Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-09-04 19:55:23.671 00:05:00.689 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 19:59:15.302 00:00:10.325 TCP 23.104.0.1:36594 -> 1.101.0.1:3000 11 1507 1 2025-09-04 19:59:33.493 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:51228 10 6452 1 2025-09-04 20:00:15.665 00:00:10.388 TCP 23.104.0.1:50498 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:00:33.705 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:45906 11 6504 1 2025-09-04 20:01:16.105 00:00:10.371 TCP 23.104.0.1:49396 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:01:33.932 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:39414 10 6452 1 2025-09-04 20:02:16.515 00:00:10.377 TCP 23.104.0.1:34510 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:02:34.160 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:51108 10 6452 1 2025-09-04 20:03:14.795 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:03:14.779 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:03:16.935 00:00:10.373 TCP 23.104.0.1:34016 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:03:34.375 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:39248 10 6452 1 2025-09-04 20:00:23.671 00:05:00.694 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:04:17.343 00:00:10.364 TCP 23.104.0.1:41984 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:04:34.592 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:36812 10 6452 1 2025-09-04 20:01:23.675 00:05:00.689 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:05:17.748 00:00:10.364 TCP 23.104.0.1:50646 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:05:34.803 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:35362 10 6452 1 2025-09-04 20:06:18.147 00:00:10.366 TCP 23.104.0.1:57468 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:06:35.017 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:48548 10 6452 1 2025-09-04 20:07:18.550 00:00:10.367 TCP 23.104.0.1:42576 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:07:35.228 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:60854 10 6452 1 2025-09-04 20:08:14.957 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:08:14.936 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:08:18.952 00:00:10.452 TCP 23.104.0.1:50402 -> 1.101.0.1:3000 15 1926 1 2025-09-04 20:08:35.441 00:00:10.217 TCP 1.101.0.1:3000 -> 22.102.0.1:45402 12 10367 1 2025-09-04 20:09:19.443 00:00:10.363 TCP 23.104.0.1:46092 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:09:35.699 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:53510 10 6452 1 2025-09-04 20:06:23.674 00:05:00.693 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:10:19.841 00:00:10.390 TCP 23.104.0.1:51104 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:10:35.915 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:39704 10 6452 1 2025-09-04 20:07:23.676 00:05:00.690 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:11:20.274 00:00:10.376 TCP 23.104.0.1:37326 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:11:36.132 00:00:10.185 TCP 1.101.0.1:3000 -> 22.102.0.1:37164 10 6452 1 2025-09-04 20:12:20.675 00:00:10.323 TCP 23.104.0.1:56662 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:12:36.354 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:54342 10 6452 1 2025-09-04 20:13:14.691 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:13:14.732 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:13:21.044 00:00:10.366 TCP 23.104.0.1:52546 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:13:36.566 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:46030 10 6452 1 2025-09-04 20:14:21.445 00:00:10.362 TCP 23.104.0.1:33316 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:14:36.782 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:44682 10 6452 1 2025-09-04 20:15:21.844 00:00:10.381 TCP 23.104.0.1:55642 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:15:37.000 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:55840 10 6452 1 2025-09-04 20:12:23.674 00:05:00.696 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:16:22.260 00:00:10.363 TCP 23.104.0.1:48924 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:16:37.221 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:57820 10 6452 1 2025-09-04 20:13:23.676 00:05:00.692 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:17:22.662 00:00:10.370 TCP 23.104.0.1:56684 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:17:37.442 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:39470 10 6452 1 2025-09-04 20:18:15.205 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:18:14.881 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:18:23.094 00:00:10.402 TCP 23.104.0.1:45052 -> 1.101.0.1:3000 15 1926 1 2025-09-04 20:18:37.660 00:00:10.242 TCP 1.101.0.1:3000 -> 22.102.0.1:48972 12 10365 1 2025-09-04 