The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Data mining

Prev Next

Applications that require the real-time synchronization of Manager data, including packet logs, are best served by performing regular SQL queries to the Manager database. An example would be Security Information and Event Management (SIEM) applications. SIEM applications can use direct database-based integration through which they can poll the Manager database and monitor specific tables for new records. Applications that do not require the packet log data that is associated with an alert can use the push techniques of SNMP or Syslog.

For applications like reports that are more ad-hoc in nature, an efficient approach would be to copy the database and manipulate it off-line. The less work the database has to do within the Manager, the better will be the performance of the Manager. Therefore, by cloning or copying the database, operations, such as large queries, or creating additional indices, can be performed on the off-line database. In addition to just copying the files from the Manager, you can use the Manager’s data back-up feature (i.e. back-up, alert & packet log archival). See Trellix Intrusion Prevention System Product Guide for details about these features.

Note

Alert information is stored in the iv_alert and iv_alert_data tables. Packet captures for alerts are stored in the iv_packetlog table.

You can query Manager database tables for several types of IV_<variable> information.

The following table describes IV_Alert information.

Field

Type

Null

Key

Default value

Description/Comments

uuid

bigint(20)

NO

MUL

Unique

Unique ID number of message

state

smallint(6)

YES

MUL

state of alert (NULL = closed, 1 = new, others)

1: unacknowledged

10: acknowledged

markForDelete

char(1)

YES

First in line for deletion during old-alert purging

lastModTime

timestamp

NO

Current time stamp.

the last time this alert was modified in the database

lastModUserRef

char(32)

YES

User who last modified the alert in the database

assignedUserRef

char(32)

YES

To whom the alert is assigned to for action

sensorId

int(11)

NO

PRI

The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager.

vsaId

int(11)

NO

-1

The VSA ID of the VIDS to which the alert applies

vidsId

int(11)

YES

The VSA ID of the VIDS to which the alert applies

liId

int(11)

NO

-1

The LI ID to which the alert applies.

subscriberId1

int(11)

YES

Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this VIDS belongs, and the earlier ones being its parents going back to the root admin domain ID. Alerts for the root subscriber will have all these columns as NULL.

subscriberId2

int(11)

YES

subscriberId3

int(11)

YES

subscriberId4

int(11)

YES

alertType

smallint(6)

NO

The type of alert, where:

  • 1 = signature

  • 2 = statistical anomaly

  • 3 = threshold anomaly

  • 4 = port scan

  • 5 = host sweep

  • 6 = throttle summary

categoryId

int(11)

YES

The attack category id of the alert

subCategoryId

int(11)

YES

The attack sub-category id of the alert

detectionMechanism

int(11)

YES

The method used to detect the attack

attackId

int(11)

NO

The 24-bit part of the attack ID

creationTime

timestamp

NO

MUL

The timestamp on the Sensor when this alert raised

emsReceivedTime

timestamp

YES

The timestamp on the Manager when this alert is received. This may be greater than creation time if alert was in Sensor buffer due to connectivity issues with Manager.

severity

tinyint(4)

NO

High, Medium, Low, Informational

alertDuration

int(11)

YES

If alerts are suppressed, then these many alerts were suppressed for this duration before this one. These are only filled for a throttle summary alert.

slotId

smallint(6)

NO

The slot number of the port from which the alert was raised

portId

smallint(6)

NO

The port number of the port from which the alert was raised

alertCount

int(11)

YES

Greater than 1 in case of throttled alerts

packetLogId

bigint(20)

YES

The packet log ID corresponding to this alert

packetLogGrpId

bigint(20)

NO

The packet log group ID corresponding to this alert

packetLogSeq

int(11)

YES

A sequence number within the packet log stream

lastByteReqStreamOffset

int(11)

YES

For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the request streams.

lastByteRespStreamOffset

int(11)

YES

For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the response streams.

hasPreviousBuffer

char(1)

YES

Whether a previous-256-byte fragment was sent

signatureId

smallint(6)

YES

The signature ID within the attack ID

ivProtocolId

int(11)

YES

The protocol ID from protocols.xml file

networkProtocolId

smallint(6)

YES

The protocol ID from the IP-header of the packet

sourceIPAddr

char(32)

YES

The IP address of the source of the attack

sourcePort

int(11)

YES

The source port for the attack traffic

targetIPAddr

char(32)

YES

The IP address of the target for the attack

targetPort

int(11)

YES

The destination port of the attack traffic

confidence

tinyint(4)

YES

The confidence level of the signature that was matched.

