Commit graph

7854 commits

Author SHA1 Message Date
Alfredo Cardigliano
1e31c6bfd9 Remove SNMP pool 2022-02-25 15:55:22 +01:00
Alfredo Cardigliano
c430a58a62 Remove active monitoring pools 2022-02-25 11:59:06 +01:00
MatteoBiscosi
6559396810 Changed virustotal and greygoose color 2022-02-24 18:07:37 +01:00
Alfredo Cardigliano
f741dd26be Fix alert engage/disengage 2022-02-24 13:18:37 +01:00
Alfredo Cardigliano
7b2db43e32 Fix Active Monitoring link to Settings 2022-02-24 12:10:39 +01:00
Alfredo Cardigliano
c55e38235e Temporarily validate AM type as single word 2022-02-24 11:38:46 +01:00
Alfredo Cardigliano
5d103c0394 Remove pools configuration in active monitoring 2022-02-23 19:02:54 +01:00
Alfredo Cardigliano
fb441a73a6 Hide host pools selection in the default recipient 2022-02-23 15:53:23 +01:00
Alfredo Cardigliano
7a225929ed Remove interface pool selection in recipients 2022-02-23 15:38:50 +01:00
Alfredo Cardigliano
fb8128e0d4 Remove device pool 2022-02-23 15:22:37 +01:00
MatteoBiscosi
588e5ae8dd Fixes vlan not correctly added (#6342) 2022-02-23 15:18:40 +01:00
Alfredo Cardigliano
5b0eddea7a Cleanup tab 2022-02-23 15:06:14 +01:00
Alfredo Cardigliano
a7b6107d71 Remove flow pool 2022-02-23 15:05:22 +01:00
Alfredo Cardigliano
5623b9c6f7 Remove system endpoint 2022-02-23 14:53:48 +01:00
Alfredo Cardigliano
c1ef1bb9f4 Remove host_pool pool 2022-02-23 12:40:20 +01:00
Alfredo Cardigliano
c3a5950c6f Enable support for pool-based filtering in recipients 2022-02-23 12:29:58 +01:00
MatteoBiscosi
f8db1fecf9 Fixes l7proto filtering not working 2022-02-23 11:52:22 +01:00
Alfredo Cardigliano
dcd23241c7 Pools configuration in Recipients (WIP) 2022-02-22 18:33:09 +01:00
Alfredo Cardigliano
6c9dd9f7df Support 'contains' op in alerts 2022-02-22 16:32:20 +01:00
Alfredo Cardigliano
9bd30a049a Do not print nil for empty values 2022-02-22 15:55:50 +01:00
Alfredo Cardigliano
90b7c5fd91 Do not print nil for empty values 2022-02-22 15:25:42 +01:00
Luca Deri
f6db6ff910 Implements (#6338) Efficient Alert Download with ClickHouse 2022-02-22 12:02:27 +01:00
MatteoBiscosi
25f78c075a Added Active Monitoring and SNMP categories (#6334) 2022-02-21 12:59:45 +01:00
Luca Deri
c430f9d6e6 Updated scan detection code (work in progress) 2022-02-21 10:39:29 +01:00
Luca Deri
269e9da142 (C) Update 2022-02-20 23:17:50 +01:00
Luca Deri
1fe96bc73b Initial work for implementing host/port scan detection (#6327) (#6328) 2022-02-20 23:17:04 +01:00
Alfredo Cardigliano
c8f879ee0c Add offline check setting up lists 2022-02-18 15:53:28 +01:00
Alfredo Cardigliano
58c14ce216 Remove exceptions for hsot/flow recipients 2022-02-18 12:28:53 +01:00
Alfredo Cardigliano
61ca86bc7c Cleanup _set_cache_flag 2022-02-18 12:01:52 +01:00
MatteoBiscosi
5a13a0725b Removed double include 2022-02-18 11:45:46 +01:00
Alfredo Cardigliano
29c0ba4594 Removed recipient selection from pools. Only severity and category are used as filters now. New filtering based on pool to be done. 2022-02-18 11:45:16 +01:00
Luca Deri
c724f0fbb2 Implemented spider/bot detection risk
Fixes for double flag visualization
2022-02-17 21:06:44 +01:00
Alfredo Cardigliano
8c4c6c58d2 Add placeholder for pcap download modal 2022-02-17 15:15:15 +01:00
Alfredo Cardigliano
d527b88347 Improve alert sql generation for l7 proto 2022-02-17 12:38:53 +01:00
Alfredo Cardigliano
be72968ab8 Fix rowid generation for alerts on clickhouse 2022-02-17 12:14:52 +01:00
Luca Deri
2628b2b239 Added GreyNoise link in host page 2022-02-16 18:08:33 +01:00
Luca Deri
0813470eb7 Fixed application label 2022-02-16 17:04:10 +01:00
Alfredo Cardigliano
ea970aea74 Improve tags to BPF generation 2022-02-16 10:43:43 +01:00
Alfredo Cardigliano
e0a94a30ff Remove warning 2022-02-16 10:16:58 +01:00
MatteoBiscosi
41d85577a8 Fixes blog post not working 2022-02-15 17:05:32 +01:00
Luca Deri
4d0db5c44e Fixed DB creation state
Removed test file
2022-02-15 11:15:34 +01:00
Alfredo Cardigliano
1dff8975d3 Move tag filters info 2022-02-15 11:05:21 +01:00
Matteo Biscosi
a3d791add9 Fixes flows not showing blacklisted symbol 2022-02-15 09:51:13 +01:00
Luca Deri
172bd5445d Removed double flag 2022-02-14 22:36:29 +01:00
Luca Deri
9e2414e70f Hidden DSCP when both are zero 2022-02-14 22:36:29 +01:00
Alfredo Cardigliano
c1c9f91d87 Implemented rest/v2/get/alert/filter/consts.lua 2022-02-14 19:05:24 +01:00
Alfredo Cardigliano
3aeed99115 Improve flow alert to historical flow lookup 2022-02-14 17:27:13 +01:00
Alfredo Cardigliano
acdf0aa7be Add missing require 2022-02-14 15:07:03 +01:00
Alfredo Cardigliano
f38f090957 Add lua/rest/v2/get/alert/filter/consts.lua endpoint 2022-02-14 12:55:41 +01:00
Alfredo Cardigliano
e0d41a0167 Move definition of alert tags and cleanup declarations 2022-02-14 12:55:20 +01:00