Network flows format reference
Esc
Start typing to search...

Network flows format reference

Review the specifications for the network flow format, which is used internally and for exporting flow data to Kafka.

Network Flows format reference

This is the specification of the network flows format. That format is used when a Kafka exporter is configured, for Prometheus metrics labels as well as internally for the Loki store.

The "Filter ID" column shows which related name to use when defining Quick Filters (see spec.consolePlugin.quickFilters in the FlowCollector specification).

The "Loki label" column is useful when querying Loki directly: label fields need to be selected using stream selectors.

The "Cardinality" column gives information about the implied metric cardinality if this field was to be used as a Prometheus label with the FlowMetrics API. Refer to the FlowMetrics documentation for more information on using this API.

NameTypeDescriptionFilter IDLoki labelCardinalityOpenTelemetry
BytesnumberNumber of bytesn/anoavoidbytes
DnsErrnonumberError number returned from DNS tracker ebpf hook functiondns_errnonofinedns.errno
DnsFlagsnumberDNS flags for DNS recordn/anofinedns.flags
DnsFlagsResponseCodestringParsed DNS header RCODEs namedns_flag_response_codenofinedns.responsecode
DnsIdnumberDNS record iddns_idnoavoiddns.id
DnsLatencyMsnumberTime between a DNS request and response, in millisecondsdns_latencynoavoiddns.latency
DnsNamestringDNS queried namedns_namenocarefuldns.name
DscpnumberDifferentiated Services Code Point (DSCP) valuedscpnofinedscp
DstAddrstringDestination IP address (ipv4 or ipv6)dst_addressnoavoiddestination.address
DstK8S_HostIPstringDestination node IPdst_host_addressnofinedestination.k8s.host.address
DstK8S_HostNamestringDestination node namedst_host_namenofinedestination.k8s.host.name
DstK8S_NamestringName of the destination Kubernetes object, such as Pod name, Service name or Node name.dst_namenocarefuldestination.k8s.name
DstK8S_NamespacestringDestination namespacedst_namespaceyesfinedestination.k8s.namespace.name
DstK8S_NetworkNamestringDestination network namedst_networknofinedestination.network.name
DstK8S_OwnerNamestringName of the destination owner, such as Deployment name, StatefulSet name, etc.dst_owner_nameyesfinedestination.k8s.owner.name
DstK8S_OwnerTypestringKind of the destination owner, such as Deployment, StatefulSet, etc.dst_kindnofinedestination.k8s.owner.kind
DstK8S_TypestringKind of the destination Kubernetes object, such as Pod, Service or Node.dst_kindyesfinedestination.k8s.kind
DstK8S_ZonestringDestination availability zonedst_zoneyesfinedestination.zone
DstMacstringDestination MAC addressdst_macnoavoiddestination.mac
DstPortnumberDestination portdst_portnocarefuldestination.port
DstSubnetLabelstringDestination subnet labeldst_subnet_labelnofinedestination.subnet.label
Flagsstring[]List of TCP flags comprised in the flow, according to RFC-9293, with additional custom flags to represent the following per-packet combinations:
- SYN_ACK
- FIN_ACK
- RST_ACK
tcp_flagsnocarefultcp.flags
FlowDirectionnumberFlow interpreted direction from the node observation point. Can be one of:
- 0: Ingress (incoming traffic, from the node observation point)
- 1: Egress (outgoing traffic, from the node observation point)
- 2: Inner (with the same source and destination node)
node_directionyesfinehost.direction
IPSecStatusstringStatus of the IPsec encryption (on egress, given by the kernel xfrm_output function) or decryption (on ingress, via xfrm_input)ipsec_statusnofineipsec.status
IcmpCodenumberICMP codeicmp_codenofineicmp.code
IcmpTypenumberICMP typeicmp_typenofineicmp.type
IfDirectionsnumber[]Flow directions from the network interface observation point. Can be one of:
- 0: Ingress (interface incoming traffic)
- 1: Egress (interface outgoing traffic)
ifdirectionsnofineinterface.directions
Interfacesstring[]Network interfacesinterfacesnocarefulinterface.names
K8S_ClusterNamestringCluster name or identifiercluster_nameyesfinek8s.cluster.name
K8S_FlowLayerstringFlow layer: 'app' or 'infra'flow_layeryesfinek8s.layer
NetworkEventsobject[]Network events, such as network policy actions, composed of nested fields:
- Feature (such as "acl" for network policies)
- Type (such as an "AdminNetworkPolicy")
- Namespace (namespace where the event applies, if any)
- Name (name of the resource that triggered the event)
- Action (such as "allow" or "drop")
- Direction (Ingress or Egress)
network_eventsnoavoidn/a
PacketsnumberNumber of packetsn/anoavoidpackets
PktDropBytesnumberNumber of bytes dropped by the kerneln/anoavoiddrops.bytes
PktDropLatestDropCausestringLatest drop causepkt_drop_causenofinedrops.latestcause
PktDropLatestFlagsnumberTCP flags on last dropped packetn/anofinedrops.latestflags
PktDropLatestStatestringTCP state on last dropped packetpkt_drop_statenofinedrops.lateststate
PktDropPacketsnumberNumber of packets dropped by the kerneln/anoavoiddrops.packets
ProtonumberL4 protocolprotocolnofineprotocol
SamplingnumberSampling interval used for this flown/anofinen/a
SrcAddrstringSource IP address (ipv4 or ipv6)src_addressnoavoidsource.address
SrcK8S_HostIPstringSource node IPsrc_host_addressnofinesource.k8s.host.address
SrcK8S_HostNamestringSource node namesrc_host_namenofinesource.k8s.host.name
SrcK8S_NamestringName of the source Kubernetes object, such as Pod name, Service name or Node name.src_namenocarefulsource.k8s.name
SrcK8S_NamespacestringSource namespacesrc_namespaceyesfinesource.k8s.namespace.name
SrcK8S_NetworkNamestringSource network namesrc_networknofinesource.network.name
SrcK8S_OwnerNamestringName of the source owner, such as Deployment name, StatefulSet name, etc.src_owner_nameyesfinesource.k8s.owner.name
SrcK8S_OwnerTypestringKind of the source owner, such as Deployment, StatefulSet, etc.src_kindnofinesource.k8s.owner.kind
SrcK8S_TypestringKind of the source Kubernetes object, such as Pod, Service or Node.src_kindyesfinesource.k8s.kind
SrcK8S_ZonestringSource availability zonesrc_zoneyesfinesource.zone
SrcMacstringSource MAC addresssrc_macnoavoidsource.mac
SrcPortnumberSource portsrc_portnocarefulsource.port
SrcSubnetLabelstringSource subnet labelsrc_subnet_labelnofinesource.subnet.label
TLSCipherSuitestringTLS cipher suitetls_cipher_suitenofinetls.ciphersuite
TLSGroupstringTLS group nametls_groupnofinetls.group
TLSTypesstring[]TLS message types (bitfield)tls_typesnocarefultls.types
TLSVersionstringTLS versiontls_versionnofinetls.version
TimeFlowEndMsnumberEnd timestamp of this flow, in millisecondsn/anoavoidtimeflowend
TimeFlowRttNsnumberTCP Smoothed Round Trip Time (SRTT), in nanosecondstime_flow_rttnoavoidtcp.rtt
TimeFlowStartMsnumberStart timestamp of this flow, in millisecondsn/anoavoidtimeflowstart
TimeReceivednumberTimestamp when this flow was received and processed by the flow collector, in secondsn/anoavoidtimereceived
Udnsstring[]List of User Defined Networksudnsnocarefuln/a
XlatDstAddrstringpacket translation destination addressxlat_dst_addressnoavoidn/a
XlatDstPortnumberpacket translation destination portxlat_dst_portnocarefuln/a
XlatSrcAddrstringpacket translation source addressxlat_src_addressnoavoidn/a
XlatSrcPortnumberpacket translation source portxlat_src_portnocarefuln/a
ZoneIdnumberpacket translation zone idxlat_zone_idnoavoidn/a
_HashIdstringIn conversation tracking, the conversation identifieridnoavoidn/a
_RecordTypestringType of record: flowLog for regular flow logs, or newConnection, heartbeat, endConnection for conversation trackingtypeyesfinen/a