NGFCTI

Download 81
Last updated Aug 5, 2023

ngfcti-alerts

Get alerts from NGFCTI service.

ngfcti-alerts [proxy=PROXY] [from=yyyyMMdd] [raw=t]
proxy=PROXY
Proxy server setting If not specified, send feed requests directly without proxy server. e.g. IP:PORT
from=yyyyMMdd
Target date in yyyyMMdd format. If not specified, it is set to current date.
raw=t
If 't' is specified, output the JSON data to the raw field.

Output Fields

FieldTypeNameDescription
_timeDateDetection time
src_ipIP addressSource IP address
src_portIntegerSource port
dst_ipIP addressDestination IP address
dst_portIntegerDestination port
src_countryStringSource country
signatureStringSignature
reasonStringReason
raw_dataStringRaw datae.g. WAF payload
stix_idStringSTIX ID
createdDateCreated
updatedDateUpdated