TMS zl Management and Configuration Guide ST.1.0.090213
C-17
Log Messages
Log Message Formats and Fields
Table C-12. IPS Application Detection Family Fields
Session Open/Close Logs Family
Log messages from the session open or session close log family
(id=session_open_logs_family, id=session_close_logs_family) contain these
fields:
Table C-13. Session Open/Close Logs Family Fields
Field Name Value Format Description
actiontype 2 The action setting of the IDS rule: 2 = report
attacktime [YYYY-MM-DD
HH:MM:SS]
The time of the attack
packetdirection [0 | 1 | 2] The direction of the packet that triggered the rule:
0 = common; 1 = inbound; 2 = outbound
connectiondirection [both | initiator |
responder]
The direction of the connection that triggered the event
applicationname text The name of the application that was detected
Field Name Value Format Description
packetdirection [0 | 1 | 2] The direction of the packet that triggered the rule:
0 = common, 1 = inbound, 2 = outbound
sessionesablishedtime [YYYY-MM-DD HH:MM:SS] The time at which the session was established
sessionclosetime [YYYY-MM-DD HH:MM:SS] The time at which the session was closed
noofpktstoclient integer The number of packets that were transferred from the server to
the client
noofpktstoserver integer The number of packets that were transferred from the client to
the server
sent integer The number of bytes that were transferred from source to
destination
rcvd integer The number of bytes that were transferred from destination to
source