#separator \x09 #set_separator , #empty_field (empty) #unset_field - #path dpd #open 2019-08-26-17-26-39 #fields ts uid id.orig_h id.orig_p id.resp_h id.resp_p proto analyzer failure_reason #types time string addr port addr port enum string string 1056991898.901892 CHhAvVGS1DHFjwGM9 192.168.0.173 1068 192.168.0.2 4997 tcp NTLM NTLM AV Pair loop underflow #close 2019-08-26-17-26-39