Details
MSG_ALERT_TAG
#define MSG_ALERT_TAG 0
MSG_CREATE_TIME_TAG
#define MSG_CREATE_TIME_TAG 1
MSG_DETECT_TIME_TAG
#define MSG_DETECT_TIME_TAG 2
MSG_ANALYZER_TIME_TAG
#define MSG_ANALYZER_TIME_TAG 3
MSG_SOURCE_TAG
#define MSG_SOURCE_TAG 4
MSG_NODE_TAG
#define MSG_NODE_TAG 5
MSG_ADDRESS_TAG
#define MSG_ADDRESS_TAG 6
MSG_USER_TAG
#define MSG_USER_TAG 7
MSG_USERID_TAG
#define MSG_USERID_TAG 8
MSG_PROCESS_TAG
#define MSG_PROCESS_TAG 9
MSG_SERVICE_TAG
#define MSG_SERVICE_TAG 10
MSG_WEBSERVICE_TAG
#define MSG_WEBSERVICE_TAG 11
MSG_SNMPSERVICE_TAG
#define MSG_SNMPSERVICE_TAG 12
MSG_CLASSIFICATION_TAG
#define MSG_CLASSIFICATION_TAG 13
MSG_ADDITIONALDATA_TAG
#define MSG_ADDITIONALDATA_TAG 14
MSG_ANALYZER_TAG
#define MSG_ANALYZER_TAG 15
MSG_TARGET_TAG
#define MSG_TARGET_TAG 16
MSG_HEARTBEAT_TAG
#define MSG_HEARTBEAT_TAG 17
MSG_TOOL_ALERT_TAG
#define MSG_TOOL_ALERT_TAG 18
MSG_CORRELATION_ALERT_TAG
#define MSG_CORRELATION_ALERT_TAG 19
MSG_OVERFLOW_ALERT_TAG
#define MSG_OVERFLOW_ALERT_TAG 20
MSG_ALERTIDENT_TAG
#define MSG_ALERTIDENT_TAG 21
MSG_FILE_TAG
#define MSG_FILE_TAG 22
MSG_ACCESS_TAG
#define MSG_ACCESS_TAG 23
MSG_LINKAGE_TAG
#define MSG_LINKAGE_TAG 24
MSG_INODE_TAG
#define MSG_INODE_TAG 25
MSG_CONFIDENCE_TAG
#define MSG_CONFIDENCE_TAG 26
MSG_ACTION_TAG
#define MSG_ACTION_TAG 27
MSG_IMPACT_TAG
#define MSG_IMPACT_TAG 28
MSG_ASSESSMENT_TAG
#define MSG_ASSESSMENT_TAG 29
MSG_OWN_FORMAT
#define MSG_OWN_FORMAT 253
MSG_END_OF_TAG
#define MSG_END_OF_TAG 254
MSG_FORMAT_PRELUDE_NIDS
#define MSG_FORMAT_PRELUDE_NIDS 1
MSG_CONFIDENCE_RATING
#define MSG_CONFIDENCE_RATING 0
MSG_CONFIDENCE_CONFIDENCE
#define MSG_CONFIDENCE_CONFIDENCE 1
MSG_ACTION_CATEGORY
#define MSG_ACTION_CATEGORY 0
MSG_ACTION_DESCRIPTION
#define MSG_ACTION_DESCRIPTION 1
MSG_IMPACT_SEVERITY
#define MSG_IMPACT_SEVERITY 0
MSG_IMPACT_COMPLETION
#define MSG_IMPACT_COMPLETION 1
MSG_IMPACT_TYPE
#define MSG_IMPACT_TYPE 2
MSG_IMPACT_DESCRIPTION
#define MSG_IMPACT_DESCRIPTION 3
MSG_FILE_IDENT
#define MSG_FILE_IDENT 0
MSG_FILE_CATEGORY
#define MSG_FILE_CATEGORY 1
MSG_FILE_FSTYPE
#define MSG_FILE_FSTYPE 2
MSG_FILE_NAME
#define MSG_FILE_NAME 3
MSG_FILE_PATH
