The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Data mining

Prev Next

Applications that require the real-time synchronization of Manager data, including packet logs, are best served by performing regular SQL queries to the Manager database. An example would be Security Information and Event Management (SIEM) applications. SIEM applications can use direct database-based integration through which they can poll the Manager database and monitor specific tables for new records. Applications that do not require the packet log data that is associated with an alert can use the push techniques of SNMP or Syslog.

For applications like reports that are more ad-hoc in nature, an efficient approach would be to copy the database and manipulate it off-line. The less work the database has to do within the Manager, the better will be the performance of the Manager. Therefore, by cloning or copying the database, operations, such as large queries, or creating additional indices, can be performed on the off-line database. In addition to just copying the files from the Manager, you can use the Manager’s data back-up feature (i.e. back-up, alert & packet log archival). See Trellix Intrusion Prevention System Product Guide for details about these features.

Note

Alert information is stored in the iv_alert and iv_alert_data tables. Packet captures for alerts are stored in the iv_packetlog table.

You can query Manager database tables for several types of IV_<variable> information.

The following table describes IV_Alert information.

Field Type Null Key Default value Description/Comments
uuid bigint(20) NO MUL Unique Unique ID number of message
state smallint(6) YES MUL state of alert (NULL = closed, 1 = new, others)

1: unacknowledged

10: acknowledged

markForDelete char(1) YES First in line for deletion during old-alert purging
lastModTime timestamp NO Current time stamp. the last time this alert was modified in the database
lastModUserRef char(32) YES User who last modified the alert in the database
assignedUserRef char(32) YES To whom the alert is assigned to for action
sensorId int(11) NO PRI The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager.
vsaId int(11) NO -1 The VSA ID of the VIDS to which the alert applies
vidsId int(11) YES The VSA ID of the VIDS to which the alert applies
liId int(11) NO -1 The LI ID to which the alert applies.
subscriberId1 int(11) YES Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this VIDS belongs, and the earlier ones being its parents going back to the root admin domain ID. Alerts for the root subscriber will have all these columns as NULL.
subscriberId2 int(11) YES
subscriberId3 int(11) YES
subscriberId4 int(11) YES
alertType smallint(6) NO The type of alert, where:
  • 1 = signature
  • 2 = statistical anomaly
  • 3 = threshold anomaly
  • 4 = port scan
  • 5 = host sweep
  • 6 = throttle summary
categoryId int(11) YES The attack category id of the alert
subCategoryId int(11) YES The attack sub-category id of the alert
detectionMechanism int(11) YES The method used to detect the attack
attackId int(11) NO The 24-bit part of the attack ID
creationTime timestamp NO MUL The timestamp on the Sensor when this alert raised
emsReceivedTime timestamp YES The timestamp on the Manager when this alert is received. This may be greater than creation time if alert was in Sensor buffer due to connectivity issues with Manager.
severity tinyint(4) NO High, Medium, Low, Informational
alertDuration int(11) YES If alerts are suppressed, then these many alerts were suppressed for this duration before this one. These are only filled for a throttle summary alert.
slotId smallint(6) NO The slot number of the port from which the alert was raised
portId smallint(6) NO The port number of the port from which the alert was raised
alertCount int(11) YES Greater than 1 in case of throttled alerts
packetLogId bigint(20) YES The packet log ID corresponding to this alert
packetLogGrpId bigint(20) NO The packet log group ID corresponding to this alert
packetLogSeq int(11) YES A sequence number within the packet log stream
lastByteReqStreamOffset int(11) YES For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the request streams.
lastByteRespStreamOffset int(11) YES For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the response streams.
hasPreviousBuffer char(1) YES Whether a previous-256-byte fragment was sent
signatureId smallint(6) YES The signature ID within the attack ID
ivProtocolId int(11) YES The protocol ID from protocols.xml file
networkProtocolId smallint(6) YES The protocol ID from the IP-header of the packet
sourceIPAddr char(32) YES The IP address of the source of the attack
sourcePort int(11) YES The source port for the attack traffic
targetIPAddr char(32) YES The IP address of the target for the attack
targetPort int(11) YES The destination port of the attack traffic
confidence tinyint(4) YES The confidence level of the signature that was matched.

