-
+appid.aim_clients: count of aim clients discovered by appid
+
+
+-
+
appid.battlefield_flows: count of battle field flows discovered by appid
@@ -22063,6 +22630,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.bootp_flows: count of bootp flows discovered by appid
+
+
+-
+
appid.dcerpc_tcp_flows: count of dce rpc flows over tcp discovered by appid
@@ -22073,6 +22645,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.direct_connect_flows: count of direct connect flows discovered by appid
+
+
+-
+
appid.dns_tcp_flows: count of dns flows over tcp discovered by appid
@@ -22093,6 +22670,16 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.http_flows: count of http flows discovered by appid
+
+
+-
+
+appid.ignored packets: count of packets ignored by appid inspector
+
+
+-
+
appid.imap_flows: count of imap service flows discovered by appid
@@ -22133,17 +22720,42 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.msn_clients: count of msn clients discovered by appid
+
+
+-
+
appid.mysql_flows: count of mysql service flows discovered by appid
-
-appid.netbios_flows: count of netbios service flows discovered by appid
+appid.netbios_dgm_flows: count of netbios-dgm service flows discovered by appid
-
-appid.packets: count of packets processed by appid
+appid.netbios_ns_flows: count of netbios-ns service flows discovered by appid
+
+
+-
+
+appid.netbios_ssn_flows: count of netbios-ssn service flows discovered by appid
+
+
+-
+
+appid.nntp_flows: count of nntp flows discovered by appid
+
+
+-
+
+appid.ntp_flows: count of ntp flows discovered by appid
+
+
+-
+
+appid.packets: count of packets received by appid inspector
-
@@ -22153,16 +22765,141 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.processed packets: count of packets processed by appid inspector
+
+
+-
+
+appid.radius_flows: count of radius flows discovered by appid
+
+
+-
+
+appid.rexec_flows: count of rexec flows discovered by appid
+
+
+-
+
+appid.rfb_flows: count of rfb flows discovered by appid
+
+
+-
+
+appid.rlogin_flows: count of rlogin flows discovered by appid
+
+
+-
+
+appid.rpc_flows: count of rpc flows discovered by appid
+
+
+-
+
+appid.rshell_flows: count of rshell flows discovered by appid
+
+
+-
+
+appid.rsync_flows: count of rsync service flows discovered by appid
+
+
+-
+
+appid.rtmp_flows: count of rtmp flows discovered by appid
+
+
+-
+
+appid.rtp_clients: count of rtp clients discovered by appid
+
+
+-
+
+appid.sip_clients: count of SIP clients discovered by appid
+
+
+-
+
+appid.sip_flows: count of SIP flows discovered by appid
+
+
+-
+
+appid.smtp_aol_clients: count of AOL smtp clients discovered by appid
+
+
+-
+
+appid.smtp_applemail_clients: count of Apple Mail smtp clients discovered by appid
+
+
+-
+
+appid.smtp_eudora_clients: count of Eudora smtp clients discovered by appid
+
+
+-
+
+appid.smtp_eudora_pro_clients: count of Eudora Pro smtp clients discovered by appid
+
+
+-
+
+appid.smtp_evolution_clients: count of Evolution smtp clients discovered by appid
+
+
+-
+
appid.smtp_flows: count of smtp flows discovered by appid
-
+appid.smtp_kmail_clients: count of KMail smtp clients discovered by appid
+
+
+-
+
+appid.smtp_lotus_notes_clients: count of Lotus Notes smtp clients discovered by appid
+
+
+-
+
+appid.smtp_microsoft_outlook_clients: count of Microsoft Outlook smtp clients discovered by appid
+
+
+-
+
+appid.smtp_microsoft_outlook_express_clients: count of Microsoft Outlook Express smtp clients discovered by appid
+
+
+-
+
+appid.smtp_microsoft_outlook_imo_clients: count of Microsoft Outlook IMO smtp clients discovered by appid
+
+
+-
+
+appid.smtp_mutt_clients: count of Mutt smtp clients discovered by appid
