Network Traffic Stream Dictionary

Jamf Protect Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US
Default Field NameDescriptionField TypeExample Value
DeviceIdJamf's unique identifier for the deviceString79fbd274-23eb-42cc-8dd8-a88acdc02e0b
CustomerIdCustomer account IDString8d0f5344-7488-469c-9b06-61d0990565e9
ParentIdCustomer global account IDString5555defa-1042-4a85-9fff-763ae00c8354
SourceIpPublic-facing IP address of the device where the request originatedString123.45.6.789
NetworkInterfaceThe network interface that the request is taking place overString possible values: WIFI, CELLULAR, UNKNOWNCELLULAR
RequestFull URL of the requestStringhttp://website.com/exa_mple1
DomainSecond-level domain of the requestStringwebsite
TldTop-level domain of the requestStringcom
DestinationIpIP address of the destination server where the request is goingString123.45.6.789
DnsResponseStatusThe response code given by a DNS service when doing a DNS queryStringNOERROR
TimestampTime that the request took placeString (ISO 8601)2019-11-01T02:04:56.084Z
TtlDNS record ttlString298
DnsRecordTypeDNS record typeStringAAAA
UpstreamSizeTotal bytes read from upstream connection (upload from device)String9816
UserAgentUser agent header from requestStringDalvik/2.1.0 (Linux; U; Android 9; SM-G390F Build/PPR1.180610.011)
HostNameFully Qualified Domain Name (FQDN) of the requestStringwebsite.com
ThreatResultIndicator of whether the request was found to be malicious or notString, possible values: CLEAN, DIRTYCLEAN
ThreatTypesThreat type of the request if classified as maliciousArray of Strings OR empty OR "-"malware, cryptojacking
CategoryContent classification of the requestStringNews
MethodHTTP request methodString, possible values: GET, POSTGET
sptPort where the request originatedString1234
dptPort of the destination server where the request is goingString80
HttpProtocolVersionVersion of HTTP protocol used by the clientStringHTTP/1.1
TotalSizeTotal bytes transferred from the connection (downstream + upstream)String20933728
DownstreamSizeTotal bytes transferred from downstream connectionString229700
UserEmailDevice user email addressStringjohn.smith@megacorp.com
suserAlso known as sourceUserName – Identifies the source user by nameStringJohn Smith
rtTime that the request took placeString (Unix epoch time in ms)1615889489063
blockedIndicates whether the request was blocked or not. This could be due to security policy, data management policy, or content filtering policy.String, possible values: true, falsefalse
OsTypeInformation about the device OS (ANDROID/IOS/...)StringIOS
refererOptional HTTP header field that identifies the address of the web pageStringwww.google.com
refererSiteDomain name of the HTTP referrerStringgoogle
externalIdOptional field or fields containing identifying information from an external system, such as a UEM or MDM solution.StringCan be any piece of identifying information, such as a UUID.