Inverse of BTP value. High confidence means low BTP.

Confidence value ranges from 1-7.

<3: high confidence

3-5: Medium

>=6: Low

Note

When the BTP value is 0, there is no corresponding confidence value for the attack.

protoQual1 int(11) YES
protoQual2 int(11) YES
protoParsingState int(11) YES The inner state of the protocol parsing machine
direction tinyint(4) YES Whether the attack was inbound or outbound
suppressedSigIds int(11) YES Corresponding signature IDs of the alerts that were suppressed
nidId int(11) YES Global VIDS network ID from where the alert is raised
firstAlarmTime timestamp YES
accumulateTime int(11) YES
thresholdId int(11) YES
observedValue bigint(20) YES The threshold measurement which triggered the alarm
thresholdValue int(11) YES The actual threshold value that was crossed
thresholdDuration int(11) YES The duration over which the value was measured
attackIdRef char(20) YES The Trellix IPS attack ID reference
resultSetValue int(11) YES Whether the attack succeeded, blocked, failed, suspicious and so on.

100 ATTACK_SUCCESSFUL

200 INCONCLUSIVE

300 ATTACK_FAILED

400 NOT_APPLICABLES

999 ATTACK_BLOCKED

888 DOS_BLOCKING_ACTIVATED

10100 BLOCKING_SIMULATED_ATTACK SUCCESSFUL

10200 BLOCKING_SIMULATED_INCONCLUSIVE

10300 BLOCKING_SIMULATED_ATTACK_FAILED

10400 BLOCKING_SIMULATED_N

inlineDropAction int(11) YES Information used by the Sensor to tell the Manager whether the attack was blocked or not.

INLINE_ACTION_PACKET_DROPPED = 0x01;

INLINE_ACTION_BROWSER_MATCHED = 0x04;

INLINE_ACTION_BROWSER_FAILED = 0x08;

INLINE_ACTION_SMART_BLOCK = 0x80;

INLINE_ACTION_IPS_SIMULATION = 0x40;

relevance char(1) YES Y/N/U. It is related to vulnerability scanner reports.

Y – relevant. As per vulnerability report, this host is vulnerable to attack in the context.

N – not relevant. As per vulnerability report, this host is not vulnerable to attack in the context.

U – unknown. U is very common.

Y and N shows up in TA only if the Manager has integration with MVM or they have imported vulnerability report.

VLANId int(11) YES The VLAN found in the attack traffic
policyid char(20) YES The Trellix IPS policy that was applied on the Sensor interface
hostIsolationState tinyint(4) NO Whether the attacking host is quarantined or not. This action is based on the attack quarantine settings.
sensorAlertUUID bigint(20) NO PRI Unique ID sent by Sensor
sourceUserId int(11) YES User name of the attacking host
destinationUserId int(11) YES User name of the targeted host
sourceOSId int(11) YES The ID of the operating system on the source host of the attack
destinationOSId int(11) YES The ID of the operating system on the target of the attack
sourceOSId1 tinyint(4) YES
sourceOSId2 tinyint(4) YES
sourceOSId3 tinyint(4) YES
sourceOSId4 tinyint(4) YES
destinationOSId1 tinyint(4) YES
destinationOSId2 tinyint(4) YES
destinationOSId3 tinyint(4) YES
destinationOSId4 tinyint(4) YES
zoneId int(11) YES Zone in which the alert was raised; applicable only to NTBA alerts.
deviceType tinyint(3) NO IPS Sensor – 0

NTBA Appliance – 1

HIPS Sensor – 2

sourceReputation smallint(6) YES Reputation of the source host of the attack. This reputation is fetched from Trellix Global Threat Intelligence.

Low: good

<14: minimal risk.

