This report is displayed when both the -F and -D options are specified with the trmdstat command. It displays the contents of flood event records. The information that is presented in this report is derived from EZZ8650I, EZZ8651I, EZZ8654I, EZZ8655I, EZZ8677I, and EZZ8678I types of syslog messages.
Data that is related to SYN floods, interface floods, and EE XID floods is shown in separate sections of the report. Data for SYN floods and EE XID floods is sorted by IP address. Data for interface floods is sorted by interface name. For the interface flood exit and continuing record types, some information about the discarded packets is also provided. This information includes the protocol discarded most frequently during the flood and the category of discards seen most frequently during the interface flood. If the interface type provides the source MAC address of the prior hop, the most frequently seen prior hop source MAC address is also provided.
>trmdstat -FD /tmp/tstlog.log
trmdstat for z/OS CS V2R1 Fri Dec 2 14:09:41 2011
Command Entered : trmdstat -FD /tmp/tstlog.log
Log Time Interval : Nov 11 20:35:01 - Nov 23 14:50:52
Stack Time Interval : Nov 11 20:34:41 - Nov 23 14:50:32
TRM Records Scanned : 227
SYN FLOOD Events
Date and Time/ Local
Local IP Address Port Type SYNsRecvd FirstAck SYNsDiscd SYNsTimeO Duration Correlator
--------------------------------------------- ----- ---- ---------- ---------- ---------- ---------- ---------- ----------
11/20/2011 18:18:15.58 360 E 4536
0.0.0.0
11/20/2011 18:21:18.96 360 X 29 0 29 1 183 4536
0.0.0.0
11/21/2011 14:59:57.18 452 E 4583
192.168.105.25
11/21/2011 15:02:46.79 452 X 197 0 194 257 169 4583
192.168.105.25
11/21/2011 16:59:39.97 444 E 4586
192.168.105.25
11/21/2011 17:02:28.24 444 X 198 0 195 257 168 4586
192.168.105.25
11/21/2011 19:26:42.40 345 E 4610
::
11/21/2011 19:28:21.93 345 X 499 0 495 257 99 4610
::
11/21/2011 18:41:44.76 345 E 4589
2001:db8:0:3:9:42:103:132
11/21/2011 18:44:33.71 345 X 198 1 195 256 168 4589
2001:db8:0:3:9:42:103:132
Interface FLOOD Events
Date and Time/ Interface Type Duration Discard Correlator/ ----------------Most Frequent--------------------
Last Last Source IP/ Count/ ProbeID -----Overall----- -------Source MAC Data-------
Count Dest Address Percent Proto/ Category/ SrcMAC/ Proto/ Category/
Percent Percent Percent Percent Percent
11/22/2011 00:53:07.29 LOSAQDIO4 E 1000 4751
192.168.105.50 89 04070010
192.168.105.25
11/22/2011 00:58:09.65 LOSAQDIO4 C 266 21022 4751 6 Queue 000D602432AE 6 Queue
20023 192.168.105.50 95 04070011 95 94 95 100 99
192.168.105.25
11/22/2011 00:59:10.70 LOSAQDIO4 X 324 21022 4751 6 Queue 000D602432AE 6 Queue
20023 192.168.105.50 95 04070014 95 94 95 100 99
192.168.105.25
11/22/2011 00:53:29.78 OSAQDIO46 E 1000 4752
2001:db8::20a:5eff:fe04:8f16 94 04070010
2001:db8::4039:900:540e:3d0
11/22/2011 00:58:33.62 OSAQDIO46 C 269 16814 4752 6 Queue 00062A714400 6 Queue
15815 2001:db8::20a:5eff:fe04:8f16 92 04070011 94 93 93 100 99
2001:db8::4039:900:540e:3d0
11/22/2011 00:59:33.69 OSAQDIO46 X 325 16821 4752 6 Queue 00062A714400 6 Queue
15822 2001:db8::20a:5eff:fe04:8f16 79 04070014 94 93 93 100 99
2001:db8::4039:900:540e:3d0
11/23/2011 14:46:31.78 OSAQDIO46 E 1000 4832
2001:db8::20a:5eff:fe04:8f16 100 04070010
2001:db8::4039:900:610e:3d0
11/23/2011 14:50:32.28 OSAQDIO46 X 225 6018 4832 6 Queue 00062A714400 6 Queue
5019 2001:db8::20a:5eff:fe04:8f16 51 04070014 83 73 83 100 88
2001:db8::4039:900:610e:3d0
XID FLOOD Events
Local IP Address/ -----XID timeouts----- Last
Date and Time Last Source IP Address Type Threshold Flood Count Duration Correlator
---------------------- --------------------------------------- ---- ---------- ---------- ---------- ---------- ----------
11/11/2011 20:34:41.48 192.168.105.53 E 2 3 36
192.168.105.50
11/11/2011 20:38:34.53 192.168.105.53 X 15 17 233 36
192.168.105.50
11/12/2011 03:53:55.49 2001:db8::9:42:105:53 E 2 14 43
2001:db8::20a:5eff:fe04:8f16
11/12/2011 03:58:50.37 2001:db8::9:42:105:53 X 13 26 295 43
2001:db8::20a:5eff:fe04:8f16
This data is reported for interface flood continuing and exit record types. The data is cumulative from the time the interface flood started until the time the record was generated.
The interface flood events report width is 132 characters. If you are displaying or printing this report, use an output device that can accommodate this width.