#define MSG_FILE_PATH 4
MSG_FILE_CREATE_TIME_TAG
#define MSG_FILE_CREATE_TIME_TAG 5
MSG_FILE_MODIFY_TIME_TAG
#define MSG_FILE_MODIFY_TIME_TAG 6
MSG_FILE_ACCESS_TIME_TAG
#define MSG_FILE_ACCESS_TIME_TAG 7
MSG_FILE_DATASIZE
#define MSG_FILE_DATASIZE 8
MSG_FILE_DISKSIZE
#define MSG_FILE_DISKSIZE 9
MSG_LINKAGE_CATEGORY
#define MSG_LINKAGE_CATEGORY 0
MSG_LINKAGE_NAME
#define MSG_LINKAGE_NAME 1
MSG_LINKAGE_PATH
#define MSG_LINKAGE_PATH 2
MSG_LINKAGE_FILE
#define MSG_LINKAGE_FILE 3
MSG_INODE_CHANGE_TIME
#define MSG_INODE_CHANGE_TIME 0
MSG_INODE_NUMBER
#define MSG_INODE_NUMBER 1
MSG_INODE_MAJOR_DEVICE
#define MSG_INODE_MAJOR_DEVICE 2
MSG_INODE_MINOR_DEVICE
#define MSG_INODE_MINOR_DEVICE 3
MSG_INODE_C_MAJOR_DEVICE
#define MSG_INODE_C_MAJOR_DEVICE 4
MSG_INODE_C_MINOR_DEVICE
#define MSG_INODE_C_MINOR_DEVICE 5
MSG_ACCESS_PERMISSION
#define MSG_ACCESS_PERMISSION 0
MSG_ALERT_IDENT
#define MSG_ALERT_IDENT 0
MSG_SOURCE_IDENT
#define MSG_SOURCE_IDENT 0
MSG_SOURCE_SPOOFED
#define MSG_SOURCE_SPOOFED 1
MSG_SOURCE_INTERFACE
#define MSG_SOURCE_INTERFACE 2
MSG_NODE_IDENT
#define MSG_NODE_IDENT 0
MSG_NODE_CATEGORY
#define MSG_NODE_CATEGORY 1
MSG_NODE_LOCATION
#define MSG_NODE_LOCATION 2
MSG_NODE_NAME
#define MSG_NODE_NAME 3
MSG_ADDRESS_IDENT
#define MSG_ADDRESS_IDENT 0
MSG_ADDRESS_CATEGORY
#define MSG_ADDRESS_CATEGORY 1
MSG_ADDRESS_VLAN_NAME
#define MSG_ADDRESS_VLAN_NAME 2
MSG_ADDRESS_VLAN_NUM
#define MSG_ADDRESS_VLAN_NUM 3
MSG_ADDRESS_ADDRESS
#define MSG_ADDRESS_ADDRESS 4
MSG_ADDRESS_NETMASK
#define MSG_ADDRESS_NETMASK 5
MSG_USER_IDENT
#define MSG_USER_IDENT 0
MSG_USER_CATEGORY
#define MSG_USER_CATEGORY 1
MSG_USERID_IDENT
#define MSG_USERID_IDENT 0
MSG_USERID_TYPE
#define MSG_USERID_TYPE 1
MSG_USERID_NAME
#define MSG_USERID_NAME 2
MSG_USERID_NUMBER
#define MSG_USERID_NUMBER 3
MSG_PROCESS_IDENT
#define MSG_PROCESS_IDENT 0
MSG_PROCESS_NAME
#define MSG_PROCESS_NAME 1
MSG_PROCESS_PID
#define MSG_PROCESS_PID 2
MSG_PROCESS_PATH
#define MSG_PROCESS_PATH 3
MSG_PROCESS_ARG
#define MSG_PROCESS_ARG 4
MSG_PROCESS_ENV
#define MSG_PROCESS_ENV 5
MSG_SERVICE_IDENT
#define MSG_SERVICE_IDENT 0
MSG_SERVICE_NAME
