All alerts that have iv_alert.alertType = 21 are NTBA host sweep alerts. Its iv_alert_data.typeSpecific data has the following format:
First byte contains number of the IP information to follow. If there are ten IPs involved in the hostsweep, then the first byte of typeSpecificData will have a value of 10. Every subsequent four bytes will contain the actual IP values.
Total length of typeSpecificData in the above example will be 1 + ( 10* 4) + 8 = 49 bytes.
The details of the alert are as follows:
| Number of bytes | Value |
|---|---|
| 4 | Connection rule ID |
| 4 | Connection drop count |
| 1 | External geographical location |
| 1 | External reputation |
| 1 | Connection rule type |
| 4 | Protocol ID |
| 2 | IP address count |
| 4 (IPv4) or 16 (IPv6) | Version of the target IP address |
| 1 | Version information |
| 4 (IPv4) or 16 (IPv6) | Proxy IP address |
| Variable length | Packet log |
