Skip to main content
Version: 2.10.1

Events Correlator

KeyField DescriptionComments
NFO timestampFormat: Mmm dd hh:mm:ss
NFO server IP addressFormat: IPv4_address
NFO server NetFlow source IDConfigurable.
nfc_idMessage type identifier"nfc_id=20196"
exp_ipNetwork device (exporter) IP address<IPv4 address>
t_lastNFO time of event<number>, unix sec. NFO time of a most recent event which contributed to this report.
t_firstNFO time of report<number>, unix sec. NFO time of an oldest event which contributed to this report
event_countEvent count<number>, The number of indicators which contributed to this report
indicatorIndicator<string>, Textual representation of the indicators which contributed to this report. See table in Appendix 1 for details
confidenceConfidence score<number/number>, Cumulative confidence score and reporting threshold confidence value
confidence_bonusConfidence bonus<number>, Bonus confidence score included in the cumulative confidence score