+
+
+-
+
appid.smtps_flows: count of smtps flows discovered by appid
-
+appid.smtp_thunderbird_clients: count of Thunderbird smtp clients discovered by appid
+
+
+-
+
+appid.snmp_flows: count of snmp flows discovered by appid
+
+
+-
+
appid.ssh_clients: count of ssh clients discovered by appid
@@ -22183,11 +22920,36 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+appid.tftp_flows: count of tftp flows discovered by appid
+
+
+-
+
appid.timbuktu_flows: count of timbuktu flows discovered by appid
-
+appid.tns_clients: count of tns clients discovered by appid
+
+
+-
+
+appid.tns_flows: count of tns flows discovered by appid
+
+
+-
+
+appid.vnc_clients: count of vnc clients discovered by appid
+
+
+-
+
+appid.yahoo_messenger_clients: count of Yahoo Messenger clients discovered by appid
+
+
+-
+
arp_spoof.packets: total packets
@@ -22393,6 +23155,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+dce_smb.Ignored bytes: total ignored bytes
+
+
+-
+
dce_smb.Max outstanding requests: total smb maximum outstanding requests
@@ -22413,237 +23180,387 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-dce_smb.Other responses: total connection-oriented other responses
+dce_smb.Other responses: total connection-oriented other responses
+
+
+-
+
+dce_smb.Packets: total smb packets
+
+
+-
+
+dce_smb.PDUs: total connection-oriented PDUs
+
+
+-
+
+dce_smb.Rejects: total connection-oriented rejects
+
+
+-
+
+dce_smb.Request fragments: total connection-oriented request fragments
+
+
+-
+
+dce_smb.Requests: total connection-oriented requests
+
+
+-
+
+dce_smb.Response fragments: total connection-oriented response fragments
+
+
+-
+
+dce_smb.Responses: total connection-oriented responses
+
+
+-
+
+dce_smb.Server frags reassembled: total connection-oriented server fragments reassembled
+
+
+-
+
+dce_smb.Server max fragment size: connection-oriented server maximum fragment size
+
+
+-
+
+dce_smb.Server min fragment size: connection-oriented server minimum fragment size
+
+
+-
+
+dce_smb.Server segs reassembled: total connection-oriented server segments reassembled
+
+
+-
+
+dce_smb.Server segs reassembled: total smb server segments reassembled
+
+
+-
+
+dce_smb.Sessions: total smb sessions
+
+
+-
+
+dce_smb.Shutdowns: total connection-oriented shutdowns
+
+
+-
+
+dce_smb.SMBv2 close: total number of SMBv2 close packets seen
+
+
+-
+
+dce_smb.SMBv2 create: total number of SMBv2 create packets seen
+
+
+-
+
+dce_smb.SMBv2 read: total number of SMBv2 read packets seen
+
+
+-
+
+dce_smb.SMBv2 set info: total number of SMBv2 set info packets seen
+
+
+-
+
+dce_smb.SMBv2 tree connect: total number of SMBv2 tree connect packets seen
+
+
+-
+
+dce_smb.SMBv2 tree disconnect: total number of SMBv2 tree disconnect packets seen
+
+
+-
+
+dce_smb.SMBv2 write: total number of SMBv2 write packets seen
+
+
+-
+
+dce_tcp.aborted sessions: total aborted sessions
+
+
+-
+
+dce_tcp.Alter context responses: total connection-oriented alter context responses
+
+
+-
+
+dce_tcp.Alter contexts: total connection-oriented alter contexts
+
+
+-
+
+dce_tcp.Auth3s: total connection-oriented auth3s
+
+
+-
+
+dce_tcp.bad autodetects: total bad autodetects
+
+
+-
+
+dce_tcp.Bind acks: total connection-oriented binds acks
+
+
+-
+
+dce_tcp.Bind naks: total connection-oriented bind naks
+
+
+-
+
+dce_tcp.Binds: total connection-oriented binds
+
+
+-
+
+dce_tcp.Cancels: total connection-oriented cancels
-
-dce_smb.Packets: total smb packets
+dce_tcp.Client frags reassembled: total connection-oriented client fragments reassembled
-
-dce_smb.PDUs: total connection-oriented PDUs
