Applications that require the real-time synchronization of Manager data, including packet logs, are best served by performing regular SQL queries to the Manager database. An example would be Security Information and Event Management (SIEM) applications. SIEM applications can use direct database-based integration through which they can poll the Manager database and monitor specific tables for new records. Applications that do not require the packet log data that is associated with an alert can use the push techniques of SNMP or Syslog.
For applications like reports that are more ad-hoc in nature, an efficient approach would be to copy the database and manipulate it off-line. The less work the database has to do within the Manager, the better will be the performance of the Manager. Therefore, by cloning or copying the database, operations, such as large queries, or creating additional indices, can be performed on the off-line database. In addition to just copying the files from the Manager, you can use the Manager’s data back-up feature (i.e. back-up, alert & packet log archival). See Trellix Intrusion Prevention System Product Guide for details about these features.
Note
Alert information is stored in the iv_alert and iv_alert_data tables. Packet captures for alerts are stored in the iv_packetlog table.
You can query Manager database tables for several types of IV_<variable> information.
The following table describes IV_Alert information.
Field | Type | Null | Key | Default value | Description/Comments |
|---|---|---|---|---|---|
| bigint(20) | NO | MUL | Unique | Unique ID number of message |
| smallint(6) | YES | MUL | state of alert (NULL = closed, 1 = new, others) 1: unacknowledged 10: acknowledged | |
| char(1) | YES | First in line for deletion during old-alert purging | ||
| timestamp | NO | Current time stamp. | the last time this alert was modified in the database | |
| char(32) | YES | User who last modified the alert in the database | ||
| char(32) | YES | To whom the alert is assigned to for action | ||
| int(11) | NO | PRI | The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager. | |
| int(11) | NO | -1 | The VSA ID of the VIDS to which the alert applies | |
| int(11) | YES | The VSA ID of the VIDS to which the alert applies | ||
| int(11) | NO | -1 | The LI ID to which the alert applies. | |
| int(11) | YES | Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this VIDS belongs, and the earlier ones being its parents going back to the root admin domain ID. Alerts for the root subscriber will have all these columns as NULL. | ||
| int(11) | YES | |||
| int(11) | YES | |||
| int(11) | YES | |||
| smallint(6) | NO | The type of alert, where:
| ||
| int(11) | YES | The attack category id of the alert | ||
| int(11) | YES | The attack sub-category id of the alert | ||
| int(11) | YES | The method used to detect the attack | ||
| int(11) | NO | The 24-bit part of the attack ID | ||
| timestamp | NO | MUL | The timestamp on the Sensor when this alert raised | |
| timestamp | YES | The timestamp on the Manager when this alert is received. This may be greater than creation time if alert was in Sensor buffer due to connectivity issues with Manager. | ||
| tinyint(4) | NO | High, Medium, Low, Informational | ||
| int(11) | YES | If alerts are suppressed, then these many alerts were suppressed for this duration before this one. These are only filled for a throttle summary alert. | ||
| smallint(6) | NO | The slot number of the port from which the alert was raised | ||
| smallint(6) | NO | The port number of the port from which the alert was raised | ||
| int(11) | YES | Greater than 1 in case of throttled alerts | ||
| bigint(20) | YES | The packet log ID corresponding to this alert | ||
| bigint(20) | NO | The packet log group ID corresponding to this alert | ||
| int(11) | YES | A sequence number within the packet log stream | ||
