1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 | Packet profile dump:
IP ver Proto cnt min max avg tot %%
------ ----- ---------- ------------ ------------ ----------- ----------- ---
IPv4 6 39 2421398 81084676 65073140 2.5b 49.45
IPv4 17 59 7600746 75875290 36487520 2.2b 41.94
IPv6 17 14 9216526 72487998 31558210 441.8m 8.61
Note: Protocol 256 tracks pseudo/tunnel packets.
Per Thread module stats:
Thread Module IP ver Proto cnt min max avg tot %%
------------------------ ------ ----- ---------- ------------ ------------ ----------- ----------- ---
TMM_FLOWWORKER IPv4 6 39 116902 3360520 406875 15.9m 24.10
TMM_FLOWWORKER IPv4 17 59 205000 23947898 764881 45.1m 68.53
TMM_RECEIVEPCAPFILE IPv4 6 35 4442 5616 4790 167.7k 0.25
TMM_RECEIVEPCAPFILE IPv4 17 59 4436 12720 4843 285.8k 0.43
TMM_DECODEPCAPFILE IPv4 6 35 4562 18758 5175 181.1k 0.28
TMM_DECODEPCAPFILE IPv4 17 59 4570 34710 5277 311.4k 0.47
TMM_FLOWWORKER IPv6 17 14 187010 426360 267554 3.7m 5.69
TMM_RECEIVEPCAPFILE IPv6 17 14 4426 21670 5858 82.0k 0.12
TMM_DECODEPCAPFILE IPv6 17 14 4622 18242 5695 79.7k 0.12
Flow Worker IP ver Proto cnt min max avg
-------------------- ------ ----- ---------- ------------ ------------ -----------
flow IPv4 6 35 4780 13586 5353 187.4k 0.31
flow IPv4 17 59 4568 50112 5991 353.5k 0.58
stream IPv4 6 39 5636 1069370 43896 1.7m 2.79
app-layer IPv4 17 59 4444 61190 7898 466.0k 0.76
detect IPv4 6 39 77862 3034616 318127 12.4m 20.21
detect IPv4 17 59 176978 23912432 722019 42.6m 69.38
tcp-prune IPv4 6 39 4458 17772 5292 206.4k 0.34
flow IPv6 17 14 4776 26174 8422 117.9k 0.19
app-layer IPv6 17 14 4480 17898 9376 131.3k 0.21
detect IPv6 17 14 158418 381406 229935 3.2m 5.24
Note: stream includes app-layer for TCP
Per App layer parser stats:
App Layer IP ver Proto cnt min max avg
-------------------- ------ ----- ---------- ------------ ------------ -----------
tls IPv4 6 4 4676 5530 4941 19.8k 27.92
dns IPv4 17 2 22770 28250 25510 51.0k 72.08
Proto detect IPv4 17 9 4600 41394 13099 117.9k
Proto detect IPv6 17 6 5020 8248 6205 37.2k
Log Thread Module IP ver Proto cnt min max avg tot %%
------------------------ ------ ----- ---------- ------------ ------------ ----------- ----------- ---
Logger/output stats:
Logger IP ver Proto cnt min max avg tot
------------------------ ------ ----- ---------- ------------ ------------ ----------- -----------
LOGGER_ALERT_FAST IPv4 6 1 64254 64254 64254 64.3k 6.64
LOGGER_UNIFIED2 IPv4 6 1 118434 118434 118434 118.4k 12.24
LOGGER_JSON_ALERT IPv4 6 1 78400 78400 78400 78.4k 8.10
LOGGER_JSON_DNS IPv4 17 2 51152 515066 283109 566.2k 58.52
LOGGER_JSON_TLS IPv4 6 2 56944 83248 70096 140.2k 14.49
Prefilter IP ver Proto cnt min max avg tot %%
-------------------- ------ ----- ---------- ------------ ------------ ----------- --------- ---
payload IPv4 6 17 4580 249900 86148 1.5m 41.97
payload IPv4 17 59 5132 91494 15389 908.0k 26.02