Inverse of BTP value. High confidence means low BTP.

Confidence value ranges from 1-7.

<3: high confidence

3-5: Medium

>=6: Low

Note

When the BTP value is 0, there is no corresponding confidence value for the attack.

protoQual1

int(11)

YES

protoQual2

int(11)

YES

protoParsingState

int(11)

YES

The inner state of the protocol parsing machine

direction

tinyint(4)

YES

Whether the attack was inbound or outbound

suppressedSigIds

int(11)

YES

Corresponding signature IDs of the alerts that were suppressed

nidId

int(11)

YES

Global VIDS network ID from where the alert is raised

firstAlarmTime

timestamp

YES

accumulateTime

int(11)

YES

thresholdId

int(11)

YES

observedValue

bigint(20)

YES

The threshold measurement which triggered the alarm

thresholdValue

int(11)

YES

The actual threshold value that was crossed

thresholdDuration

int(11)

YES

The duration over which the value was measured

attackIdRef

char(20)

YES

The Trellix IPS attack ID reference

resultSetValue

int(11)

YES

Whether the attack succeeded, blocked, failed, suspicious and so on.

100 ATTACK_SUCCESSFUL

200 INCONCLUSIVE

300 ATTACK_FAILED

400 NOT_APPLICABLES

999 ATTACK_BLOCKED

888 DOS_BLOCKING_ACTIVATED

10100 BLOCKING_SIMULATED_ATTACK SUCCESSFUL

10200 BLOCKING_SIMULATED_INCONCLUSIVE

10300 BLOCKING_SIMULATED_ATTACK_FAILED

10400 BLOCKING_SIMULATED_N

inlineDropAction

int(11)

YES

Information used by the Sensor to tell the Manager whether the attack was blocked or not.

INLINE_ACTION_PACKET_DROPPED = 0x01;

INLINE_ACTION_BROWSER_MATCHED = 0x04;

INLINE_ACTION_BROWSER_FAILED = 0x08;

INLINE_ACTION_SMART_BLOCK = 0x80;

INLINE_ACTION_IPS_SIMULATION = 0x40;

relevance

char(1)

YES

Y/N/U. It is related to vulnerability scanner reports.

Y – relevant. As per vulnerability report, this host is vulnerable to attack in the context.

N – not relevant. As per vulnerability report, this host is not vulnerable to attack in the context.

U – unknown. U is very common.

Y and N shows up in TA only if you have imported vulnerability report to the Manager.

VLANId

int(11)

YES

The VLAN found in the attack traffic

policyid

char(20)

YES

The Trellix IPS policy that was applied on the Sensor interface

hostIsolationState

tinyint(4)

NO

Whether the attacking host is quarantined or not. This action is based on the attack quarantine settings.

sensorAlertUUID

bigint(20)

NO

PRI

Unique ID sent by Sensor

sourceUserId

int(11)

YES

User name of the attacking host

destinationUserId

int(11)

YES

User name of the targeted host

sourceOSId

int(11)

YES

The ID of the operating system on the source host of the attack

destinationOSId

int(11)

YES

The ID of the operating system on the target of the attack

sourceOSId1

tinyint(4)

YES

sourceOSId2

tinyint(4)

YES

sourceOSId3

tinyint(4)

YES

sourceOSId4

tinyint(4)

YES

destinationOSId1

tinyint(4)

YES

destinationOSId2

tinyint(4)

YES

destinationOSId3

tinyint(4)

YES

destinationOSId4

tinyint(4)

YES

zoneId

int(11)

YES

Zone in which the alert was raised; applicable only to NTBA alerts.

deviceType

tinyint(3)

NO

IPS Sensor – 0

NTBA Appliance – 1

sourceReputation

smallint(6)

YES

Reputation of the source host of the attack. This reputation is fetched from Trellix Global Threat Intelligence.

Low: good

<14: minimal risk.

15-29: unverified,

30-49:medium risk

>49: high risk

high: bad

destinationReputation

smallint(6)

YES

Reputation of the targeted host.

