‘alert’
namespace for IDMEF pattern matching in SEC (table layout)
|
messageid |
|
|
|
|
|
assessment |
impact |
severity |
|
|
|
|
|
completion |
|
|
|
|
|
type |
|
|
|
|
|
description |
|
|
|
|
action |
category |
|
|
|
|
|
description |
|
|
|
|
confidence |
rating |
|
|
|
|
|
confidence |
|
|
|
analyzer |
analyzerid |
|
|
|
|
|
manufacturer |
|
|
|
|
|
model |
|
|
|
|
|
name |
|
|
|
|
|
version |
|
|
|
|
|
class |
|
|
|
|
|
ostype |
|
|
|
|
|
osversion |
|
|
|
|
|
node |
ident |
|
|
|
|
|
category |
|
|
|
|
|
location |
|
|
|
|
|
name |
|
|
|
|
|
address |
ident |
|
|
|
|
|
category |
|
|
|
|
|
vlan_name |
|
|
|
|
|
vlan_num |
|
|
|
|
|
address |
|
|
|
|
|
netmask |
|
|
|
process |
ident |
|
|
|
|
|
name |
|
|
|
|
|
pid |
|
|
|
|
|
path |
|
|
|
|
|
arg |
|
|
|
|
|
env |
|
|
|
create_time |
sec |
|
|
|
|
|
usec |
|
|
|
|
detect_time |
sec |
|
|
|
|
|
usec |
|
|
|
|
analyzer_time |
sec |
|
|
|
|
|
usec |
|
|
|
|
source |
ident |
|
|
|
|
|
spoofed |
|
|
|
|
|
interface |
|
|
|
|
|
node |
ident |
|
|
|
|
|
category |
|
|
|
|
|
location |
|
|
|
|
|
name |
|
|
|
|
|
address |
ident |
|
|
|
|
|
category |
|
|
|
|
|
vlan_name |
|
|
|
|
|
vlan_num |
|
|
|
|
|
address |
|
|
|
|
|
netmask |
|
|
|
user |
ident |
|
|
|
|
|
category |
|
|
|
|
|
userid |
ident |
|
|
|
|
|
type |
|
|
|
|
|
name |
|
|
|
|
|
number |
|
|
|
process |
ident |
|
|
|
|
|
name |
|
|
|
|
|
pid |
|
|
|
|
|
path |
|
|
|
|
|
arg |
|
|
|
|
|
env |
|
|
|
|
service |
ident |
|
|
|
|
|
name |
|
|
|
|
|
port |
|
|
|
|
|