331
SQL reference
Using Oracle tables
poolID
varchar(33)
Indicates the ID of the pool ("poolID" from
ifpooldb) where this event was detected.
Used internally
poolName
varchar(41)
Indicates the name of the interface group where
this event was detected.
prot
varchar(33)
Indicates that the protocol was either
IP
,
TCP
,
UDP
, or
ICMP
.
pyld
varchar(513)
Indicates the portion of the packet that triggered
this event.
Base-64 encoded
reliability
integer
Indicates the reliability of this event.
Valid values are 1-10
severity
integer
Indicates the severity of this event.
Valid values are 1-10
sips
varchar(195)
Indicates a list of source IPs for this event.
src_etheraddr
varchar(33)
Indicates the source ethernet address.
sttTime
integer
Indicates the start time for this event, according
to the sensor.
Standard UNIX time
format.
trgtname
varchar(3000)
Indicates the name of the attacker's target, or
blank if not applicable.
trgtntype
integer
Indicates the type of the attacker's target.
type
varchar(129)
Identifies the type of this event. This is the
violation/anomaly that caused the event to be
triggered.
Format is as follows:
VENDOR/EVENT_TAG
Example:
RCRS/COUNTER_ICM
P_HIGH
vlanId
integer
Indicates the VLAN ID.
vndr
varchar(33)
Indicates the vendor of the sensor that detected
the event.
Table B-2
Oracle Event Table
Field Name
Type
Description
Notes
Summary of Contents for 10521146 - Network Security 7120
Page 1: ...Symantec Network Security Administration Guide...
Page 12: ...12 Contents Index...
Page 14: ...14...
Page 70: ...70...
Page 110: ...110 Populating the topology database Adding nodes and objects...
Page 158: ...158 Responding Managing flow alert rules...
Page 188: ...188...
Page 242: ...242 Reporting Playing recorded traffic...
Page 268: ...268 Managing log files Exporting data...
Page 316: ...316 Advanced configuration Configuring advanced parameters...
Page 318: ...318...
Page 338: ...338 SQL reference Using MySQL tables...
Page 366: ...366 Glossary...
Page 392: ...392 Index...