15-29: unverified,

30-49:medium risk

>49: high risk

high: bad

destinationReputation smallint(6) YES Reputation of the targeted host.

Same as sourceReputation

sourceGeoLocation char(32) YES Geographical location of the source host from Trellix Global Threat Intelligence.

two-digit country code: CN:China, US:USA, IN:India.

destinationGeoLocation char(32) YES Geographical location of the targeted host.

Same as above

exporterId int(11) NO -1 This is relevant only for NTBA alerts. This is the ID of the exporter.
interfaceId int(11) NO -1
sourceVmId bigint(20) NO
targetVmId bigint(20) NO
appId int(11) NO -1 The ID of the layer 7 application that matched a Firewall access rule
appCategoryId int(11) NO The ID of the application category that matched a Firewall access rule
proxyIpFlag smallint(6) NO
appRisk int(11) NO
xffTarget smallint(6) NO
tag int(11) NO -1 The userId for which the alert has been assigned, (-1 in case it is unassigned).
srcPhone char(16) YES Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the source mobile equipment

srcIMSI char(16) YES Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment

srcAPN varchar(120) YES Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic

destPhone char(16) YES Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the targeted mobile equipment

destIMSI char(16) YES Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment

destAPN varchar(120) YES Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the targeted mobile equipment

fileType int(11) YES Malware File type
fileLength int(11) YES Malware File length
fileMD5Hash Char(32) YES Malware File MD5 Hash
virusName Varchar(256) YES Malware Virus Name
fileUUID Varchar(16) YES Malware file id
malwareScore Int(11) YES Malware confidence
detectionEngine Int(11) YES Malware detection engine
srcDNSName Varchar(255) YES Source DNS name
destDNSName Varchar(255) YES Destination DNS Name

The following table describes IV_PacketLog information.

Field Type Null Key Default Description/Comments
sensorId int(11) NO Primary The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager.
packetLogId bigint(20) NO Primary The packet log ID corresponding to this alert
packetLogGrpId bigint(20) NO MUL The packet log group ID corresponding to this alert
packetLogType char(1) NO Primary F in case of a fragment; P in case of a packet.
packetLogSeq int(11) NO Primary A sequence number within the packet log stream. In case of fragments, this is 1 for request logs, and 2 for response logs.
lastReqByteStreamOffset int(11) NO Primary The offset in the TCP stream of the last byte of a request fragment. It is 0 for packet logs.
lastRespByteStreamOffset int(11) NO Primary The offset in the TCP stream of the last byte of a response fragment. It is 0 for packet logs.
markForDelete char(1) YES First in line for deletion during old-alert purging
vsaId int(11) YES The VSA ID of the VIDS to which the alert applies
vidsId int(11) NO The VSA ID of the VIDS to which the alert applies
slotId smallint(6) NO The slot number of the port from which the log packet originated
portId smallint(6) NO The port number of the port from which the log packet originated
creationTime timestamp NO MUL Current time stamp The time stamp on the log
creationSeqNumber int(11) YES The sequence number used to differentiate records with the same creation time
sensorPacketlogUUID bigint(20) NO Primary Unique ID generated by the Sensor for each packet log
packetData longblob YES The actual packet or fragment data

The following table describes IV_Sensor information.

