This report is displayed when the -A option is specified with the trmdstat command. It displays the summary of all attack events. The information presented in this report is derived from EZZ8648I and EZZ8649I types of syslog messages. Information is grouped by destination IP address - source IP address pair. It is sorted by destination IP address and then by destination port.
>trmdstat -A /tmp/tstlog.log
trmdstat for z/OS CS V2R1 Fri Nov 25 09:12:26 2011
Command Entered : trmdstat -A /tmp/tstlog.log
Log Time Interval : Nov 12 04:36:51 - Nov 29 19:55:50
Stack Time Interval : Nov 12 04:36:47 - Nov 29 19:55:46
TRM Records Scanned : 227
ATTACK Summary
Packets Discarded
Destination IP Address: 192.168.105.53
Source IP Address: 192.168.105.50
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
11000 0 0 0 0 0 0 0 1 0
0 0 0 0 0 0 0
12000 0 0 0 0 0 0 0 2 0
0 0 0 0 0 0 1
Packets Discarded
Destination IP Address: 2001:db8:0:3:9:42:103:132
Source IP Address: 2001:db8::20d:60ff:fe24:32ae
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
0 0 0 1 0 0 0 0 0 0
0 1 0 0 0 0 0
Packets Discarded
Destination IP Address: 2001:db8:0:3:9:42:103:132
Source IP Address: 2001:db8:0:3:20a:5eff:fe04:8f16
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
0 2 0 0 0 0 0 0 0 0
0 0 0 0 2 0 0
Packets Would Have Been Discarded
Destination IP Address: 192.168.0.5
Source IP Address: 192.168.101.3
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
0 0 1 0 0 0 0 0 0 0
0 0 0 0 0 0 0
Packets Would Have Been Discarded
Destination IP Address: 2001:db8:0:3:9:42:103:132
Source IP Address: 2001:db8::20d:60ff:fe24:32ae
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
0 0 0 1 0 0 0 0 0 0
0 0 0 0 0 0 0
7 0 0 0 0 0 1 0 0 0
0 0 0 0 0 0 0
Packets Would Have Been Discarded
Destination IP Address: 2001:db8:0:3:9:42:103:132
Source IP Address: 2001:db8:0:3:20a:5eff:fe04:8f16
Dest Malform/ OutRaw4/ Redirect/ DestOpts/ IPProto/ PerpEcho/ EELDLC/
Port Fragment OutRaw6 IPOption HopOpts NextHdrs DataHide EEPort EEMalfmd NoId
----- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ---------- ----------
0 0 0 0 2 0 0 0 0 0
0 0 0 1 1 0 0