Network Blackbox

Download 39
Last updated Jan 1, 2024

nbb-custom-alerts

Get custom alerts from Quad Miners Network Blackbox.

nbb-custom-alerts [profile=PROFILE] [duration=NUM{mon|w|d|h|m|s}] [from=yyyyMMddHHmmss] [to=yyyyMMddHHmmss] src-ip=SRC-IP dst-ip=DST-IP [id=ID]
profile=PROFILE
The identifier of Network Blackbox connect profile.
duration=NUM{mon|w|d|h|m|s}
Scan only recent sessions. You should use s(second), m(minute), h(hour), d(day), mon(month) time unit. For example, 10s means data from 10 seconds earlier.
from=yyyyMMddHHmmss
Start time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
to=yyyyMMddHHmmss
End time of range. yyyyMMddHHmmss format. If you omit time part, it will be padded by zero.
src-ip=SRC-IP
Source IP address of target session.
dst-ip=DST-IP
Destination IP address of target session.
id=ID
Comma separated ID values.

Output Fields

FieldTypeNameDescription
_timeDateTime
profileStringConnect profileThe identifier of Network Blackbox connect profile
server_idIntegerServer IDe.g. 1000
row_idLongRow IDe.g. 9318647
hashLongHashe.g. 3159604307
src_ipIP addressSource IP
src_portIntegerSource port
dst_ipIP addressDestination IP
dst_portIntegerDestination port
sent_syslogBoolSent syslog
signature_idIntegerSignature ID
metaMapMetadata