InlineIDSEventsSummary1
{
"affected_vm_count": 0,
"first_occurence": 0,
"idsflow_details": {},
"is_ongoing": false,
"is_rule_valid": false,
"latest_occurence": 0,
"resource_type": "string",
"rule_id": 0,
"signature_id": 0,
"signature_metadata": {},
"total_count": 0,
"user_details": {},
"vm_details": {}
}
Count of VMs on which a particular signature was detected.
First occurence of the intrusion, in epoch milliseconds.
IDS event flow data specific to each IDS event. The data includes source ip, source port, destination ip, destination port, and protocol.
Flag indicating an ongoing intrusion.
Indicates if the rule id is valid or not.
Latest occurence of the intrusion, in epoch milliseconds.
IDSEvent resource type.
The IDS Rule id that detected this particular intrusion.
Signature ID pertaining to the detected intrusion.
Metadata about the detected signature including name, id, severity, product affected, protocol etc.
Number of times this particular signature was detected.
List of users logged into VMs on which a particular signature was detected.
List of VMs on which a particular signature was detected with the count.