Data Field Reference

Use the Query Value column to construct queries in the query bar. Example: classification:malicious or source.ip:1.2.3.4

General

FieldQuery ValueDescription
Session ID_idUnique identifier for the session
Src DSCPsrcDscpSource non zero differentiated services class selector set for session
Src DSCP CountsrcDscpCntUnique number of Source DSCP values for session
Dest DSCPdstDscpDestination non zero differentiated services class selector set for session
Dest DSCP CountdstDscpCntUnique number of Destination DSCP values for session
TCP Flag SYNtcpflags.synCount of packets with SYN and no ACK flag set
TCP Flag SYN-ACKtcpflags.syn-ackCount of packets with SYN and ACK flag set
TCP Flag ACKtcpflags.ackCount of packets with only the ACK flag set
TCP Flag PSHtcpflags.pshCount of packets with PSH flag set
TCP Flag FINtcpflags.finCount of packets with FIN flag set
TCP Flag RSTtcpflags.rstCount of packets with RST flag set
TCP Flag URGtcpflags.urgCount of packets with URG flag set
Initial RTTinitRTTInitial round trip time (SYN to ACK delta / 2) in ms
Session SegmentssegmentCntNumber of segments in session so far
Session LengthlengthSession length in milliseconds
UseruserExternal user set for session
User CountuserCntUnique number of external users set for session
ICMP Typeicmp.typeICMP type field values
ICMP Codeicmp.codeICMP code field values
ProtocolsprotocolProtocols set for session
Protocols CntprotocolCntUnique number of protocols set for session
Src RIRsrcRIRSource Regional Internet Registry (RIR)
Dest RIRdstRIRDestination Regional Internet Registry (RIR)
Data bytestotDataBytesTotal number of data bytes sent AND received in a session
IP ProtocolipProtocolIP protocol number or friendly name
Arkime NodenodeArkime node name the session was recorded on
Src Payload UTF8srcPayload8First 8 bytes of source payload in utf8
Dest Payload UTF8dstPayload8First 8 bytes of destination payload in utf8
Start TimefirstPacketSession start time
Stop TimelastPacketSession stop time
Src Portsource.portSource port
Src Bytessource.bytesTotal raw bytes sent by source in a session
Dest Portdestination.portDestination port
Dest IPdestination.ipDestination IP address
Dest Bytesdestination.bytesTotal raw bytes sent by destination in a session
Dst Data Bytesserver.bytesTotal data bytes sent by destination in a session
Src IPsource.ipSource IP address
Bytesnetwork.bytesTotal raw bytes sent AND received in a session
Src Data Bytesclient.bytesTotal data bytes sent by source in a session
Packetsnetwork.packetsTotal packets sent AND received in a session
SpoofablespoofableWhether the session completed a three-way handshake
Is BogonisBogonIf the source IP is private or not
TCP No AcktcpNoAckTCP sessions with no Ack packets
ClassificationclassificationGreyNoise tag classification of the session
Src Packetssource.packetsTotal packets sent by source in a session
Dest Packetsdestination.packetsTotal packets sent by destination in a session
Community Idnetwork.community_idCommunity id flow hash

Source Metadata

FieldQuery ValueDescription
Src Country CodesourceMetadata.country_codeSource IP country code from IPInfo
Src isBotsourceMetadata.is_botWhether source IP is a known bot
Src isMobilesourceMetadata.is_mobileWhether source IP is a mobile network
Src isTorsourceMetadata.is_torWhether source IP is a Tor exit node
Src isVpnsourceMetadata.is_vpnWhether source IP is associated with a VPN
Src OrganizationsourceMetadata.orgSource IP organization from IPInfo
Src Postal CodesourceMetadata.postalSource IP postal code from IPInfo
Src rdns ParentsourceMetadata.rdns_parentSource IP reverse DNS parent domain
Src rdns ValidatedsourceMetadata.rdns_validatedWhether source IP reverse DNS is validated
Src VPN ServicesourceMetadata.vpn_serviceVPN service associated with source IP
Src ASNsourceMetadata.asnSource IP ASN from IPInfo
Src CarriersourceMetadata.carrierSource IP carrier from IPInfo
Src DatacentersourceMetadata.datacenterSource IP datacenter from IPInfo
Src DomainsourceMetadata.domainSource IP domain from IPInfo
Src CitysourceMetadata.citySource IP city from IPInfo
Src CountrysourceMetadata.countrySource IP country name from IPInfo
Src LatitudesourceMetadata.latitudeSource IP latitude from IPInfo
Src LongitudesourceMetadata.longitudeSource IP longitude from IPInfo
Src PhonesourceMetadata.phoneSource IP phone prefix from IPInfo
Src rdnssourceMetadata.rdnsSource IP reverse DNS from IPInfo
Src RegionsourceMetadata.regionSource IP region from IPInfo
Src RoutesourceMetadata.routeSource IP route from IPInfo
Src TypesourceMetadata.typeSource IP network type from IPInfo
Src URLsourceMetadata.urlSource IP info URL from IPInfo

