Professional Documents
Culture Documents
06
Diagram created Sept 10, 2004 Standard Snort Table
chris.reid@codecraftconsultants.com
SnortDB Extra Table
Bold fields are “not null”
signature
sig_class
PK sig_id
PK sig_class_id
sig_name
detail encoding sig_class_name
FK1 sig_class_id
sig_priority
PK detail_type PK encoding_type
sig_rev
sig_sid
detail_text encoding_text
sensor event
PK sid PK,FK2 sid
PK cid
hostname
interface FK1 signature
filter timestamp
FK2 detail
FK1 encoding
last_cid
data
iphdr
PK,FK1 cid
protocols PK,FK1 cid PK,FK1 sid
PK,FK1 sid
protocol data_payload
ip_src
name ip_dst
description ip_ver
ip_hlen opt
ip_tos
ip_len PK,FK1 cid
ip_id PK,FK1 sid
ip_flags PK optid
ip_off
ip_ttl opt_proto
FK2 ip_proto opt_code
ip_csum opt_len
opt_data
name
description