stats.log
------------------------------------------------------------------------------------
Date: 6/23/2023 -- 17:52:34 (uptime: 0d, 03h 31m 01s)
------------------------------------------------------------------------------------
Counter | TM Name | Value
------------------------------------------------------------------------------------
decoder.pkts | Total | 33234
decoder.bytes | Total | 21131709
decoder.ipv4 | Total | 33234
decoder.tcp | Total | 29450
decoder.udp | Total | 3783
decoder.icmpv4 | Total | 1
decoder.avg_pkt_size | Total | 635
decoder.max_pkt_size | Total | 1278
flow.tcp | Total | 3549
flow.udp | Total | 1756
flow.icmpv4 | Total | 1
flow.wrk.spare_sync_avg | Total | 100
flow.wrk.spare_sync | Total | 44
flow.wrk.flows_evicted | Total | 1002
tcp.sessions | Total | 345
tcp.syn | Total | 350
tcp.rst | Total | 49
detect.alert | Total | 1
app_layer.flow.failed_udp | Total | 1756
ips.accepted | Total | 32924
ips.blocked | Total | 310
flow.mgr.full_hash_pass | Total | 53
flow.spare | Total | 9889
flow.mgr.rows_maxlen | Total | 2
flow.mgr.flows_checked | Total | 5520
flow.mgr.flows_notimeout | Total | 1231
flow.mgr.flows_timeout | Total | 4289
flow.mgr.flows_evicted | Total | 4289
tcp.memuse | Total | 1212416
tcp.reassembly_memuse | Total | 196608
flow.memuse | Total | 7394304
since I turned on flow logging, eve.json contains only this
{"timestamp":"2023-06-23T17:49:06.188242+0200","flow_id":1109973059411870,"event_type":"flow","src_ip":" hidden_ip_address","src_port":49618,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":2,"pkts_toclient":0,"bytes_toserver":104,"bytes_toclient":0,"start":"2023-06-23T17:44:42.303006+0200","end":"2023-06-23T17:45:32.324213+0200","age":50,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:49:21.545981+0200","flow_id":133224490063226,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51453,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:46:47.513402+0200","end":"2023-06-23T17:46:47.513402+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:49:31.562196+0200","flow_id":138992636071416,"event_type":"flow","src_ip":"hidden_ip_address","src_port":64370,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":105,"bytes_toclient":0,"start":"2023-06-23T17:48:03.265720+0200","end":"2023-06-23T17:48:03.265720+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:50:26.320044+0200","flow_id":1015977717686838,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51275,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":142,"bytes_toclient":0,"start":"2023-06-23T17:49:10.942646+0200","end":"2023-06-23T17:49:10.942646+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:50:33.665055+0200","flow_id":1864272405523545,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51488,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":64,"bytes_toclient":0,"start":"2023-06-23T17:47:10.126041+0200","end":"2023-06-23T17:47:10.126041+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"02","tcp_flags_ts":"02","tcp_flags_tc":"00","syn":true,"state":"syn_sent"}}
{"timestamp":"2023-06-23T17:50:34.333100+0200","flow_id":1161564217307850,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51244,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":5,"pkts_toclient":0,"bytes_toserver":378,"bytes_toclient":0,"start":"2023-06-23T17:47:26.881354+0200","end":"2023-06-23T17:48:13.858094+0200","age":47,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:50:50.446882+0200","flow_id":1039359518222579,"event_type":"flow","src_ip":"hidden_ip_address","src_port":50309,"dest_ip":"hidden_ip_address","dest_port":993,"proto":"TCP","flow":{"pkts_toserver":2,"pkts_toclient":0,"bytes_toserver":138,"bytes_toclient":0,"start":"2023-06-23T17:48:48.239859+0200","end":"2023-06-23T17:48:48.239997+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:51:03.046736+0200","flow_id":474721636571954,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51478,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:47:15.056114+0200","end":"2023-06-23T17:47:15.056114+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:51:09.057618+0200","flow_id":1744992584970117,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51500,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:50:01.962437+0200","end":"2023-06-23T17:50:01.962437+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:51:15.066454+0200","flow_id":622666091000574,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51503,"dest_ip":"hidden_ip_address","dest_port":80,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":414,"bytes_toclient":0,"start":"2023-06-23T17:50:02.127742+0200","end":"2023-06-23T17:50:02.127742+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:51:26.418638+0200","flow_id":629168660624618,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51489,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:47:17.931050+0200","end":"2023-06-23T17:47:17.931050+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:51:29.089789+0200","flow_id":349162560556260,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51479,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":2,"pkts_toclient":0,"bytes_toserver":104,"bytes_toclient":0,"start":"2023-06-23T17:46:44.593124+0200","end":"2023-06-23T17:46:44.593306+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:52:24.514889+0200","flow_id":1085199703023132,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51493,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":64,"bytes_toclient":0,"start":"2023-06-23T17:48:31.335388+0200","end":"2023-06-23T17:48:31.335388+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"02","tcp_flags_ts":"02","tcp_flags_tc":"00","syn":true,"state":"syn_sent"}}