+dce_tcp.Client max fragment size: connection-oriented client maximum fragment size
-
-dce_smb.Rejects: total connection-oriented rejects
+dce_tcp.Client min fragment size: connection-oriented client minimum fragment size
-
-dce_smb.Request fragments: total connection-oriented request fragments
+dce_tcp.Client segs reassembled: total connection-oriented client segments reassembled
-
-dce_smb.Requests: total connection-oriented requests
+dce_tcp.events: total events
-
-dce_smb.Response fragments: total connection-oriented response fragments
+dce_tcp.Faults: total connection-oriented faults
-
-dce_smb.Responses: total connection-oriented responses
+dce_tcp.MS RPC/HTTP PDUs: total connection-oriented MS requests to send RPC over HTTP
-
-dce_smb.Server frags reassembled: total connection-oriented server fragments reassembled
+dce_tcp.Orphaned: total connection-oriented orphaned
-
-dce_smb.Server max fragment size: connection-oriented server maximum fragment size
+dce_tcp.Other requests: total connection-oriented other requests
-
-dce_smb.Server min fragment size: connection-oriented server minimum fragment size
+dce_tcp.Other responses: total connection-oriented other responses
-
-dce_smb.Server segs reassembled: total connection-oriented server segments reassembled
+dce_tcp.PDUs: total connection-oriented PDUs
-
-dce_smb.Server segs reassembled: total smb server segments reassembled
+dce_tcp.Rejects: total connection-oriented rejects
-
-dce_smb.Sessions: total smb sessions
+dce_tcp.Request fragments: total connection-oriented request fragments
-
-dce_smb.Shutdowns: total connection-oriented shutdowns
+dce_tcp.Requests: total connection-oriented requests
-
-dce_tcp.aborted sessions: total aborted sessions
+dce_tcp.Response fragments: total connection-oriented response fragments
-
-dce_tcp.Alter context responses: total connection-oriented alter context responses
+dce_tcp.Responses: total connection-oriented responses
-
-dce_tcp.Alter contexts: total connection-oriented alter contexts
+dce_tcp.Server frags reassembled: total connection-oriented server fragments reassembled
-
-dce_tcp.Auth3s: total connection-oriented auth3s
+dce_tcp.Server max fragment size: connection-oriented server maximum fragment size
-
-dce_tcp.bad autodetects: total bad autodetects
+dce_tcp.Server min fragment size: connection-oriented server minimum fragment size
-
-dce_tcp.Bind acks: total connection-oriented binds acks
+dce_tcp.Server segs reassembled: total connection-oriented server segments reassembled
-
-dce_tcp.Bind naks: total connection-oriented bind naks
+dce_tcp.Shutdowns: total connection-oriented shutdowns
-
-dce_tcp.Binds: total connection-oriented binds
+dce_tcp.tcp packets: total tcp packets
-
-dce_tcp.Cancels: total connection-oriented cancels
+dce_tcp.tcp sessions: total tcp sessions
-
-dce_tcp.Client frags reassembled: total connection-oriented client fragments reassembled
+dce_udp.aborted sessions: total aborted sessions
-
-dce_tcp.Client max fragment size: connection-oriented client maximum fragment size
+dce_udp.Acks: total connection-less acks
-
-dce_tcp.Client min fragment size: connection-oriented client minimum fragment size
+dce_udp.bad autodetects: total bad autodetects
-
-dce_tcp.Client segs reassembled: total connection-oriented client segments reassembled
+dce_udp.Cancel acks: total connection-less cancel acks
-
-dce_tcp.events: total events
+dce_udp.Cancels: total connection-less cancels
-
-dce_tcp.Faults: total connection-oriented faults
+dce_udp.Client facks: total connection-less client facks
-
-dce_tcp.MS RPC/HTTP PDUs: total connection-oriented MS requests to send RPC over HTTP
+dce_udp.events: total events
