Network Connection Information
network_connection_info
The Network Connection Information object describes characteristics of an OSI Transport Layer communication, including TCP and UDP.
Attributes
| Caption | Name | Type | Description |
|---|---|---|---|
| Boundary | boundary |
String | The boundary of the connection, normalized to the caption of 'boundary_id'. In the case of 'Other', it is defined by the event source. For cloud connections, this translates to the traffic-boundary(same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External. |
| Boundary ID | boundary_id |
Integer |
The normalized identifier of the boundary of the connection. For cloud connections, this translates to the traffic-boundary (same VPC, through IGW, etc.). For traditional networks, this is described as Local, Internal, or External.
|
| Community ID | community_uid |
String | The Community ID of the network connection. |
| Direction | direction |
String | The direction of the initiated connection, traffic, or email, normalized to the caption of the direction_id value. In the case of 'Other', it is defined by the event source. |
| Direction ID | direction_id |
Integer |
The normalized identifier of the direction of the initiated connection, traffic, or email.
|
| Connection Flag History | flag_history |
String | The Connection Flag History summarizes events in a network connection. For example flags ShAD representing SYN, SYN/ACK, ACK and Data exchange. |
| Protocol Name | protocol_name |
String | The IP protocol name in lowercase, as defined by the Internet Assigned Numbers Authority (IANA). For example: tcp or udp. |
| Protocol Number | protocol_num |
Integer | The IP protocol number, as defined by the Internet Assigned Numbers Authority (IANA). For example: 6 for TCP and 17 for UDP. |
| IP Version | protocol_ver |
String | The Internet Protocol version. |
| IP Version ID | protocol_ver_id |
Integer |
The Internet Protocol version identifier.
|
| Raw Data | raw_data |
JSON |
Group:contextThe event data as received from the event source. |
| Record ID | record_id |
String |
Group:primaryUnique identifier for the object |
| Session | session |
Session[] | The authenticated user or service session. |
| TCP Flags | tcp_flags |
Integer | The network connection TCP header flags (i.e., control bits). |
| Connection UID | uid |
String | The unique identifier of the connection. |
| Unmapped | unmapped |
Unmapped[] | Data from the source that was not mapped into the schema. |
Relationships
Inbound Relationships
These objects and events reference Network Connection Information in their attributes:
- FTP Activity
- Network File Activity
- File Hosting Activity
- Web Resource Access Activity
- Query Evidence
- DNS Activity
- Network Activity
- Airborne Broadcast Activity
- Drone Flights Activity
- DHCP Activity
- RDP Activity
- HTTP Activity
- Network Connection Query
- SSH Activity
- Network Remediation Activity
- Web Resources Activity
- Tunnel Activity
- NTP Activity
- Windows Evidence Artifacts
- SMB Activity
Outbound Relationships
Network Connection Information references the following objects and events in its attributes:
This page describes qdm-1.5.1+ocsf-1.6.0
Updated 3 days ago