Same as sourceReputation

sourceGeoLocation

char(32)

YES

Geographical location of the source host from Trellix Global Threat Intelligence.

two-digit country code: CN:China, US:USA, IN:India.

destinationGeoLocation

char(32)

YES

Geographical location of the targeted host.

Same as above

exporterId

int(11)

NO

-1

This is relevant only for NTBA alerts. This is the ID of the exporter.

interfaceId

int(11)

NO

-1

sourceVmId

bigint(20)

NO

targetVmId

bigint(20)

NO

appId

int(11)

NO

-1

The ID of the layer 7 application that matched a Firewall access rule

appCategoryId

int(11)

NO

The ID of the application category that matched a Firewall access rule

proxyIpFlag

smallint(6)

NO

appRisk

int(11)

NO

xffTarget

smallint(6)

NO

tag

int(11)

NO

-1

The userId for which the alert has been assigned, (-1 in case it is unassigned).

srcPhone

char(16)

YES

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the source mobile equipment

srcIMSI

char(16)

YES

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment

srcAPN

varchar(120)

YES

Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic

destPhone

char(16)

YES

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The phone number of the targeted mobile equipment

destIMSI

char(16)

YES

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment

destAPN

varchar(120)

YES

Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC.

The Access Point Name (APN) of the targeted mobile equipment

fileType

int(11)

YES

Malware File type

fileLength

int(11)

YES

Malware File length

fileMD5Hash

Char(32)

YES

Malware File MD5 Hash

virusName

Varchar(256)

YES

Malware Virus Name

fileUUID

Varchar(16)

YES

Malware file id

malwareScore

Int(11)

YES

Malware confidence

detectionEngine

Int(11)

YES

Malware detection engine

srcDNSName

Varchar(255)

YES

Source DNS name

destDNSName

Varchar(255)

YES

Destination DNS Name

The following table describes IV_PacketLog information.

Field

Type

Null

Key

Default

Description/Comments

sensorId

int(11)

NO

Primary

The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager.

packetLogId

bigint(20)

NO

Primary

The packet log ID corresponding to this alert

packetLogGrpId

bigint(20)

NO

MUL

The packet log group ID corresponding to this alert

packetLogType

char(1)

NO

Primary

F in case of a fragment; P in case of a packet.

packetLogSeq

int(11)

NO

Primary

A sequence number within the packet log stream. In case of fragments, this is 1 for request logs, and 2 for response logs.

lastReqByteStreamOffset

int(11)

NO

Primary

The offset in the TCP stream of the last byte of a request fragment. It is 0 for packet logs.

lastRespByteStreamOffset

int(11)

NO

Primary

The offset in the TCP stream of the last byte of a response fragment. It is 0 for packet logs.

markForDelete

char(1)

YES

First in line for deletion during old-alert purging

vsaId

int(11)

YES

The VSA ID of the VIDS to which the alert applies

vidsId

int(11)

NO

The VSA ID of the VIDS to which the alert applies

slotId

smallint(6)

NO

The slot number of the port from which the log packet originated

portId

smallint(6)

NO

The port number of the port from which the log packet originated

creationTime

timestamp

NO

MUL

Current time stamp

The time stamp on the log

creationSeqNumber

int(11)

YES

The sequence number used to differentiate records with the same creation time

sensorPacketlogUUID

bigint(20)

NO

Primary

Unique ID generated by the Sensor for each packet log

packetData

longblob

YES

The actual packet or fragment data

The following table describes IV_Sensor information.

Field

Type

Null

Key

Default value

Description/Comments

sensor_id

int(11)

NO

Primary

The ID is assigned to a Sensor by the Manager

subscriber_id

int(11)

NO

MUL

The ID of the admin domain to which the Sensor belongs

last_modified

timestamp

NO

Current time stamp

When this record was last modified

name

varchar(255)

NO

MUL

User-defined name of the Sensor

description

varchar(255)

YES

User-provided description for the Sensor

location

varchar(255)

YES

An arbitrary string filled in by the user

contact

varchar(255)

YES

An arbitrary string filled in by user

nepk

varchar(36)

YES

MUL

A pointer to the Lumos network element record for this Sensor

shared_secret

varchar(255)

YES

The shared secret to be used to initialize keys for the Sensor

device_class

tinyint(4)

YES

Not used

model

varchar(50)

YES

The main model name for this Sensor; populated after Sensor discovery

sub_model

tinyint(4)