-
-dce_tcp.Orphaned: total connection-oriented orphaned
+dce_udp.Faults: total connection-less faults
-
-dce_tcp.Other requests: total connection-oriented other requests
+dce_udp.Fragments: total connection-less fragments
-
-dce_tcp.Other responses: total connection-oriented other responses
+dce_udp.Frags reassembled: total connection-less fragments reassembled
-
-dce_tcp.PDUs: total connection-oriented PDUs
+dce_udp.Max fragment size: connection-less maximum fragment size
-
-dce_tcp.Rejects: total connection-oriented rejects
+dce_udp.Max seqnum: max connection-less seqnum
-
-dce_tcp.Request fragments: total connection-oriented request fragments
+dce_udp.No calls: total connection-less no calls
-
-dce_tcp.Requests: total connection-oriented requests
+dce_udp.Other requests: total connection-less other requests
-
-dce_tcp.Response fragments: total connection-oriented response fragments
+dce_udp.Other responses: total connection-less other responses
-
-dce_tcp.Responses: total connection-oriented responses
+dce_udp.Ping: total connection-less ping
-
-dce_tcp.Server frags reassembled: total connection-oriented server fragments reassembled
+dce_udp.Rejects: total connection-less rejects
-
-dce_tcp.Server max fragment size: connection-oriented server maximum fragment size
+dce_udp.Requests: total connection-less requests
-
-dce_tcp.Server min fragment size: connection-oriented server minimum fragment size
+dce_udp.Responses: total connection-less responses
-
-dce_tcp.Server segs reassembled: total connection-oriented server segments reassembled
+dce_udp.Server facks: total connection-less server facks
-
-dce_tcp.Shutdowns: total connection-oriented shutdowns
+dce_udp.udp packets: total udp packets
-
-dce_tcp.tcp packets: total tcp packets
+dce_udp.udp sessions: total udp sessions
-
-dce_tcp.tcp sessions: total tcp sessions
+dce_udp.Working: total connection-less working
-
@@ -22688,6 +23605,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+detection.hard evals: non-fast pattern rule evaluations
+
+
+-
+
detection.header searches: fast pattern searches in header buffer
@@ -22733,11 +23655,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-detection.slow searches: non-fast pattern rule evaluations
-
-
--
-
detection.total alerts: alerts including IP reputation
@@ -23043,27 +23960,37 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-latency.packet_timeouts: packets that timed out
+latency.max usecs: maximum usecs elapsed
-
-latency.rule_eval_timeouts: rule evals that timed out
+latency.packet timeouts: packets that timed out
-
-latency.rule_tree_enables: rule tree re-enables
+latency.rule eval timeouts: rule evals that timed out
-
-latency.total_packets: total packets monitored
+latency.rule tree enables: rule tree re-enables
-
-latency.total_rule_evals: total rule evals monitored
+latency.total packets: total packets monitored
+
+
+-
+
+latency.total rule evals: total rule evals monitored
+
+
+-
+
+latency.total usecs: total usecs elapsed
-
@@ -23873,32 +24800,32 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.file memcap prunes: file sessions pruned due to memcap
+stream.file ha prunes: file sessions pruned by high availability sync
-
-stream.file preemptive prunes: file sessions pruned during preemptive pruning
+stream.file idle prunes: file sessions pruned due to timeout
-
-stream.file timeout prunes: file sessions pruned due to timeout
+stream.file memcap prunes: file sessions pruned due to memcap
-
-stream.file total prunes: total file sessions pruned
+stream.file preemptive prunes: file sessions pruned during preemptive pruning
-
-stream.file uni prunes: file uni sessions pruned
