Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-10-24 21:59:39.569 00:00:10.170 TCP 1.101.0.1:3000 -> 22.102.0.1:50072 10 6661 1 2025-10-24 21:55:46.948 00:05:03.047 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 21:59:40.308 00:00:10.363 TCP 23.104.0.1:55166 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:00:39.779 00:00:10.201 TCP 1.101.0.1:3000 -> 22.102.0.1:51732 12 10787 1 2025-10-24 21:56:46.945 00:05:03.052 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:00:40.708 00:00:10.438 TCP 23.104.0.1:45106 -> 1.101.0.1:3000 15 1926 1 2025-10-24 22:01:40.023 00:00:10.129 TCP 1.101.0.1:3000 -> 22.102.0.1:35226 10 6870 1 2025-10-24 22:01:41.185 00:00:10.359 TCP 23.104.0.1:54138 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:02:28.510 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:02:28.776 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:02:40.192 00:00:10.180 TCP 1.101.0.1:3000 -> 22.102.0.1:43478 10 6870 1 2025-10-24 22:02:41.579 00:00:10.365 TCP 23.104.0.1:59172 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:03:40.411 00:00:10.356 TCP 1.101.0.1:3000 -> 22.102.0.1:34842 10 6870 1 2025-10-24 22:03:41.985 00:00:10.334 TCP 23.104.0.1:53192 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:04:40.802 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:60192 10 6870 1 2025-10-24 22:04:42.362 00:00:10.366 TCP 23.104.0.1:51132 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:01:46.948 00:05:03.049 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:05:41.041 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:43134 10 6870 1 2025-10-24 22:05:42.769 00:00:10.375 TCP 23.104.0.1:48176 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:06:41.276 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:56444 10 6870 1 2025-10-24 22:02:46.947 00:05:03.056 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:06:43.183 00:00:10.366 TCP 23.104.0.1:58140 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:07:28.813 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:07:28.736 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:07:41.495 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:49856 10 6870 1 2025-10-24 22:07:43.582 00:00:10.338 TCP 23.104.0.1:42292 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:08:41.718 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:46902 10 6870 1 2025-10-24 22:08:43.961 00:00:10.492 TCP 23.104.0.1:56936 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:09:41.935 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:38194 10 6870 1 2025-10-24 22:09:44.490 00:00:10.368 TCP 23.104.0.1:34716 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:10:44.892 00:00:10.380 TCP 23.104.0.1:37918 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:10:42.157 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:55910 10 6870 1 2025-10-24 22:07:46.950 00:05:03.051 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:11:45.315 00:00:10.324 TCP 23.104.0.1:34352 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:11:42.371 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:33390 10 6870 1 2025-10-24 22:12:28.847 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:12:28.944 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:12:45.672 00:00:10.373 TCP 23.104.0.1:59582 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:08:46.948 00:05:03.056 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:12:42.583 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:38564 10 6870 1 2025-10-24 22:13:42.795 00:00:10.126 TCP 1.101.0.1:3000 -> 22.102.0.1:44560 10 6870 1 2025-10-24 22:13:46.105 00:00:10.323 TCP 23.104.0.1:45738 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:14:42.957 00:00:10.199 TCP 1.101.0.1:3000 -> 22.102.0.1:53220 10 6870 1 2025-10-24 22:14:46.464 00:00:10.323 TCP 23.104.0.1:54034 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:15:43.194 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:53664 10 6870 1 2025-10-24 22:15:46.827 00:00:10.378 TCP 23.104.0.1:35258 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:16:43.402 00:00:10.131 TCP 1.101.0.1:3000 -> 22.102.0.1:57734 10 6870 1 2025-10-24 22:16:47.243 00:00:10.985 TCP 23.104.0.1:55814 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:17:28.741 00:00:00.021 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:17:29.022 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:13:46.956 00:05:03.076 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:17:43.576 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:51308 10 6870 1 2025-10-24 22:17:48.267 00:00:10.359 TCP 23.104.0.1:50162 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:14:46.954 00:05:03.081 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:18:43.789 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:43824 10 6870 1 2025-10-24 22:18:48.664 