| A | 
The event date, in DD/MM/YYYY format
 | 
| B | 
The event time, in hh:mm:ss.uuu format, where uuu represents milliseconds
 | 
| C | 
The event number within the logfile, starting from 1.
 | 
| a | 
Ethernet source address
 | 
| b | 
Ethernet destination address
 | 
| c | 
Ether Type
 | 
| d | 
LLC protocol
 | 
| e | 
LLC source address
 | 
| f | 
LLC destination address
 | 
| g | 
LLC control field
 | 
| h | 
SNAP OUI field
 | 
| i | 
IP source address
 | 
| j | 
IP destination address
 | 
| k | 
IP protocol
 | 
| l | 
IP Datagram ID
 | 
| m | 
IP datagram/fragment size, in bytes
 | 
| n | 
ICMP Type field
 | 
| o | 
ICMP Code field
 | 
| p | 
TCP sequence number number
 | 
| q | 
TCP Acknowledgement number
 | 
| r | 
TCP flags
 | 
| s | 
TCP or UDP source port
 | 
| t | 
TCP or UDP destination port
 | 
| u | 
ARP Operation ID
 | 
| v | 
ARP's target IP address
 | 
| w | 
For text-based protocols, eg. HTTP, this represents the entire protocol string conveyed by the current packet.
 |