We're now a non-profit! Support open source packet analysis by making a donation.

Display Filter Reference: SEBEK - Kernel Data Capture

Protocol field name: sebek

Versions: 1.0.0 to 4.0.8

Back to Display Filter Reference

Field name Description Type Versions
sebek.cmdCommand NameCharacter string1.0.0 to 4.0.8
sebek.counterCounterUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.dataDataCharacter string1.0.0 to 4.0.8
sebek.fdFile DescriptorUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.inodeInode IDUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.lenData LengthUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.magicMagicUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.pidProcess IDUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.ppidParent Process IDUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.socket.callSocket.Call_idUnsigned integer (16 bits)1.0.0 to 4.0.8
sebek.socket.dst_ipSocket.remote_ipIPv4 address1.0.0 to 4.0.8
sebek.socket.dst_portSocket.remote_portUnsigned integer (16 bits)1.0.0 to 4.0.8
sebek.socket.ip_protoSocket.ip_protoUnsigned integer (8 bits)1.0.0 to 4.0.8
sebek.socket.src_ipSocket.local_ipIPv4 address1.0.0 to 4.0.8
sebek.socket.src_portSocket.local_portUnsigned integer (16 bits)1.0.0 to 4.0.8
sebek.time.secTimeDate and time1.0.0 to 4.0.8
sebek.typeTypeUnsigned integer (16 bits)1.0.0 to 4.0.8
sebek.uidUser IDUnsigned integer (32 bits)1.0.0 to 4.0.8
sebek.versionVersionUnsigned integer (16 bits)1.0.0 to 4.0.8