Hey Jason,
Sorry… That ‘stats.log’ is my EVE file. Here’s an example output of the it (just the ending)…
… http":3997,“ftp”:0,“smtp”:0,“tls”:64397,“ssh”:5,“imap”:0,“smb”:0,“dcerpc_tcp”:0,“dns_tcp”:7,“nfs_tcp”:0,“ntp”:3944,“ftp-data”:0,“tftp”:0,“ikev2”:0,“krb5_tcp”:0,“dhcp”:213,“snmp”:6,“sip”:26,“rdp”:0,“failed_tcp”:13,“dcerpc_udp”:0,“dns_udp”:51894,“nfs_udp”:0,“krb5_udp”:0,“failed_udp”:24871},“tx”:{“http”:16042,“ftp”:0,“smtp”:0,“tls”:0,“ssh”:0,“imap”:0,“smb”:0,“dcerpc_tcp”:0,“dns_tcp”:22,“nfs_tcp”:0,“ntp”:4588,“ftp-data”:0,“tftp”:0,“ikev2”:0,“krb5_tcp”:0,“dhcp”:278,“snmp”:9,“sip”:26,“rdp”:0,“dcerpc_udp”:0,“dns_udp”:105191,“nfs_udp”:0,“krb5_udp”:0},“expectations”:0},“flow_mgr”:{“closed_pruned”:68274,“new_pruned”:43700,“est_pruned”:52360,“bypassed_pruned”:0,“flows_checked”:26,“flows_notimeout”:13,“flows_timeout”:13,“flows_timeout_inuse”:3,“flows_removed”:10,“rows_checked”:65536,“rows_skipped”:65506,“rows_empty”:6,“rows_busy”:0,“rows_maxlen”:2},“http”:{“memuse”:19757,“memcap”:0},“ftp”:{“memuse”:0,“memcap”:0}}}
No “host” key present. However, in the alert EVE…
… “start”:“2020-08-05T22:30:01.741712-0400”},“payload”:“LWsrXwAAAACQUwsAAAAAAE9GVFdJTkstUElOR9raU09GVFdJTkstUElOR9raU09GVFdJTkstUEk=”,“stream”:0,“packet”:“VDloDw7EADAYyy2NCABFAABUCHpAAEABJfQMnwIKDJHxAQgAmbBYQAAFLWsrXwAAAACQUwsAAAAAAE9GVFdJTkstUElOR9raU09GVFdJTkstUElOR9raU09GVFdJTkstUEk=”,“packet_info”:{“linktype”:1},“host”:“MEER”}