00:00:10.322 TCP 23.104.0.1:41220 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:19:44.002 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:59618 10 6870 1 2025-10-24 22:19:49.023 00:00:10.364 TCP 23.104.0.1:33384 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:20:44.213 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:40868 10 6870 1 2025-10-24 22:20:49.431 00:00:10.324 TCP 23.104.0.1:45884 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:21:44.423 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:50962 10 6870 1 2025-10-24 22:21:49.791 00:00:10.772 TCP 23.104.0.1:43926 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:22:28.931 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:22:29.048 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:22:44.644 00:00:10.191 TCP 1.101.0.1:3000 -> 22.102.0.1:43734 10 6870 1 2025-10-24 22:22:50.605 00:00:10.373 TCP 23.104.0.1:37862 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:19:46.957 00:05:03.077 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:23:44.867 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:37850 10 6870 1 2025-10-24 22:23:51.017 00:00:10.361 TCP 23.104.0.1:56838 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:20:46.955 00:05:03.081 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:24:45.091 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:48814 10 6870 1 2025-10-24 22:24:51.414 00:00:10.324 TCP 23.104.0.1:52466 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:25:45.311 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:42928 10 6870 1 2025-10-24 22:25:51.776 00:00:10.373 TCP 23.104.0.1:39902 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:26:45.488 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:51542 10 6870 1 2025-10-24 22:26:52.186 00:00:10.361 TCP 23.104.0.1:59046 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:27:29.197 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:27:29.188 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:27:45.661 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:53144 10 6870 1 2025-10-24 22:27:52.587 00:00:10.953 TCP 23.104.0.1:50130 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:28:45.875 00:00:10.135 TCP 1.101.0.1:3000 -> 22.102.0.1:56460 10 6870 1 2025-10-24 22:28:53.576 00:00:10.365 TCP 23.104.0.1:36180 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:25:46.958 00:05:03.078 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:29:46.068 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:54422 10 6870 1 2025-10-24 22:29:53.982 00:00:10.336 TCP 23.104.0.1:52944 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:26:46.957 00:05:03.082 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:30:46.239 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:33938 10 6870 1 2025-10-24 22:30:54.364 00:00:10.374 TCP 23.104.0.1:36794 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:31:46.441 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:37528 10 6870 1 2025-10-24 22:31:54.774 00:00:10.367 TCP 23.104.0.1:42054 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:32:29.424 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:32:29.132 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:32:46.652 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:60766 10 6870 1 2025-10-24 22:32:55.180 00:00:10.362 TCP 23.104.0.1:56344 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:33:46.862 00:00:10.136 TCP 1.101.0.1:3000 -> 22.102.0.1:46036 10 6870 1 2025-10-24 22:33:55.583 00:00:10.368 TCP 23.104.0.1:40040 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:34:47.053 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:40020 10 6870 1 2025-10-24 22:34:55.987 00:00:10.365 TCP 23.104.0.1:51390 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:31:46.961 00:05:03.086 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:35:47.272 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:49208 10 6870 1 2025-10-24 22:35:56.391 00:00:10.365 TCP 23.104.0.1:39034 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:32:46.959 00:05:03.092 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:36:47.486 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:54330 10 6870 1 2025-10-24 22:36:56.795 00:00:10.349 TCP 23.104.0.1:50630 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:37:29.385 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:37:29.423 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:37:47.694 00:00:10.177 TCP 1.101.0.1:3000 -> 22.102.0.1:51378 10 6870 1 2025-10-24 22:37:57.181 00:00:10.320 TCP 23.104.0.1:57746 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:38:47.912 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:41526 10 6870 1 2025-10-24 22:38:57.544 00:00:10.366 TCP 23.104.0.1:54908 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:39:48.134 