+stream.file total prunes: total file sessions pruned
-
-stream.file user prunes: file sessions pruned for other reasons
+stream.file uni prunes: file uni sessions pruned
-
@@ -23918,6 +24845,16 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+stream.icmp ha prunes: icmp sessions pruned by high availability sync
+
+
+-
+
+stream.icmp idle prunes: icmp sessions pruned due to timeout
+
+
+-
+
stream_icmp.max: max icmp sessions
@@ -23948,11 +24885,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.icmp timeout prunes: icmp sessions pruned due to timeout
-
-
--
-
stream_icmp.timeouts: icmp session timeouts
@@ -23968,11 +24900,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.icmp user prunes: icmp sessions pruned for other reasons
-
-
--
-
stream_ip.alerts: alerts generated
@@ -23988,7 +24915,7 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream_ip.current: current fragments
+stream_ip.current frags: current fragments
-
@@ -24023,6 +24950,16 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+stream.ip ha prunes: ip sessions pruned by high availability sync
+
+
+-
+
+stream.ip idle prunes: ip sessions pruned due to timeout
+
+
+-
+
stream_ip.max frags: max fragments
@@ -24088,22 +25025,17 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.ip timeout prunes: ip sessions pruned due to timeout
-
-
--
-
stream_ip.timeouts: ip session timeouts
-
-stream.ip total prunes: total ip sessions pruned
+stream_ip.total frags: total fragments
-
-stream_ip.total: total fragments
+stream.ip total prunes: total ip sessions pruned
-
@@ -24133,11 +25065,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.ip user prunes: ip sessions pruned for other reasons
-
-
--
-
stream_tcp.3way trackers: tcp session tracking started on ack
@@ -24193,6 +25120,16 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+stream.tcp ha prunes: tcp sessions pruned by high availability sync
+
+
+-
+
+stream.tcp idle prunes: tcp sessions pruned due to timeout
+
+
+-
+
stream_tcp.ignored: tcp packets ignored
@@ -24313,11 +25250,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.tcp timeout prunes: tcp sessions pruned due to timeout
-
-
--
-
stream_tcp.timeouts: tcp session timeouts
@@ -24338,22 +25270,27 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.tcp user prunes: tcp sessions pruned for other reasons
+stream_udp.created: udp session trackers created
-
-stream_udp.created: udp session trackers created
+stream.udp excess prunes: udp sessions pruned due to excess
-
-stream.udp excess prunes: udp sessions pruned due to excess
+stream.udp flows: total udp sessions
-
-stream.udp flows: total udp sessions
+stream.udp ha prunes: udp sessions pruned by high availability sync
+
+
+-
+
+stream.udp idle prunes: udp sessions pruned due to timeout
-
@@ -24388,11 +25325,6 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.udp timeout prunes: udp sessions pruned due to timeout
-
-
--
-
stream_udp.timeouts: udp session timeouts
@@ -24408,32 +25340,32 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.udp user prunes: udp sessions pruned for other reasons
+stream.user excess prunes: user sessions pruned due to excess
-
-stream.user excess prunes: user sessions pruned due to excess
+stream.user flows: total user sessions
-
-stream.user flows: total user sessions
+stream.user ha prunes: user sessions pruned by high availability sync
-
-stream.user memcap prunes: user sessions pruned due to memcap
+stream.user idle prunes: user sessions pruned due to timeout
-
-stream.user preemptive prunes: user sessions pruned during preemptive pruning
+stream.user memcap prunes: user sessions pruned due to memcap