Field Type Null Key Default value Description/Comments
sensor_id int(11) NO Primary The ID is assigned to a Sensor by the Manager
subscriber_id int(11) NO MUL The ID of the admin domain to which the Sensor belongs
last_modified timestamp NO Current time stamp When this record was last modified
name varchar(255) NO MUL User-defined name of the Sensor
description varchar(255) YES User-provided description for the Sensor
location varchar(255) YES An arbitrary string filled in by the user
contact varchar(255) YES An arbitrary string filled in by user
nepk varchar(36) YES MUL A pointer to the Lumos network element record for this Sensor
shared_secret varchar(255) YES The shared secret to be used to initialize keys for the Sensor
device_class tinyint(4) YES Not used
model varchar(50) YES The main model name for this Sensor; populated after Sensor discovery
sub_model tinyint(4) YES The sub model name for this Sensor; populated after Sensor discovery
serial_number varchar(50) YES Sensor's serial number; populated after Sensor discovery
slot_count tinyint(4) YES The number of slots in the chassis
tempSensorCount tinyint(4) YES The number of the temperature Sensors on the device
shellMgrCount tinyint(4) YES The number of the shell managers
fanCount tinyint(4) YES The number of the fans
powerSupplyCount tinyint(4) YES The number of power supplies
ip_address varchar(32) YES The user-assigned IP address for the Sensor's management port
command_port int(11) YES The port on which the Sensor contacts the Manager for its command channel
transport_type varchar(10) YES Whether TCP or UDP
snmp_version varchar(5) YES Whether v1, v2c or v3
foPeerAddress varchar(32) YES The IP address of the peer Sensor
failover_enable enum('Y','N') NO N Whether failover is enabled
failopen_enable enum('Y','N') NO N Whether failopen is enabled when the Sensor is in failover mode
peer_sensorid int(11) YES The Sensor ID of the peer Sensor
real_time_update_allowed enum('Y','N') NO N Whether real-time updates to the Sensor are allowed
sch_update_allowed enum('Y','N') NO N Whether schedule updates to the Sensor are allowed
sensorReservedVLANId int(11) YES The VLAN ID reserved for the Sensor. If this value is -1, then there is no VLAN ID reserved.
isFOEnforced enum('Y','N') NO N Is the Sensor, a failover-only Sensor.
createDefaultLogicConfig enum('Y','N') NO Y
tacacsConfig tinyint(4) YES Whether the tacacs configuration is inherited from the admin domain. 0 means yes.
inheritMPE tinyint(4) NO 0 Status of MPE configuration inherited from the admin domain. 0 means yes.

-- inheritHQ Status of HQ config inherited from AD. 0-No

0
inheritHQ tinyint(4) NO 0 Status of HQ configuration inherited from the admin domain. 0 means no.
config_flags int(11) YES A flag set maintained by the Sensor config service indicating an internal maintenance state
lastRebootTime timestamp NO Time when the Sensor rebooted last as per the information in the Manager
lastSignatureUpdateTime timestamp NO The latest time that a sigset update went through successfully
isRateLimitEnabled enum('Y','N') NO N Whether the rate limit feature is enabled
lastRLmodifiedTS timestamp NO Time when the rate limit feature was last modified
sw_version varchar(25) YES The Sensor software version
fips_mode int(11) NO 0 Whether the Sensor is FIPS compliant
strong_crypto_version varchar(5) YES
download_mode tinyint(4) NO 0 Whether the Sensor uses offline download(1) or online download mode (0)
inheritArtemis tinyint(4) NO 0 Status of File Reputation feature configuration inherited from the admin domain. 0 means no.
foStpForwardStatus tinyint(4) NO 2 This column is now deprecated
lastSoftwareUpdateTime timestamp NO Time when the Sensor was last successfully updated

The following table describes IV_Categories information.

Field Type Null Key Default value Description/comments
categoryId int(11) Yes Represents a category ID. The possible values are 111, 112, 113, and 114.
displayableName varchar(64) Yes The displayableName for each categoryId is provided below:
  • 111 - Exploit
  • 112 - Volume DOS
  • 113 - Reconnaissance
  • 114 - Policy violation
description varchar(64) Yes The description for each categoryId is provided below:
  • 111 - Exploit category
  • 112 - Volume DOS category
  • 113 - Reconnaissance category
  • 114 - Policy violation category

The following table describes IV_NTBA information.

