true, "icmp_id": 5, "ip4_dest": "10.0.0.2", "ip4_source": "10.0.0.1", "last_time": "2016-02-11T11:12:09.416Z", "mac_dest": "00:00:00:00:00:02", "mac_source": "00:00:00:00:00:01", "start_time": "2016-02-11T11:12:09.416Z", "stats_dest": { "net_bytes_total": 50, "net_packets_total": 1 }, "stats_source": { "net_bytes_total": 50, "net_packets_total": 1 }, "type": "flow", "vlan": 10 } • Look into data for which we don’t understand the application layer protocol • TLS • Protocols we don’t yet support • Get data about IP / TCP / UDP layers • number of packets • retransmissions • inter-arrival time