Fields specific to the “l_connection” log

The fields described below are shown in the firewall's web administration interface in the Network connections module in the Audit logs > Logs menu and in the All logs, Network traffic, Web and E-mails views in the Audit logs > Views menu.

sent

Number of bytes sent.

Decimal format. Example: "14623"

Sent

Example: “13 KB

rcvd

Number of bytes received.

Decimal format. Example: "23631"

Received

Example: “23 KB

duration

Duration of the connection in seconds.

Decimal format. Example: "173.15"

Duration

Example: "2m 53s 15"

domain

Authentication method used or LDAP directory of the user authenticated by the firewall.

String of characters in UTF-8 format.

Example: domain="documentation.stormshield.eu"

Method or directory
action

Behavior associated with the filter rule.

Value: “pass” or “block” (empty field for “Log” action).

Action
clientappid

Last client application detected on the connection.

Character string.

Example: clientappid=firefox

Client application
serverappid

Last server application detected on the connection.

Character string.

Example: serverappid=google

Server application