mirror of
https://github.com/ntop/ntopng.git
synced 2026-04-28 23:19:33 +00:00
Adds search by tcp flags in SYN scan alert
This commit is contained in:
parent
d84fc3405a
commit
805b99f03c
2 changed files with 9 additions and 3 deletions
|
|
@ -590,7 +590,13 @@ function alert_utils.getLinkToPastFlows(ifid, alert, alert_json)
|
|||
end
|
||||
elseif string.contains(name, "tcp_flags") then
|
||||
-- Assumes IN query
|
||||
tags[#tags + 1] = {name = name, op = "in", val = tostring(val)}
|
||||
if val >= 0 then
|
||||
-- Assumes IN
|
||||
tags[#tags + 1] = {name = name, op = "in", val = tostring(val)}
|
||||
else
|
||||
-- A negative value assumes NOT IN
|
||||
tags[#tags + 1] = {name = name, op = "nin", val = tostring(-val)}
|
||||
end
|
||||
else
|
||||
-- Fallback, assume equality
|
||||
tags[#tags + 1] = {name = name, op = "eq", val = tostring(val)}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue