Document toolboxDocument toolbox

netstat.pcap

Introduction

The tags beginning with netstat.pcap identify PCAP (Packet Capture) event data.

Valid tags and data tables 

The full tag must have 3 levels. The first two are fixed as netstat.pcac. The third level identifies the type of events sent.

These are the valid tags and corresponding data tables that will receive the parsers' data:

Product / Service

Tags

Data tables

Product / Service

Tags

Data tables

PCAP (Packet Capture)

netstat.pcap.b16

netstat.pcap.b16

netstat.pcap.b16simple

netstat.pcap.b16simple

For more information, read more About Devo tags.

Table structure

These are the fields displayed in this table:

netstat.pcap.b16simple

Field

Type

Field Transformation

Source field name

Extra Label

Field

Type

Field Transformation

Source field name

Extra Label

eventdate

timestamp

 

 

 

source

str

 

vsource

 

machine

str

 

vmachine

 

pkt

packet

pcap(8, int8(0), length(b16Pkt), from16(b16Pkt))

b16Pkt

 

rawMessage

str

 

 

✓

hostchain

str

 

 

✓

tag

str

 

 

✓