Destination Metadata

FieldQuery ValueDescription
Dest Country CodedestinationMetadata.country_codeDestination IP country code from IPInfo
Dest isBotdestinationMetadata.is_botWhether destination IP is a known bot
Dest isMobiledestinationMetadata.is_mobileWhether destination IP is a mobile network
Dest isTordestinationMetadata.is_torWhether destination IP is a Tor exit node
Dest isVpndestinationMetadata.is_vpnWhether destination IP is associated with a VPN
Dest OrganizationdestinationMetadata.orgDestination IP organization from IPInfo
Dest Postal CodedestinationMetadata.postalDestination IP postal code from IPInfo
Dest rdns ParentdestinationMetadata.rdns_parentDestination IP reverse DNS parent domain
Dest rdns ValidateddestinationMetadata.rdns_validatedWhether destination IP reverse DNS is validated
Dest VPN ServicedestinationMetadata.vpn_serviceVPN service associated with destination IP
Dest ASNdestinationMetadata.asnDestination IP ASN from IPInfo
Dest CarrierdestinationMetadata.carrierDestination IP carrier from IPInfo
Dest DatacenterdestinationMetadata.datacenterDestination IP datacenter from IPInfo
Dest DomaindestinationMetadata.domainDestination IP domain from IPInfo
Dest CitydestinationMetadata.cityDestination IP city from IPInfo
Dest CountrydestinationMetadata.countryDestination IP country name from IPInfo
Dest LatitudedestinationMetadata.latitudeDestination IP latitude from IPInfo
Dest LongitudedestinationMetadata.longitudeDestination IP longitude from IPInfo
Dest PhonedestinationMetadata.phoneDestination IP phone prefix from IPInfo
Dest rdnsdestinationMetadata.rdnsDestination IP reverse DNS from IPInfo
Dest RegiondestinationMetadata.regionDestination IP region from IPInfo
Dest RoutedestinationMetadata.routeDestination IP route from IPInfo
Dest TypedestinationMetadata.typeDestination IP network type from IPInfo
Dest URLdestinationMetadata.urlDestination IP info URL from IPInfo

GN Metadata

FieldQuery ValueDescription
Workspace UUIDgnMetadata.workspace.idUnique identifier of the workspace
Sensor UUIDgnMetadata.sensor.idUnique identifier of the sensor
Profile UUIDgnMetadata.persona.idUnique identifier of the profile
Sensor NamegnMetadata.sensor.nameHuman-readable name given to a sensor
Profile NamegnMetadata.persona.nameHuman-readable name given to a profile
Profile CategoriesgnMetadata.persona.categoriesCategories that apply to a profile
Profile Application ProtocolsgnMetadata.persona.application_protocolsApplication layer protocols that the profile mimics
Profile Associated VulnerabilitiesgnMetadata.persona.associated_vulnerabilitiesKnown vulnerabilities associated with the profile
Profile PortsgnMetadata.persona.portsTCP ports on which the profile listens
SPI Gen TimestampgnMetadata.spi_gen_timestampTimestamp of when Arkime SPI Gen processed the PCAP file
Replay FlaggnMetadata.replayWhether this session was replayed from a retrohunt