20:19:23.533 00:00:10.369 TCP 23.104.0.1:59880 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:19:37.943 00:00:10.150 TCP 1.101.0.1:3000 -> 22.102.0.1:43794 10 6452 1 2025-09-04 20:20:23.935 00:00:10.346 TCP 23.104.0.1:53168 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:20:38.128 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:36236 10 6452 1 2025-09-04 20:21:24.320 00:00:10.360 TCP 23.104.0.1:47008 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:21:38.346 00:00:10.186 TCP 1.101.0.1:3000 -> 22.102.0.1:57076 10 6452 1 2025-09-04 20:18:23.674 00:05:00.697 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:22:24.723 00:00:10.381 TCP 23.104.0.1:58202 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:22:38.569 00:00:10.149 TCP 1.101.0.1:3000 -> 22.102.0.1:44916 10 6452 1 2025-09-04 20:23:15.366 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:23:15.257 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:19:23.677 00:05:00.692 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:23:25.142 00:00:10.401 TCP 23.104.0.1:45080 -> 1.101.0.1:3000 15 1926 1 2025-09-04 20:23:38.758 00:00:10.205 TCP 1.101.0.1:3000 -> 22.102.0.1:44912 12 10365 1 2025-09-04 20:24:25.578 00:00:10.370 TCP 23.104.0.1:40000 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:24:39.002 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:52858 10 6452 1 2025-09-04 20:25:25.989 00:00:10.371 TCP 23.104.0.1:59384 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:25:39.226 00:00:10.152 TCP 1.101.0.1:3000 -> 22.102.0.1:49272 10 6452 1 2025-09-04 20:26:26.399 00:00:10.380 TCP 23.104.0.1:54482 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:26:39.420 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:44776 10 6452 1 2025-09-04 20:27:26.815 00:00:10.372 TCP 23.104.0.1:33036 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:27:39.637 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:51254 10 6452 1 2025-09-04 20:28:14.967 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:28:14.930 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:24:23.676 00:05:00.696 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:28:27.223 00:00:10.369 TCP 23.104.0.1:34722 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:28:39.855 00:00:10.193 TCP 1.101.0.1:3000 -> 22.102.0.1:35412 10 6452 1 2025-09-04 20:25:23.678 00:05:00.693 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:29:27.626 00:00:10.369 TCP 23.104.0.1:33984 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:29:40.087 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:59310 10 6452 1 2025-09-04 20:30:28.031 00:00:10.331 TCP 23.104.0.1:52102 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:30:40.264 00:00:10.129 TCP 1.101.0.1:3000 -> 22.102.0.1:57058 10 6452 1 2025-09-04 20:31:28.411 00:00:10.364 TCP 23.104.0.1:56496 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:31:40.442 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:60182 10 6452 1 2025-09-04 20:32:28.810 00:00:10.414 TCP 23.104.0.1:41996 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:32:40.654 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:47900 10 6452 1 2025-09-04 20:33:15.180 00:00:00.030 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:33:15.202 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:33:29.264 00:00:10.551 TCP 23.104.0.1:55236 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:33:40.827 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:55538 10 6452 1 2025-09-04 20:30:23.680 00:05:00.694 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:34:29.874 00:00:10.364 TCP 23.104.0.1:36844 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:34:41.068 00:00:10.141 TCP 1.101.0.1:3000 -> 22.102.0.1:36066 10 6452 1 2025-09-04 20:31:23.683 00:05:00.689 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:35:30.279 00:00:10.322 TCP 23.104.0.1:38906 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:35:41.245 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:39728 10 6452 1 2025-09-04 20:36:30.637 00:00:10.364 TCP 23.104.0.1:39760 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:36:41.462 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:53340 10 6452 1 2025-09-04 20:37:31.058 00:00:10.370 TCP 23.104.0.1:36410 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:37:41.676 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:46364 10 6452 1 2025-09-04 20:38:15.482 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:38:15.337 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:38:31.461 00:00:10.366 TCP 23.104.0.1:41486 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:38:41.908 00:00:10.151 TCP 1.101.0.1:3000 -> 22.102.0.1:43756 10 6452 1 2025-09-04 20:39:31.863 00:00:10.371 TCP 23.104.0.1:35646 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:39:42.090 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:35400 