| int(11) | YES | For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the request streams. | ||
| int(11) | YES | For alerts that have previous-256-byte fragments, the offset of the last byte in that packet in the response streams. | ||
| char(1) | YES | Whether a previous-256-byte fragment was sent | ||
| smallint(6) | YES | The signature ID within the attack ID | ||
| int(11) | YES | The protocol ID from protocols.xml file | ||
| smallint(6) | YES | The protocol ID from the IP-header of the packet | ||
| char(32) | YES | The IP address of the source of the attack | ||
| int(11) | YES | The source port for the attack traffic | ||
| char(32) | YES | The IP address of the target for the attack | ||
| int(11) | YES | The destination port of the attack traffic | ||
| tinyint(4) | YES | The confidence level of the signature that was matched. Inverse of BTP value. High confidence means low BTP. Confidence value ranges from 1-7. <3: high confidence 3-5: Medium >=6: Low NoteWhen the BTP value is 0, there is no corresponding confidence value for the attack. | ||
| int(11) | YES | |||
| int(11) | YES | |||
| int(11) | YES | The inner state of the protocol parsing machine | ||
| tinyint(4) | YES | Whether the attack was inbound or outbound | ||
| int(11) | YES | Corresponding signature IDs of the alerts that were suppressed | ||
| int(11) | YES | Global VIDS network ID from where the alert is raised | ||
| timestamp | YES | |||
| int(11) | YES | |||
| int(11) | YES | |||
| bigint(20) | YES | The threshold measurement which triggered the alarm | ||
| int(11) | YES | The actual threshold value that was crossed | ||
| int(11) | YES | The duration over which the value was measured | ||
| char(20) | YES | The Trellix IPS attack ID reference | ||
| int(11) | YES | Whether the attack succeeded, blocked, failed, suspicious and so on. 100 ATTACK_SUCCESSFUL 200 INCONCLUSIVE 300 ATTACK_FAILED 400 NOT_APPLICABLES 999 ATTACK_BLOCKED 888 DOS_BLOCKING_ACTIVATED 10100 BLOCKING_SIMULATED_ATTACK SUCCESSFUL 10200 BLOCKING_SIMULATED_INCONCLUSIVE 10300 BLOCKING_SIMULATED_ATTACK_FAILED 10400 BLOCKING_SIMULATED_N | ||
| int(11) | YES | Information used by the Sensor to tell the Manager whether the attack was blocked or not. INLINE_ACTION_PACKET_DROPPED = 0x01; INLINE_ACTION_BROWSER_MATCHED = 0x04; INLINE_ACTION_BROWSER_FAILED = 0x08; INLINE_ACTION_SMART_BLOCK = 0x80; INLINE_ACTION_IPS_SIMULATION = 0x40; | ||
| char(1) | YES | Y/N/U. It is related to vulnerability scanner reports. Y – relevant. As per vulnerability report, this host is vulnerable to attack in the context. N – not relevant. As per vulnerability report, this host is not vulnerable to attack in the context. U – unknown. U is very common. Y and N shows up in TA only if you have imported vulnerability report to the Manager. | ||
| int(11) | YES | The VLAN found in the attack traffic | ||
| char(20) | YES | The Trellix IPS policy that was applied on the Sensor interface | ||
| tinyint(4) | NO | Whether the attacking host is quarantined or not. This action is based on the attack quarantine settings. | ||
| bigint(20) | NO | PRI | Unique ID sent by Sensor | |
| int(11) | YES | User name of the attacking host | ||
| int(11) | YES | User name of the targeted host | ||
| int(11) | YES | The ID of the operating system on the source host of the attack | ||
| int(11) | YES | The ID of the operating system on the target of the attack | ||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| tinyint(4) | YES | |||
| int(11) | YES | Zone in which the alert was raised; applicable only to NTBA alerts. | ||
| tinyint(3) | NO | IPS Sensor – 0 NTBA Appliance – 1 | ||
| smallint(6) | YES | Reputation of the source host of the attack. This reputation is fetched from Trellix Global Threat Intelligence. Low: good <14: minimal risk. 15-29: unverified, 30-49:medium risk >49: high risk high: bad | ||
