Skip to main content
Version: 2.2.1

Data streams

Data streams available in the system with default fields and user created fields are located in [Dashboard>Raw Data] menu.

The Data streams implemented in the system along with the available fields are listed and described below.

netflow

Deduplicated Netflow and Sflow records stream.

Field NameNQL FieldDescription
TIMESTAMPTimeTime
CLIENT_IPClient IPClient IP Address
SERVER_IPServer IPServer IP Address
PROTOCOLProtocolProtocol Number
CLIENT_PORTClient PortClient Port
SERVER_PORTServer PortServer Port
APPLICATIONApplicationApplication Number
UNIQUE_SRC_EXP_IPSExporter IPsUnique IP Adresses of Netflow Exporters
UNIQUE_INTERFACESInterfacesUnique numbers of Netflow Exporters's Inrefaces
CLIENT_FUNCTIONClient FunctionFunction Group of Client IP Adresses
SERVER_FUNCTIONServer FunctionFunction Group of Server IP Adresses
CLIENT_LOCATIONClient LocationLocation Group of Client IP Adresses
SERVER_LOCATIONServer LocationLocation Group of Server IP Adresses
CLIENT_ROLEClient RoleRole Group of Client IP Adresses
SERVER_ROLEServer RoleRole Group of Server IP Adresses
CLIENT_TCP_FLAGSClient TCP FlagsTCP Flags (Client -> Sever)
SERVER_TCP_FLAGSServer TCP FlagsTCP Flags (Sever -> Client)
UNIQUE_TOS_VALUESToS NumbersUnique Type of Service values
UNIQUE_MPLS_LABELSMPLS LabelsUnique MPLS Labels
UNIQUE_ASN_NUMBERSAS NumbersUnique Autonomous Systems Numbes
ICMP_TYPEICMP TypeICMP Type
CLIENT_IP_COUNTRYClient CountryCountry of Client IP Adresses
SERVER_IP_COUNTRYServer CountryCountry of Server IP Adresses
CLIENT_IP_AS_NUMBERClient AS NumberAS Number of Client IP Adresses
SERVER_IP_AS_NUMBERServer AS NumberAS Number of Server IP Adresses
ACTIVE_TIMEActive TimeActive Time of unique flow (session)
FIRST_TIMESTAMPFirst TimestampFirst Timestamp of unique flow (session)
LAST_TIMESTAMPLast TimestampLast Timestamp of unique flow (session)
CLIENT_BYTESClient BytesBytes (Client -> Sever)
SERVER_BYTESServer BytesBytes (Sever -> Client)
CLIENT_PACKETSClient PacketsPackets (Client > Sever)
SERVER_PACKETSServer PacketsPackets (Sever -> Client)
CLIENT_BITS_PER_SECClient Bits/sBits per Active Time (Client -> Sever)
SERVER_BITS_PER_SECServer Bits/sBits per Active Time (Sever -> Client)
CLIENT_PACKETS_PER_SECClient Packets/sPackets per Active Time (Client -> Sever)
SERVER_PACKETS_PER_SECServer Packets/sPackets per Active Time (Sever -> Client)
CLIENT_BITS_PER_PACKETAvg Client Bits/pktAvg Bits per Packet (Client -> Sever)
SERVER_BITS_PER_PACKETAvg Server Bits/pktAvg Bits per Packet (Sever -> Client)
AVG_CLIENT_BITS_PER_SECAvg Client Bits/sAvg Bits per Interval (Client -> Sever)
AVG_SERVER_BITS_PER_SECAvg Server Bits/sAvg Bits per Interval (Sever -> Client)
AVG_CLIENT_PACKETS_PER_SECAvg Client Packets/sAvg Packets per Interval (Client -> Sever)
AVG_SERVER_PACKETS_PER_SECAvg Server Packets/sAvg Packets per Interval (Sever -> Client)
CLIENT_MIN_IP_LENGTHClient Min Packet LengthMin Packet Length (Client -> Sever)
CLIENT_MAX_IP_LENGTHClient Max Packet LengthMax Packet Length (Client -> Sever)
RETRANSMITTED_IN_BYTESRentransmitted In BytesRentransmitted Bytes (Incomming)
RETRANSMITTED_OUT_BYTESRentransmitted Out BytesRentransmitted Bytes (Outgoing)
RETRANSMITTED_IN_PKTSRentransmitted In PacketsRentransmitted Packets (Incomming)
RETRANSMITTED_OUT_PKTSRentransmitted Out PacketsRentransmitted Packets (Outgoing)
CLIENT_MAX_TTLClient Max TTLMax TTL (Client -> Sever)
CLIENT_NW_LATENCY_MSClient Network TimeNetwork Latency (Client -> Server)
SERVER_NW_LATENCY_MSServer Network TimeNetwork Latency (Server -> Client)
APPL_LATENCY_MSInitial Server Response TimeResponse Time (Latency) (Application)
IN_INTERFACEIn InterfaceInterface (Incomming)
OUT_INTERFACEOut InterfaceInterface (Outgoing)
FIREWALL_EVENTFirewall EventFirewall Event (ASA)
FW_EXT_EVENTFirewall Ext EventFirewall Extended Event (ASA)
MPLS_TOP_LABEL_EXPMPLS Top LabelMPLS Top Label
MPLS_LABEL_1MPLS Label 1MPLS Label 1
MPLS_LABEL_2MPLS Label 2MPLS Label 2
MPLS_LABEL_3MPLS Label 3MPLS Label 3
MPLS_LABEL_4MPLS Label 4MPLS Label 4
MPLS_LABEL_5MPLS Label 5MPLS Label 5
SRC_ASSource ASSource Autonomous Systems
DST_ASDestination ASDestination Autonomous Systems
NF_F_XLATE_SRC_ADDR_IPV4Post Nat Source IPPost Nat Source IP Address
NF_F_XLATE_SRC_PORTPost Nat Source PortPost Nat Source Port
MIN_IP_LENGTHMin Packet LengthMin Packet Length
MAX_IP_LENGTHMax Packet LengthMax Packet Length
FLOW_LABELFlow LabelFlow Label
IPV6_OPTION_HEADERSIpv6 OptionsIPv6 Options
SRC_VLANSource VLANSource VLAN
DST_VLANDestination VLANDestination VLAN
IP_TOSToSType of Service number
FORWARDING_STATUSForwarding StatusForwarding Status
RETRANSMITTED_IN_BYTESRentransmitted In BytesRentransmitted Bytes (Incomming)
RETRANSMITTED_OUT_BYTESRentransmitted Out BytesRentransmitted Bytes (Outgoing)
RETRANSMITTED_IN_PKTSRentransmitted In PacketsRentransmitted Packets (Incomming)
RETRANSMITTED_OUT_PKTSRentransmitted Out PacketsRentransmitted Packets (Outgoing)
CLIENT_MAX_TTLClient Max TTLMax TTL (Client -> Sever)
CLIENT_NW_LATENCY_MSClient Network TimeNetwork Latency (Client -> Server)
SERVER_NW_LATENCY_MSServer Network TimeNetwork Latency (Server -> Client)
APPLICATION_IDApplication IDApplication ID
APPL_LATENCY_MSInitial Server Response TimeInitial Server Response Time

