Commit graph

458 commits

Author SHA1 Message Date
Simone Mainardi
d16ff997ef Removes a debug flag 2020-11-10 15:13:24 +01:00
Simone Mainardi
93920ccdce Implements example of simplified flow alerts 2020-11-10 15:10:54 +01:00
Alfredo Cardigliano
683a4a727b Add LF to the end of syslog message when sending over TCP 2020-11-10 10:08:29 +01:00
Alfredo Cardigliano
841b476f59 Implement export to remote syslog server (implement #4419) 2020-11-09 18:40:24 +01:00
gabryon99
75363aae84 improved ipv4 validation function 2020-11-09 17:05:36 +01:00
Luca Deri
1ae79bfbfb Minor fixes for the shell script endpoint 2020-11-09 16:41:56 +01:00
Matteo Biscosi
cfac78e89e
Fixes #4416 Implement recipient/endpoint shell script (#4688)
* Fixes #4416 implement shell script endpoint

* removed debugging code

* Removed for windows env
2020-11-09 16:35:39 +01:00
Simone Mainardi
d42057baf5 Additional fixes for Zero TCP window detection 2020-11-07 15:38:39 +01:00
Simone Mainardi
a091efcb09 Fixes for Zero TCP window detection user script 2020-11-07 10:58:16 +01:00
Luca Deri
83816cefae Zero window alert improvement 2020-11-07 00:41:02 +01:00
Simone Mainardi
5c0c23feb6 Fixes execution of periodicUpdate flow callback
Fixes #4687
2020-11-06 18:17:54 +01:00
gabryon99
9dfed97e56 fixed add active monitoring with ipv4 and ports combination (#4677) 2020-11-06 17:02:09 +01:00
Simone Mainardi
073fd5f6cd Fixes flow score to low for suspicious file transfer risk 2020-11-06 13:40:36 +00:00
Luca Deri
e5d97d7120 Removed trace 2020-11-06 10:41:29 +01:00
Luca Deri
6d5178c9e5 Fixes bug in TCP zero windows alert report 2020-11-06 10:40:51 +01:00
Luca Deri
ecc3208e10
Removed debug code 2020-11-05 22:09:47 +01:00
Luca
e84f2be741 Added missing initialization 2020-11-05 19:32:39 +01:00
Luca
3455f79e9f Zero window fixes 2020-11-05 18:53:19 +01:00
Matteo Biscosi
e5a48cb5d2
TCP Zero Window alert from issue #3417 (#4684)
* Added no_if_activity alert to user script keys

* Added no_if_activity description alert

* Fixes #4648 trigger an alert when no flows are collected

* Changed the time past one call of the alert and an other

* Fixes #4648 reorganized files and cache management

* Added status flow check regarding issue #3417

* Removed debug code

Co-authored-by: matteo <biscosi@ntop.org>
Co-authored-by: Luca Deri <lucaderi@users.noreply.github.com>
2020-11-05 18:20:09 +01:00
Luca
f5f98468b3 Cosmetic fix 2020-11-05 18:12:17 +01:00
Matteo Biscosi
383a6659dc
Fixes #4648 trigger an alert when no flows are collected (#4679)
* Added no_if_activity alert to user script keys

* Added no_if_activity description alert

* Fixes #4648 trigger an alert when no flows are collected

* Changed the time past one call of the alert and an other

* Fixes #4648 reorganized files and cache management

Co-authored-by: matteo <biscosi@ntop.org>
2020-11-05 17:58:38 +01:00
Simone Mainardi
53ee09c4b3 Fixes slack recipient
Fixes #4672
2020-11-04 15:37:43 +01:00
Simone Mainardi
358ec1dfd5 Handles Discord failures due to rate-limiting 2020-11-03 18:34:34 +01:00
Simone Mainardi
2849267af8 Reworks plugin template definition keys
Implements #4651
2020-11-03 18:09:29 +01:00
Simone Mainardi
d9b16e7fc4 Adds slack_recipient.template stub 2020-11-03 17:40:12 +01:00
gabryon99
6e410e0b4b add reload button for active monitoring 2020-11-02 15:30:21 +01:00
Luca Deri
9664b20d64 Cosmetic alarm fixes
Added emoji to Discord
2020-11-02 14:42:16 +01:00
MatteoBiscosi
4a9a9feff1 Changed notification text and Http method #4269 2020-11-02 13:17:21 +01:00
gabryon99
cf16003826 add notification for unexpected plugins (#4659) 2020-11-02 11:42:30 +01:00
Luca Deri
cc2df1d66e Added emoji support in alert messages 2020-10-30 18:52:40 +01:00
Matteo Biscosi
5c6367e7bd
Added Telegram plugin (#4269) 2020-10-30 17:27:32 +01:00
Simone Mainardi
389f9c2beb Reworks TCP issues flow user script 2020-10-30 15:56:36 +01:00
Luca Deri
515704a040 Fixes #4634
Fixes bug introduced by 6d11a43ddd
2020-10-28 19:02:08 +01:00
gabryon99
bf258ab15a rework for ui nofitications (#4630, #4615) 2020-10-26 19:13:50 +01:00
Luca Deri
966b743e78 Retrasmissions are accunted only when 10 pkts per directions are observed
Tiny cosmetic changes
2020-10-25 18:56:00 +01:00
Luca Deri
82fab91a2e
Merge pull request #4604 from Wallace4/retry_project
Retransmissions Plugin updated
2020-10-25 18:18:57 +01:00
Simone Mainardi
2e29a8d246 Implements user script for ip reassociation alerts
Addresses #4614
2020-10-22 16:49:50 +02:00
Simone Mainardi
cbfd2c8025 Implements user script for remote to remote host alerts
Addresses #4614
2020-10-22 16:25:31 +02:00
Simone Mainardi
8ca7daf889 Implements user script for quota exceeded alerts
Addresses #4614
2020-10-22 15:02:47 +02:00
Simone Mainardi
4346b55734 Implements user script for host pool connection/disconnection alerts
Addresses #4614
2020-10-22 14:51:54 +02:00
Simone Mainardi
f65aa2bc19 Implements user script for device connection/disconnection alerts
Addresses #4614
2020-10-22 14:27:26 +02:00
Simone Mainardi
d7f1ce0d8c Reworks and optimizes flow alerted status 2020-10-19 16:50:22 +02:00
Wallace4
ca88369ef3 New version of retransmission plugin, fixed and tested 2020-10-19 16:40:22 +02:00
Alfredo Cardigliano
a5a8030e35 Cleanup trigger flow external alert 2020-10-19 13:12:31 +02:00
Simone Mainardi
00f1ae731a Keeps configured enabled/disabled flow risks into account inside plugin 2020-10-19 11:56:41 +02:00
Simone Mainardi
27c1318ab6 Fixes risk not shown in generated flow-risk alerts
Fixes #4594
2020-10-19 11:10:19 +02:00
Luca Deri
a5076c0d27 Implemented multiselect to be used in #4589 2020-10-16 22:29:12 +02:00
Simone Mainardi
d3dda0bb82 Unifies misbehaving with alerted flows
Implements #4596
2020-10-16 18:58:20 +02:00
Simone Mainardi
92ed28cf4c Prevents unidirectional traffic alerts from NoIP from being triggered
Fixes #4592 along with companion pro commit
2020-10-16 12:20:15 +02:00
Luca Deri
374b97c516 Unexpected protocol plugins default to disable 2020-10-15 21:44:24 +02:00