| smallint(6) | YES | Reputation of the targeted host. Same as sourceReputation | ||
| char(32) | YES | Geographical location of the source host from Trellix Global Threat Intelligence. two-digit country code: CN:China, US:USA, IN:India. | ||
| char(32) | YES | Geographical location of the targeted host. Same as above | ||
| int(11) | NO | -1 | This is relevant only for NTBA alerts. This is the ID of the exporter. | |
| int(11) | NO | -1 | ||
| bigint(20) | NO | |||
| bigint(20) | NO | |||
| int(11) | NO | -1 | The ID of the layer 7 application that matched a Firewall access rule | |
| int(11) | NO | The ID of the application category that matched a Firewall access rule | ||
| smallint(6) | NO | |||
| int(11) | NO | |||
| smallint(6) | NO | |||
| int(11) | NO | -1 | The userId for which the alert has been assigned, (-1 in case it is unassigned). | |
| char(16) | YES | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC. The phone number of the source mobile equipment | ||
| char(16) | YES | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC. The International Mobile Subscriber Identity (IMSI) ID of the source mobile equipment | ||
| varchar(120) | YES | Applicable only to attacks from data-enabled mobile equipments such as a mobile phone or a tablet PC. The Access Point Name (APN) of the mobile equipment that is the source of the attack traffic | ||
| char(16) | YES | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC. The phone number of the targeted mobile equipment | ||
| char(16) | YES | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC. The International Mobile Subscriber Identity (IMSI) of the targeted mobile equipment | ||
| varchar(120) | YES | Applicable only to attacks targeted at data-enabled mobile equipments such as a mobile phone or a tablet PC. The Access Point Name (APN) of the targeted mobile equipment | ||
| int(11) | YES | Malware File type | ||
| int(11) | YES | Malware File length | ||
| Char(32) | YES | Malware File MD5 Hash | ||
| Varchar(256) | YES | Malware Virus Name | ||
| Varchar(16) | YES | Malware file id | ||
| Int(11) | YES | Malware confidence | ||
| Int(11) | YES | Malware detection engine | ||
| Varchar(255) | YES | Source DNS name | ||
| Varchar(255) | YES | Destination DNS Name |
The following table describes IV_PacketLog information.
Field | Type | Null | Key | Default | Description/Comments |
|---|---|---|---|---|---|
| int(11) | NO | Primary | The ID of the Sensor raising the alert. This ID is assigned to a Sensor by the Manager. | |
| bigint(20) | NO | Primary | The packet log ID corresponding to this alert | |
| bigint(20) | NO | MUL | The packet log group ID corresponding to this alert | |
| char(1) | NO | Primary | F in case of a fragment; P in case of a packet. | |
| int(11) | NO | Primary | A sequence number within the packet log stream. In case of fragments, this is 1 for request logs, and 2 for response logs. | |
| int(11) | NO | Primary | The offset in the TCP stream of the last byte of a request fragment. It is 0 for packet logs. | |
| int(11) | NO | Primary | The offset in the TCP stream of the last byte of a response fragment. It is 0 for packet logs. | |
| char(1) | YES | First in line for deletion during old-alert purging | ||
| int(11) | YES | The VSA ID of the VIDS to which the alert applies | ||
| int(11) | NO | The VSA ID of the VIDS to which the alert applies | ||
| smallint(6) | NO | The slot number of the port from which the log packet originated | ||
| smallint(6) | NO | The port number of the port from which the log packet originated | ||
| timestamp | NO | MUL | Current time stamp | The time stamp on the log |
| int(11) | YES | The sequence number used to differentiate records with the same creation time | ||
| bigint(20) | NO | Primary | Unique ID generated by the Sensor for each packet log | |
| longblob | YES | The actual packet or fragment data |
The following table describes IV_Sensor information.