YES

The sub model name for this Sensor; populated after Sensor discovery

serial_number

varchar(50)

YES

Sensor's serial number; populated after Sensor discovery

slot_count

tinyint(4)

YES

The number of slots in the chassis

tempSensorCount

tinyint(4)

YES

The number of the temperature Sensors on the device

shellMgrCount

tinyint(4)

YES

The number of the shell managers

fanCount

tinyint(4)

YES

The number of the fans

powerSupplyCount

tinyint(4)

YES

The number of power supplies

ip_address

varchar(32)

YES

The user-assigned IP address for the Sensor's management port

command_port

int(11)

YES

The port on which the Sensor contacts the Manager for its command channel

transport_type

varchar(10)

YES

Whether TCP or UDP

snmp_version

varchar(5)

YES

Whether v1, v2c or v3

foPeerAddress

varchar(32)

YES

The IP address of the peer Sensor

failover_enable

enum('Y','N')

NO

N

Whether failover is enabled

failopen_enable

enum('Y','N')

NO

N

Whether failopen is enabled when the Sensor is in failover mode

peer_sensorid

int(11)

YES

The Sensor ID of the peer Sensor

real_time_update_allowed

enum('Y','N')

NO

N

Whether real-time updates to the Sensor are allowed

sch_update_allowed

enum('Y','N')

NO

N

Whether schedule updates to the Sensor are allowed

sensorReservedVLANId

int(11)

YES

The VLAN ID reserved for the Sensor. If this value is -1, then there is no VLAN ID reserved.

isFOEnforced

enum('Y','N')

NO

N

Is the Sensor, a failover-only Sensor.

createDefaultLogicConfig

enum('Y','N')

NO

Y

tacacsConfig

tinyint(4)

YES

Whether the tacacs configuration is inherited from the admin domain. 0 means yes.

inheritMPE

tinyint(4)

NO

0

Status of MPE configuration inherited from the admin domain. 0 means yes.

-- inheritHQ Status of HQ config inherited from AD. 0-No

0

inheritHQ

tinyint(4)

NO

0

Status of HQ configuration inherited from the admin domain. 0 means no.

config_flags

int(11)

YES

A flag set maintained by the Sensor config service indicating an internal maintenance state

lastRebootTime

timestamp

NO

Time when the Sensor rebooted last as per the information in the Manager

lastSignatureUpdateTime

timestamp

NO

The latest time that a sigset update went through successfully

isRateLimitEnabled

enum('Y','N')

NO

N

Whether the rate limit feature is enabled

lastRLmodifiedTS

timestamp

NO

Time when the rate limit feature was last modified

sw_version

varchar(25)

YES

The Sensor software version

fips_mode

int(11)

NO

0

Whether the Sensor is FIPS compliant

strong_crypto_version

varchar(5)

YES

download_mode

tinyint(4)

NO

0

Whether the Sensor uses offline download(1) or online download mode (0)

inheritArtemis

tinyint(4)

NO

0

Status of File Reputation feature configuration inherited from the admin domain. 0 means no.

foStpForwardStatus

tinyint(4)

NO

2

This column is now deprecated

lastSoftwareUpdateTime

timestamp

NO

Time when the Sensor was last successfully updated

The following table describes IV_Categories information.

Field

Type

Null

Key

Default value

Description/comments

categoryId

int(11)

Yes

Represents a category ID. The possible values are 111, 112, 113, and 114.

displayableName

varchar(64)

Yes

The displayableName for each categoryId is provided below:

  • 111 - Exploit

  • 112 - Volume DOS

  • 113 - Reconnaissance

  • 114 - Policy violation

description

varchar(64)

Yes

The description for each categoryId is provided below:

  • 111 - Exploit category

  • 112 - Volume DOS category

  • 113 - Reconnaissance category

  • 114 - Policy violation category

The following table describes IV_NTBA information.

Field

Type

Null

Key

Default value

Description/comments

nba_id

int (11)

NO

PRI

The unique ID that the Manager assigns to an NTBA device.

subscriber_id

int (11)

NO

MUL

ID of the admin domain that owns the NTBA device.

last_modified

timestamp

NO

Current time stamp

Time when this record was last modified.

