Thank you for the help, but that page only describes the kind of events that can occur and gives examples, but it does not actually define the data inside. Most of them are easy to identify (src is obviously source ip) but the unlabeled fields are my problem.