netstat.pcap
[ 1 Introduction ] [ 2 Valid tags and data tables ] [ 3 Table structure ]
Introduction
The tags beginning with netstat.pcap
identify PCAP (Packet Capture) event data.
Valid tags and data tablesÂ
The full tag must have 3 levels. The first two are fixed as netstat.pcac
. The third level identifies the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
PCAP (Packet Capture) |
|
|
|
|
For more information, read more About Devo tags.
Table structure
These are the fields displayed in this table:
netstat.pcap.b16simple
Field | Type | Field Transformation | Source field name | Extra Label |
---|---|---|---|---|
eventdate |
| Â | Â | Â |
source |
| Â | vsource | Â |
machine |
| Â | vmachine | Â |
pkt |
| pcap(8, int8(0), length(b16Pkt), from16(b16Pkt)) | b16Pkt | Â |
rawMessage |
|  |  | ✓ |
hostchain |
|  |  | ✓ |
tag |
|  |  | ✓ |