Trellix Network Security

Download 50
Last updated Aug 2, 2023

trellix-nx-flows

Fetch flows for alert from Trellix Network Security devices

trellix-nx-flows field=FIELD
field=FIELD
Alert uuid field name

Output Fields

FieldTypeNameDescription
_timeDateTimeFlow time
_profileStringConnect profile
uuidStringAlert UUID
idIntegerFlow ID
vlanIntegerVLAN ID
src_ipIP addressSource IP address
src_portIntegerSource port
dst_ipIP addressDestination IP address
dst_portIntegerDestination port
protocolStringProtocol
event_typeStringEvent typedns, tls, flow, http, fileinfo
tls_sniStringTLS SNI
file_nameStringFile name
file_sizeLongFile size
md5StringMD5
http_statusIntegerHTTP status
http_methodStringHTTP methode.g. GET, POST
http_hostStringHTTP host
http_urlStringHTTP URI
dns_typeStringDNS packet typequery or answer
dns_rr_typeStringDNS resource typee.g. A, CNAME, MX
dns_rr_nameStringDNS resource nameResource record name (domain)
smb_commandStringSMB commande.g. Tree Connect, Session Setup, Session Logoff
smb_pidIntegerSMB process ID
smb_pathStringSMB file path