Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-09-02 12:59:09.643 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:59848 10 6452 1 2025-09-02 12:59:19.221 00:00:10.385 TCP 23.104.0.1:36848 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:00:09.860 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:35102 10 6452 1 2025-09-02 13:00:19.642 00:00:10.364 TCP 23.104.0.1:34436 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:01:10.085 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:43188 10 6452 1 2025-09-02 13:01:20.044 00:00:10.365 TCP 23.104.0.1:38938 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:02:08.322 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:02:08.678 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:02:10.303 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:46334 10 6452 1 2025-09-02 13:02:20.443 00:00:10.319 TCP 23.104.0.1:41500 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:03:10.522 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:41630 10 6452 1 2025-09-02 12:59:22.420 00:05:00.727 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:03:20.805 00:00:10.337 TCP 23.104.0.1:33078 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:04:10.742 00:00:10.146 TCP 1.101.0.1:3000 -> 22.102.0.1:49328 10 6452 1 2025-09-02 13:00:22.417 00:05:00.733 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:04:21.180 00:00:10.594 TCP 23.104.0.1:33906 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:05:10.925 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:59942 10 6452 1 2025-09-02 13:05:21.811 00:00:10.361 TCP 23.104.0.1:47512 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:06:11.145 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:53990 10 6452 1 2025-09-02 13:06:22.217 00:00:10.328 TCP 23.104.0.1:41770 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:07:08.496 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:07:08.631 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:07:11.354 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:33326 10 6452 1 2025-09-02 13:07:22.593 00:00:10.359 TCP 23.104.0.1:51754 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:08:11.563 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:46658 10 6452 1 2025-09-02 13:08:22.990 00:00:10.364 TCP 23.104.0.1:59774 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:09:11.778 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:35908 10 6452 1 2025-09-02 13:05:22.423 00:05:00.726 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:09:23.401 00:00:10.369 TCP 23.104.0.1:53006 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:10:11.988 00:00:10.198 TCP 1.101.0.1:3000 -> 22.102.0.1:37610 10 6452 1 2025-09-02 13:06:22.419 00:05:00.731 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:10:23.810 00:00:10.365 TCP 23.104.0.1:59656 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:11:12.216 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:54626 10 6452 1 2025-09-02 13:11:24.212 00:00:10.334 TCP 23.104.0.1:41684 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:12:08.697 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:12:08.944 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:12:12.434 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:33664 10 6452 1 2025-09-02 13:12:24.579 00:00:10.371 TCP 23.104.0.1:59320 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:13:12.651 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:51038 10 6452 1 2025-09-02 13:13:24.985 00:00:10.370 TCP 23.104.0.1:55724 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:14:12.877 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:48022 10 6452 1 2025-09-02 13:14:25.392 00:00:10.365 TCP 23.104.0.1:49928 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:15:13.103 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:47274 10 6452 1 2025-09-02 13:11:22.423 00:05:00.728 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:15:25.803 00:00:10.341 TCP 23.104.0.1:44486 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:16:13.321 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:55868 10 6452 1 2025-09-02 13:12:22.421 00:05:00.732 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:16:26.183 00:00:10.367 TCP 23.104.0.1:48744 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:17:08.852 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:17:08.757 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:17:13.540 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:48442 10 6452 1 2025-09-02 13:17:26.592 00:00:10.365 TCP 23.104.0.1:60744 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:18:13.762 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:46426 10 6452 1 2025-09-02 13:18:26.989 00:00:10.362 TCP 23.104.0.1:56338 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:19:13.979 00:00:10.202 TCP 1.101.0.1:3000 -> 22.102.0.1:46656 10 6452 1 2025-09-02 13:19:27.396 00:00:10.714 TCP 23.104.0.1:56680 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:20:14.219 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:52636 10 6452 1 2025-09-02 13:20:28.154 00:00:10.364 TCP 23.104.0.1:33018 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:17:22.424 00:05:00.728 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:21:14.444 00:00:10.148 TCP 1.101.0.1:3000 -> 22.102.0.1:49938 10 6452 1 2025-09-02 13:21:28.555 00:00:10.359 TCP 23.104.0.1:49604 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:22:08.927 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:22:08.864 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:18:22.422 00:05:00.733 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:22:14.633 00:00:10.142 TCP 1.101.0.1:3000 -> 22.102.0.1:38844 10 6452 1 2025-09-02 13:22:28.954 00:00:10.367 TCP 23.104.0.1:50280 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:23:14.811 00:00:10.211 TCP 1.101.0.1:3000 -> 22.102.0.1:37102 10 6452 1 2025-09-02 13:23:29.362 00:00:10.365 TCP 23.104.0.1:38462 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:24:15.088 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:34124 10 6452 1 2025-09-02 13:24:29.765 00:00:10.329 TCP 23.104.0.1:49242 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:25:15.304 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:35298 10 6452 1 2025-09-02 13:25:30.130 00:00:10.368 TCP 23.104.0.1:37298 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:26:15.520 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:38182 10 6452 1 2025-09-02 13:26:30.535 00:00:10.365 TCP 23.104.0.1:56878 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:27:09.088 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:27:08.934 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:27:15.728 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:33970 10 6452 1 2025-09-02 13:23:22.425 00:05:00.730 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:27:30.932 00:00:10.379 TCP 23.104.0.1:37798 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:28:15.939 00:00:10.224 TCP 1.101.0.1:3000 -> 22.102.0.1:48904 10 6452 1 2025-09-02 13:24:22.423 00:05:00.734 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:28:31.348 00:00:10.372 TCP 23.104.0.1:43072 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:29:16.209 00:00:10.147 TCP 1.101.0.1:3000 -> 22.102.0.1:45020 10 6452 1 2025-09-02 