netflowTotalAggr

Field NameNQL FieldDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Bits/savgBitsPerSecondAvg Bits per Interval
Avg Packets/savgPacketsPerSecondAvg Packets per Interval
Bits/sbitsPerSecondBits per Active Time

netflowByIfcAggr

Netflow 1 min aggregated by interface flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Interface IndexifcIndexInterface Index
Interface NameifcNameLookup - Interface Index as Interface Name from SNMP database
FlowsflowsFlows sended by Exporter
In BytesinBytesBytes (In)
Out BytesoutBytesBytes (Out)
In PacketsinPacketsPackets (In)
Out PacketsoutPacketsPackets (Out)
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
In BitsinBitsBits (In)
Out BitsoutBitsBits (Out)
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg In Packets/savgInPacketsPerSecondAvg Packets (In) per Interval
Avg Out Packets/savgOutPacketsPerSecondAvg Packets (Out) per Interval
Avg In Bits/savgInBitsPerSecondAvg Bits (In) per Interval
Avg Out Bits/savgOutBitsPerSecondAvg Bits (Out) per Interval
% In UtilizationpctInUtilization% Utilization (In)
% Out UtilizationpctOutUtilization% Utilization (Out)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

netflowByAppAggr

Netflow 1 min aggregated by application flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
ApplicationapplicationApplication
Application NameapplicationNameApplication Name
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
Server Network TimeserverNetworkTimeNetwork Latency from Server Side
Initial Server Response TimeinitialServerResponseTimeInitial Server Response Time
Client Network TimeclientNetworkTimeNetwork Latency from Client Side
In Retransmitted PacketsretransmittedInPacketsRetransmitted Packets (Client -> Server)
Out Retransmitted PacketsretransmittedOutPacketsRetransmitted Packets (Server -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
% In Retransmitted PacketspercentRetransmittedInPacketsPercent of Retransmitted Packets (Client -> Server)
% Out Retransmitted PacketspercentRetransmittedOutPacketsPercent of Retransmitted Packets (Server -> Client)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time
Client TCP FlagsclientTcpFlagsMapper - TCP Flags (Client -> Sever)
Server TCP FlagsserverTcpFlagsMapper - TCP Flags (Sever -> Client)

netflowByAsnAggr

Netflow 1 min aggregated by ASN flows stream.