Field | Type | Null | Key | Default value | Description/Comments |
|---|---|---|---|---|---|
| int(11) | NO | Primary | The ID is assigned to a Sensor by the Manager | |
| int(11) | NO | MUL | The ID of the admin domain to which the Sensor belongs | |
| timestamp | NO | Current time stamp | When this record was last modified | |
| varchar(255) | NO | MUL | User-defined name of the Sensor | |
| varchar(255) | YES | User-provided description for the Sensor | ||
| varchar(255) | YES | An arbitrary string filled in by the user | ||
| varchar(255) | YES | An arbitrary string filled in by user | ||
| varchar(36) | YES | MUL | A pointer to the Lumos network element record for this Sensor | |
| varchar(255) | YES | The shared secret to be used to initialize keys for the Sensor | ||
| tinyint(4) | YES | Not used | ||
| varchar(50) | YES | The main model name for this Sensor; populated after Sensor discovery | ||
| tinyint(4) | YES | The sub model name for this Sensor; populated after Sensor discovery | ||
| varchar(50) | YES | Sensor's serial number; populated after Sensor discovery | ||
| tinyint(4) | YES | The number of slots in the chassis | ||
| tinyint(4) | YES | The number of the temperature Sensors on the device | ||
| tinyint(4) | YES | The number of the shell managers | ||
| tinyint(4) | YES | The number of the fans | ||
| tinyint(4) | YES | The number of power supplies | ||
| varchar(32) | YES | The user-assigned IP address for the Sensor's management port | ||
| int(11) | YES | The port on which the Sensor contacts the Manager for its command channel | ||
| varchar(10) | YES | Whether TCP or UDP | ||
| varchar(5) | YES | Whether v1, v2c or v3 | ||
| varchar(32) | YES | The IP address of the peer Sensor | ||
| enum('Y','N') | NO | N | Whether failover is enabled | |
| enum('Y','N') | NO | N | Whether failopen is enabled when the Sensor is in failover mode | |
| int(11) | YES | The Sensor ID of the peer Sensor | ||
| enum('Y','N') | NO | N | Whether real-time updates to the Sensor are allowed | |
| enum('Y','N') | NO | N | Whether schedule updates to the Sensor are allowed | |
| int(11) | YES | The VLAN ID reserved for the Sensor. If this value is -1, then there is no VLAN ID reserved. | ||
| enum('Y','N') | NO | N | Is the Sensor, a failover-only Sensor. | |
| enum('Y','N') | NO | Y | ||
| tinyint(4) | YES | Whether the tacacs configuration is inherited from the admin domain. 0 means yes. | ||
| tinyint(4) | NO | 0 | Status of MPE configuration inherited from the admin domain. 0 means yes. -- inheritHQ Status of HQ config inherited from AD. 0-No 0 | |
| tinyint(4) | NO | 0 | Status of HQ configuration inherited from the admin domain. 0 means no. | |
| int(11) | YES | A flag set maintained by the Sensor config service indicating an internal maintenance state | ||
| timestamp | NO | Time when the Sensor rebooted last as per the information in the Manager | ||
| timestamp | NO | The latest time that a sigset update went through successfully | ||
| enum('Y','N') | NO | N | Whether the rate limit feature is enabled | |
| timestamp | NO | Time when the rate limit feature was last modified | ||
| varchar(25) | YES | The Sensor software version | ||
| int(11) | NO | 0 | Whether the Sensor is FIPS compliant | |
| varchar(5) | YES | |||
| tinyint(4) | NO | 0 | Whether the Sensor uses offline download(1) or online download mode (0) | |
| tinyint(4) | NO | 0 | Status of File Reputation feature configuration inherited from the admin domain. 0 means no. | |
| tinyint(4) | NO | 2 | This column is now deprecated | |
| timestamp | NO | Time when the Sensor was last successfully updated |
The following table describes IV_Categories information.
Field | Type | Null | Key | Default value | Description/comments |
|---|---|---|---|---|---|
| int(11) | Yes | Represents a category ID. The possible values are 111, 112, 113, and 114. | ||
| varchar(64) | Yes | The displayableName for each categoryId is provided below:
| ||
| varchar(64) | Yes | The description for each categoryId is provided below:
|
The following table describes IV_NTBA information.
