Cisco Cisco Firepower Management Center 2000 Guía Del Desarrollador
Version 5.3
Sourcefire 3D System eStreamer Integration Guide
586
Understanding Legacy Data Structures
Legacy Connection Data Structures
Appendix B
The following diagram shows the format of a Connection Statistics data block for
4.10.2.x:
Byte
0
1
2
3
Bit
0 1 2 3 4 5 6 7 8 9 10 11
1
2
1
3
1
4
1
5
1
6
1
7
1
8
1
9
2
0
2
1
2
2
2
3
2
4
2
5
2
6
2
7
2
8
2
9
3
0
3
1
Connection Data Block Type (125)
Connection Data Block Length
Initiator IP Address
Responder IP Address
Initiator Port
Responder Port
First Packet Timestamp
Last Packet Timestamp
Connection Type
NetFlow Src TOS
NetFlow Dst TOS
NetFlow SNMP Input
NetFlow SNMP Input
cont.
NetFlow SNMP Output
Source Device IP
Address
Source Device IP Address cont.
TCP Flags
Packets Sent
Packets Received
Bytes Sent
Bytes Received
Protocol
Server ID...
Server ID, cont...
Client App Type ID
Client Application
Type ID cont....
Client App ID
Client
Ap
p V
er
sion
Client Application ID
cont....
String Block Type (0)
Block Type cont.
String Block Length
String Block Length
Client Application Version...
Client App URL
String Block Type (0)
String Block Length
Client Application URL...