00:00:10.171 TCP 1.101.0.1:3000 -> 22.102.0.1:43124 10 6870 1 2025-10-24 22:39:57.948 00:00:10.372 TCP 23.104.0.1:33856 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:40:48.347 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:51616 10 6870 1 2025-10-24 22:40:58.356 00:00:10.362 TCP 23.104.0.1:54970 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:37:46.960 00:05:03.087 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:41:48.563 00:00:10.130 TCP 1.101.0.1:3000 -> 22.102.0.1:55080 10 6870 1 2025-10-24 22:41:58.752 00:00:10.388 TCP 23.104.0.1:52436 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:42:29.300 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:42:29.386 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:38:46.958 00:05:03.092 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:42:48.734 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:40562 10 6870 1 2025-10-24 22:42:59.189 00:00:10.327 TCP 23.104.0.1:34724 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:43:48.950 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:49646 10 6870 1 2025-10-24 22:43:59.552 00:00:10.328 TCP 23.104.0.1:60370 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:44:49.175 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:59182 10 6870 1 2025-10-24 22:44:59.927 00:00:10.392 TCP 23.104.0.1:53978 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:45:49.389 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:50582 10 6870 1 2025-10-24 22:46:00.359 00:00:10.362 TCP 23.104.0.1:36262 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:46:49.623 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:50226 10 6870 1 2025-10-24 22:47:00.755 00:00:10.385 TCP 23.104.0.1:43830 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:47:29.539 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:47:29.753 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:43:46.961 00:05:03.087 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:47:49.834 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:53604 10 6870 1 2025-10-24 22:48:01.175 00:00:10.363 TCP 23.104.0.1:49676 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:44:46.960 00:05:03.092 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:48:50.077 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:51514 10 6870 1 2025-10-24 22:49:01.571 00:00:10.370 TCP 23.104.0.1:47408 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:49:50.296 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:43738 10 6870 1 2025-10-24 22:50:01.976 00:00:10.368 TCP 23.104.0.1:39034 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:50:50.471 00:00:10.133 TCP 1.101.0.1:3000 -> 22.102.0.1:60594 10 6870 1 2025-10-24 22:51:02.378 00:00:10.373 TCP 23.104.0.1:48244 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:51:50.642 00:00:10.187 TCP 1.101.0.1:3000 -> 22.102.0.1:32882 10 6870 1 2025-10-24 22:52:02.784 00:00:10.370 TCP 23.104.0.1:41686 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:52:29.371 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:52:29.786 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:52:50.870 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:45886 10 6870 1 2025-10-24 22:53:03.197 00:00:10.366 TCP 23.104.0.1:39080 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:49:46.963 00:05:03.087 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-10-24 22:53:51.100 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:57202 10 6870 1 2025-10-24 22:54:03.601 00:00:10.318 TCP 23.104.0.1:38210 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:50:46.960 00:05:03.092 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-10-24 22:54:51.315 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:39398 10 6870 1 2025-10-24 22:55:03.954 00:00:10.399 TCP 23.104.0.1:42130 -> 1.101.0.1:3000 15 1926 1 2025-10-24 22:55:51.527 00:00:10.202 TCP 1.101.0.1:3000 -> 22.102.0.1:38190 12 10375 1 2025-10-24 22:56:04.388 00:00:10.326 TCP 23.104.0.1:41672 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:56:51.767 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:49384 10 6452 1 2025-10-24 22:57:04.759 00:00:10.384 TCP 23.104.0.1:44366 -> 1.101.0.1:3000 11 1507 1 2025-10-24 22:57:29.855 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-10-24 22:57:29.699 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-10-24 22:57:51.979 00:00:10.189 TCP 1.101.0.1:3000 -> 22.102.0.1:41952 10 6452 1 2025-10-24 22:58:05.187 00:00:10.366 TCP 23.104.0.1:36028 -> 1.101.0.1:3000 11 1507 1 Summary: total flows: 162, total bytes: 522266, total packets: 1563, avg bps: 1114, avg pps: 0, avg bpp: 334 Time window: 2025-10-24 21:55:46 - 2025-10-24 22:58:15 Total flows processed: 162, passed: 162, Blocks skipped: 0, Bytes read: 16912 Sys: 0.0042s User: 0.0008s Wall: 0.0025s flows/second: 64699.8 Runtime: 0.0025s