Name

varchar (255)

NO

MUL

User-specified name of the NTBA device.

description

varchar (255)

YES

Description of the NTBA device that a user optionally provides.

location

varchar (255)

YES

An arbitrary string entered by the user.

contact

varchar (255)

YES

An arbitrary string entered by the user.

shared_secret

varchar (255)

YES

The shared secret to be used to initialize keys for this Sensor.

device_class

tinyint (4)

YES

NTBA device class.

model

varchar (50)

YES

NTBA device model.

sub_model

tinyint (4)

YES

The submodel that is populated after device discovery.

serial_number

varchar (50)

YES

The serial number of the device populated after device discovery.

ip_address

varchar (32)

YES

User-assigned IP address to the NTBA device management port.

command_protocol

varchar (32)

YES

\N

command_port

int (11)

YES

The port on which the NTBA device contacts the Manager for its command channel.

ne_pk

varchar (36)

YES

MUL

A pointer to the Lumos network element record for this NTBA device.

real_time_update_allowed

enum('Y','N')

NO

n

Whether real-time updates to the NTBA device are allowed.

sch_update_allowed

enum('Y','N')

NO

n

Whether schedule updates to the NTBA device are allowed.

config_flags

int (11)

YES

A flag set maintained by the NTBA device config service indicating an internal maintenance state.

last_reboot_time

timestamp

NO

Time when the NTBA device rebooted last as per the information in the Manager.

last_signature_update_time

timestamp

NO

The latest time that a sigset update went through successfully.

sw_version

varchar (25)

YES

The NTBA device software version.

fips_mode

int (11)

NO

0

Whether the NTBA device is FIPS compliant

The following table describes IV_Alarm information.

Field

Type

Null

Key

Default

Description/comments

Id

char (36)

NO

PRI

The alarm PK from Lumos.

Name

varchar (128)

YES

The name of the alarm.

Source

varchar (255)

NO

A human-readable string version of the alarm source entity (not used to reconstruct the alarm).

sourceBlob

blob

YES

Serialized copy of the actual source entity object.

conditionType

varchar (128)

YES

Name of the alarm condition, for example, down and lowmem

Type

varchar (128)

YES

Type of alarm, for example, management, equipment.

Severity

varchar (128)

YES

Severity of the alarm, for example, critical, major, minor, and so on.

lastUpdated

timestamp

NO

Time stamp

When this alarm was last modified.

creationTime

timestamp

NO

Time stamp

When this alarm was created.

serviceAffecting

char (1)

NO

Indication to the user whether this will interrupt service. For example, a condition type of "down" will but "lowmem" may not.

autoCleared

char (1)

NO

Indication whether the Manager will auto-clear this alarm eventually.

acknowledged

char (1)

NO

Whether this alarm has been acknowledged by a user.

additionalText

text

YES

Additional text provided by alarm-creating component.

additionalData

blob

YES

Additional data provided by alarm-creating component.

customData

blob

YES

Used by user agents to piggyback client data on the alarm.

occurrenceCount

int (11)

YES

The number of times the alarm occurred.

lastUpdateTime

bigint (20)

YES

The last time this record was updated.

sensorId

int (11)

YES

Unique ID assigned to the Sensor by the Manager.

The following table describes iv_subcategories information.

Field

Type

Null

Key

Default value

Description/comments

idnum

int(11)

No

Primary

The unique ID number of the subcategory.

category_name

varchar(50)

No

Primary

The name of the subcategory.

parent_category

varchar(50)

The corresponding parent category name.

display_name

varchar(50)

The displayable name of the subcategory.

description

text

Description of the subcategory.

release_version

varchar(20)

No

Primary

Version of the signature set.

ts

date

Time stamp when a row was last updated.

The following table describes iv_vids information.

Field

Type

Null

Key

Default value

Description/comments

vids_id

int(11)

No

Primary

The primary key. This is assigned by the Manager.

subscriber_id

int(11)

No

MUL

ID of the corresponding admin domain. This is a foreign key.

entity_subscriber_id

int(11)

No

parent_id

int(11)

Yes

MUL

ID of the parent VIDS.

last_modified

Timestamp

No

When this record was last modified.

last_resourcechildchanged

Timestamp

last_resourcetreechanged

Timestamp

name

varchar(255)

No

User-specified name of the VIDS.

description

varchar(255)

Yes

User-specified description of the VIDS.

intftype

enum ('C','D','V','F','B')

