Network connection information

Prev Next

Events pertaining to network connections.

Parsing should prioritize primary source and destination information, including IP addresses that can be used in intel and analytics. These events belong to the connection, firewall, or http_proxy metaclass.

Taxonomy

Type

Description

dsthost

string

Hostname of the destination machine

dstipv4

IPv4

Destination IPv4 address. Provides additional geolocation information about events (such as dstisp, dstcountry, dstlatitude, dstlongitude).

dstipv6

IPv6

Destination IPv6 address. Provides additional geolocation information about events (such as dstisp, dstcountry, dstlatitude, dstlongitude).

dstport

integer

Destination port number

srchost

string

Hostname of the source machine

srcipv4

IPv4

Source IPv4 address. Used in all detection rules for global exclusions. Provides additional geolocation information about events (such as srcisp, srccountry, srclatitude, srclongitude).

srcipv6

IPv6

Source IPv6 address. Used in all detection rules for global exclusions. Provides additional geolocation information about events (such as srcisp, srccountry, srclatitude, srclongitude).

srcport

integer

Source port number