~ipv4

Prev Next

The alias ~ipv4 references fields that contain IP addresses such as:

srcipv4

IPv4 address of the source

dstipv4

IPv4 address of the destination

transdstip

Translated IPv4 address of the destination

rawmsghostipv4

IPv4 address of the host sending the raw message

cidr

Classless Inter-Domain Routing (CIDR) notation

transsrcip

Translated IPv4 address of the source

defgw

Default gateway typically referenced in network events

ipmask

IP network mask

intnatip

Internal NAT IP address used in NAT logs

extnatip

External NAT IP address used in NAT logs

xfwdforip

X-forwarded-for header value, command+ space delimited if more than one

callingsrcip

Source IP of a remote calling identity, typically observed in Windows event logs as calling address

targetip

Typically observed in host IDS/IPS, AV, and other logs when referencing a targeted system or user

For example:

~ipv4=215.18.25.33

~ipv4:215.18.25.0/24

~dstipv4=215.18.25.33