10 6452 1 2025-09-04 20:36:23.681 00:05:00.695 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:40:32.271 00:00:10.362 TCP 23.104.0.1:44302 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:40:42.305 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:50238 10 6452 1 2025-09-04 20:37:23.684 00:05:00.690 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:41:32.669 00:00:10.320 TCP 23.104.0.1:43328 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:41:42.515 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:57218 10 6452 1 2025-09-04 20:42:33.028 00:00:10.364 TCP 23.104.0.1:51534 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:42:42.691 00:00:10.193 TCP 1.101.0.1:3000 -> 22.102.0.1:58570 10 6452 1 2025-09-04 20:43:15.395 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:43:15.452 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:43:33.430 00:00:10.445 TCP 23.104.0.1:50194 -> 1.101.0.1:3000 15 1926 1 2025-09-04 20:43:42.929 00:00:10.217 TCP 1.101.0.1:3000 -> 22.102.0.1:33686 12 10367 1 2025-09-04 20:44:33.912 00:00:10.362 TCP 23.104.0.1:47474 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:44:43.183 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:42294 10 6452 1 2025-09-04 20:45:34.319 00:00:10.366 TCP 23.104.0.1:44646 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:45:43.394 00:00:10.140 TCP 1.101.0.1:3000 -> 22.102.0.1:33162 10 6452 1 2025-09-04 20:42:23.683 00:05:00.698 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:46:34.730 00:00:10.376 TCP 23.104.0.1:35110 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:46:43.571 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:42126 10 6452 1 2025-09-04 20:43:23.686 00:05:00.693 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:47:35.149 00:00:10.320 TCP 23.104.0.1:40484 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:47:43.783 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:54286 10 6452 1 2025-09-04 20:48:15.522 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:48:15.607 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:48:35.510 00:00:10.363 TCP 23.104.0.1:42154 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:48:44.008 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:39064 10 6452 1 2025-09-04 20:49:35.914 00:00:10.322 TCP 23.104.0.1:55474 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:49:44.227 00:00:10.151 TCP 1.101.0.1:3000 -> 22.102.0.1:35140 10 6452 1 2025-09-04 20:50:36.275 00:00:10.364 TCP 23.104.0.1:44578 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:50:44.415 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:33904 10 6452 1 2025-09-04 20:51:36.683 00:00:10.377 TCP 23.104.0.1:40358 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:51:44.594 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:49196 10 6452 1 2025-09-04 20:48:23.687 00:05:00.696 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:52:37.111 00:00:10.366 TCP 23.104.0.1:55470 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:52:44.813 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:50424 10 6452 1 2025-09-04 20:53:15.604 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:53:15.687 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:49:23.691 00:05:00.690 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-09-04 20:53:37.513 00:00:10.362 TCP 23.104.0.1:53316 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:53:45.041 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:52736 10 6452 1 2025-09-04 20:54:37.911 00:00:10.365 TCP 23.104.0.1:42474 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:54:45.219 00:00:10.133 TCP 1.101.0.1:3000 -> 22.102.0.1:47616 10 6452 1 2025-09-04 20:55:38.311 00:00:10.321 TCP 23.104.0.1:50866 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:55:45.392 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:49226 10 6452 1 2025-09-04 20:56:38.670 00:00:10.383 TCP 23.104.0.1:36906 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:56:45.605 00:00:10.401 TCP 1.101.0.1:3000 -> 22.102.0.1:56674 10 6452 1 2025-09-04 20:57:39.123 00:00:10.365 TCP 23.104.0.1:43886 -> 1.101.0.1:3000 11 1507 1 2025-09-04 20:57:46.071 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:38002 10 6452 1 2025-09-04 20:58:15.812 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-09-04 20:58:15.548 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-09-04 20:54:23.690 00:05:00.694 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-09-04 20:58:39.528 00:00:10.365 TCP 23.104.0.1:46542 -> 1.101.0.1:3000 11 1507 1 Summary: total flows: 163, total bytes: 509280, total packets: 1587, avg bps: 1060, avg pps: 0, avg bpp: 320 Time window: 2025-09-04 19:55:23 - 2025-09-04 20:59:24 Total flows processed: 163, passed: 163, Blocks skipped: 0, Bytes read: 17016 Sys: 0.0047s User: 0.0000s Wall: 0.0056s flows/second: 28977.7 Runtime: 0.0056s