All alerts that have iv_alert.alertType = 200 are NTBA policy violation alerts.
The details of the alert are as follows:
| Number of bytes | Value |
|---|---|
| 4 | Rule ID |
| 4 (Empty/String Length) | Uniform Resource Locator (URL) |
| 4 (Empty/String Length) | File name |
| 2 | Type of access for the file |
| 4 | Operating System ID |
| 4 | Service ID |
| 4 | Protocol ID |
| 4 | Port ID |
| 4 | Application type ID |
| 1 | IP address version |
| 4 (IPv4) or 16 (IPv6) | Host ID |
| 4 | Source VLAN ID |
| 4 | Destination VLAN ID |
| 4 (Empty/String Length) | Email address |
| 4 | Email duration |
| 4 | Source zone ID |
| 4 | Destination zone ID |
| 4 | Match bitmap object |
| 2 | Behavioral index of the host |
