All alerts that have iv_alert.alertType = 200 are NTBA policy violation alerts.
The details of the alert are as follows:
Number of bytes | Value |
|---|---|
4 | Rule ID |
4 (Empty/String Length) | Uniform Resource Locator (URL) |
4 (Empty/String Length) | File name |
2 | Type of access for the file |
4 | Operating System ID |
4 | Service ID |
4 | Protocol ID |
4 | Port ID |
4 | Application type ID |
1 | IP address version |
4 (IPv4) or 16 (IPv6) | Host ID |
4 | Source VLAN ID |
4 | Destination VLAN ID |
4 (Empty/String Length) | Email address |
4 | Email duration |
4 | Source zone ID |
4 | Destination zone ID |
4 | Match bitmap object |
2 | Behavioral index of the host |
.png)