12 KiB
12 KiB
| 1 | common_recv_time | common_log_id | common_stream_trace_id | common_direction | common_stream_dir | common_start_time | common_end_time | common_con_duration_ms | common_establish_latency_ms | common_processing_time | common_ingestion_time | common_entrance_id | common_device_id | common_egress_link_id | common_ingress_link_id | common_isp | common_data_center | common_sled_ip | common_device_group | common_app_behavior | common_action | common_sub_action | common_policy_id | common_user_tags | common_user_region | common_client_ip | common_internal_ip | common_client_port | common_client_location | common_client_asn | common_subscriber_id | common_imei | common_imsi | common_phone_number | common_server_ip | common_external_ip | common_server_port | common_server_location | common_server_asn | common_app_id | common_userdefine_app_name | common_app_identify_info | common_app_label | common_app_surrogate_id | common_l7_protocol | common_protocol_label | common_service_category | common_service | common_l4_protocol | common_sessions | common_c2s_pkt_num | common_s2c_pkt_num | common_c2s_pkt_diff | common_s2c_pkt_diff | common_c2s_byte_num | common_s2c_byte_num | common_c2s_byte_diff | common_s2c_byte_diff | common_c2s_ipfrag_num | common_s2c_ipfrag_num | common_c2s_tcp_lostlen | common_s2c_tcp_lostlen | common_c2s_tcp_unorder_num | common_s2c_tcp_unorder_num | common_c2s_pkt_retrans | common_s2c_pkt_retrans | common_c2s_byte_retrans | common_s2c_byte_retrans | common_first_ttl | common_tcp_client_isn | common_tcp_server_isn | common_mirrored_pkts | common_mirrored_bytes | common_address_type | common_schema_type | common_vsys_id | common_t_vsys_id | common_device_tag | common_encapsulation | common_tunnels | common_address_list | common_has_dup_traffic | common_stream_error | common_link_info_c2s | common_link_info_s2c | common_packet_capture_file | common_tunnel_endpoint_a_desc | common_tunnel_endpoint_b_desc | http_url | http_host | http_domain | http_request_line | http_response_line | http_request_header | http_response_header | http_request_content | http_response_content | http_request_body | http_response_body | http_request_body_key | http_response_body_key | http_proxy_flag | http_sequence | http_snapshot | http_cookie | http_referer | http_user_agent | http_request_content_length | http_request_content_type | http_response_content_length | http_response_content_type | http_content_length | http_content_type | http_set_cookie | http_version | http_response_latency_ms | http_session_duration_ms | http_action_file_size | mail_protocol_type | mail_account | mail_to_cmd | mail_from_cmd | mail_from | mail_to | mail_cc | mail_bcc | mail_subject | mail_subject_charset | mail_content | mail_content_charset | mail_attachment_name | mail_attachment_name_charset | mail_attachment_content | mail_eml_file | mail_snapshot | dns_message_id | dns_qr | dns_opcode | dns_aa | dns_tc | dns_rd | dns_ra | dns_rcode | dns_qdcount | dns_ancount | dns_nscount | dns_arcount | dns_qname | dns_qtype | dns_qclass | dns_cname | dns_sub | dns_rr | dns_response_latency_ms | ssl_version | ssl_sni | ssl_san | ssl_cn | ssl_pinningst | ssl_intercept_state | ssl_passthrough_reason | ssl_server_side_latency | ssl_client_side_latency | ssl_server_side_version | ssl_client_side_version | ssl_cert_verify | ssl_error | ssl_con_latency_ms | ssl_ja3_fingerprint | ssl_ja3_hash | ssl_ja3s_fingerprint | ssl_ja3s_hash | ssl_cert_issuer | ssl_cert_subject | dtls_cookie | dtls_version | dtls_sni | dtls_san | dtls_cn | dtls_con_latency_ms | dtls_ja3_fingerprint | dtls_ja3_hash | dtls_cert_issuer | dtls_cert_subject | quic_version | quic_sni | quic_user_agent | ftp_account | ftp_url | ftp_content | ftp_link_type | bgp_type | bgp_as_num | bgp_route | voip_calling_account | voip_called_account | voip_calling_number | voip_called_number | streaming_media_url | streaming_media_protocol | app_extra_info | rdp_cookie | rdp_security_protocol | rdp_client_channels | rdp_keyboard_layout | rdp_client_version | rdp_client_name | rdp_client_product_id | rdp_desktop_width | rdp_desktop_height | rdp_requested_color_depth | rdp_certificate_type | rdp_certificate_count | rdp_certificate_permanent | rdp_encryption_level | rdp_encryption_method | sip_call_id | sip_originator_description | sip_responder_description | sip_user_agent | sip_server | sip_originator_sdp_connect_ip | sip_originator_sdp_media_port | sip_originator_sdp_media_type | sip_originator_sdp_content | sip_responder_sdp_connect_ip | sip_responder_sdp_media_port | sip_responder_sdp_media_type | sip_responder_sdp_content | sip_duration_s | sip_bye | rtp_payload_type_c2s | rtp_payload_type_s2c | rtp_pcap_path | rtp_originator_dir | ssh_version | ssh_auth_success | ssh_client_version | ssh_server_version | ssh_cipher_alg | ssh_mac_alg | ssh_compression_alg | ssh_kex_alg | ssh_host_key_alg | ssh_host_key | ssh_hassh | stratum_cryptocurrency | stratum_mining_pools | stratum_mining_program |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | 1701142472 | 1.60825E+18 | 7.3374E+13 | 69 | 3 | 1701142472 | 1701142472 | 1.70114E+12 | 1.70114E+12 | 1701142592 | 1701142592 | 0 | 512 | 513 | CUCC | 10.111.192.182 | 0 | 0 | 124.88.144.139 | 124.88.144.139 | 56025 | 659001,,659000 | 4837 | 116.177.242.239 | 116.177.242.239 | 443 | Unknown,Unknown,China | 4837 | {"THIRD":[{"app_name":"qq_web","app_id":1241,"surrogate_id":0,"packet_sequence":5},{"app_name":"qqvideo","app_id":2887,"surrogate_id":0,"packet_sequence":5}]} | qqvideo | HTTPS | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 26 | 35 | 26 | 35 | 2796 | 39161 | 2796 | 39161 | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 7 | 60 | 8864 | 59 | 1011038595 | 3160113298 | 0 | 0 | 4 | SSL | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | qq.com | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | findermp.video.qq.com | *.video.qq.com;video.qq.com | *.video.qq.com | \N | \N | \N | \N | \N | 335422873 | c59b5aeb69936c251f090be89e1c4ca5 | 3a1455a84fe415a4d75b0084ca474a79 | CN=DigiCert Secure Site CN CA G3;O=DigiCert Inc;C=US;;;; | CN=*.video.qq.com;O=Shenzhen Tencent Computer Systems Company Limited;C=CN;S=Guangdong Province;L=Shenzhen;; | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 3 | 1701183547 | 1.60894E+18 | 3.00651E+12 | 69 | 2 | 1701181817 | 1701183547 | 1730557 | 540807 | 1701183667 | 1701183667 | 0 | 0 | 1281 | CUCC | 10.111.192.132 | 0 | 0 | 116.178.110.29 | 116.178.110.29 | 21646 | 650100,,650100 | 4837 | 103.102.202.181 | 103.102.202.181 | 13401 | Unknown,Unknown,China | 23724 | {"UNKNOWN":[{"app_name":"unknown","app_id":4,"surrogate_id":0,"packet_sequence":77}]} | [{"app_name":"unknown","packet_sequence":77}] | unknown | HTTP | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 164 | 0 | 164 | 0 | 20808 | 0 | 20808 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 16 | 0 | 1074 | 0 | 0 | 1246021723 | 0 | 0 | 4 | HTTP | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | HTTP/1.1 200 OK | 0 | 93 | 0 | http1 | 540807 | 540807 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 4 | 1701139837 | 1.60821E+18 | 5.57817E+13 | 69 | 2 | 1701139258 | 1701139837 | 578633 | 327192 | 1701139957 | 1701139957 | 0 | 0 | 1537 | CUCC | 10.111.192.184 | 0 | 0 | 124.88.250.44 | 124.88.250.44 | 5993 | 652900,,652900 | 4837 | 110.242.70.51 | 110.242.70.51 | 80 | Unknown,Unknown,China | 4837 | {"THIRD":[{"app_name":"bittorrent","app_id":15,"surrogate_id":0,"packet_sequence":72}]} | bittorrent | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 111 | 0 | 111 | 0 | 7492 | 0 | 7492 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 14 | 0 | 954 | 0 | 0 | 1160700988 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 5 | 1701161082 | 1.60856E+18 | 3.00582E+12 | 69 | 1 | 1701160756 | 1701161082 | 326319 | 320715 | 1701161082 | 1701161082 | 0 | 1280 | 0 | CUCC | 10.111.192.136 | 0 | 0 | 124.88.210.130 | 124.88.210.130 | 13042 | 653100,,653100 | 4837 | 223.109.81.209 | 223.109.81.209 | 80 | Unknown,Unknown,China | 56046 | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 129 | 0 | 129 | 0 | 146934 | 0 | 146934 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 99 | 0 | 145134 | 0 | 0 | 3086112863 | 0 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 6 | 1701109083 | 1.60769E+18 | 3.00412E+12 | 69 | 2 | 1701108749 | 1701109083 | 334514 | 320539 | 1701109083 | 1701109083 | 0 | 0 | 1537 | CUCC | 10.111.192.166 | 0 | 0 | 124.88.79.89 | 124.88.79.89 | 48413 | 650100,,650100 | 4837 | 39.105.135.199 | 39.105.135.199 | 443 | Unknown,Unknown,China | 37963 | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 31 | 0 | 31 | 0 | 2335 | 0 | 2335 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 3014640405 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 7 | 1701141029 | 1.60823E+18 | 5.57817E+13 | 69 | 3 | 1701140456 | 1701141029 | 573430 | 312168 | 1701141029 | 1701141029 | 0 | 1536 | 1537 | CUCC | 10.111.192.184 | 0 | 0 | 124.88.250.44 | 124.88.250.44 | 24241 | 652900,,652900 | 4837 | 110.242.70.51 | 110.242.70.51 | 80 | Unknown,Unknown,China | 4837 | {"UNKNOWN":[{"app_name":"unknown","app_id":4,"surrogate_id":0,"packet_sequence":191}]} | [{"app_name":"unknown","packet_sequence":191}] | unknown | QUIC | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 100 | 109 | 100 | 109 | 6846 | 7332 | 6846 | 7332 | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 16 | 444 | 1066 | 59 | 2917770588 | 2668919157 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 8 | 1701109067 | 1.60769E+18 | 3.00412E+12 | 69 | 2 | 1701108748 | 1701109067 | 319440 | 306431 | 1701109067 | 1701109067 | 0 | 0 | 1537 | CUCC | 10.111.192.166 | 0 | 0 | 124.88.79.89 | 124.88.79.89 | 49032 | 650100,,650100 | 4837 | 39.105.135.199 | 39.105.135.199 | 443 | Unknown,Unknown,China | 37963 | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 30 | 0 | 30 | 0 | 2261 | 0 | 2261 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 3510817054 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 9 | 1701109047 | 1.60769E+18 | 3.00412E+12 | 69 | 2 | 1701108747 | 1701109047 | 299543 | 286651 | 1701109047 | 1701109047 | 0 | 0 | 1537 | CUCC | 10.111.192.166 | 0 | 0 | 124.88.79.89 | 124.88.79.89 | 49123 | 650100,,650100 | 4837 | 39.105.135.199 | 39.105.135.199 | 443 | Unknown,Unknown,China | 37963 | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 27 | 0 | 27 | 0 | 2039 | 0 | 2039 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 3831560987 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 10 | 1701161082 | 1.60856E+18 | 3.00582E+12 | 69 | 1 | 1701160758 | 1701161082 | 324098 | 285630 | 1701161082 | 1701161082 | 0 | 1280 | 0 | CUCC | 10.111.192.136 | 0 | 0 | 124.88.210.130 | 124.88.210.130 | 7690 | 653100,,653100 | 4837 | 223.109.81.209 | 223.109.81.209 | 80 | Unknown,Unknown,China | 56046 | UNCATEGORIZED | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 129 | 0 | 129 | 0 | 160994 | 0 | 160994 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 110 | 0 | 159854 | 0 | 0 | 4011966652 | 0 | 0 | 0 | 4 | BASE | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| 11 | 1701106482 | 1.60765E+18 | 1.34945E+14 | 69 | 2 | 1701106172 | 1701106482 | 309887 | 284274 | 1701106482 | 1701106482 | 0 | 0 | 513 | CUCC | 10.111.192.139 | 0 | 0 | 43.224.53.89 | 43.224.53.89 | 47418 | 650100,,650100 | 4837 | 116.177.236.87 | 116.177.236.87 | 80 | Unknown,Unknown,China | 4837 | HTTP | ETHERNET.IPv4.TCP | [] | 0 | IPv4_TCP | 1 | 0 | 164 | 0 | 164 | 0 | 206002 | 0 | 206002 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 134 | 0 | 189224 | 0 | 0 | 1333432587 | 0 | 0 | 4 | HTTP | 1 | 1 | {"tags":[{"tag":"data_center","value":"CUCC"}]} | 0 | 0 | HTTP/1.1 206 Partial Content | 0 | 1 | 13875 | application/octet-stream | http1 | 284276 | 284277 | 0 | 0 | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | \N | \N | \N | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | \N | \N | 0 |