Field | Type | Null | Key | Default value | Description/comments |
|---|---|---|---|---|---|
| int (11) | NO | PRI | The unique ID that the Manager assigns to an NTBA device. | |
| int (11) | NO | MUL | ID of the admin domain that owns the NTBA device. | |
| timestamp | NO | Current time stamp | Time when this record was last modified. | |
| varchar (255) | NO | MUL | User-specified name of the NTBA device. | |
| varchar (255) | YES | Description of the NTBA device that a user optionally provides. | ||
| varchar (255) | YES | An arbitrary string entered by the user. | ||
| varchar (255) | YES | An arbitrary string entered by the user. | ||
| varchar (255) | YES | The shared secret to be used to initialize keys for this Sensor. | ||
| tinyint (4) | YES | NTBA device class. | ||
| varchar (50) | YES | NTBA device model. | ||
| tinyint (4) | YES | The submodel that is populated after device discovery. | ||
| varchar (50) | YES | The serial number of the device populated after device discovery. | ||
| varchar (32) | YES | User-assigned IP address to the NTBA device management port. | ||
| varchar (32) | YES | \N | ||
| int (11) | YES | The port on which the NTBA device contacts the Manager for its command channel. | ||
| varchar (36) | YES | MUL | A pointer to the Lumos network element record for this NTBA device. | |
| enum('Y','N') | NO | n | Whether real-time updates to the NTBA device are allowed. | |
| enum('Y','N') | NO | n | Whether schedule updates to the NTBA device are allowed. | |
| int (11) | YES | A flag set maintained by the NTBA device config service indicating an internal maintenance state. | ||
| timestamp | NO | Time when the NTBA device rebooted last as per the information in the Manager. | ||
| timestamp | NO | The latest time that a sigset update went through successfully. | ||
| varchar (25) | YES | The NTBA device software version. | ||
| int (11) | NO | 0 | Whether the NTBA device is FIPS compliant |
The following table describes IV_Alarm information.
Field | Type | Null | Key | Default | Description/comments |
|---|---|---|---|---|---|
| char (36) | NO | PRI | The alarm PK from Lumos. | |
| varchar (128) | YES | The name of the alarm. | ||
| varchar (255) | NO | A human-readable string version of the alarm source entity (not used to reconstruct the alarm). | ||
| blob | YES | Serialized copy of the actual source entity object. | ||
| varchar (128) | YES | Name of the alarm condition, for example, down and lowmem | ||
| varchar (128) | YES | Type of alarm, for example, management, equipment. | ||
| varchar (128) | YES | Severity of the alarm, for example, critical, major, minor, and so on. | ||
| timestamp | NO | Time stamp | When this alarm was last modified. | |
| timestamp | NO | Time stamp | When this alarm was created. | |
| char (1) | NO | Indication to the user whether this will interrupt service. For example, a condition type of "down" will but "lowmem" may not. | ||
| char (1) | NO | Indication whether the Manager will auto-clear this alarm eventually. | ||
| char (1) | NO | Whether this alarm has been acknowledged by a user. | ||
| text | YES | Additional text provided by alarm-creating component. | ||
| blob | YES | Additional data provided by alarm-creating component. | ||
| blob | YES | Used by user agents to piggyback client data on the alarm. | ||
| int (11) | YES | The number of times the alarm occurred. | ||
| bigint (20) | YES | The last time this record was updated. | ||
| int (11) | YES | Unique ID assigned to the Sensor by the Manager. |
The following table describes iv_subcategories information.
Field | Type | Null | Key | Default value | Description/comments |
|---|---|---|---|---|---|
| int(11) | No | Primary | The unique ID number of the subcategory. | |
| varchar(50) | No | Primary | The name of the subcategory. | |
| varchar(50) | The corresponding parent category name. | |||
| varchar(50) | The displayable name of the subcategory. | |||
| text | Description of the subcategory. | |||
| varchar(20) | No | Primary | Version of the signature set. | |
| date | Time stamp when a row was last updated. |
The following table describes iv_vids information.
