以下描述详细介绍了 magic_ids_detections 的可用字段。
Type: string
对数据包采取的操作。可能的值为 pass | block。
Type: string
发生检测的城市。
Type: string
发生检测的地点对应的 IATA 机场代码。
Type: string
触发检测的数据包的目标 IP。
Type: int
触发检测的数据包的目标端口。如果协议字段设为 any,则设为 0。
Type: string
触发检测的数据包的第 4 层协议。可能的值为 tcp | udp | any。变体 any 表示检测发生在较低层(例如 IP)。
Type: int
检测的签名 ID。
Type: string
检测的签名消息。描述数据包试图执行的操作。
Type: int
检测的签名版本。
Type: string
触发检测的数据包的源 IP。
Type: int
触发检测的数据包的源端口。如果协议字段设为 any,则设为 0。
Type: int or string
发生检测的时间戳。