]> git.ipfire.org Git - thirdparty/suricata.git/commitdiff
eve/schema: add new flow fields
authorVictor Julien <vjulien@oisf.net>
Fri, 10 Jun 2022 12:59:55 +0000 (14:59 +0200)
committerVictor Julien <vjulien@oisf.net>
Mon, 13 Jun 2022 14:59:47 +0000 (16:59 +0200)
etc/schema.json

index 1268fcaba816abeaac6ab7b1b69a7fe6803625c0..835858ea4a8be2871c82dfeb0272edf6564bce27 100644 (file)
                 "flow": {
                     "type": "object",
                     "properties": {
+                        "active": {
+                            "type": "integer"
+                        },
                         "emerg_mode_entered": {
                             "type": "integer"
                         },
                         "tcp_reuse": {
                             "type": "integer"
                         },
+                        "total": {
+                            "type": "integer"
+                        },
                         "udp": {
                             "type": "integer"
                         },
+                        "end": {
+                            "type": "object",
+                            "properties": {
+                                "state": {
+                                    "type": "object",
+                                    "properties": {
+                                        "new": {
+                                            "type": "integer"
+                                        },
+                                        "established": {
+                                            "type": "integer"
+                                        },
+                                        "closed": {
+                                            "type": "integer"
+                                        },
+                                        "local_bypassed": {
+                                            "type": "integer"
+                                        },
+                                        "capture_bypassed": {
+                                            "type": "integer"
+                                        }
+                                    },
+                                    "additionalProperties": false
+                                },
+                                "tcp_state": {
+                                    "type": "object",
+                                    "properties": {
+                                        "none": {
+                                            "type": "integer"
+                                        },
+                                        "syn_sent": {
+                                            "type": "integer"
+                                        },
+                                        "syn_recv": {
+                                            "type": "integer"
+                                        },
+                                        "established": {
+                                            "type": "integer"
+                                        },
+                                        "fin_wait1": {
+                                            "type": "integer"
+                                        },
+                                        "fin_wait2": {
+                                            "type": "integer"
+                                        },
+                                        "time_wait": {
+                                            "type": "integer"
+                                        },
+                                        "last_ack": {
+                                            "type": "integer"
+                                        },
+                                        "close_wait": {
+                                            "type": "integer"
+                                        },
+                                        "closing": {
+                                            "type": "integer"
+                                        },
+                                        "closed": {
+                                            "type": "integer"
+                                        }
+                                    },
+                                    "additionalProperties": false
+                                },
+                                "tcp_liberal": {
+                                    "type": "integer"
+                                }
+                            },
+                            "additionalProperties": false
+                        },
                         "mgr": {
                             "type": "object",
                             "properties": {
                                 },
                                 "rows_maxlen": {
                                     "type": "integer"
+                                },
+                                "rows_per_sec": {
+                                    "type": "integer"
+                                }
+                            },
+                            "additionalProperties": false
+                        },
+                        "recycler": {
+                            "type": "object",
+                            "properties": {
+                                "recycled": {
+                                    "type": "integer"
+                                },
+                                "queue_avg": {
+                                    "type": "integer"
+                                },
+                                "queue_max": {
+                                    "type": "integer"
                                 }
                             },
                             "additionalProperties": false
                 "tcp": {
                     "type": "object",
                     "properties": {
+                        "active_sessions": {
+                            "type": "integer"
+                        },
                         "insert_data_normal_fail": {
                             "type": "integer"
                         },