Deep Network Analyzer (DNA)

HTTP Parser: HTTPSummary Definition and Ouput

Data Dictionary
HTTPSummary - Summary of the session after all packets have been processed
startTime
java.sql.timestamp - Time the first packet was seen for this session
sensorName
String - The configured name of the DNASensor that captured this session
interface_f1
String - The name of the network interface that the client->server flow was captured
interface_f2
String - The name of the network interface that the server->client flow was captured
session
String - The unique key that descibes the session
duration
Long - Then time in milliseconds from the first packet to the last packet
protocol
String - The name of the Layer 4 protocol |TCP|UDP|ICMP|
client_addr
String - The IP Address of the client which initiated the session
client_port
Integer - The port of the client that the session was sent on
server_addr
String - The IP Address of the server which recieved the connection
server_port
Integer - The port of the server which recived the connection
status
String - The closed status of the session determined by the sensor at the point the session was flushed for output |open|closed|
service_name
String - The Layer 7 protocol name. see /etc/services
packets_sent
Long - The number of packets sent from the client to the server
packets_recv
Long - The number of packets sent from the server to the client
data_sent
Long - The number of bytes sent from the client to the server
data_recv
Long - The number of bytes sent from the server to the client
retry_packets_sent
Long - The number of retry packets sent from the client to the server
retry_packets_recv
Long - The number of retry packets sent from the server to the client
hostName
String - The Host Name servering the HTTP Requests
numRequests
Integer -The number of requests in the HTTP session
maxURLSize
Integer - The size in bytes of the largest URL request in the session
agentType
String - The HTTP Agent type requesting the session

HTTPSummary Output

startTimesensorNameinterface_f1interface_f2sessionKeydurationprotoNamclientAddrclientPortserverAddrserverPortstatusserviceNamepacketsSentpacketsRecvdataSentdataRecvretryPktSentretryPktRecvhostNamenumRequestsmaxURLSizeagentType
2005-12-28 21:49:13home.laneth1eth1267655155045697dbaef1c6282tcp69.105.125.1866121238.118.85.2180closedhttp5446537500isapi60.wxbug.com1136Mozilla/3.0 (compatible; MSIE 4.0; Win32)
2005-12-28 21:54:14home.laneth1eth1267655155045697dbaef2b6283tcp69.105.125.1866122738.118.85.2180closedhttp5446537500isapi60.wxbug.com1136Mozilla/3.0 (compatible; MSIE 4.0; Win32)
2005-12-28 21:59:14home.laneth1eth1267655155045697dbaef366286tcp69.105.125.1866123838.118.85.2180closedhttp5446535500isapi60.wxbug.com1136Mozilla/3.0 (compatible; MSIE 4.0; Win32)
2005-12-28 22:04:14home.laneth1eth1267655155045697dbaef436284tcp69.105.125.1866125138.118.85.2180closedhttp5446535500isapi60.wxbug.com1136Mozilla/3.0 (compatible; MSIE 4.0; Win32)
2005-12-28 22:05:24home.laneth1eth142a3ab815045697dbaef4761042tcp69.105.125.1866125566.163.171.12980closedhttp203317494281500my.yahoo.com11Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:29home.laneth1eth142a3ab815045697dbaef4e6103tcp69.105.125.1866126266.163.171.12980closedhttp54142827800my.yahoo.com119Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:29home.laneth1eth142a3ab815045697dbaef4f695tcp69.105.125.1866126366.163.171.12980closedhttp54142927900my.yahoo.com120Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth1425eea485045697dbaef536112tcp69.105.125.1866126766.94.234.7280closedhttp65276762700bc.us.yahoo.com10Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth1448ed8f65045697dbaef526236tcp69.105.125.1866126668.142.216.24680closedhttp54116833800pl.plus.yahoo.com116Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth1448ed8f65045697dbaef546384tcp69.105.125.1866126868.142.216.24680closedhttp54111393700pl.plus.yahoo.com149Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth142da48365045697dbaef56685tcp69.105.125.1866127066.218.72.5480closedhttp54111269700us.rd.yahoo.com150Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth142a3ab915045697dbaef57664tcp69.105.125.1866127166.163.171.14580closedhttp54122227800e.my.yahoo.com11Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth1448ed8f65045697dbaef556396tcp69.105.125.1866126968.142.216.24680closedhttp54111393800pl.plus.yahoo.com149Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:31home.laneth1eth142da48365045697dbaef58661tcp69.105.125.1866127266.218.72.5480closedhttp54111869700us.rd.yahoo.com156Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:40home.laneth1eth14009968b5045697dbaef5b630742tcp69.105.125.1866127564.9.150.13980openhttp80148451320187000www.snapstream.net210Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:27home.laneth1eth145697dbaef4945e25c4550660959tcp69.105.125.1866125769.226.92.6980openhttp54513244000us.a1.yimg.com154Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:27home.laneth1eth145697dbaef4a45e25c4550660959tcp69.105.125.1866125869.226.92.6980openhttp5349959900us.a1.yimg.com140Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:27home.laneth1eth145697dbaef4b45e1af6350660571tcp69.105.125.1866125969.225.175.9980openhttp5360631900a1452.g.akamaitech.net175Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:27home.laneth1eth145697dbaef4845e25c4c50666121tcp69.105.125.1866125669.226.92.7680openhttp181822981875200us.i1.yimg.com590Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:30home.laneth1eth145697dbaef5145e25c4c50662972tcp69.105.125.1866126569.226.92.7680openhttp78624787100us.i1.yimg.com184Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:28home.laneth1eth145697dbaef4d45e25c4f50664373tcp69.105.125.1866126169.226.92.7980openhttp771325711200i.plus.yahoo.com1182Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:28home.laneth1eth145697dbaef4c45e25c4f50664374tcp69.105.125.1866126069.226.92.7980openhttp771319711200i.plus.yahoo.com1176Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:40home.laneth1eth14009968b5045697dbaef5c660061tcp69.105.125.1866127664.9.150.13980openhttp15127216211900www.snapstream.net1029Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:41home.laneth1eth1ffffffffd8ef39635045697dbaef5d6188407tcp69.105.125.18661277216.239.57.9980closedhttp8102274381600pagead2.googlesyndication.com3355Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
2005-12-28 22:05:41home.laneth1eth1ffffffffd8ef39635045697dbaef5d6200846tcp69.105.125.18661277216.239.57.9980closedhttp8112274385600(null)00(null)
2005-12-28 22:09:14home.laneth1eth1267655155045697dbaef666284tcp69.105.125.1866128638.118.85.2180closedhttp5446535500isapi60.wxbug.com1136Mozilla/3.0 (compatible; MSIE 4.0; Win32)