This is all the
information to go on. All other fields are blank. This is only an except of the
log, there are many more entries.
num
|
date
|
time
|
orig
|
type
|
action
|
alert
|
i/f_name
|
i/f_dir
|
proto
|
product
|
additionals:
|
101258
|
4-Jun-2002
|
7:34:26
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=successive_alerts
|
121056
|
4-Jun-2002
|
7:46:43
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=successive_alerts
|
143801
|
4-Jun-2002
|
7:58:40
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=successive_alerts
|
148916
|
4-Jun-2002
|
8:00:54
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=syn_attack
|
149080
|
4-Jun-2002
|
8:00:56
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=syn_attack
|
149237
|
4-Jun-2002
|
8:00:58
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=syn_attack
|
150354
|
4-Jun-2002
|
8:01:30
|
127.0.0.1
|
alert
|
accept
|
![alert]
|
daemon
|
inbound
|
ip
|
MAD
|
attack=syn_attack
|