No

Whether the interface is of type CIDR, dedicated, or VLAN.

vids_level

tinyint(4)

No

0 for Sensor; 1 for interface; 2 for subinterface.

sensor_id

int(11)

Yes

ID of the Sensor on which this VIDS is created.

wasp_inherit_status

tinyint(4)

No

0

vsa_id

int(11)

Yes

This column is deprecated.

network_link_id

int(11)

Yes

The network link on which this VIDS is created.

has_anomaly

enum('Y', 'N')

No

N

Whether anomaly detection is enabled for this VIDS.

ids_profile_id

varchar(20)

Yes

The IDS profile ID. References iv_policy(policy_id)

recon_policy_id

int(11)

Yes

Foreign key (recon_policy_id) References iv_recon_policy(recon_policy_id)

anomaly_profile_id

varchar(20)

Yes

The Anomaly profile ID.

ref_vids_id

int(11)

Yes

MUL

In an interface group, ref_vids_id is set to the primary VIDS of the group; otherwise set to nil.

intf_group_id

int(11)

Yes

The interface group this refers to (if any).

subintf_id

int(11)

Yes

The sub-interface this refers to (if any)

lwg_profile_id

varchar(20)

Yes

Local IPS Policy ID.

ipsSimulationVal

int(11)

No

0

Whether the Simulation Blocking feature is enabled for the VIDS.

The following table describes IV_Policy information.

Field

Type

Null

Key

Default

Description / Comments

policy_id

varchar(20)

NO

Primary

Unique ID of the policy.

policy_name

varchar(255)

YES

Unique

Name of the policy.

outbound_id

varchar(20)

YES

Outbound policy ID for the policy.

isOutboundPolicy

varchar(10)

YES

Whether it is an outbound policy or not.

owner_id

varchar(20)

NO

Corresponding admin domain ID.

env_ref_fks

text

YES

iv_env_pref foreign key.

ui_filter_fks

text

YES

iv_ui_filter foreign key.

isVisibleToChild

varchar(10)

YES

Whether this policy can be inherited by a child admin domain.

Digest

varchar(100)

YES

Digest value.

isEditable

varchar(10)

YES

Whether this policy is editable.

last_Modified

timestamp

NO

Time stamp when this policy was last modified.

is_mom_defined

enum('Y','N')

NO

N

Whether this policy is inherited from the Central Manager.

lwg_flag ENUM('Y','N') NOT NULL default 'N',

enum('Y','N')

N

Whether this policy is local.

policy_desc

varchar(150)

User-defined description for the policy.

version_num

int(11)

YES

0

Manager-assigned policy version number.

The following table describes iv_attack information.

Field

Type

Null

Key

Default

id

varchar(20)

NO

Primary

Unique ID assigned by Trellix.

version

varchar(20)

NO

Primary

Attack version. CONSTRAINT ivattack_pk PRIMARY KEY (id, version)

name

varchar(255)

YES

Name for the attack.

launchpoint

varchar(50)

YES

visible

varchar(50)

YES

specversion

varchar(20)

YES

description

longtext

YES

Description of the attack.

xml

longblob

YES

Attack definition in the XML format.

isUserDefined

varchar(10)

YES

Whether this is a Custom Attack.

TS

timestamp

NO

Timestamp of when the record was last modified.

isActive

varchar(10)

YES

Whether the attack is active.

release_version

varchar(15)

NO

Attack release version.

digest

varchar(100)

YES

Digest value.

isUDSDeleted

varchar(10)

NO

False

The following table describes IV_Filtered_Attack_List information.

Field

Type

Null

Key

Default

Description / Comments

owner_id

varchar(20)

YES

MUL

Corresponding policy ID. CONSTRAINT ifal_ownerid_fk FOREIGN KEY (owner_id) REFERENCES iv_policy (policy_id)

attack_id

varchar(20)

YES

MUL

Attack ID.

filter_id

varchar(20)

YES

MUL

CONSTRAINT iv_filteredattklist_fk FOREIGN KEY (owner_id, filter_id) REFERENCES iv_ui_filter (owner_id, filter_id)

isActive

varchar(10)

YES

Status of the attack in a policy.

last_modified

timestamp

NO

When the record was last modified.

attack_membership

varchar(20)

YES

digest

varchar(100)

YES

Digest value.

The following table describes IV_impact information.

