The instant that the first packet in this flow was observed.
The duration between the instants the first and last packets in this flow were observed.
The source port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The destination port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The IP protocol of this flow.
The SiLK flow type (class and type) of this flow,
or FlowType(0) if unknown.
The SiLK sensor that observed this flow, or Sensor(0)
if unknown.
The union of all TCP flags observed in this flow, or
TCPFlags(0) if this flow is not a TCP flow.
The flags observed in the initial packet of this
TCP flow, or TCPFlags(0) if this flow is not a TCP flow or
if extended flags are not available.
The union of all TCP flags observed after the
initial packet of this flow, or TCPFlags(0) if this flow is
not a TCP flow or if extended flags are not available.
Flags relating to the observed status of this flow, including whether extended TCP flags are available. See TCPState for more details.
The detected application of this flow,
expressed as the common port number for that application, or
Port(0) if no application was detected.
A Short value stored as a memo on this flow, or zero if no such memo has been set.
The input SNMP routing interface for this flow, or
SNMPInterface(0) if routing information is not available.
The output SNMP routing interface for this flow, or
SNMPInterface(0) if routing information is not available.
The number of IP packets observed in this flow.
The number of bytes in packets observed in this flow.
The source IP address of packets in this flow.
The destination IP address of packets in this flow.
The next-hop IP address of packets in this flow, or
IPAddress("0.0.0.0") or IPAddress("::") if routing
information is not available.
The detected application of this flow,
expressed as the common port number for that application, or
Port(0) if no application was detected.
The number of bytes in packets observed in this flow.
The destination IP address of packets in this flow.
The destination port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The duration between the instants the first and last packets in this flow were observed.
The instant that the last packet in this flow was observed.
The union of all TCP flags observed in this flow, or
TCPFlags(0) if this flow is not a TCP flow.
The SiLK flow type (class and type) of this flow,
or FlowType(0) if unknown.
The code of this ICMP flow, or garbage if this is a TCP or UDP
flow, or ICMPType(0) if this is not an ICMP, TCP, or UDP flow.
The type of this ICMP flow, or garbage if this is a TCP or UDP
flow, or ICMPType(0) if this is not an ICMP, TCP, or UDP flow.
The flags observed in the initial packet of this
TCP flow, or TCPFlags(0) if this flow is not a TCP flow or
if extended flags are not available.
The input SNMP routing interface for this flow, or
SNMPInterface(0) if routing information is not available.
True if this flow's addresses are IPv6 addresses.
A Short value stored as a memo on this flow, or zero if no such memo has been set.
The next-hop IP address of packets in this flow, or
IPAddress("0.0.0.0") or IPAddress("::") if routing
information is not available.
The output SNMP routing interface for this flow, or
SNMPInterface(0) if routing information is not available.
The number of IP packets observed in this flow.
The IP protocol of this flow.
The union of all TCP flags observed after the
initial packet of this flow, or TCPFlags(0) if this flow is
not a TCP flow or if extended flags are not available.
The source IP address of packets in this flow.
The source port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The SiLK sensor that observed this flow, or Sensor(0)
if unknown.
The instant that the first packet in this flow was observed.
Flags relating to the observed status of this flow, including whether extended TCP flags are available.
Flags relating to the observed status of this flow, including whether extended TCP flags are available. See TCPState for more details.
A SiLK flow record.
Note that in addition to the fields of the case class, some derived fields are also provided. (See below.)
The instant that the first packet in this flow was observed.
The duration between the instants the first and last packets in this flow were observed.
The source port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The destination port of this flow, or zero if this flow is neither a TCP nor a UDP flow.
The IP protocol of this flow.
The SiLK flow type (class and type) of this flow, or
FlowType(0)if unknown.The SiLK sensor that observed this flow, or
Sensor(0)if unknown.The union of all TCP flags observed in this flow, or
TCPFlags(0)if this flow is not a TCP flow.The flags observed in the initial packet of this TCP flow, or
TCPFlags(0)if this flow is not a TCP flow or if extended flags are not available.The union of all TCP flags observed after the initial packet of this flow, or
TCPFlags(0)if this flow is not a TCP flow or if extended flags are not available.Flags relating to the observed status of this flow, including whether extended TCP flags are available. See TCPState for more details.
The detected application of this flow, expressed as the common port number for that application, or
Port(0)if no application was detected.A Short value stored as a memo on this flow, or zero if no such memo has been set.
The input SNMP routing interface for this flow, or
SNMPInterface(0)if routing information is not available.The output SNMP routing interface for this flow, or
SNMPInterface(0)if routing information is not available.The number of IP packets observed in this flow.
The number of bytes in packets observed in this flow.
The source IP address of packets in this flow.
The destination IP address of packets in this flow.
The next-hop IP address of packets in this flow, or
IPAddress("0.0.0.0")orIPAddress("::")if routing information is not available.