Field NameNQL FieldDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
AS NumberasNumberAS Number
AS NameasNameLookup - AS Number to AS Name from build-in database
DirectionasDirectionDirection
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByGroupAggr

Netflow 1 min aggregated by group flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Group NamegroupNameLocation Group Name
DirectiongroupDirectionDirection
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

Group Function

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Interface IndexifcIndexInterface Index
Interface NameifcNameLookup - Interface Index as Interface Name from SNMP database
FlowsflowsFlows sended by Exporter
In BytesinBytesBytes (In)
Out BytesoutBytesBytes (Out)
In PacketsinPacketsPackets (In)
Out PacketsoutPacketsPackets (Out)
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
In BitsinBitsBits (In)
Out BitsoutBitsBits (Out)
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg In Packets/savgInPacketsPerSecondAvg Packets (In) per Interval
Avg Out Packets/savgOutPacketsPerSecondAvg Packets (Out) per Interval
Avg In Bits/savgInBitsPerSecondAvg Bits (In) per Interval
Avg Out Bits/savgOutBitsPerSecondAvg Bits (Out) per Interval
% In UtilizationpctInUtilization% Utilization (In)
% Out UtilizationpctOutUtilization% Utilization (Out)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

Group Role

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Group NamegroupNameRole Group Name
DirectiongroupDirectionDirection
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByCountryAggr

Netflow 1 min aggregated by country flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Country NamecountryNameCountry Name
Country CodecountryCodeCountry Code
DirectioncountryDirectionDirection
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByExporterAggr

Netflow 1 min aggregated by exporter flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Exporter IPexporterIpExporter IP
Exporter NameexporterNameLookup - Exporter IP as Exporter Name from SNMP database
Exporter DescriptionexporterDescriptionLookup - Exporter IP as Exporter Description from SNMP database
Exporter LocationexporterLocationlookup("snmp-int-exp", "dev.loc", {"exporterIp": exporterIp})
FlowsflowsFlows sended by Exporter
BytesbytesBytes
PacketspacketsPackets
BitsbitsBits
Avg Flows/savgFlowsPerSecondAvg Flows per Interval
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval

netflowByIpAggr

Netflow 1 min aggregated by top IP flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
IP AddressipAddressIP Address
IP Address NameipAddressNameIP Address Name
AS NameasNameLookup - AS Number to AS Name from build-in database
Country CodecountryCodeMapper - IP Address to Country Code from build-in database
DirectionipDirectionDirection
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
Server Network TimeserverNetworkTimeNetwork Latency from Server Side
Initial Server Response TimeinitialServerResponseTimeInitial Server Response Time
Client Network TimeclientNetworkTimeNetwork Latency from Client Side
In Retransmitted PacketsretransmittedInPacketsRetransmitted Packets (Client -> Server)
Out Retransmitted PacketsretransmittedOutPacketsRetransmitted Packets (Server -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Client Bits/pktavgClientBitsPerPacketAvg Bits per Packet (Client -> Sever)
Avg Server Bits/pktavgServerBitsPerPacketAvg Bits per Packet (Sever -> Client)
Avg Client Bits/flowavgClientBitsPerFlowAvg Bits per Flow (Client -> Sever)
Avg Server Bits/flowavgServerBitsPerFlowAvg Bits per Flow (Sever -> Client)
Avg Client Packets/flowavgClientPacketsPerFlowAvg Packets per Flow (Client -> Sever)
Avg Server Packets/flowavgServerPacketsPerFlowAvg Packets per Flow (Sever -> Client)
% In Retransmitted PacketspercentRetransmittedInPacketsPercent of Retransmitted Packets (Client -> Server)
% Out Retransmitted PacketspercentRetransmittedOutPacketsPercent of Retransmitted Packets (Server -> Client)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByMplsAggr

Netflow 1 min aggregated by MPLS flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
MPLS LabelmplsUnique MPLS Label
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByProtocolAggr

Netflow 1 min aggregated by IP protocol flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
Protocol NumberprotocolProtocol Number
Protocol NameprotocolNameProtocol Name
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

netflowByTosAggr

Netflow 1 min aggregated by TOS flows stream.

