMacAlgorithm | string | ||||
The negotiated MAC algorithm used for an SSH session. | ||||||
475 | sshCompressionMethod | string | ||||
The negotiated compression algorithm used for an SSH session. | ||||||
476 | sshKeyExchangeAlgorithm | string | ||||
The negotiated key exchange algorithm used for an SSH session. | ||||||
477 | sshHostKeyAlgorithm | string | ||||
The negotiated host key algorithm used for an SSH session. | ||||||
478 | sshServerHostKey | octetArray | ||||
The MD5 hash of the public key of the SSH server. | ||||||
479 | pop3StartTLS | unsigned8 | ||||
Element indicating whether the POP3 session sent the START TLS command. | ||||||
480-499 | Unassigned | |||||
500 | smallPacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseSmallPacketCount (ElementID 16884). The number of packets that contain less than 60 bytes of payload. | ||||||
501 | nonEmptyPacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseNonEmptyPacketCount (ElementID 16885). The number of packets that contain at least 1 byte of payload. | ||||||
502 | dataByteCount | unsigned64 | totalCounter | octets | ||
Reversible as reverseDataByteCount (ElementID 16886). Total bytes transferred as payload. | ||||||
503 | averageInterarrivalTime | unsigned64 | milliseconds | |||
Reversible as reverseAverageInterarrivalTime (ElementID 16887). Average number of milliseconds between packets. | ||||||
504 | standardDeviationInterarrivalTime | unsigned64 | milliseconds | |||
Reversible as reverseStandardDeviationInterarrivalTime (ElementID 16888). Standard deviation of the interarrival time for up to the first ten packets. | ||||||
505 | firstNonEmptyPacketSize | unsigned16 | quantity | octets | ||
Reversible as reverseFirstNonEmptyPacketSize (ElementID 16889). Payload length of the first non-empty packet. | ||||||
506 | maxPacketSize | unsigned16 | quantity | octets | ||
Reversible as reverseMaxPacketSize (ElementID 16890). The largest payload length transferred in the flow. | ||||||
507 | firstEightNonEmptyPacketDirections | unsigned8 | flags | |||
Reversible as reverseFirstEightNonEmptyPacketDirections (ElementID 16891). Represents directionality for the first 8 non-empty packets. 0 for forward direction, 1 for reverse direction. | ||||||
508 | standardDeviationPayloadLength | unsigned16 | octets | |||
Reversible as reverseStandardDeviationPayloadLength (ElementID 16892). The standard deviation of the payload length for up to the first 10 non empty packets. | ||||||
509 | tcpUrgentCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseTcpUrgentCount (ElementID 16893). The number of TCP packets that have the URGENT Flag set. | ||||||
510 | largePacketCount | unsigned32 | totalCounter | packets | ||
Reversible as reverseLargePacketCount (ElementID 16894). The number of packets that contain more than 225 bytes of payload. | ||||||
511-549 | Unassigned | |||||
550 | certToolTombstoneId | unsigned32 | identifier | |||
An identifier of a tombstone record that is unique within the process that initially generates the record. Prior to YAF 3.0, this element was named "tombstoneId". | ||||||
551 | certToolExporterConfiguredId | unsigned16 | identifier | |||
An identifier for this process chosen by the user. Prior to YAF 3.0, this element was named "exporterConfiguredId". | ||||||
552 | certToolExporterUniqueId | unsigned16 | identifier | |||
A pseudo-random number to identify this exporting process. Prior to YAF 3.0, this element was named "exporterUniqueId". | ||||||
553 | certToolId | unsigned32 | identifier | 1-6 | ||
An identifier for each CERT tool. 1 - YAF 2 - super_mediator 3 - SiLK rwflowpack 4 - SiLK rwflowappend 5 - Mothra IPFIX Packer 6 - Analysis Pipeline | ||||||
554 | certToolTombstoneAccessList | subTemplateList | list | |||
A subTemplateList of records containing a certToolId (CERT/553) and the observationTimeSeconds when that tool accessed the tombstone record. Prior to YAF 3.0, this element was named "tombstoneAccessList". | ||||||