{"timestamp":"2023-06-23T17:52:39.206068+0200","flow_id":108803325260437,"event_type":"flow","src_ip":"hidden_ip_address","src_port":59529,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"UDP","app_proto":"failed","flow":{"pkts_toserver":2,"pkts_toclient":0,"bytes_toserver":126,"bytes_toclient":0,"start":"2023-06-23T17:51:41.291477+0200","end":"2023-06-23T17:51:41.291596+0200","age":0,"state":"new","reason":"timeout","alerted":false}}
{"timestamp":"2023-06-23T17:52:49.223150+0200","flow_id":1803541583018419,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51505,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":3,"pkts_toclient":0,"bytes_toserver":904,"bytes_toclient":0,"start":"2023-06-23T17:51:00.899507+0200","end":"2023-06-23T17:51:01.025106+0200","age":1,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:53:06.584453+0200","flow_id":1109973082364444,"event_type":"flow","src_ip":"hidden_ip_address","src_port":49618,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":106,"bytes_toclient":0,"start":"2023-06-23T17:50:32.317980+0200","end":"2023-06-23T17:50:32.317980+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:53:13.262534+0200","flow_id":973290047371440,"event_type":"flow","src_ip":"hidden_ip_address","src_port":50761,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":40,"bytes_toclient":0,"start":"2023-06-23T17:51:37.096432+0200","end":"2023-06-23T17:51:37.096432+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:53:19.272286+0200","flow_id":273158834686100,"event_type":"flow","src_ip":"hidden_ip_address","src_port":50695,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:50:39.592020+0200","end":"2023-06-23T17:50:39.592020+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:53:32.571530+0200","flow_id":153067258790291,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51507,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":189,"bytes_toclient":0,"start":"2023-06-23T17:51:50.475539+0200","end":"2023-06-23T17:51:50.475539+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:53:34.629939+0200","flow_id":1689355581190180,"event_type":"flow","src_ip":"hidden_ip_address","src_port":56522,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"UDP","app_proto":"failed","flow":{"pkts_toserver":3,"pkts_toclient":0,"bytes_toserver":2649,"bytes_toclient":0,"start":"2023-06-23T17:50:40.847908+0200","end":"2023-06-23T17:50:40.848044+0200","age":0,"state":"new","reason":"timeout","alerted":false}}
{"timestamp":"2023-06-23T17:53:42.641631+0200","flow_id":849234216078983,"event_type":"flow","src_ip":"hidden_ip_address","src_port":57628,"dest_ip":"hidden_ip_address","dest_port":80,"proto":"TCP","flow":{"pkts_toserver":15,"pkts_toclient":0,"bytes_toserver":1596,"bytes_toclient":0,"start":"2023-06-23T17:52:39.380551+0200","end":"2023-06-23T17:52:41.634976+0200","age":2,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:00.004843+0200","flow_id":1422839969086646,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51494,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:49:01.720054+0200","end":"2023-06-23T17:49:01.720054+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:01.339329+0200","flow_id":1845662323503814,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51504,"dest_ip":"hidden_ip_address","dest_port":80,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":403,"bytes_toclient":0,"start":"2023-06-23T17:50:02.127686+0200","end":"2023-06-23T17:50:02.127686+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:20.038167+0200","flow_id":1856631668579202,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51472,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":40,"bytes_toclient":0,"start":"2023-06-23T17:49:41.957314+0200","end":"2023-06-23T17:49:41.957314+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:26.048838+0200","flow_id":1015977726926675,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51275,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":52,"bytes_toclient":0,"start":"2023-06-23T17:51:31.155475+0200","end":"2023-06-23T17:51:31.155475+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:34.061078+0200","flow_id":1161564232000771,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51244,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":3,"pkts_toclient":0,"bytes_toserver":195,"bytes_toclient":0,"start":"2023-06-23T17:51:10.500995+0200","end":"2023-06-23T17:51:10.501067+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:54:49.418891+0200","flow_id":1733142784946534,"event_type":"flow","src_ip":"hidden_ip_address","src_port":50765,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":102,"bytes_toclient":0,"start":"2023-06-23T17:53:46.962918+0200","end":"2023-06-23T17:53:46.962918+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:55:06.113619+0200","flow_id":1039359526228285,"event_type":"flow","src_ip":"hidden_ip_address","src_port":50309,"dest_ip":"hidden_ip_address","dest_port":993,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":86,"bytes_toclient":0,"start":"2023-06-23T17:50:50.446781+0200","end":"2023-06-23T17:50:50.446781+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:55:10.122141+0200","flow_id":338339266568590,"event_type":"flow","src_ip":"hidden_ip_address","src_port":57626,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":40,"bytes_toclient":0,"start":"2023-06-23T17:52:44.991630+0200","end":"2023-06-23T17:52:44.991630+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}
{"timestamp":"2023-06-23T17:55:10.625200+0200","flow_id":153067265505326,"event_type":"flow","src_ip":"hidden_ip_address","src_port":51507,"dest_ip":"hidden_ip_address","dest_port":443,"proto":"TCP","flow":{"pkts_toserver":1,"pkts_toclient":0,"bytes_toserver":131,"bytes_toclient":0,"start":"2023-06-23T17:53:32.571438+0200","end":"2023-06-23T17:53:32.571438+0200","age":0,"state":"new","reason":"timeout","alerted":false},"tcp":{"tcp_flags":"00","tcp_flags_ts":"00","tcp_flags_tc":"00"}}