Incidents: Difference between revisions

Jump to navigation Jump to search
mNo edit summary
Line 157: Line 157:
(ip_flow_end)
(ip_flow_end)
|This trigger checks the attributes whenever an IP flow ended.
|This trigger checks the attributes whenever an IP flow ended.
|total_packets, total_bytes, tcp_handshake_time, percent_retransmissions, zero_window_packets, duration, l7_protocol
|total_packets, total_bytes, tcp_handshake_time, percent_retransmissions, zero_window_packets, duration, l7_protocol, l4_port, l4_client_port, l4_server_port
|mandatory
|mandatory
|-
|-
340

edits

Navigation menu