The alias ~ipv4 references fields that contain IP addresses such as:
| IPv4 address of the source |
| IPv4 address of the destination |
| Translated IPv4 address of the destination |
| IPv4 address of the host sending the raw message |
| Classless Inter-Domain Routing (CIDR) notation |
| Translated IPv4 address of the source |
| Default gateway typically referenced in network events |
| IP network mask |
| Internal NAT IP address used in NAT logs |
| External NAT IP address used in NAT logs |
| X-forwarded-for header value, command+ space delimited if more than one |
| Source IP of a remote calling identity, typically observed in Windows event logs as calling address |
| Typically observed in host IDS/IPS, AV, and other logs when referencing a targeted system or user |
For example:
~ipv4=215.18.25.33
~ipv4:215.18.25.0/24
~dstipv4=215.18.25.33