record
- ts:
time &log
Time when the SSH connection began.
- uid:
string &log
Unique ID for the connection.
- id:
conn_id &log
The connection’s 4-tuple of endpoint addresses/ports.
- version:
count &log
SSH major version (1 or 2)
- auth_success:
bool &log &optional
Authentication result (T=success, F=failure, unset=unknown)
- direction:
Direction &log &optional
Direction of the connection. If the client was a local host
logging into an external host, this would be OUTBOUND. INBOUND
would be set for the opposite situation.
- client:
string &log &optional
The client’s version string
- server:
string &log &optional
The server’s version string
- cipher_alg:
string &log &optional
The encryption algorithm in use
- mac_alg:
string &log &optional
The signing (MAC) algorithm in use
- compression_alg:
string &log &optional
The compression algorithm in use
- kex_alg:
string &log &optional
The key exchange algorithm in use
- host_key_alg:
string &log &optional
The server host key’s algorithm
- host_key:
string &log &optional
The server’s key fingerprint
logged: bool &default = F &optional
num_failures: count &default = 0 &optional
capabilities: SSH::Capabilities &optional
- remote_location:
geo_location &log &optional
(present if policy/protocols/ssh/geo-data.bro is loaded)
Add geographic data related to the “remote” host of the
connection.
|