All alerts that have iv_alert.alertType = 15, are NTBA simple threshold alerts.
Note
Either the serviceId or applicationId will be -1 in an alert depending upon the type of the attack.
The details of the alert are as follows:
Number of bytes | Value |
|---|---|
4 | Service ID |
4 | Source VLAN ID |
4 | Destination VLAN ID |
NTBA simple threshold type specific data
.png)