Field Type Null Key Default value Description/comments
nba_id int (11) NO PRI The unique ID that the Manager assigns to an NTBA device.
subscriber_id int (11) NO MUL ID of the admin domain that owns the NTBA device.
last_modified timestamp NO Current time stamp Time when this record was last modified.
Name varchar (255) NO MUL User-specified name of the NTBA device.
description varchar (255) YES Description of the NTBA device that a user optionally provides.
location varchar (255) YES An arbitrary string entered by the user.
contact varchar (255) YES An arbitrary string entered by the user.
shared_secret varchar (255) YES The shared secret to be used to initialize keys for this Sensor.
device_class tinyint (4) YES NTBA device class.
model varchar (50) YES NTBA device model.
sub_model tinyint (4) YES The submodel that is populated after device discovery.
serial_number varchar (50) YES The serial number of the device populated after device discovery.
ip_address varchar (32) YES User-assigned IP address to the NTBA device management port.
command_protocol varchar (32) YES \N
command_port int (11) YES The port on which the NTBA device contacts the Manager for its command channel.
ne_pk varchar (36) YES MUL A pointer to the Lumos network element record for this NTBA device.
real_time_update_allowed enum('Y','N') NO n Whether real-time updates to the NTBA device are allowed.
sch_update_allowed enum('Y','N') NO n Whether schedule updates to the NTBA device are allowed.
config_flags int (11) YES A flag set maintained by the NTBA device config service indicating an internal maintenance state.
last_reboot_time timestamp NO Time when the NTBA device rebooted last as per the information in the Manager.
last_signature_update_time timestamp NO The latest time that a sigset update went through successfully.
sw_version varchar (25) YES The NTBA device software version.
fips_mode int (11) NO 0 Whether the NTBA device is FIPS compliant

The following table describes IV_Alarm information.

Field Type Null Key Default Description/comments
Id char (36) NO PRI The alarm PK from Lumos.
Name varchar (128) YES The name of the alarm.
Source varchar (255) NO A human-readable string version of the alarm source entity (not used to reconstruct the alarm).
sourceBlob blob YES Serialized copy of the actual source entity object.
conditionType varchar (128) YES Name of the alarm condition, for example, down and lowmem
Type varchar (128) YES Type of alarm, for example, management, equipment.
Severity varchar (128) YES Severity of the alarm, for example, critical, major, minor, and so on.
lastUpdated timestamp NO Time stamp When this alarm was last modified.
creationTime timestamp NO Time stamp When this alarm was created.
serviceAffecting char (1) NO Indication to the user whether this will interrupt service. For example, a condition type of "down" will but "lowmem" may not.
autoCleared char (1) NO Indication whether the Manager will auto-clear this alarm eventually.
acknowledged char (1) NO Whether this alarm has been acknowledged by a user.
additionalText text YES Additional text provided by alarm-creating component.
additionalData blob YES Additional data provided by alarm-creating component.
customData blob YES Used by user agents to piggyback client data on the alarm.
occurrenceCount int (11) YES The number of times the alarm occurred.
lastUpdateTime bigint (20) YES The last time this record was updated.
