Display Filter Reference: SEBEK - Kernel Data Capture

Protocol field name: sebek

Versions: 1.0.0 to 2.6.1

Back to Display Filter Reference

Field name Description Type Versions
sebek.cmd Command Name Character string 1.0.0 to 2.6.1
sebek.counter Counter Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.data Data Character string 1.0.0 to 2.6.1
sebek.fd File Descriptor Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.inode Inode ID Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.len Data Length Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.magic Magic Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.pid Process ID Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.ppid Parent Process ID Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.socket.call Socket.Call_id Unsigned integer, 2 bytes 1.0.0 to 2.6.1
sebek.socket.dst_ip Socket.remote_ip IPv4 address 1.0.0 to 2.6.1
sebek.socket.dst_port Socket.remote_port Unsigned integer, 2 bytes 1.0.0 to 2.6.1
sebek.socket.ip_proto Socket.ip_proto Unsigned integer, 1 byte 1.0.0 to 2.6.1
sebek.socket.src_ip Socket.local_ip IPv4 address 1.0.0 to 2.6.1
sebek.socket.src_port Socket.local_port Unsigned integer, 2 bytes 1.0.0 to 2.6.1
sebek.time.sec Time Date and time 1.0.0 to 2.6.1
sebek.type Type Unsigned integer, 2 bytes 1.0.0 to 2.6.1
sebek.uid User ID Unsigned integer, 4 bytes 1.0.0 to 2.6.1
sebek.version Version Unsigned integer, 2 bytes 1.0.0 to 2.6.1
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ NetShark appliance
  • • Troubleshoot problems faster
  • • Quickly identify the applications running on your network
  • • Monitor your virtual machine traffic
Learn More