335
SQL reference
Using MySQL tables
clusterID
integer
Indicates the user-defined Network Security
cluster ID where the incident originated.
contextBuffer
text
Indicates additional information sent by the
sensor. Not every event will have context
information.
Example: For HTTP
events, this may be a
URL. For FTP events,
this may be a
username.
contextDesc
text
Indicates the description of the data in
contextBuffer
.
Base-64 encoded.
crtTime
integer
Indicates the time when this event was realized in
the analysis framework.
Standard UNIX time
format (seconds since
1970 GMT)
custID
varchar(41)
Indicates the Customer ID that this event is
associated with.
dips
varchar(195)
Indicates a list of destination IPs for this event.
dst_etheraddr
varchar(33)
Indicates the destination ethernet address.
dvName
varchar(41)
Indicates the name of the network device where
the event was detected.
endTime
integer
Indicates the end time for this event, according to
the sensor.
Standard UNIX time
format.
eventCode
varchar(65)
Indicates the Symantec standard code
representing the event.
eventNum
integer
Indicates the event number for this incident. The
first event in an incident will have an
eventNum
of 1. The
eventNum
will be incremented by 1 for
each subsequent event.
flowcookie
text
Indicates the flowcookie.
fmly
varchar(33)
Indicates the event family.
For class=
sniffer
events, this is
integrity
or
availability
. For
class=
generic
events, this is
fnotice
or
notice
guiTxt
varchar(65)
Deprecated.
Table B-4
MySQL Event Table
Field Name
Type
Description
Notes
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...