555-926 | Unassigned | |||||
927 | smDNSData | string | ||||
Field used by super_mediator to export DNS information. Prior to YAF 3.0, this element was named "dnsRName". | ||||||
928 | dnsHitCount | unsigned16 | ||||
Deprecated in favor of smDedupHitCount (CERT/929). | ||||||
929 | smDedupHitCount | unsigned64 | totalCounter | |||
The number of times the deduplicated item was seen. Prior to YAF 3.0, this element was named "observedDataTotalCount". | ||||||
930 | smDedupData | octetArray | ||||
A representation of data that is being deduplicated. Prior to YAF 3.0, this element was named "observedData". | ||||||
931 | smIPSetMatchesSource | unsigned8 | flags | |||
Used by super_mediator to indicate that the record's source IP address matched an IPset. A value of 0 means the source address was not present in the IPset; a value of 1 means it was present. | ||||||
932 | smIPSetMatchesDestination | unsigned8 | flags | |||
Used by super_mediator to indicate that the record's destination IP address matched an IPset. A value of 0 means the destination address was not present in the IPset; a value of 1 means it was present. | ||||||
933 | smIPSetName | string | default | |||
Used by super_mediator to record the name of the IPset used to determine smIPSetMatchesSource (CERT/931) and smIPSetMatchesDestination (CERT/932). | ||||||
934 | smPrefixMapLabelSource | string | default | |||
Used by super_mediator to record the label for the source IP or protocol/source-port pair as defined by a SiLK Prefix Map. | ||||||
935 | smPrefixMapLabelDestination | string | default | |||
Used by super_mediator to record the label for the destination IP or protocol/destination-port pair as defined by a SiLK Prefix Map. | ||||||
936 | smPrefixMapTypeId | unsigned8 | identifier | |||
Used by super_mediator to indicate the type of Prefix Map used to determine smPrefixMapLabelSource (CERT/934) and smPrefixMapLabelDestination (CERT/935), where 0 indicates a map from IPv4 addresses to names, 1 from protocol/port pairs, and 2 from IPv6 addresses. | ||||||
937 | smPrefixMapName | string | default | |||
Used by super_mediator to record the name of the Prefix Map used to determine smPrefixMapLabelSource (CERT/934) and smPrefixMapLabelDestination (CERT/935). | ||||||
938 | silkFlowtypeName | string | default | |||
The unique flowtype name of the flowtype identified by silkFlowtypeId (CERT/30). The flowtype name may also be represented by the pair silkClassName (CERT/939) and silkTypeName (CERT/940). | ||||||
939 | silkClassName | string | default | |||
The class name of the flowtype identified by silkFlowtypeId (CERT/30) and silkFlowtypeName (CERT/938). See also silkTypeName (CERT/940). | ||||||
940 | silkTypeName | string | default | |||
The type name of the flowtype identified by silkFlowtypeId (CERT/30) and silkFlowtypeName (CERT/938). The type name is unique within a silkClassName (CERT/939). | ||||||
941 | silkSensorName | string | default | |||
The name of the sensor identified by silkSensorId (CERT/31). | ||||||
942 | silkSensorDescription | string | default | |||
The description of the sensor identified by silkSensorId (CERT/31). | ||||||
943 | yafLayer2SegmentId | unsigned32 | identifier | |||
Identifier of a layer 2 network segment in an overlay network. The most significant byte identifies the layer 2 network overlay network encapsulation type: 0x00 reserved, 0x01 VxLAN, 0x02 NVGRE. The three lowest significant bytes hold the value of the layer 2 overlay network segment identfier. This element is a four-byte version of the IANA-defined layer2SegmentId, elementId 351. | ||||||
944-999 | Unassigned | |||||
1000 | templateName | string | ||||
Specifies a human-friendly name for an IPFIX template. | ||||||
1001 | templateDescription | string | ||||
Specifies a textual description for an IPFIX template. | ||||||
1002-16383 | Unassigned |
ID | Name | Contact URI | Last Updated |
---|---|---|---|
[Netsa_Tools] | Netsa Tools Help | mailto:netsa-help@cert.org | 2018-05-01 |