Field Identifier | Field Type | Field Name | Field description | Reference Value | Subcategory |
src_ip | string | Source IP | - | 80.64.30.122 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
dst_ip | string | Target IP | - | 42.194.199.178 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
src_port | int | Source Port | - | 50787 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
dst_port | int | Target port. | - | 63821 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
protocol | string | Protocol | - | TCP | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
direction | int | Traffic direction | 0: Outbound 1: Inbound 3: Private Network (Applicable only to CFWNetflowFl) | 0 | CFWOnline,CFWNetflowNat,CFWNetflowFl |
app_protocol | string | Application Protocol | - | HTTP | CFWNetflowFl |
src_country | string | Source Country | - | China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
dst_country | string | Destination Country | - | China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
src_country_en | string | Source Country-English | - | China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
dst_country_en | string | Destination Country-English | - | China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
src_province | string | Source Province | - | Guangdong | CFWOnline,CFWNetflowNat,CFWNetflowFl |
dst_province | string | Destination Province | - | Guangdong | CFWOnline,CFWNetflowNat,CFWNetflowFl |
src_province_en | string | Source Province-English | - | Guangdong | CFWOnline,CFWNetflowNat,CFWNetflowFl |
dst_province_en | string | Destination Province-English | - | Guangdong | CFWOnline,CFWNetflowNat,CFWNetflowFl |
address | string | Detailed address | Inbound traffic uses the source address. Outbound traffic uses the destination address. | Guangdong, China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
address_en | string | Detailed address-English | - | Guangdong, China | CFWOnline,CFWNetflowNat,CFWNetflowFl |
supplier | string | ISP | - | Tencent | CFWOnline,CFWNetflowNat,CFWNetflowFl |
supplier_en | string | ISP-English | - | tencent | CFWOnline,CFWNetflowNat,CFWNetflowFl |
dst_domain | string | Accessed destination domain name | - | www.google.com | CFWOnline,CFWNetflowNat,CFWNetflowFl |
instance_id | string | Asset Instance ID | - | ins-gpnr3uaw | CFWOnline,CFWNetflowNat,CFWNetflowFl |
src_vpc | string | Source VPC ID | - | vpc-msa9dvac | CFWNetflowVpc,CFWNetflowFl |
dst_vpc | string | Destination VPC ID | - | vpc-q9h93ip4 | CFWNetflowVpc,CFWNetflowFl |
src_vpc_name | string | Source VPC name | - | Production environment VPC | CFWNetflowVpc,CFWNetflowFl |
dst_vpc_name | string | Destination VPC name | - | Test environment VPC | CFWNetflowVpc,CFWNetflowFl |
src_ins_id | string | Source Instance ID | - | ins-17ye5faf | CFWNetflowVpc,CFWNetflowFl |
dst_ins_id | string | Destination Instance ID | - | ins-p1jyrg75 | CFWNetflowVpc,CFWNetflowFl |
src_ins_name | string | Source Instance Name | - | web-server | CFWNetflowVpc,CFWNetflowFl |
dst_ins_name | string | Destination Instance Name | - | db-server | CFWNetflowVpc,CFWNetflowFl |
cvm_id | string | Reserved field. | - | ins-4enaxc89 | CFWNetflowVpc |
ccnid | string | CCN ID | - | ccn-a1b2c3d4 | CFWNetflowVpc |
ew_ins_id | string | VPC firewall instance ID | - | cfwew-85fbe09c | CFWNetflowVpc |
fws_id | string | Firewall ID (NAT/VPC Firewall) | - | cfwnat-dce8698e / cfws-97b4f6da31 | CFWNetflowNat,CFWNetflowVpc |
fws_name | string | VPC firewall name | - | - | CFWNetflowVpc |
fwsid | string | Firewall instance identifier | - | MIRROR_NTA | CFWNetflowFl |
fw_type | string | Firewall Type | - | nat / NDR | CFWNetflowNat,CFWNetflowFl |
fw_region | string | Firewall region | - | ap-guangzhou | CFWNetflowNat |
nat_ip | string | Public IP address after NAT translation | - | 43.138.154.20 | CFWNetflowNat |
nat_port | int | Port after NAT translation | - | 90 | CFWNetflowNat |
ndr_ip | string | Mirror machine IP (NDR) | - | 172.16.10.14 | CFWNetflowFl |
tke_cluster_id | string | The ID of the TKE cluster. | - | cls-bwml6kuu | CFWNetflowFl |
count | int | Number of sessions | - | 1 | CFWOnline |
domain_flag | uint8 | Whether a domain name exists | 1: Exists. 0: Not Exist | 1 | CFWOnline,CFWNetflowFl |
port_status | uint8 | Port Status | 1: Enabled. 0: Disabled. | 1 | CFWOnline,CFWNetflowFl |
tcp_flag | int | TCP flag | 1:OUTSyn 2:OUTRst 3:OutSynAck 4:OUTFin 5:INSyn 6:INRst 7:INSynAck 8:InFin | 25 | CFWOnline |
ip_version | int | IP Type | 4:IPv4 6:IPv6 | - | CFWNetflowVpc |
retans | int8 | Whether there is a retransmission | 1: Retransmission 0: Unretransmitted | - | CFWNetflowNat,CFWNetflowVpc |
status | int | Status | - | - | CFWNetflowNat,CFWNetflowVpc |
timeout | int | Session duration | - | - | CFWNetflowNat,CFWNetflowVpc |
flow_id | bigint | Flow ID | - | 364693810879269 | CFWNetflowFl |
uuid | int | Associated ACL UUID | - | - | CFWNetflowVpc |
decrypt_flow | int | Decryption flag | 1: Decryption 0: Non-Decryption | - | CFWNetflowFl |
version | string | Software Version | - | TLS 1.2 | CFWNetflowFl |
log_version | string | Log Version | - | 5.2.0 | CFWNetflowFl |
file_info | string | File information (NDR sandbox detection) | - | - | CFWNetflowFl |
req_hex | string | Request hexadecimal data | - | - | CFWNetflowFl |
rsp_hex | string | Response hexadecimal data | - | - | CFWNetflowFl |
payload | string | Payload | - | - | CFWNetflowFl |
total_pkt_count | int | Total number of packets | - | 14 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
total_pkt_len | int | Total bytes | Unit: Byte (B) | 5116 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
in_pkt_count | int | Inbound packet quantity | - | 7 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
in_pkt_len | int | Inbound bytes | Unit: Byte (B) | 448 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
out_pkt_count | int | Outbound packet quantity | - | 7 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
out_pkt_len | int | Outbound bytes | Unit: Byte (B) | 4668 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
start_time | int | Session start time | Unix timestamp (UTC+8) | 1708600000 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
end_time | int | Session end time | Unix timestamp (UTC+8) | 1708603600 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
insert_time | int | Log ingestion time | Unix timestamp (UTC+8) | 1742110932 | CFWOnline,CFWNetflowNat,CFWNetflowFl |
timestamp | string | Unified timestamp | Time in UTC+8 | 2025-03-16 15:42:09 | CFWOnline,CFWNetflowNat,CFWNetflowVpc,CFWNetflowFl |
フィードバック