Previous Topic: FTP Folder Connection Requirements

Next Topic: Deploy the NBA

Filename Formats for Captured Data

General files in the \files subfolder and EML files in the \mails folder use the following filename formats.

Emails
ssssssssss_n_sourceIP_destIP_type_.eml

Example:

0000000520_4_201.86.52.4_10.0.0.13_SMTP_.eml

Where:

ssssssssss

Specifies a serial number used to ensure the filename is unique

n

Specifies the CPU on the NBA that the file was captured on.

On Bivio 2000 appliances, n can be 1 to 6.

On Bivio 7000 appliances, n can be 1c0 to 6c1.

sourceIP

Specifies the source IP address of the file.

destIP

Specifies the destination IP address of the file.

type

Is one of the following:

AOLMAIL
GMAIL
HOTMAIL
LIVEMAIL
NNTP-GET
NNTP-POST
POP3
SMTP
YAHOOCLASSIC
YAHOONEW
File
ssssssssss_n_sourceIP-destIP_type_filename

Example:

4C3C792BC2_2c0_au.download.windowsupdate.com(130.119.248.209)_130.119.44.131_HTTP-GET_windows-kb890830-v3.9-d...61c5fada43a2f8788d42.exe 

Where:

ssssssssss

Is a serial number used to ensure the filename is unique

n

Specifies the CPU on the NBA that the file was captured on.

On Bivio 2000 appliances, n can be 1 to 6.

On Bivio 7000 appliances, n can be 1c0 to 6c1.

sourceIP

Specifies the source machine name and, in brackets, the file’s source IP address. If the machine name is not available, only the IP address is used.

destIP

Specifies the destination machine name and, in brackets, the file’s source IP address. If the machine name is not available, only the IP address is used.

type

Is one of the following:

AOLMAIL-ATTACH
CHAT-AIMICQ
CHAT-JABBER
CHAT-MSN
CHAT-SIP
CHAT-SKYPE
CHAT-YAHOO
FILE-AIMICQ
FILE-JABBER
FILE-SIP
FILE-YAHOO
FTP-GET
FILE-MSN 
FTP-PUT
GMAIL-ATTACH
HOTMAIL-ATTACH
HTTP-GET
HTTP-POST
LIVEMAIL-ATTACH
SMB
YAHOO-ATTACH