sensorId int (11) YES Unique ID assigned to the Sensor by the Manager.
The following table describes iv_subcategories information.
Field Type Null Key Default value Description/comments
idnum int(11) No Primary The unique ID number of the subcategory.
category_name varchar(50) No Primary The name of the subcategory.
parent_category varchar(50) The corresponding parent category name.
display_name varchar(50) The displayable name of the subcategory.
description text Description of the subcategory.
release_version varchar(20) No Primary Version of the signature set.
ts date Time stamp when a row was last updated.
The following table describes iv_vids information.
Field Type Null Key Default value Description/comments
vids_id int(11) No Primary The primary key. This is assigned by the Manager.
subscriber_id int(11) No MUL ID of the corresponding admin domain. This is a foreign key.
entity_subscriber_id int(11) No
parent_id int(11) Yes MUL ID of the parent VIDS.
last_modified Timestamp No When this record was last modified.
last_resourcechildchanged Timestamp
last_resourcetreechanged Timestamp
name varchar(255) No User-specified name of the VIDS.
description varchar(255) Yes User-specified description of the VIDS.
intftype enum ('C','D','V','F','B') No Whether the interface is of type CIDR, dedicated, or VLAN.
vids_level tinyint(4) No 0 for Sensor; 1 for interface; 2 for subinterface.
sensor_id int(11) Yes ID of the Sensor on which this VIDS is created.
wasp_inherit_status tinyint(4) No 0
vsa_id int(11) Yes This column is deprecated.
network_link_id int(11) Yes The network link on which this VIDS is created.
has_anomaly enum('Y', 'N') No N Whether anomaly detection is enabled for this VIDS.
ids_profile_id varchar(20) Yes The IDS profile ID. References iv_policy(policy_id)
recon_policy_id int(11) Yes Foreign key (recon_policy_id) References iv_recon_policy(recon_policy_id)
anomaly_profile_id varchar(20) Yes The Anomaly profile ID.
ref_vids_id int(11) Yes MUL In an interface group, ref_vids_id is set to the primary VIDS of the group; otherwise set to nil.
intf_group_id int(11) Yes The interface group this refers to (if any).
subintf_id int(11) Yes The sub-interface this refers to (if any)
lwg_profile_id varchar(20) Yes Local IPS Policy ID.
ipsSimulationVal int(11) No 0 Whether the Simulation Blocking feature is enabled for the VIDS.
The following table describes IV_Policy information.
Field Type Null Key Default Description / Comments
policy_id varchar(20) NO Primary Unique ID of the policy.
policy_name varchar(255) YES Unique Name of the policy.
outbound_id varchar(20) YES Outbound policy ID for the policy.
isOutboundPolicy varchar(10) YES Whether it is an outbound policy or not.
owner_id varchar(20) NO Corresponding admin domain ID.
env_ref_fks text YES iv_env_pref foreign key.
ui_filter_fks text YES iv_ui_filter foreign key.
isVisibleToChild varchar(10) YES Whether this policy can be inherited by a child admin domain.
Digest varchar(100) YES Digest value.
isEditable varchar(10) YES Whether this policy is editable.
last_Modified timestamp NO Time stamp when this policy was last modified.
is_mom_defined enum('Y','N') NO N Whether this policy is inherited from the Central Manager.
lwg_flag ENUM('Y','N') NOT NULL default 'N', enum('Y','N') N Whether this policy is local.
policy_desc varchar(150) User-defined description for the policy.
version_num int(11) YES 0 Manager-assigned policy version number.