Field | Type | Null | Key | Default value | Description/comments |
|---|---|---|---|---|---|
| int(11) | No | Primary | The primary key. This is assigned by the Manager. | |
| int(11) | No | MUL | ID of the corresponding admin domain. This is a foreign key. | |
| int(11) | No | |||
| int(11) | Yes | MUL | ID of the parent VIDS. | |
| Timestamp | No | When this record was last modified. | ||
| Timestamp | ||||
| Timestamp | ||||
| varchar(255) | No | User-specified name of the VIDS. | ||
| varchar(255) | Yes | User-specified description of the VIDS. | ||
| enum ('C','D','V','F','B') | No | Whether the interface is of type CIDR, dedicated, or VLAN. | ||
| tinyint(4) | No | 0 for Sensor; 1 for interface; 2 for subinterface. | ||
| int(11) | Yes | ID of the Sensor on which this VIDS is created. | ||
| tinyint(4) | No | 0 | ||
| int(11) | Yes | This column is deprecated. | ||
| int(11) | Yes | The network link on which this VIDS is created. | ||
| enum('Y', 'N') | No | N | Whether anomaly detection is enabled for this VIDS. | |
| varchar(20) | Yes | The IDS profile ID. References iv_policy(policy_id) | ||
| int(11) | Yes | Foreign key (recon_policy_id) References iv_recon_policy(recon_policy_id) | ||
| varchar(20) | Yes | The Anomaly profile ID. | ||
| int(11) | Yes | MUL | In an interface group, ref_vids_id is set to the primary VIDS of the group; otherwise set to nil. | |
| int(11) | Yes | The interface group this refers to (if any). | ||
| int(11) | Yes | The sub-interface this refers to (if any) | ||
| varchar(20) | Yes | Local IPS Policy ID. | ||
| int(11) | No | 0 | Whether the Simulation Blocking feature is enabled for the VIDS. |
The following table describes IV_Policy information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| varchar(20) | NO | Primary | Unique ID of the policy. | |
| varchar(255) | YES | Unique | Name of the policy. | |
| varchar(20) | YES | Outbound policy ID for the policy. | ||
| varchar(10) | YES | Whether it is an outbound policy or not. | ||
| varchar(20) | NO | Corresponding admin domain ID. | ||
| text | YES | iv_env_pref foreign key. | ||
| text | YES | iv_ui_filter foreign key. | ||
| varchar(10) | YES | Whether this policy can be inherited by a child admin domain. | ||
| varchar(100) | YES | Digest value. | ||
| varchar(10) | YES | Whether this policy is editable. | ||
| timestamp | NO | Time stamp when this policy was last modified. | ||
| enum('Y','N') | NO | N | Whether this policy is inherited from the Central Manager. | |
| enum('Y','N') | N | Whether this policy is local. | ||
| varchar(150) | User-defined description for the policy. | |||
| int(11) | YES | 0 | Manager-assigned policy version number. |
The following table describes iv_attack information.