GN Tag Metadata

FieldQuery ValueDescription
Tag CategorygnTagMetadata.categoryGreyNoise tag category
Tag ConfidencegnTagMetadata.confidenceConfidence of the GreyNoise tag classification
Tag CreatedgnTagMetadata.createdTimestamp when GreyNoise tag was created
Tag CVEsgnTagMetadata.cvesCVEs related to the GreyNoise tag
Tag DescriptiongnTagMetadata.descriptionDescription of the GreyNoise tag
Tag EnabledgnTagMetadata.enabledWhether the GreyNoise tag is enabled
GreyNoise Tag IDgnTagMetadata.idThe GreyNoise tag ID
Tag Inserted AtgnTagMetadata.inserted_atTimestamp when GreyNoise tag was inserted
Tag IntentiongnTagMetadata.intentionGreyNoise tag intention (malicious, benign, etc.)
Tag NamegnTagMetadata.nameName of the GreyNoise tag
Tag NegatesgnTagMetadata.negatesWhether the GreyNoise tag is a negation
Tag Recommend BlockgnTagMetadata.recommend_blockWhether GreyNoise recommends blocking this traffic
Tag ReferencesgnTagMetadata.referencesReferences to GreyNoise tag research
Tag SilentgnTagMetadata.silentWhether the GreyNoise tag is silent
Tag SluggnTagMetadata.slugThe GreyNoise tag slug
Tag Updated AtgnTagMetadata.updated_atLast time the GreyNoise tag was updated
Tag User SubmittedgnTagMetadata.submittedWhether the GreyNoise tag was user submitted

HTTP

FieldQuery ValueDescription
Hostnamehttp.hostHTTP host header field
Hostname Counthttp.hostCntUnique number of HTTP host header values
URIhttp.uriURIs for request
URI Counthttp.uriCntUnique number of URIs for request
URI Pathhttp.pathPath portion of URI
URI Path Counthttp.pathCntUnique number of URI path values
Useragenthttp.useragentUser-Agent header
Useragent Counthttp.useragentCntUnique number of User-Agent header values
Request Methodhttp.methodHTTP request method
Request Method Counthttp.methodCntUnique number of HTTP request methods
Method GET Counthttp.method-GETNumber of GET method calls in session
Method POST Counthttp.method-POSTNumber of POST method calls in session
Method CONNECT Counthttp.method-CONNECTNumber of CONNECT method calls in session
Request Headershttp.requestHeaderRequest headers present
Request Header Counthttp.requestHeaderCntUnique number of request headers
Request Header Valueshttp.requestHeaderValueRequest header values
Request Header Values Counthttp.requestHeaderValueCntUnique number of request header values
Request HTTP Versionhttp.clientVersionRequest HTTP version number
Request HTTP Version Counthttp.clientVersionCntUnique number of request HTTP version values
Request content-typehttp.request-content-typeRequest header content-type
Request content-type Counthttp.request-content-typeCntUnique number of request content-type values
Request accepthttp.request-acceptRequest header accept
Request accept Counthttp.request-acceptCntUnique number of request accept values
Request accept-encodinghttp.request-accept-encodingRequest header accept-encoding
Request accept-encoding Counthttp.request-accept-encodingCntUnique number of accept-encoding values
Request accept-languagehttp.request-accept-languageRequest header accept-language
Request accept-language Counthttp.request-accept-languageCntUnique number of accept-language values
Request connectionhttp.request-connectionRequest header connection
Request connection Counthttp.request-connectionCntUnique number of connection header values
Request content-lengthhttp.request-content-lengthRequest header content-length
Request content-length Counthttp.request-content-lengthCntUnique number of content-length values
Request Bodyhttp.requestBodyHTTP request body
Response Headershttp.responseHeaderResponse headers present
Response Headers Counthttp.responseHeaderCntUnique number of response headers
Response Header Valueshttp.responseHeaderValueResponse header values
Response Header Values Counthttp.responseHeaderValueCntUnique number of response header values
Response HTTP Versionhttp.serverVersionResponse HTTP version number
Response HTTP Version Counthttp.serverVersionCntUnique number of response HTTP version values
Response Status Codehttp.statuscodeResponse HTTP numeric status code
Response Status Code Counthttp.statuscodeCntUnique number of response status codes
Body MD5http.md5MD5 of HTTP body response
Response Body MD5 Counthttp.md5CntUnique number of HTTP body MD5 values
Body Magichttp.bodyMagicContent type of body determined by libfile/magic
Body Magic Counthttp.bodyMagicCntUnique number of body magic values
JA4hhttp.ja4hHTTP JA4h fingerprint
JA4h Counthttp.ja4hCntUnique number of JA4h fingerprint values
JA4h_rhttp.ja4h_rHTTP JA4h raw fingerprint
JA4h_r Counthttp.ja4h_rCntUnique number of JA4h raw fingerprint values

