| Variable | Description |
| timestamp | Timestamp of the alarm |
| pkt_num | Packet number |
| pkt_len | Length of the packet |
| dir | Direction of the traffic (e.g., "S2C" for server-to-client, "C2S" for client-to-server) |
| proto | Transport layer protocol of the risky packet. |
| src_addr | source IP address |
| src_port | source port number |
| dst_addr | destination IP address |
| dst_port | destination port number |
| rule | Additional information to include in the alarm. |
| priority | priority associated with the detection rule |
| class | the classification type of the event |
| action | the action taken (e.g., allowed, blocked, etc.) |
| timestamp | Timestamp of the alarm |
| pkt_num | Packet number |
| pkt_len | Length of the packet |
| dir | Direction of the traffic (e.g., "S2C" for server-to-client, "C2S" for client-to-server) |
| proto | Transport layer protocol of the risky packet. |
| src_addr | source IP address |
| src_port | source port number |
| dst_addr | destination IP address |
| dst_port | destination port number |
| rule | Additional information to include in the alarm. |
| priority | priority associated with the detection rule |
| class | the classification type of the event |
| action | the action taken (e.g., allowed, blocked, etc.) |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.