#define MSG_SERVICE_NAME 1
MSG_SERVICE_PORT
#define MSG_SERVICE_PORT 2
MSG_SERVICE_PORTLIST
#define MSG_SERVICE_PORTLIST 3
MSG_SERVICE_PROTOCOL
#define MSG_SERVICE_PROTOCOL 4
MSG_WEBSERVICE_URL
#define MSG_WEBSERVICE_URL 0
MSG_WEBSERVICE_CGI
#define MSG_WEBSERVICE_CGI 1
MSG_WEBSERVICE_HTTP_METHOD
#define MSG_WEBSERVICE_HTTP_METHOD 2
MSG_WEBSERVICE_ARG
#define MSG_WEBSERVICE_ARG 3
MSG_SNMPSERVICE_OID
#define MSG_SNMPSERVICE_OID 0
MSG_SNMPSERVICE_COMMUNITY
#define MSG_SNMPSERVICE_COMMUNITY 1
MSG_SNMPSERVICE_COMMAND
#define MSG_SNMPSERVICE_COMMAND 2
MSG_CLASSIFICATION_ORIGIN
#define MSG_CLASSIFICATION_ORIGIN 0
MSG_CLASSIFICATION_NAME
#define MSG_CLASSIFICATION_NAME 1
MSG_CLASSIFICATION_URL
#define MSG_CLASSIFICATION_URL 2
MSG_ADDITIONALDATA_TYPE
#define MSG_ADDITIONALDATA_TYPE 0
MSG_ADDITIONALDATA_MEANING
#define MSG_ADDITIONALDATA_MEANING 1
MSG_ADDITIONALDATA_DATA
#define MSG_ADDITIONALDATA_DATA 2
MSG_ANALYZER_ID
#define MSG_ANALYZER_ID 0
MSG_ANALYZER_MANUFACTURER
#define MSG_ANALYZER_MANUFACTURER 1
MSG_ANALYZER_MODEL
#define MSG_ANALYZER_MODEL 2
MSG_ANALYZER_VERSION
#define MSG_ANALYZER_VERSION 3
MSG_ANALYZER_CLASS
#define MSG_ANALYZER_CLASS 4
MSG_ANALYZER_OSTYPE
#define MSG_ANALYZER_OSTYPE 6
MSG_ANALYZER_OSVERSION
#define MSG_ANALYZER_OSVERSION 7
MSG_TARGET_IDENT
#define MSG_TARGET_IDENT 0
MSG_TARGET_DECOY
#define MSG_TARGET_DECOY 1
MSG_TARGET_INTERFACE
#define MSG_TARGET_INTERFACE 2
MSG_HEARTBEAT_IDENT
#define MSG_HEARTBEAT_IDENT 0
MSG_TOOL_ALERT_NAME
#define MSG_TOOL_ALERT_NAME 0
MSG_TOOL_ALERT_COMMAND
#define MSG_TOOL_ALERT_COMMAND 1
MSG_TOOL_ALERT_ANALYZER_ID
#define MSG_TOOL_ALERT_ANALYZER_ID 2
MSG_CORRELATION_ALERT_NAME
#define MSG_CORRELATION_ALERT_NAME 0
MSG_CORRELATION_ALERT_IDENT
#define MSG_CORRELATION_ALERT_IDENT 1
MSG_OVERFLOW_ALERT_PROGRAM
#define MSG_OVERFLOW_ALERT_PROGRAM 0
MSG_OVERFLOW_ALERT_SIZE
#define MSG_OVERFLOW_ALERT_SIZE 1
MSG_OVERFLOW_ALERT_BUFFER
#define MSG_OVERFLOW_ALERT_BUFFER 2
MSG_TIME_SEC
#define MSG_TIME_SEC 0
MSG_TIME_USEC
#define MSG_TIME_USEC 1
MSG_ALERTIDENT_IDENT
#define MSG_ALERTIDENT_IDENT 0
MSG_ALERTIDENT_ANALYZER_IDENT
#define MSG_ALERTIDENT_ANALYZER_IDENT 1