Alfredo Cardigliano
|
97ca40a349
|
Add ja4 client fingerprint and custom queries
|
2025-03-12 16:57:10 +01:00 |
|
Alfredo Cardigliano
|
bb9216ba7b
|
Add QOE_SCORE column
|
2025-02-25 09:39:05 +01:00 |
|
Matteo Biscosi
|
db787a01c0
|
Removed deprecated blacklist (#8900)
|
2025-01-22 18:00:12 +01:00 |
|
Matteo Biscosi
|
3150761f26
|
Added first implementation of Assets
|
2025-01-21 12:30:56 +01:00 |
|
Matteo Biscosi
|
bf6d02902d
|
Added rest api doc for inactive assets (#6794)
|
2025-01-15 10:01:53 +01:00 |
|
Matteo Biscosi
|
5c4509c62e
|
Removed unused tables
|
2025-01-14 17:59:48 +01:00 |
|
YellowMan
|
3969fc9d9e
|
added rest API mac traffic information (#8885)
* added asset management utils
* added rest API mac traffic information
|
2025-01-13 17:56:27 +01:00 |
|
Alfredo Cardigliano
|
a4b7228a3a
|
Cleanup CH schema
|
2024-12-31 10:23:23 +01:00 |
|
Alfredo Cardigliano
|
db4810a1e6
|
Cleanup schema for sqlite (remove backticks creating issues, indentation)
|
2024-12-31 10:15:34 +01:00 |
|
Matteo Biscosi
|
a63dec0dcc
|
Reworked assets table
|
2024-12-30 12:37:54 +01:00 |
|
Alfredo Cardigliano
|
ae5128c620
|
Split protocol and alert info from ALERT_JSON: new PROTOCOL_INFO_JSON column
|
2024-12-05 15:13:16 +01:00 |
|
Alfredo Cardigliano
|
8c0094f354
|
Fix flow alerts lookup for non predominant alerts (alerts_map_h/alerts_map_l integer columns)
|
2024-11-20 11:44:06 +01:00 |
|
Alfredo Cardigliano
|
0447fe89a7
|
Fix asset_management schema
|
2024-11-19 13:05:47 +01:00 |
|
Alfredo Cardigliano
|
27d5a80ff9
|
Fix sqlite schema
|
2024-11-13 15:00:22 +01:00 |
|
Alfredo Cardigliano
|
6cfd45b648
|
Update sqlite schema
|
2024-11-13 14:42:49 +01:00 |
|
Alfredo Cardigliano
|
173e0aaca0
|
Add in-memory tables for all alert families. Add aggregated views for all families.
|
2024-11-12 09:57:02 +01:00 |
|
Alfredo Cardigliano
|
f412a7dc5e
|
Add require_attention to all alert families on CH Cluster
|
2024-11-11 18:30:50 +01:00 |
|
Alfredo Cardigliano
|
12407d6604
|
Add require_attention to all alert families on CH
|
2024-11-11 18:23:21 +01:00 |
|
Alfredo Cardigliano
|
6f9d0690c6
|
Add require_attention to all alert families on SQLite. Cleanup SQLite schema
|
2024-11-11 18:12:27 +01:00 |
|
Alfredo Cardigliano
|
2da5925181
|
Fix all alerts page. Fix require attention results.
