Date first seen Duration Proto Src IP Addr:Port Dst IP Addr:Port Packets Bytes Flows 2025-11-20 11:59:33.862 00:00:10.194 TCP 1.101.0.1:3000 -> 22.102.0.1:51820 10 6452 1 2025-11-20 11:59:38.475 00:00:10.361 TCP 23.104.0.1:52228 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:00:17.876 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:00:18.229 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:00:34.085 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:43882 10 6452 1 2025-11-20 12:00:38.875 00:00:10.401 TCP 23.104.0.1:33256 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:01:34.314 00:00:10.190 TCP 1.101.0.1:3000 -> 22.102.0.1:41462 10 6452 1 2025-11-20 12:01:39.315 00:00:10.328 TCP 23.104.0.1:40440 -> 1.101.0.1:3000 11 1507 1 2025-11-20 11:57:05.215 00:05:55.638 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 11:58:00.850 00:05:04.365 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:02:34.545 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:39448 10 6452 1 2025-11-20 12:02:39.677 00:00:10.371 TCP 23.104.0.1:33748 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:03:34.717 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:53158 10 6452 1 2025-11-20 12:03:40.101 00:00:10.363 TCP 23.104.0.1:57598 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:04:34.935 00:00:10.207 TCP 1.101.0.1:3000 -> 22.102.0.1:46386 10 6452 1 2025-11-20 12:04:40.504 00:00:10.373 TCP 23.104.0.1:53922 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:05:18.314 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:05:18.200 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:05:35.182 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:60636 10 6452 1 2025-11-20 12:05:40.911 00:00:10.365 TCP 23.104.0.1:52568 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:06:35.400 00:00:10.132 TCP 1.101.0.1:3000 -> 22.102.0.1:52296 10 6452 1 2025-11-20 12:06:41.318 00:00:10.365 TCP 23.104.0.1:56954 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:07:35.587 00:00:10.238 TCP 1.101.0.1:3000 -> 22.102.0.1:60194 10 6452 1 2025-11-20 12:07:41.726 00:00:10.368 TCP 23.104.0.1:45254 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:03:05.217 00:05:55.638 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:04:00.855 00:05:04.361 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:08:35.859 00:00:10.195 TCP 1.101.0.1:3000 -> 22.102.0.1:49812 10 6452 1 2025-11-20 12:08:42.131 00:00:10.368 TCP 23.104.0.1:35350 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:09:36.099 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:54470 10 6452 1 2025-11-20 12:09:42.548 00:00:10.328 TCP 23.104.0.1:33314 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:10:18.151 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:10:17.982 00:00:00.024 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:10:36.319 00:00:10.192 TCP 1.101.0.1:3000 -> 22.102.0.1:46152 10 6452 1 2025-11-20 12:10:42.916 00:00:10.351 TCP 23.104.0.1:40486 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:11:36.551 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:36834 10 6452 1 2025-11-20 12:11:43.308 00:00:10.371 TCP 23.104.0.1:48908 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:12:36.774 00:00:10.203 TCP 1.101.0.1:3000 -> 22.102.0.1:54574 12 10369 1 2025-11-20 12:12:43.712 00:00:10.449 TCP 23.104.0.1:51318 -> 1.101.0.1:3000 15 1926 1 2025-11-20 12:13:37.024 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:38156 10 6452 1 2025-11-20 12:13:44.214 00:00:10.368 TCP 23.104.0.1:47404 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:09:05.218 00:05:55.637 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:10:00.858 00:05:04.360 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:14:37.236 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:41540 10 6452 1 2025-11-20 12:14:44.623 00:00:10.326 TCP 23.104.0.1:41960 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:15:18.431 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:15:18.053 00:00:00.030 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:15:37.448 00:00:10.782 TCP 1.101.0.1:3000 -> 22.102.0.1:51532 10 6452 1 2025-11-20 12:15:44.991 00:00:10.372 TCP 23.104.0.1:40116 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:16:38.271 00:00:10.205 TCP 1.101.0.1:3000 -> 22.102.0.1:48020 10 6452 1 2025-11-20 12:16:45.404 00:00:10.392 TCP 23.104.0.1:34080 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:17:38.512 00:00:10.138 TCP 1.101.0.1:3000 -> 22.102.0.1:54386 10 6452 1 2025-11-20 12:17:45.815 00:00:10.370 TCP 23.104.0.1:56136 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:18:38.689 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:44356 10 6452 1 2025-11-20 12:18:46.222 00:00:10.367 TCP 23.104.0.1:52870 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:19:38.902 00:00:10.150 TCP 1.101.0.1:3000 -> 22.102.0.1:50916 10 6452 1 2025-11-20 12:19:46.632 00:00:10.327 TCP 23.104.0.1:40638 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:15:05.220 00:05:55.637 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:16:00.858 00:05:04.365 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:20:18.052 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:20:18.532 00:00:00.029 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:20:39.092 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:47436 10 6452 1 2025-11-20 12:20:47.002 00:00:10.367 TCP 23.104.0.1:60282 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:21:39.320 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:49866 10 6452 1 2025-11-20 12:21:47.404 00:00:10.363 TCP 23.104.0.1:39264 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:22:39.499 00:00:10.181 TCP 1.101.0.1:3000 -> 22.102.0.1:46020 10 6452 1 2025-11-20 12:22:47.807 00:00:10.370 TCP 23.104.0.1:48226 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:23:39.723 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:57714 10 6452 1 2025-11-20 12:23:48.217 00:00:10.322 TCP 23.104.0.1:36212 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:24:39.938 00:00:10.298 TCP 1.101.0.1:3000 -> 22.102.0.1:51428 10 6452 1 2025-11-20 12:24:48.575 00:00:10.608 TCP 23.104.0.1:40092 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:25:18.710 00:00:00.021 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:25:18.555 00:00:00.025 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:25:40.283 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:59422 10 6452 1 2025-11-20 12:25:49.219 00:00:10.324 TCP 23.104.0.1:35224 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:21:05.226 00:05:55.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:22:00.884 00:05:04.339 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:26:40.501 00:00:10.140 TCP 1.101.0.1:3000 -> 22.102.0.1:59104 10 6452 1 2025-11-20 12:26:49.578 00:00:10.364 TCP 23.104.0.1:41700 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:27:40.683 00:00:10.172 TCP 1.101.0.1:3000 -> 22.102.0.1:39136 10 6452 1 2025-11-20 12:27:49.981 00:00:10.385 TCP 23.104.0.1:49404 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:28:40.899 00:00:10.184 TCP 1.101.0.1:3000 -> 22.102.0.1:58060 10 6452 1 2025-11-20 12:28:50.409 00:00:10.363 TCP 23.104.0.1:59564 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:29:41.123 00:00:10.127 TCP 1.101.0.1:3000 -> 22.102.0.1:34748 10 6452 1 2025-11-20 12:29:50.809 00:00:10.340 TCP 23.104.0.1:44618 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:30:18.572 00:00:00.024 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:30:18.707 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:30:41.291 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:37136 10 6452 1 2025-11-20 12:30:51.182 00:00:10.359 TCP 23.104.0.1:60650 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:31:41.514 00:00:10.191 TCP 1.101.0.1:3000 -> 22.102.0.1:41978 10 6452 1 2025-11-20 12:31:51.583 00:00:10.367 TCP 23.104.0.1:43622 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:27:05.226 00:05:55.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:28:00.870 00:05:04.358 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:32:41.740 00:00:10.182 TCP 1.101.0.1:3000 -> 22.102.0.1:44204 10 6452 1 2025-11-20 12:32:51.990 00:00:10.327 TCP 23.104.0.1:37034 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:33:41.961 00:00:10.156 TCP 1.101.0.1:3000 -> 22.102.0.1:57362 10 6452 1 2025-11-20 12:33:52.354 00:00:10.365 TCP 23.104.0.1:36616 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:34:42.156 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:37482 10 6452 1 2025-11-20 12:34:52.755 00:00:10.390 TCP 23.104.0.1:56200 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:35:18.849 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:35:18.901 00:00:00.023 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:35:42.369 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:59380 10 6452 1 2025-11-20 12:35:53.184 00:00:10.360 TCP 23.104.0.1:49262 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:36:42.589 00:00:10.178 TCP 1.101.0.1:3000 -> 22.102.0.1:56684 10 6452 1 2025-11-20 12:36:53.589 00:00:10.323 TCP 23.104.0.1:43018 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:37:42.805 00:00:10.168 TCP 1.101.0.1:3000 -> 22.102.0.1:42016 10 6452 1 2025-11-20 12:33:05.229 00:05:55.642 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:34:00.870 00:05:04.369 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:37:53.953 00:00:10.367 TCP 23.104.0.1:50302 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:38:43.010 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:59574 10 6452 1 2025-11-20 12:38:54.357 00:00:10.364 TCP 23.104.0.1:45388 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:39:43.223 