Field Identifier | Field Type | Field Name | Field Description | Reference Values | Specific Types | Remarks |
src_ip | string | Source IP | - | 192.168.0.1 | CFWRuleAcl,CFWRuleVpcAcl | - |
dst_ip | string | Destination IP | - | 192.168.0.1 | CFWRuleAcl,CFWRuleVpcAcl | - |
src_port | uint16 | Source port | - | 22 | CFWRuleAcl,CFWRuleVpcAcl | - |
dst_port | uint16 | Destination port | - | 22 | CFWRuleAcl,CFWRuleVpcAcl | - |
protocol | string | Protocol | - | tcp | CFWRuleAcl,CFWRuleVpcAcl | - |
info | string | URL information | URL of HTTP hit log | domain/testphp | CFWRuleAcl | - |
direction | int8 | Direction | Specify the traffic direction of a rule | Outbound | CFWRuleAcl,CFWRuleVpcAcl | - |
detail | string | Rule alarm description (including rule description) | Alarm details information | - | CFWRuleAcl,CFWRuleVpcAcl | - |
rule_info | string | Rule alarm details (for associating with rules) | - | - | CFWRuleAcl | - |
strategy | string | Policies | Action policy for rule execution | | CFWRuleAcl,CFWRuleVpcAcl | - |
time | int64 | Events | Time of rule hit | - | CFWRuleAcl,CFWRuleVpcAcl | - |
appid | string | appid | Account appid | - | CFWRuleAcl | - |
instance_id | string | Victim-related asset ID | Victim-related asset ID | - | CFWRuleAcl,CFWRuleVpcAcl | - |
uuid | string | Unique ID of the original alarm log | Unique ID of the original alarm log | - | CFWRuleAcl | - |
uid | int64 | Unique ID of the rule | Unique ID of the rule (for internal use) | - | CFWRuleAcl | - |
insert_time | int64 | Log insertion time | Time of recording this log | - | CFWRuleAcl,CFWRuleVpcAcl | - |
mode | uint8 | Firewall attributes | 0: bypass 1: serial | - | CFWRuleAcl | - |
type | uint8 | Protocol TYPE | Protocol TYPE: 1: TCP 3: HTTP | - | CFWRuleAcl | - |
fw_type | string | Firewall type | Firewall type to which the rule belongs | NAT Firewall | CFWRuleAcl,CFWRuleVpcAcl | - |
timestamp | string | Timestamp | Current time | - | CFWRuleAcl,CFWRuleVpcAcl | - |
fws_id | string | Engine instance ID | | cfwnat-fd7f678e | CFWRuleVpcAcl | - |
nat_ins_name | string | NAT instance name | - | - | CFWRuleVpcAcl | - |
log_type | uint8 | Log type (for internal use) | Current log type fixed value: 5 | - | CFWRuleVpcAcl | - |
dst_vpc | string | Victim assets VPCID | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
fws_name | string | Engine instance name | - | - | CFWRuleVpcAcl | - |
src_vpc | string | Attacker assets VPCID | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
region | string | Region | - | - | CFWRuleVpcAcl | - |
dst_domain | string | External domain name | External domain name information | - | CFWRuleVpcAcl | - |
l7proto | string | Seven-Layer protocol name | - | DNS,SMTP,HTTP | CFWRuleVpcAcl | - |
src_vpc_name | string | Access source VPC name | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
dst_vpc_name | string | Access destination VPC name | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
ew_ins_id | string | VPC wall instance ID | - | - | CFWRuleVpcAcl | - |
ew_ins_name | string | VPC wall instance name | - | - | CFWRuleVpcAcl | - |
src_ins_id | string | Access source asset ID | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
dst_ins_id | string | Access destination asset ID | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
src_ins_name | string | Access source instance name | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
dst_ins_name | string | Access destination instance name | - | - | CFWRuleVpcAcl | When the current log field is a null value, the current field is hidden by default. |
Was this page helpful?