Field | Type | Null | Key | Default | |
|---|---|---|---|---|---|
| varchar(20) | NO | Primary | Unique ID assigned by Trellix. | |
| varchar(20) | NO | Primary | Attack version. CONSTRAINT ivattack_pk PRIMARY KEY (id, version) | |
| varchar(255) | YES | Name for the attack. | ||
| varchar(50) | YES | |||
| varchar(50) | YES | |||
| varchar(20) | YES | |||
| longtext | YES | Description of the attack. | ||
| longblob | YES | Attack definition in the XML format. | ||
| varchar(10) | YES | Whether this is a Custom Attack. | ||
| timestamp | NO | Timestamp of when the record was last modified. | ||
| varchar(10) | YES | Whether the attack is active. | ||
| varchar(15) | NO | Attack release version. | ||
| varchar(100) | YES | Digest value. | ||
| varchar(10) | NO | False |
The following table describes IV_Filtered_Attack_List information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| varchar(20) | YES | MUL | Corresponding policy ID. CONSTRAINT ifal_ownerid_fk FOREIGN KEY (owner_id) REFERENCES iv_policy (policy_id) | |
| varchar(20) | YES | MUL | Attack ID. | |
| varchar(20) | YES | MUL | CONSTRAINT iv_filteredattklist_fk FOREIGN KEY (owner_id, filter_id) REFERENCES iv_ui_filter (owner_id, filter_id) | |
| varchar(10) | YES | Status of the attack in a policy. | ||
| timestamp | NO | When the record was last modified. | ||
| varchar(20) | YES | |||
| varchar(100) | YES | Digest value. |
The following table describes IV_impact information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| int(11) | YES | Attack severity. | ||
| varchar(20) | YES | Attack category. | ||
| longtext | YES | Impact definition in XML format. | ||
| varchar(20) | NO | MUL | CONSTRAINT ivimpact_fk FOREIGN KEY(attack_id_ref,attack_version) REFERENCES iv_attack(id, version) | |
| varchar(20) | YES | MUL | Attack version. | |
| timestamp | NO | Timestamp when this record was last modified. | ||
| varchar(10) | NO | Whether the record is active. | ||
| varchar(15) | NO | Signature set version. | ||
| varchar(100) | YES | Digest value. |
The following table describes iv_intf_group information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| int(11) | NO | Primary | Unique ID assigned by the Manager to a port cluster. | |
| timestamp | NO | The time when this record was last modified. | ||
| int(11) | NO | MUL | Unique ID of the Sensor. CONSTRAINT iig_sensorid_fk FOREIGN KEY(sensor_id) | |
| varchar(255) | NO | User-defined name for the port cluster. | ||
| int(11) | NO | MUL | ID of the primary interface in the port cluster. |
The following table describes IV_Subscriber information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| int (11) | NO | PRI | \N | The primary key of the admin domain. |
| timestamp | NO | CURRENT _TIMESTAMP | When this record was last modified. | |
| timestamp | NO | 0000-00-00 00:00:00 | ||
| timestamp | NO | 0000-00-00 00:00:00 | ||
| timestamp | NO | 0000-00-00 00:00:00 | ||
| timestamp | NO | 0000-00-00 00:00:00 | ||
| varchar(255) | NO | \N | User-defined name of the admin domain. | |
| varchar(255) | NO | \N | User-specified description for the admin domain. | |
| varchar(255) | YES | \N | The name of the company or owner of this admin domain. | |
| int(11) | YES | MUL | \N | Reference to the primary contact for this subscriber. CONSTRAINT is_primarycontactid_fk FOREIGN KEY(primary_contact_id) REFERENCES iv_contact(contact_id), |
| int(11) | YES | MUL | \N | Secondary contact (unused for now) CONSTRAINT is_secondarycontactid_fk FOREIGN KEY(secondary_contact_id) REFERENCES iv_contact(contact_id) |
| varchar(255) | YES | \N | Default email address for Manager responses | |
| varchar(255) | YES | \N | Default text-pager email address for Manager responses | |
| varchar(255) | YES | \N | Default script to be executed for script responses | |
| tinyint(4) | NO | \N | The level in the admin-domain tree that this admin domain is defined at. | |
| int(11) | YES | MUL | \N | ID of the parent admin domain. It is 0 if the parent admin domain is My Company. |
| tinyint(4) | NO | 0 | 0 if this is a leaf subscriber, 1 if it is not. | |
| int(11) | NO | 0 | The maximum number of users that can be defined under this admin domain. | |