Field

Type

Null

Key

Default

Description / Comments

severity

int(11)

YES

Attack severity.

category

varchar(20)

YES

Attack category.

xml

longtext

YES

Impact definition in XML format.

attack_id_ref

varchar(20)

NO

MUL

CONSTRAINT ivimpact_fk FOREIGN KEY(attack_id_ref,attack_version) REFERENCES iv_attack(id, version)

attack_version

varchar(20)

YES

MUL

Attack version.

TS

timestamp

NO

Timestamp when this record was last modified.

isActive

varchar(10)

NO

Whether the record is active.

release_version

varchar(15)

NO

Signature set version.

digest

varchar(100)

YES

Digest value.

The following table describes iv_intf_group information.

Field

Type

Null

Key

Default

Description / Comments

intf_group_id

int(11)

NO

Primary

Unique ID assigned by the Manager to a port cluster.

last_modified

timestamp

NO

The time when this record was last modified.

sensor_id

int(11)

NO

MUL

Unique ID of the Sensor. CONSTRAINT iig_sensorid_fk FOREIGN KEY(sensor_id)

name

varchar(255)

NO

User-defined name for the port cluster.

primary_intf_id

int(11)

NO

MUL

ID of the primary interface in the port cluster.

The following table describes IV_Subscriber information.

Field

Type

Null

Key

Default

Description / Comments

SUBSCRIBER_ID

int (11)

NO

PRI

\N

The primary key of the admin domain.

LAST_MODIFIED

timestamp

NO

CURRENT

_TIMESTAMP

When this record was last modified.

LAST_RESOURCECHILDCHANGED

timestamp

NO

0000-00-00 00:00:00

LAST_RESOURCETREECHANGED

timestamp

NO

0000-00-00 00:00:00

LAST_SUBCHILDCHANGED

timestamp

NO

0000-00-00 00:00:00

LAST_SUBTREECHANGED

timestamp

NO

0000-00-00 00:00:00

NAME

varchar(255)

NO

\N

User-defined name of the admin domain.

DESCRIPTION

varchar(255)

NO

\N

User-specified description for the admin domain.

COMPANY

varchar(255)

YES

\N

The name of the company or owner of this admin domain.

PRIMARY_CONTACT_ID

int(11)

YES

MUL

\N

Reference to the primary contact for this subscriber.

CONSTRAINT is_primarycontactid_fk FOREIGN KEY(primary_contact_id) REFERENCES iv_contact(contact_id),

SECONDARY_CONTACT_ID

int(11)

YES

MUL

\N

Secondary contact (unused for now)

CONSTRAINT is_secondarycontactid_fk FOREIGN KEY(secondary_contact_id) REFERENCES iv_contact(contact_id)

RESP_EMAIL_ADDR

varchar(255)

YES

\N

Default email address for Manager responses

RESP_PAGER_EMAIL_ADDR

varchar(255)

YES

\N

Default text-pager email address for Manager responses

RESP_SCRIPT_PATH

varchar(255)

YES

\N

Default script to be executed for script responses

SUBSCRIBER_LEVEL

tinyint(4)

NO

\N

The level in the admin-domain tree that this admin domain is defined at.

PARENT_ID

int(11)

YES

MUL

\N

ID of the parent admin domain. It is 0 if the parent admin domain is My Company.

GROUP_TYPE

tinyint(4)

NO

0

0 if this is a leaf subscriber, 1 if it is not.

MAXUSERS

int(11)

NO

0

The maximum number of users that can be defined under this admin domain.

MAXSUBSCRIBERS

int(11)

NO

0

The maximum number of child admin domains that can be defined under this admin domain.

MAXALERTS

int(11)

NO

10000

HAS_ANOMALY

enum('Y','N')

NO

N

Whether this admin domain has anomaly detection turned on by default for all its VIDS.

ALLOW_CHILD_SUBSCRIBERS

enum('Y','N')

NO

N

Whether this admin domain can create additional child admin domains under itself.

ALLOW_DELEGATION

enum('Y','N')

NO

N

Whether child admin domains of this admin domain can set their own policies.

ALLOW_VIDS

enum('Y','N')

NO

N

Whether this admin domain can create additional VIDS as subsets of its overall VIDS.

ALLOW_NONSTD_PORTS

enum('Y','N')

NO

N

Whether this admin domain can specify nonstandard ports to be considered equivalent to standard protocol ports, for example, alternate HTTPserver ports.