13:29:31.757 00:00:10.381 TCP 23.104.0.1:58132 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:30:16.397 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:45906 10 6452 1 2025-09-02 13:30:32.171 00:00:10.365 TCP 23.104.0.1:36910 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:31:16.615 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:37252 10 6452 1 2025-09-02 13:31:32.576 00:00:10.363 TCP 23.104.0.1:51644 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:32:09.094 00:00:00.036 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:32:09.128 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:32:16.825 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:53276 10 6452 1 2025-09-02 13:32:32.977 00:00:10.368 TCP 23.104.0.1:36490 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:29:22.427 00:05:00.729 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:33:17.051 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:40582 10 6452 1 2025-09-02 13:33:33.383 00:00:10.332 TCP 23.104.0.1:45894 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:30:22.425 00:05:00.735 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:34:17.265 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:38678 10 6452 1 2025-09-02 13:34:33.748 00:00:10.372 TCP 23.104.0.1:36946 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:35:17.491 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:58756 10 6452 1 2025-09-02 13:35:34.159 00:00:10.369 TCP 23.104.0.1:56918 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:36:17.698 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:38790 10 6452 1 2025-09-02 13:36:34.558 00:00:10.367 TCP 23.104.0.1:52930 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:37:09.111 00:00:00.036 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:37:09.054 00:00:00.038 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:37:17.870 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:56086 10 6452 1 2025-09-02 13:37:34.964 00:00:10.326 TCP 23.104.0.1:53796 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:38:18.097 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:38636 10 6452 1 2025-09-02 13:38:35.330 00:00:10.363 TCP 23.104.0.1:53372 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:35:22.427 00:05:00.729 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:39:18.309 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:44958 10 6452 1 2025-09-02 13:39:35.734 00:00:10.370 TCP 23.104.0.1:54588 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:36:22.427 00:05:00.733 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:40:18.525 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:41504 10 6452 1 2025-09-02 13:40:36.140 00:00:10.372 TCP 23.104.0.1:35488 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:41:18.697 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:43858 10 6452 1 2025-09-02 13:41:36.547 00:00:10.371 TCP 23.104.0.1:54530 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:42:09.402 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:42:09.265 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:42:18.913 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:48604 10 6452 1 2025-09-02 13:42:36.967 00:00:10.367 TCP 23.104.0.1:40004 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:43:19.085 00:00:10.128 TCP 1.101.0.1:3000 -> 22.102.0.1:44262 10 6452 1 2025-09-02 13:43:37.374 00:00:10.365 TCP 23.104.0.1:36518 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:44:19.255 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:42496 10 6452 1 2025-09-02 13:44:37.770 00:00:10.329 TCP 23.104.0.1:34258 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:41:22.428 00:05:00.729 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:45:19.468 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:48944 10 6452 1 2025-09-02 13:45:38.141 00:00:10.367 TCP 23.104.0.1:53364 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:42:22.426 00:05:00.733 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:46:19.684 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:56444 10 6452 1 2025-09-02 13:46:38.541 00:00:10.368 TCP 23.104.0.1:34644 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:47:09.252 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:47:09.283 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:47:19.899 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:42146 10 6452 1 2025-09-02 13:47:38.948 00:00:10.372 TCP 23.104.0.1:56716 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:48:20.116 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:56494 10 6452 1 2025-09-02 13:48:39.359 00:00:10.365 TCP 23.104.0.1:42530 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:49:20.328 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:47514 10 6452 1 2025-09-02 13:49:39.763 00:00:10.379 TCP 23.104.0.1:35710 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:50:20.541 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:42856 10 6452 1 2025-09-02 13:50:40.181 00:00:10.370 TCP 23.104.0.1:56304 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:47:22.432 00:05:00.728 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:51:20.754 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:51246 10 6452 1 2025-09-02 13:51:40.589 00:00:10.366 TCP 23.104.0.1:33436 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:52:09.585 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:52:09.409 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:48:22.428 00:05:00.734 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:52:20.930 00:00:10.200 TCP 1.101.0.1:3000 -> 22.102.0.1:47730 10 6452 1 2025-09-02 13:52:40.991 00:00:10.373 TCP 23.104.0.1:32840 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:53:21.173 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:54738 10 6452 1 2025-09-02 13:53:41.396 00:00:10.369 TCP 23.104.0.1:40730 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:54:21.403 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:51288 10 6452 1 2025-09-02 13:54:41.797 00:00:10.364 TCP 23.104.0.1:44650 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:55:21.614 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:50172 10 6452 1 2025-09-02 13:55:42.198 00:00:10.367 TCP 23.104.0.1:49120 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:56:21.834 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:51676 10 6452 1 2025-09-02 13:56:42.602 00:00:10.364 TCP 23.104.0.1:51968 -> 1.101.0.1:3000 11 1507 1 2025-09-02 13:57:09.899 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-02 13:57:09.657 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-02 13:53:22.432 00:05:00.730 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-02 13:57:22.080 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:37846 10 6452 1 2025-09-02 13:57:43.004 00:00:10.439 TCP 23.104.0.1:44986 -> 1.101.0.1:3000 15 1926 1 2025-09-02 13:54:22.430 00:05:00.734 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-02 13:58:22.287 00:00:10.199 TCP 1.101.0.1:3000 -> 22.102.0.1:52934 12 10365 1 Summary: total flows: 163, total bytes: 501173, total packets: 1567, avg bps: 1109, avg pps: 0, avg bpp: 319 Time window: 2025-09-02 12:59:09 - 2025-09-02 13:59:23 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0031s User: 0.0016s Wall: 0.0022s flows/second: 73261.0 Runtime: 0.0022s