|
2024-11-11 15:59:58 +01:00 |
|
Alfredo Cardigliano
|
f3963c9eb1
|
Split alert_status (engaged, historical, acknowledged) and require_attention flag
|
2024-11-11 12:46:25 +01:00 |
|
Alfredo Cardigliano
|
009288bdc2
|
Add schema for in-memory engaged_host_alerts table and host_alerts_view aggregated view on ClickHouse Cluster
|
2024-11-08 12:48:46 +01:00 |
|
Alfredo Cardigliano
|
7dedfa1a8c
|
Add schema for in-memory engaged_host_alerts table and host_alerts_view aggregated view on ClickHouse
|
2024-11-08 12:46:41 +01:00 |
|
Alfredo Cardigliano
|
64028e3f8b
|
Add/remove engaged alerts from the in-memory db (currently working on SQLite)
|
2024-11-08 09:07:56 +01:00 |
|
Alfredo Cardigliano
|
b48c0e0d1d
|
Add schema for in-memory mem_db.engaged_host_alerts table and host_alerts_view aggregated view on SQLite
|
2024-11-07 10:58:48 +01:00 |
|
Luca Deri
|
5e3c7c2721
|
SQlite schema split with '@' to avoid long queries that can fail
|
2024-11-05 19:04:36 +01:00 |
|
Matteo Biscosi
|
679ef8edab
|
Possible fix for asset management not working
|
2024-11-05 15:51:03 +01:00 |
|
Matteo Biscosi
|
6ab628cab9
|
Added missing schema to ch cluster
|
2024-11-05 14:34:42 +01:00 |
|
Matteo Biscosi
|
df4344273c
|
Moved asset management table
|
2024-11-05 13:47:20 +01:00 |
|
Matteo Biscosi
|
20ed95fcb0
|
Added asset management table
|
2024-11-05 13:46:57 +01:00 |
|
YellowMan
|
3320160670
|
Cloned in sqlite db information about inactive macs and hosts (#8797)
* Cloned in sqlite db information about inactive macs and hosts
* minor fix
* minor fix
* removed file
|
2024-11-05 12:19:53 +01:00 |
|
Alfredo Cardigliano
|
89f59cde5a
|
Migrate local networks type from 16 to 32 bit
|
2024-10-29 15:31:37 +01:00 |
|
Alfredo Cardigliano
|
fb30f7592f
|
Fix schema. Add DOMAIN_NAME.
|
2024-10-28 11:22:36 +01:00 |
|
Alfredo Cardigliano
|
1eab4beac5
|
Restore SRC_NETWORK_ID DST_NETWORK_ID data type to UInt16 for the time being
|
2024-10-25 11:59:17 +02:00 |
|
Alfredo Cardigliano
|
d25e23a599
|
Remove SRC_NETWORK_ID DST_NETWORK_ID type change from init (to be moved to the startup script)
|
2024-10-25 11:55:17 +02:00 |
|
Alfredo Cardigliano
|
5fd9b1c1f6
|
Change SRC_NETWORK_ID DST_NETWORK_ID from UInt16 to UInt32
|
2024-10-25 11:05:41 +02:00 |
|
Alfredo Cardigliano
|
3eed41e918
|
Delete old schemas
|
2024-10-22 08:59:16 +02:00 |
|
Luca Deri
|
5832d6ad5d
|
Typo
|
2024-10-03 12:47:14 +02:00 |
|
Matteo Biscosi
|
1fe009b9cc
|
Fixes issue with ntopng report page (#8688)
|
2024-09-30 15:31:39 +02:00 |
|
Luca Deri
|
cdf52549a5
|
Set ellio community list to manual enable as it now required reginstration on the Ellio website
|
2024-09-20 10:36:30 +02:00 |
|
Alfredo Cardigliano
|
d9057e8236
|
Add WLAN_SSID WTP_MAC_ADDRESS to hourly_flows
|
2024-09-19 12:39:22 +02:00 |
|
Alfredo Cardigliano
|
7b291f5fca
|
Dump WLAN_SSID and WTP_MAC_ADDRESS in historical flows
|
2024-09-16 18:31:42 +02:00 |
|
Luca Deri
|
b702c1d81a
|
Moved to 6.3
|
2024-09-03 17:10:07 +02:00 |
|
Alfredo Cardigliano
|
3b0b60c422
|
Remove JA3 leftovers. Update alert keys. Rename malivious JA3 to malicious Fingerprint.
|
2024-09-02 18:34:17 +02:00 |
|
GabrieleDeri
|
12c0d7fa32
|
Fixed score filter alerts page, updated dist, removed logging (#8648)
* Fixed score filter alerts page, updated dist, removed logging
* Reverted to correct version
|
2024-08-21 09:25:01 +02:00 |
|
GabrieleDeri
|
438cf9861d
|
Update db_schema_clickhouse_cluster.sql
|
2024-08-19 18:13:47 +02:00 |
|
DGabri
|
869fcbf626
|
Added useful columns in table, removed unnecessary columns
|
2024-08-19 18:11:40 +02:00 |
|
DGabri
|
35b1700620
|
Added documentation for clickhouse tables and added forgotten columns to flow_alerts_view
|
2024-08-19 18:05:14 +02:00 |
|
Alfredo Cardigliano
|
5768dd88d6
|
Add mitre table and flow/host alerts views on clickhouse cluster
|
2024-08-19 09:00:41 +02:00 |
|
Alfredo Cardigliano
|
d944725bbb
|
Optimize selects for left join
|
2024-08-09 16:04:04 +02:00 |
|