ALLOW_PHYSICAL_RESOURCES

enum('Y','N')

NO

N

Whether this admin domain can have Sensors and the network links owned by them.

IS_OVERRIDERULESET_ENABLE

enum('Y','N')

NO

N

ALLOW_SENSORLVL_HST_ISOLATION

enum('Y','N')

NO

Y

Whether this admin domain is allowed to config Sensor level host quarantine.

IDS_PROFILE_ID

varchar(20)

YES

MUL

\N

The default signature profile ID for this admin domain.

CONSTRAINT is_idsprofileid_fk FOREIGN KEY(ids_profile_id) REFERENCES iv_policy(policy_id)

RECON_POLICY_ID

int(11)

YES

0

ID of the Sensor recon policy.

EMAIL_ENABLED

enum('Y','N')

NO

N

A flag to enable email responses.

EMAIL_THRESHOLD

tinyint(4)

YES

\N

An alert severity threshold beyond which the Manager must send email notification of alerts. If null, the Manager must never send email notifications of alerts.

EMAIL_SUPP_INTERVAL

int(11)

YES

600

Once the Manager has emailed a notification, it should not send any more email notification for this interval (seconds).

PAGER_ENABLED

enum('Y','N')

NO

N

A flag to enable pager responses.

PAGER_THRESHOLD

tinyint(4)

YES

\N

An alert severity threshold beyond which the Manager must send pager notification of alerts. If null, the Manager must never send pager notifications of alerts.

PAGER_SUPP_INTERVAL

int(11)

YES

600

Once the Manager has paged a notification, it should not send any more pages for this interval (seconds).

SCRIPT_ENABLED

enum('Y','N')

NO

N

A flag to enable Script responses.

SCRIPT_THRESHOLD

tinyint(4)

YES

\N

An alert severity threshold beyond which the Manager must execute the corresponding scripts. If null, the Manager must never execute scripts.

SCRIPT_SUPP_INTERVAL

int(11)

YES

600

Once the Manager has executed the scripts, it should not execute any more scripts for this interval (seconds).

BYATTACK_EMAIL

tinyint(4)

YES

\N

Per attack forwarder based on global policy settings.

BYATTACK_PAGER

tinyint(4)

YES

\N

Per attack forwarder based on global policy settings.

BYATTACK_SCRIPT

tinyint(4)

YES

\N

Per attack forwarder based on global policy settings.

BYAV_EMAIL

tinyint(4)

YES

\N

BYAV_PAGER

tinyint(4)

YES

\N

BYAV_SCRIPT

tinyint(4)

YES

\N

IS_MPE_POLICY_ENABLE

enum('Y','N')

NO

Y

EMAIL_FILTERID

int(11)

YES

Email alert filter ID associated with this admin domain.

PAGER_FILTERID

int(11)

YES

Pager alert filter ID associated with this admin domain.

SCRIPT_FILTERID

int(11)

YES

Script alert filter ID associated with this admin domain.

ANAMOLY_POLICY_ID

int(11)

YES

ID of the NTBA anamoly policy.

WORM_POLICY_ID

int(11)

YES

ID of the NTBA worm policy.

The following table describes IV_Audit information.

Field

Type

Null

Key

Default

Description / Comments

TS

timestamp

NO

MUL

The time when the audit message was audited.

USERID

varchar(64)

YES

The user ID of the user whose action is audited.

ACTION

varchar(255)

YES

The action being audited.

TARGET

text

YES

The resource on which the action is performed.

SUBSCRIBERID1

int(11)

YES

Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this audit message, and the earlier ones being its parents going back to the root admin domain ID. Audit messages of the root subscriber will have all these columns as NULL.

SUBSCRIBERID2

int(11)

YES

SUBSCRIBERID3

int(11)

YES

SUBSCRIBERID4

int(11)

YES

RESULT

int(11)

YES

The result of the operation (0 == success).

MESSAGE

text

YES

Additional explanatory text (especially for failures).

ACTIONTYPE

smallint(6)

YES

The action type column "Id" in table.

STARTTS

timestamp

YES

AUDIT_DETAIL_ID

int(11)

YES

Unique

CONSTRAINT iv_auditdetailid_uq UNIQUE (audit_detail_id)