| int(11) | NO | 0 | The maximum number of child admin domains that can be defined under this admin domain. | |
| int(11) | NO | 10000 | ||
| enum('Y','N') | NO | N | Whether this admin domain has anomaly detection turned on by default for all its VIDS. | |
| enum('Y','N') | NO | N | Whether this admin domain can create additional child admin domains under itself. | |
| enum('Y','N') | NO | N | Whether child admin domains of this admin domain can set their own policies. | |
| enum('Y','N') | NO | N | Whether this admin domain can create additional VIDS as subsets of its overall VIDS. | |
| enum('Y','N') | NO | N | Whether this admin domain can specify nonstandard ports to be considered equivalent to standard protocol ports, for example, alternate HTTPserver ports. | |
| enum('Y','N') | NO | N | Whether this admin domain can have Sensors and the network links owned by them. | |
| enum('Y','N') | NO | N | ||
| enum('Y','N') | NO | Y | Whether this admin domain is allowed to config Sensor level host quarantine. | |
| varchar(20) | YES | MUL | \N | The default signature profile ID for this admin domain. CONSTRAINT is_idsprofileid_fk FOREIGN KEY(ids_profile_id) REFERENCES iv_policy(policy_id) |
| int(11) | YES | 0 | ID of the Sensor recon policy. | |
| enum('Y','N') | NO | N | A flag to enable email responses. | |
| tinyint(4) | YES | \N | An alert severity threshold beyond which the Manager must send email notification of alerts. If null, the Manager must never send email notifications of alerts. | |
| int(11) | YES | 600 | Once the Manager has emailed a notification, it should not send any more email notification for this interval (seconds). | |
| enum('Y','N') | NO | N | A flag to enable pager responses. | |
| tinyint(4) | YES | \N | An alert severity threshold beyond which the Manager must send pager notification of alerts. If null, the Manager must never send pager notifications of alerts. | |
| int(11) | YES | 600 | Once the Manager has paged a notification, it should not send any more pages for this interval (seconds). | |
| enum('Y','N') | NO | N | A flag to enable Script responses. | |
| tinyint(4) | YES | \N | An alert severity threshold beyond which the Manager must execute the corresponding scripts. If null, the Manager must never execute scripts. | |
| int(11) | YES | 600 | Once the Manager has executed the scripts, it should not execute any more scripts for this interval (seconds). | |
| tinyint(4) | YES | \N | Per attack forwarder based on global policy settings. | |
| tinyint(4) | YES | \N | Per attack forwarder based on global policy settings. | |
| tinyint(4) | YES | \N | Per attack forwarder based on global policy settings. | |
| tinyint(4) | YES | \N | ||
| tinyint(4) | YES | \N | ||
| tinyint(4) | YES | \N | ||
| enum('Y','N') | NO | Y | ||
| int(11) | YES | Email alert filter ID associated with this admin domain. | ||
| int(11) | YES | Pager alert filter ID associated with this admin domain. | ||
| int(11) | YES | Script alert filter ID associated with this admin domain. | ||
| int(11) | YES | ID of the NTBA anamoly policy. | ||
| int(11) | YES | ID of the NTBA worm policy. |
The following table describes IV_Audit information.
Field | Type | Null | Key | Default | Description / Comments |
|---|---|---|---|---|---|
| timestamp | NO | MUL | The time when the audit message was audited. | |
| varchar(64) | YES | The user ID of the user whose action is audited. | ||
| varchar(255) | YES | The action being audited. | ||
| text | YES | The resource on which the action is performed. | ||
| int(11) | YES | Subscriber1, subscriber2, and so on are the list of nested admin domains, with the last non-null id being the admin domain to whom this audit message, and the earlier ones being its parents going back to the root admin domain ID. Audit messages of the root subscriber will have all these columns as NULL. | ||
| int(11) | YES | |||
| int(11) | YES | |||
| int(11) | YES | |||
| int(11) | YES | The result of the operation (0 == success). | ||
| text | YES | Additional explanatory text (especially for failures). | ||
| smallint(6) | YES | The action type column "Id" in table. | ||
| timestamp | YES | |||
| int(11) | YES | Unique | CONSTRAINT iv_auditdetailid_uq UNIQUE (audit_detail_id) |