stream IPv4 6 17 4432 456812 42308 719.2k 20.61
dns_query IPv4 17 1 33172 33172 33172 33.2k 0.95
tls_sni IPv4 6 5 5044 12808 8170 40.9k 1.17
tls_cert_issuer IPv4 6 2 4502 17896 11199 22.4k 0.64
tls_cert_subject IPv4 6 2 4620 8362 6491 13.0k 0.37
tls_cert_serial IPv4 6 2 4762 8892 6827 13.7k 0.39
Total IPv4 105 30617 3.2m
payload IPv6 17 14 5362 77416 19630 274.8k 7.88
Total IPv6 14 19630 274.8k
General detection engine stats:
Detection phase IP ver Proto cnt min max avg tot
------------------------ ------ ----- ---------- ------------ ------------ ----------- -----------
PROF_DETECT_IPONLY IPv4 6 4 14658 70162 52809 211.2k 0.26
PROF_DETECT_IPONLY IPv4 17 9 43084 220624 78379 705.4k 0.85
PROF_DETECT_RULES IPv4 6 39 4442 2364364 111896 4.4m 5.27
PROF_DETECT_RULES IPv4 17 59 76822 536902 172820 10.2m 12.32
PROF_DETECT_STATEFUL_START IPv4 6 1 231160 231160 231160 231.2k 0.28
PROF_DETECT_STATEFUL_CONT IPv4 6 39 4408 174850 33374 1.3m 1.57
PROF_DETECT_STATEFUL_CONT IPv4 17 59 4384 57738 5937 350.3k 0.42
PROF_DETECT_STATEFUL_UPDATE IPv4 6 31 4446 5120 4560 141.4k 0.17
PROF_DETECT_STATEFUL_UPDATE IPv4 17 2 4710 20416 12563 25.1k 0.03
PROF_DETECT_PREFILTER IPv4 6 39 13722 571586 96688 3.8m 4.55
PROF_DETECT_PREFILTER IPv4 17 59 40738 23733414 456884 27.0m 32.56
PROF_DETECT_PF_PAYLOAD IPv4 6 17 35326 474744 142936 2.4m 2.93
PROF_DETECT_PF_PAYLOAD IPv4 17 59 13994 100640 24750 1.5m 1.76
PROF_DETECT_PF_TX IPv4 6 31 4570 53960 9361 290.2k 0.35
PROF_DETECT_PF_TX IPv4 17 1 43166 43166 43166 43.2k 0.05
PROF_DETECT_PF_SORT1 IPv4 6 17 4504 7398 5161 87.7k 0.11
PROF_DETECT_PF_SORT1 IPv4 17 59 4472 18300 5440 321.0k 0.39
PROF_DETECT_PF_SORT2 IPv4 6 39 4408 18946 5270 205.5k 0.25
PROF_DETECT_PF_SORT2 IPv4 17 59 4430 23691950 406396 24.0m 28.96
PROF_DETECT_NONMPMLIST IPv4 6 39 4442 20364 5155 201.1k 0.24
PROF_DETECT_NONMPMLIST IPv4 17 59 4414 6180 4757 280.7k 0.34
PROF_DETECT_ALERT IPv4 6 39 4426 14404 4803 187.3k 0.23
PROF_DETECT_ALERT IPv4 17 59 4416 22208 4835 285.3k 0.34
PROF_DETECT_CLEANUP IPv4 6 39 4496 26860 5705 222.5k 0.27
PROF_DETECT_CLEANUP IPv4 17 59 4404 222220 8675 511.9k 0.62
PROF_DETECT_GETSGH IPv4 6 39 4434 60714 7017 273.7k 0.33
PROF_DETECT_GETSGH IPv4 17 59 4404 142938 9240 545.2k 0.66
PROF_DETECT_IPONLY IPv6 17 6 4836 23950 9779 58.7k 0.07
PROF_DETECT_RULES IPv6 17 14 58490 186990 100915 1.4m 1.71
PROF_DETECT_STATEFUL_CONT IPv6 17 14 4392 4716 4588 64.2k 0.08
PROF_DETECT_PREFILTER IPv6 17 14 41380 116094 57558 805.8k 0.97
PROF_DETECT_PF_PAYLOAD IPv6 17 14 14306 86476 28640 401.0k 0.48
PROF_DETECT_PF_SORT1 IPv6 17 14 4526 6356 5142 72.0k 0.09
PROF_DETECT_PF_SORT2 IPv6 17 14 4442 20518 5724 80.1k 0.10
PROF_DETECT_NONMPMLIST IPv6 17 14 4412 5108 4632 64.9k 0.08
PROF_DETECT_ALERT IPv6 17 14 4418 4856 4496 62.9k 0.08
PROF_DETECT_CLEANUP IPv6 17 14 4420 6114 4828 67.6k 0.08
PROF_DETECT_GETSGH IPv6 17 14 4664 24494 8998 126.0k 0.15
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 |
|