The following table describes iv_attack information.

Field Type Null Key Default
id varchar(20) NO Primary Unique ID assigned by Trellix.
version varchar(20) NO Primary Attack version. CONSTRAINT ivattack_pk PRIMARY KEY (id, version)
name varchar(255) YES Name for the attack.
launchpoint varchar(50) YES
visible varchar(50) YES
specversion varchar(20) YES
description longtext YES Description of the attack.
xml longblob YES Attack definition in the XML format.
isUserDefined varchar(10) YES Whether this is a Custom Attack.
TS timestamp NO Timestamp of when the record was last modified.
isActive varchar(10) YES Whether the attack is active.
release_version varchar(15) NO Attack release version.
digest varchar(100) YES Digest value.
isUDSDeleted varchar(10) NO False

The following table describes IV_Filtered_Attack_List information.

Field Type Null Key Default Description / Comments
owner_id varchar(20) YES MUL Corresponding policy ID. CONSTRAINT ifal_ownerid_fk FOREIGN KEY (owner_id) REFERENCES iv_policy (policy_id)
attack_id varchar(20) YES MUL Attack ID.
filter_id varchar(20) YES MUL CONSTRAINT iv_filteredattklist_fk FOREIGN KEY (owner_id, filter_id) REFERENCES iv_ui_filter (owner_id, filter_id)
isActive varchar(10) YES Status of the attack in a policy.
last_modified timestamp NO When the record was last modified.
attack_membership varchar(20) YES
digest varchar(100) YES Digest value.
The following table describes IV_impact information.
Field Type Null Key Default Description / Comments
severity int(11) YES Attack severity.
category varchar(20) YES Attack category.
xml longtext YES Impact definition in XML format.
attack_id_ref varchar(20) NO MUL CONSTRAINT ivimpact_fk FOREIGN KEY(attack_id_ref,attack_version) REFERENCES iv_attack(id, version)
attack_version varchar(20) YES MUL Attack version.
TS timestamp NO Timestamp when this record was last modified.
isActive varchar(10) NO Whether the record is active.
release_version varchar(15) NO Signature set version.
digest varchar(100) YES Digest value.
The following table describes iv_intf_group information.
Field Type Null Key Default Description / Comments
intf_group_id int(11) NO Primary Unique ID assigned by the Manager to a port cluster.
last_modified timestamp NO The time when this record was last modified.
sensor_id int(11) NO MUL Unique ID of the Sensor. CONSTRAINT iig_sensorid_fk FOREIGN KEY(sensor_id)
name varchar(255) NO User-defined name for the port cluster.
primary_intf_id int(11) NO MUL ID of the primary interface in the port cluster.
The following table describes IV_Subscriber information.
Field Type Null Key Default Description / Comments
SUBSCRIBER_ID int (11) NO PRI \N The primary key of the admin domain.
LAST_MODIFIED timestamp NO CURRENT

_TIMESTAMP

When this record was last modified.
LAST_RESOURCECHILDCHANGED timestamp NO 0000-00-00 00:00:00
LAST_RESOURCETREECHANGED timestamp NO 0000-00-00 00:00:00
LAST_SUBCHILDCHANGED timestamp NO 0000-00-00 00:00:00
LAST_SUBTREECHANGED timestamp NO 0000-00-00 00:00:00
NAME varchar(255) NO \N User-defined name of the admin domain.
DESCRIPTION varchar(255) NO \N User-specified description for the admin domain.
COMPANY varchar(255) YES \N The name of the company or owner of this admin domain.
PRIMARY_CONTACT_ID int(11) YES MUL \N Reference to the primary contact for this subscriber.

CONSTRAINT is_primarycontactid_fk FOREIGN KEY(primary_contact_id) REFERENCES iv_contact(contact_id),

SECONDARY_CONTACT_ID int(11) YES MUL \N Secondary contact (unused for now)

CONSTRAINT is_secondarycontactid_fk FOREIGN KEY(secondary_contact_id) REFERENCES iv_contact(contact_id)

RESP_EMAIL_ADDR varchar(255) YES \N Default email address for Manager responses
RESP_PAGER_EMAIL_ADDR varchar(255) YES \N Default text-pager email address for Manager responses
RESP_SCRIPT_PATH varchar(255) YES \N Default script to be executed for script responses
SUBSCRIBER_LEVEL tinyint(4) NO \N The level in the admin-domain tree that this admin domain is defined at.
PARENT_ID int(11) YES MUL \N ID of the parent admin domain. It is 0 if the parent admin domain is My Company.
GROUP_TYPE tinyint(4) NO 0 0 if this is a leaf subscriber, 1 if it is not.
MAXUSERS int(11) NO 0 The maximum number of users that can be defined under this admin domain.
MAXSUBSCRIBERS int(11) NO 0 The maximum number of child admin domains that can be defined under this admin domain.
MAXALERTS int(11) NO 10000
HAS_ANOMALY enum('Y','N') NO N Whether this admin domain has anomaly detection turned on by default for all its VIDS.
ALLOW_CHILD_SUBSCRIBERS enum('Y','N') NO N Whether this admin domain can create additional child admin domains under itself.
ALLOW_DELEGATION enum('Y','N') NO N Whether child admin domains of this admin domain can set their own policies.
ALLOW_VIDS enum('Y','N') NO N Whether this admin domain can create additional VIDS as subsets of its overall VIDS.
ALLOW_NONSTD_PORTS enum('Y','N') NO N Whether this admin domain can specify nonstandard ports to be considered equivalent to standard protocol ports, for example, alternate HTTPserver ports.
ALLOW_PHYSICAL_RESOURCES enum('Y','N') NO N Whether this admin domain can have Sensors and the network links owned by them.
IS_OVERRIDERULESET_ENABLE enum('Y','N') NO N
ALLOW_SENSORLVL_HST_ISOLATION enum('Y','N') NO Y Whether this admin domain is allowed to config Sensor level host quarantine.
IDS_PROFILE_ID varchar(20) YES MUL \N The default signature profile ID for this admin domain.

CONSTRAINT is_idsprofileid_fk FOREIGN KEY(ids_profile_id) REFERENCES iv_policy(policy_id)

RECON_POLICY_ID int(11) YES 0 ID of the Sensor recon policy.
EMAIL_ENABLED enum('Y','N') NO N A flag to enable email responses.
EMAIL_THRESHOLD tinyint(4) YES \N An alert severity threshold beyond which the Manager must send email notification of alerts. If null, the Manager must never send email notifications of alerts.
EMAIL_SUPP_INTERVAL int(11) YES 600 Once the Manager has emailed a notification, it should not send any more email notification for this interval (seconds).
PAGER_ENABLED enum('Y','N') NO N A flag to enable pager responses.
PAGER_THRESHOLD tinyint(4) YES \N An alert severity threshold beyond which the Manager must send pager notification of alerts. If null, the Manager must never send pager notifications of alerts.
PAGER_SUPP_INTERVAL int(11) YES 600 Once the Manager has paged a notification, it should not send any more pages for this interval (seconds).
SCRIPT_ENABLED enum('Y','N') NO N A flag to enable Script responses.
SCRIPT_THRESHOLD tinyint(4) YES \N An alert severity threshold beyond which the Manager must execute the corresponding scripts. If null, the Manager must never execute scripts.
SCRIPT_SUPP_INTERVAL int(11) YES 600 Once the Manager has executed the scripts, it should not execute any more scripts for this interval (seconds).
BYATTACK_EMAIL tinyint(4) YES \N Per attack forwarder based on global policy settings.
BYATTACK_PAGER tinyint(4) YES \N Per attack forwarder based on global policy settings.
BYATTACK_SCRIPT tinyint(4) YES \N Per attack forwarder based on global policy settings.
BYAV_EMAIL tinyint(4) YES \N
BYAV_PAGER tinyint(4) YES \N
BYAV_SCRIPT tinyint(4) YES \N
IS_MPE_POLICY_ENABLE enum('Y','N') NO Y
EMAIL_FILTERID int(11) YES Email alert filter ID associated with this admin domain.
PAGER_FILTERID int(11) YES Pager alert filter ID associated with this admin domain.
SCRIPT_FILTERID int(11) YES Script alert filter ID associated with this admin domain.
ANAMOLY_POLICY_ID int(11) YES ID of the NTBA anamoly policy.
WORM_POLICY_ID int(11) YES ID of the NTBA worm policy.
The following table describes IV_Audit information.
Field Type Null Key Default Description / Comments
TS timestamp NO MUL The time when the audit message was audited.
USERID varchar(64) YES The user ID of the user whose action is audited.
ACTION varchar(255) YES The action being audited.
TARGET text YES The resource on which the action is performed.
SUBSCRIBERID1 int(11) YES Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this audit message, and the earlier ones being its parents going back to the root admin domain ID. Audit messages of the root subscriber will have all these columns as NULL.
SUBSCRIBERID2 int(11) YES
SUBSCRIBERID3 int(11) YES
SUBSCRIBERID4 int(11) YES
RESULT int(11) YES The result of the operation (0 == success).
MESSAGE text YES Additional explanatory text (especially for failures).
ACTIONTYPE smallint(6) YES The action type column "Id" in table.
STARTTS timestamp YES
AUDIT_DETAIL_ID int(11) YES Unique CONSTRAINT iv_auditdetailid_uq UNIQUE (audit_detail_id)