z/OS Communications Server: IP Messages Volume 4 (EZZ, SNM)
Previous topic | Next topic | Contents | Contact z/OS | Library | PDF


EZZ8650I

z/OS Communications Server: IP Messages Volume 4 (EZZ, SNM)
SC27-3657-01

EZZ8650I
EZZ8650I TRMD ATTACK SYN flood start:timestamp,dipaddr=dipaddr,dport=dport,proto=proto,correlator=correlator,probeid=probeid,
sensorhostname=sensorhostname

Explanation

SYN flood start implies the server is under SYN flood attack.

timestamp is the date and time the SYN flood attack started.

dipaddr is the bound IP address of the SYN flood target.

dport is the bound port of the SYN flood target.

proto is the IP protocol type.

correlator is the Intrusion Detection Services (IDS) trace correlator. You can use the correlator to find the corresponding EZZ8651I Syn Flood End message.

probeid is the unique identifier of the probe detection point. See z/OS Communications Server: IP and SNA Codes for a description of the Intrusion Detection Services probe IDs.

sensorhostname is the fully qualified host name of the IDS sensor.

System action

Processing continues.

Operator response

None.

System programmer response

None.

Module

EZATRMD

Procedure name

WriteLogEntries

Go to the previous page Go to the next page




Copyright IBM Corporation 1990, 2014