SSH

FieldQuery ValueDescription
Versionssh.versionSSH software version
Version Countssh.versionCntUnique number of SSH software version values
Keyssh.keySSH key
Key Cntssh.keyCntUnique number of SSH keys
HASSHssh.hasshSSH HASSH fingerprint
HASSH Countssh.hasshCntUnique number of HASSH fingerprint values
HASSH Serverssh.hasshServerSSH HASSH server fingerprint
HASSH Server Countssh.hasshServerCntUnique number of HASSH server fingerprint values
JA4sshssh.ja4sshSSH JA4ssh fingerprint
JA4ssh Countssh.ja4sshCntUnique number of JA4ssh fingerprint values

TLS

FieldQuery ValueDescription
Versiontls.versionSSL/TLS version
Version Counttls.versionCntUnique number of SSL/TLS version values
Ciphertls.cipherSSL/TLS cipher suite
Cipher Counttls.cipherCntUnique number of cipher suite values
JA3tls.ja3SSL/TLS JA3 fingerprint
JA3 Counttls.ja3CntUnique number of JA3 fingerprint values
JA3 Stringtls.ja3stringSSL/TLS JA3 string
JA3 String Counttls.ja3stringCntUnique number of JA3 string values
JA3Stls.ja3sSSL/TLS JA3S fingerprint
JA3S Counttls.ja3sCntUnique number of JA3S fingerprint values
JA3S Stringtls.ja3sstringSSL/TLS JA3S string
JA3S String Counttls.ja3sstringCntUnique number of JA3S string values
JA4tls.ja4SSL/TLS JA4 fingerprint
JA4 Counttls.ja4CntUnique number of JA4 fingerprint values
JA4_rtls.ja4_rSSL/TLS JA4_r fingerprint
JA4_r Counttls.ja4_rCntUnique number of JA4_r fingerprint values
JA4stls.ja4sSSL/TLS JA4s fingerprint
JA4s Counttls.ja4sCntUnique number of JA4s fingerprint values
JA4s_rtls.ja4s_rSSL/TLS JA4s raw fingerprint
JA4s_r Counttls.ja4s_rCntUnique number of JA4s raw fingerprint values
Dst Session Idtls.dstSessionIdSSL/TLS destination session ID
Src Session Idtls.srcSessionIdSSL/TLS source session ID

TCP

FieldQuery ValueDescription
JA4ltcp.ja4lJA4 latency client fingerprint
JA4lstcp.ja4lsJA4 latency server fingerprint
JA4ttcp.ja4tJA4 TCP client fingerprint
JA4t Counttcp.ja4tCntUnique number of JA4 TCP client fingerprint values
JA4tstcp.ja4tsJA4 TCP server fingerprint
JA4ts Counttcp.ja4tsCntUnique number of JA4 TCP server fingerprint values

Suricata

FieldQuery ValueDescription
Flow Idsuricata.flowIdSuricata flow ID
Flow Id Cntsuricata.flowIdCntUnique number of Suricata flow IDs
Actionsuricata.actionSuricata action (alert, drop, etc.)
Action Cntsuricata.actionCntUnique number of Suricata action values
Signaturesuricata.signatureSuricata IDS signature name
Signature Cntsuricata.signatureCntUnique number of Suricata signatures
Signature Idsuricata.signatureIdSuricata signature ID
Signature Id Cntsuricata.signatureIdCntUnique number of Suricata signature IDs
Categorysuricata.categorySuricata alert category
Category Cntsuricata.categoryCntUnique number of Suricata category values
Gidsuricata.gidSuricata group ID
Gid Cntsuricata.gidCntUnique number of Suricata group IDs
Severitysuricata.severitySuricata alert severity level
Severity Cntsuricata.severityCntUnique number of Suricata severity values

Krb5 (Kerberos)

FieldQuery ValueDescription
Realmkrb5.realmKerberos 5 realm
Realm Cntkrb5.realmCntUnique number of Kerberos 5 realm values
snamekrb5.snameKerberos 5 service name
sname Cntkrb5.snameCntUnique number of Kerberos 5 service name values

What’s Next