Field NameNQL NameDescription
TimetimestampTime
Active TimeactiveTimeActive Time of unique flow (ms)
ToS NumbertosNumberToS Number
ToS NametosNameToS Name
FlowsflowsFlows sended by Exporter
Client BytesclientBytesBytes (Client -> Sever)
Server BytesserverBytesBytes (Sever -> Client)
Client PacketsclientPacketsPackets (Client -> Sever)
Server PacketsserverPacketsPackets (Sever -> Client)
SessionssessionsDeduplicated Flows
BytesbytesBytes
BitsbitsBits
PacketspacketsPackets
Client BitsclientBitsBits (Client -> Sever)
Server BitsserverBitsBits (Sever -> Client)
Server Packets/sserverPacketsPerSecondPackets per Active Time (Sever -> Client)
Client Packets/sclientPacketsPerSecondPackets per Active Time (Client -> Sever)
Server Bits/sserverBitsPerSecondBits per Active Time (Sever -> Client)
Client Bits/sclientBitsPerSecondBits per Active Time (Client -> Sever)
Avg Flows/savgFlowsPerSecondAvg Flows per Actie Time
Avg Server Packets/savgServerPacketsPerSecondAvg Packets per Interval (Sever -> Client)
Avg Client Packets/savgClientPacketsPerSecondAvg Packets per Interval (Client -> Sever)
Avg Server Bits/savgServerBitsPerSecondAvg Bits per Interval (Sever -> Client)
Avg Client Bits/savgClientBitsPerSecondAvg Bits per Interval (Client -> Sever)
Avg Packets/savgPacketsPerSecondAvg Packets (In) per Interval
Avg Bits/savgBitsPerSecondAvg Bits (In) per Interval
Packets/spacketsPerSecondPackets per Active Time
Bits/sbitsPerSecondBits per Active Time

alerts

Alerts stream.

Field NameNQL NameDescription
Alert IdidAlert Identifier
TimetimestampAlert Time
Rule TypealertRuleTypeRule Type
Alert NamealertNameAlert Name
Rule IdalertRuleIdRule Identifier
Alert DescriptionalertDescriptionAlert Description
Alert SeverityalertSeverityAlert Severity
Threshold LevelalertThresholdLevelThreshold Level (Criticial, Major, Minor)
Alert TagsalertTagsTags
Mitre TacticalertMitreTacticMitre ATT&CK Tactic
Mitre TechniquealertMitreTechniqueMitre ATT&CK Technique Id
Mitre Technique IdalertMitreTechniqueIdMitre ATT&CK Technique Id
Mitre SubtechniquealertMitreSubtechniqueMitre ATT&CK Subtechnique
CorrelationsalertCorrelationsRule Correlations
Mitigation SystemalertMitigationSystemMitigation System
Mitigation IPalertMitigationIpFieldMitigation IP
Raw DatarawDataRaw Data
ACKalertAckSetting the Acknowledge flag
ACK UseralertAckUserUser updating the Acknowledge flag
ACK TimealertAckLastUpdateAcknowledge flag update Time
False PositivealertFalsePositiveAlert handling False Positive flag
FP UseralertFalsePositiveUserUser updating the False Positive flag
FP TimealertFalsePositiveLastUpdateFalse Positive flag update time
CommentalertCommentComment
Commented UseralertCommentUserUser updating a comment
Comment TimealertCommentLastUpdateComment update time
Client IPclientIpClient IP
Client PortclientPortClient Port
Client TCP FlagsclientTcpFlagsClient TCP Flags
Client GroupclientGroupsClient Group
Client CountryclientCountryClient Country
Client MacclientMacClient Mac
Client HostnameclientHostnameClient Hostname
Server IPserverIpServer IP
Server PortserverPortServer Port
Server TCP FlagsserverTcpFlagsServer TCP Flags
Server GroupserverGroupsServer Group
Server CountryserverCountryServer Country
Server MacserverMacServer Mac
Server HostnameserverHostnameServer Hostname
UsernameuserUsername
Unique Client IPsuniqueClientIPsUnique Client IPs
Unique Server IPsuniqueServerIPsUnique Server IPs
Unique Server PortsuniqueServerPortsUnique Server Ports
Unique Client ASNsuniqueClientASNsUnique Client ASNs
Unique Server ASNsuniqueServerASNsUnique Server ASNs
Unique Client CountriesuniqueClientCountriesUnique Client Countries
Unique Server CountriesuniqueServerCountriesUnique Server Countries
BPF_bpfBytes Per Flow
BPP_bppBytes Per Packet
Bytes_bytesSum Bytes
Flows_flowsSum Flows
Packets_packetsSum Packets
PPF_ppfPackets Per Flow
PPS_ppsPackets Per Second
SYN_synCount of SYN flags
Unique ASN_uniqueASNsUnique Count of ASNs
Unique ClientIPs_uniqueClientIPsUnique Count of Client IPs
Unique ServerIPs_uniqueServerIPsUnique Count of Server IPs
Unique Server Ports_uniqueServerPortUnique Count of Server Port