-
-stream.user timeout prunes: user sessions pruned due to timeout
+stream.user preemptive prunes: user sessions pruned during preemptive pruning
-
@@ -24448,17 +25380,17 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-stream.user user prunes: user sessions pruned for other reasons
+tcp.bad checksum (ip4): nonzero tcp over ip checksums
-
-tcp.bad checksum (ip4): nonzero tcp over ip checksums
+tcp.bad checksum (ip6): nonzero tcp over ipv6 checksums
-
-tcp.bad checksum (ip6): nonzero tcp over ipv6 checksums
+tcp_connector.messages: total messages
-
@@ -24538,6 +25470,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+116: ciscometadata
+
+
+-
+
116: decode
@@ -24688,6 +25625,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+133: dce_udp
+
+
+-
+
134: latency
@@ -25518,7 +26460,27 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
-116:468 (decode) too many protocols present
+116:468 (ciscometadata) truncated Cisco Metadata header
+
+
+-
+
+116:469 (ciscometadata) invalid Cisco Metadata option length
+
+
+-
+
+116:470 (ciscometadata) invalid Cisco Metadata option type
+
+
+-
+
+116:471 (ciscometadata) invalid Cisco Metadata SGT
+
+
+-
+
+116:472 (decode) too many protocols present
-
@@ -25848,6 +26810,11 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+119:66 (http_inspect) White space within header name
+
+
+-
+
119:67 (http_inspect) Excessive gzip compression
@@ -25893,6 +26860,21 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+119:76 (http_inspect) Unsupported Transfer-Encoding or Content-Encoding used
+
+
+-
+
+119:77 (http_inspect) Unknown Transfer-Encoding or Content-Encoding used
+
+
+-
+
+119:78 (http_inspect) Multiple layers of compression encodings applied
+
+
+-
+
122:1 (port_scan) TCP portscan
@@ -26593,6 +27575,26 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+133:40 (dce_udp) Connection-less DCE/RPC - Invalid major version.
+
+
+-
+
+133:41 (dce_udp) Connection-less DCE/RPC - Invalid pdu type.
+
+
+-
+
+133:42 (dce_udp) Connection-less DCE/RPC - Data length less than header size.
+
+
+-
+
+133:43 (dce_udp) Connection-less DCE/RPC - Bad sequence number.
+
+
+-
+
133:44 (dce_smb) SMB - Invalid SMB version 1 seen.
@@ -26658,6 +27660,16 @@ string wizard.spells[].to_server[].spell: sequence of data with
-
+133:58 (dce_smb) SMB - File offset provided is greater than file size specified
+
+
+-
+
+133:59 (dce_smb) SMB - Next command specified in SMB2 header is beyond payload boundary
+
+
+-
+
134:1 (latency) rule tree suspended due to latency
@@ -27489,6 +28501,11 @@ deleted -> unified2: 'filename'
-
+ciscometadata (codec): support for cisco metadata
+
+
+-
+
classifications (basic): define rule categories with priority
@@ -27539,6 +28556,11 @@ deleted -> unified2: 'filename'
-
+dce_udp (inspector): dce over udp inspection
+
+
+-
+
decode (basic): general decoder rules
@@ -28284,6 +29306,11 @@ deleted -> unified2: 'filename'
-
+tcp_connector (connector): implement the tcp stream connector
+
+
+-
+
telnet (inspector): telnet inspection and normalization
@@ -28339,6 +29366,11 @@ deleted -> unified2: 'filename'
-
+codec::ciscometadata: support for cisco metadata
+
+
+-
+
codec::erspan2: support for encapsulated remote switched port analyzer - type 2
@@ -28514,6 +29546,11 @@ deleted -> unified2: 'filename'
-
+connector::tcp_connector: implement the tcp stream connector
+
+
+-
+
inspector::appid: application and service identification
@@ -28544,6 +29581,11 @@ deleted -> unified2: 'filename'
-
+inspector::dce_udp: dce over udp inspection
+
+
+-
+
inspector::dnp3: dnp3 inspection
@@ -29296,7 +30338,7 @@ deleted -> unified2: 'filename'