Fields specific to the “l_connection” log

The fields described below appear in the web administration interface of the firewall under the Monitoring > Logs - Audit logs module, in the views: All logs, Network traffic, Web and E-mails.

sent

Number of bytes sent.

Decimal format. Example: "14623"

Available from: SNS v1.0.0.

Sent

Example: “13KB

rcvd

Number of bytes received.

Decimal format. Example: "23631"

Available from: SNS v1.0.0.

Received

Example: “23 KB

duration

Duration of the connection in seconds.

Decimal format. Example: "173.15"

Duration

Example: "2m 53s 15"

domain

Authentication method used or LDAP directory of the user authenticated by the firewall.

String of characters in UTF-8 format.

Example: domain="documentation.stormshield.eu"

Available from: SNS v3.0.0.

Method or directory
action

Behavior associated with the filter rule.

Value: “pass” or “block” (empty field for “Log” action).

Action
clientappid

Last client application detected on the connection.

Character string.

Example: clientappid=firefox

Available from: SNS v3.2.0.

Client application
serverappid

Last server application detected on the connection.

Character string.

Example: serverappid=google

Available from: SNS v3.2.0.

Server application
version

Protocol version number

Character string in UTF-8 format.

Example: version=TLSv1.2

Available from: SNS 4.2.1

Protocol version