Display Filter Reference: SEBEK - Kernel Data Capture

Protocol field name: sebek

Versions: 1.0.0 to 3.4.5

Back to Display Filter Reference

Field name Description Type Versions
sebek.cmd Command Name Character string 1.0.0 to 3.4.5
sebek.counter Counter Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.data Data Character string 1.0.0 to 3.4.5
sebek.fd File Descriptor Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.inode Inode ID Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.len Data Length Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.magic Magic Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.pid Process ID Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.ppid Parent Process ID Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.socket.call Socket.Call_id Unsigned integer, 2 bytes 1.0.0 to 3.4.5
sebek.socket.dst_ip Socket.remote_ip IPv4 address 1.0.0 to 3.4.5
sebek.socket.dst_port Socket.remote_port Unsigned integer, 2 bytes 1.0.0 to 3.4.5
sebek.socket.ip_proto Socket.ip_proto Unsigned integer, 1 byte 1.0.0 to 3.4.5
sebek.socket.src_ip Socket.local_ip IPv4 address 1.0.0 to 3.4.5
sebek.socket.src_port Socket.local_port Unsigned integer, 2 bytes 1.0.0 to 3.4.5
sebek.time.sec Time Date and time 1.0.0 to 3.4.5
sebek.type Type Unsigned integer, 2 bytes 1.0.0 to 3.4.5
sebek.uid User ID Unsigned integer, 4 bytes 1.0.0 to 3.4.5
sebek.version Version Unsigned integer, 2 bytes 1.0.0 to 3.4.5
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More