00:00:10.169 TCP 1.101.0.1:3000 -> 22.102.0.1:35798 10 6452 1 2025-11-20 12:39:54.761 00:00:10.325 TCP 23.104.0.1:45506 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:40:19.162 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:40:18.995 00:00:00.023 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:40:43.431 00:00:10.179 TCP 1.101.0.1:3000 -> 22.102.0.1:53740 10 6452 1 2025-11-20 12:40:55.129 00:00:10.367 TCP 23.104.0.1:51998 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:41:43.648 00:00:10.134 TCP 1.101.0.1:3000 -> 22.102.0.1:36948 10 6452 1 2025-11-20 12:41:55.537 00:00:10.361 TCP 23.104.0.1:35772 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:42:43.827 00:00:10.213 TCP 1.101.0.1:3000 -> 22.102.0.1:38768 10 6452 1 2025-11-20 12:42:55.937 00:00:10.374 TCP 23.104.0.1:38960 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:43:44.094 00:00:10.174 TCP 1.101.0.1:3000 -> 22.102.0.1:36478 10 6452 1 2025-11-20 12:39:05.244 00:05:55.631 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:40:00.875 00:05:04.366 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:43:56.352 00:00:10.369 TCP 23.104.0.1:53872 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:44:44.309 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:49798 10 6452 1 2025-11-20 12:44:56.757 00:00:10.388 TCP 23.104.0.1:38386 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:45:19.289 00:00:00.025 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:45:18.938 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:45:44.529 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:54834 10 6452 1 2025-11-20 12:45:57.185 00:00:10.366 TCP 23.104.0.1:36716 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:46:44.758 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:47872 10 6452 1 2025-11-20 12:46:57.588 00:00:10.324 TCP 23.104.0.1:33472 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:47:44.980 00:00:10.199 TCP 1.101.0.1:3000 -> 22.102.0.1:47854 10 6452 1 2025-11-20 12:47:57.954 00:00:10.375 TCP 23.104.0.1:55940 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:48:45.214 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:43596 10 6452 1 2025-11-20 12:48:58.370 00:00:10.371 TCP 23.104.0.1:45306 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:49:45.434 00:00:10.183 TCP 1.101.0.1:3000 -> 22.102.0.1:49614 10 6452 1 2025-11-20 12:45:05.244 00:05:55.630 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:46:00.878 00:05:04.367 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:49:58.772 00:00:10.370 TCP 23.104.0.1:51214 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:50:18.808 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:50:19.170 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:50:45.653 00:00:10.188 TCP 1.101.0.1:3000 -> 22.102.0.1:53134 10 6452 1 2025-11-20 12:50:59.184 00:00:10.372 TCP 23.104.0.1:45916 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:51:45.879 00:00:10.201 TCP 1.101.0.1:3000 -> 22.102.0.1:48460 10 6452 1 2025-11-20 12:51:59.586 00:00:10.324 TCP 23.104.0.1:51192 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:52:46.120 00:00:10.197 TCP 1.101.0.1:3000 -> 22.102.0.1:49208 13 13955 1 2025-11-20 12:52:59.944 00:00:10.449 TCP 23.104.0.1:54474 -> 1.101.0.1:3000 15 1926 1 2025-11-20 12:53:46.353 00:00:10.175 TCP 1.101.0.1:3000 -> 22.102.0.1:35834 10 6452 1 2025-11-20 12:54:00.430 00:00:10.362 TCP 23.104.0.1:59336 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:54:46.574 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:53128 10 6452 1 2025-11-20 12:55:00.838 00:00:10.391 TCP 23.104.0.1:49796 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:55:19.172 00:00:00.022 ICMP 23.107.0.1:0 -> 1.0.198.2:0.0 3 252 1 2025-11-20 12:55:18.753 00:00:00.022 ICMP 4.0.198.2:0 -> 22.102.0.1:8.0 3 252 1 2025-11-20 12:55:46.781 00:00:10.173 TCP 1.101.0.1:3000 -> 22.102.0.1:58132 10 6452 1 2025-11-20 12:51:05.246 00:05:55.631 TCP 179.1.22.1:179 -> 179.1.22.22:39396 12 738 1 2025-11-20 12:52:00.878 00:05:04.367 TCP 179.1.22.22:39396 -> 179.1.22.1:179 12 738 1 2025-11-20 12:56:01.269 00:00:10.370 TCP 23.104.0.1:48192 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:56:46.998 00:00:10.146 TCP 1.101.0.1:3000 -> 22.102.0.1:60510 10 6452 1 2025-11-20 12:57:01.678 00:00:10.370 TCP 23.104.0.1:55160 -> 1.101.0.1:3000 11 1507 1 2025-11-20 12:57:47.184 00:00:10.176 TCP 1.101.0.1:3000 -> 22.102.0.1:51236 10 6452 1 2025-11-20 12:58:02.108 00:00:10.367 TCP 23.104.0.1:40186 -> 1.101.0.1:3000 11 1507 1 Summary: total flows: 162, total bytes: 502647, total packets: 1564, avg bps: 1096, avg pps: 0, avg bpp: 321 Time window: 2025-11-20 11:57:05 - 2025-11-20 12:58:12 Total flows processed: 162, passed: 162, Blocks skipped: 0, Bytes read: 16912 Sys: 0.0039s User: 0.0019s Wall: 0.0028s flows/second: 58484.9 Runtime: 0.0028s