17.1. EVE
- 17.1.1. Eve JSON Output
- 17.1.1.1. Output types
- 17.1.1.2. Alerts
- 17.1.1.3. Anomaly
- 17.1.1.4. HTTP
- 17.1.1.5. DNS
- 17.1.1.6. TLS
- 17.1.1.7. ARP
- 17.1.1.8. MQTT
- 17.1.1.9. Drops
- 17.1.1.10. Stats
- 17.1.1.11. Date modifiers in filename
- 17.1.1.12. Threaded file output
- 17.1.1.13. Rotate log file
- 17.1.1.14. Multiple Logger Instances
- 17.1.1.15. File permissions
- 17.1.1.16. JSON flags
- 17.1.1.17. Community Flow ID
- 17.1.2. Eve JSON Format
- 17.1.2.1. Common Section
- 17.1.2.2. Event type: Alert
- 17.1.2.3. Event type: Anomaly
- 17.1.2.4. Event type: HTTP
- 17.1.2.5. Event type: DNS
- 17.1.2.6. Event type: FTP
- 17.1.2.7. Event type: FTP_DATA
- 17.1.2.8. Event type: TLS
- 17.1.2.9. Event type: TFTP
- 17.1.2.10. Event type: SMB
- 17.1.2.11. Event type: BITTORRENT-DHT
- 17.1.2.12. Event type: SSH
- 17.1.2.13. Event type: Flow
- 17.1.2.14. Event type: RDP
- 17.1.2.15. Event type: RFB
- 17.1.2.16. Event type: MQTT
- 17.1.2.16.1. Transactions
- 17.1.2.16.2. Common fields
- 17.1.2.16.3. MQTT CONNECT fields
- 17.1.2.16.4. MQTT CONNACK fields
- 17.1.2.16.5. MQTT PUBLISH fields
- 17.1.2.16.6. MQTT PUBACK/PUBREL/PUBREC/PUBCOMP fields
- 17.1.2.16.7. MQTT SUBSCRIBE fields
- 17.1.2.16.8. MQTT SUBACK fields
- 17.1.2.16.9. MQTT UNSUBSCRIBE fields
- 17.1.2.16.10. MQTT UNSUBACK fields
- 17.1.2.16.11. MQTT AUTH fields (MQTT 5.0)
- 17.1.2.16.12. MQTT DISCONNECT fields
- 17.1.2.16.13. Truncated MQTT data
- 17.1.2.17. Event type: HTTP2
- 17.1.2.18. Event type: PGSQL
- 17.1.2.19. Event type: IKE
- 17.1.2.20. Event type: Modbus
- 17.1.2.20.1. Common fields
- 17.1.2.20.2. Request/Response fields
- 17.1.2.20.3. Exception fields
- 17.1.2.20.4. Diagnostic fields
- 17.1.2.20.5. MEI fields
- 17.1.2.20.6. Read Request fields
- 17.1.2.20.7. Read Response fields
- 17.1.2.20.8. Multiple Write Request fields
- 17.1.2.20.9. Mask Write fields
- 17.1.2.20.10. Other Write fields
- 17.1.2.20.11. Generic Data fields
- 17.1.2.20.12. Example
- 17.1.2.21. Event type: QUIC
- 17.1.2.22. Event type: DHCP
- 17.1.2.23. Event type: ARP
- 17.1.3. Eve JSON 'jq' Examples