Matteo Biscosi
|
29f989ba30
|
Moved bytes sent/rcvd to KB with radius accounting
|
2024-08-13 15:33:06 +02:00 |
|
Alfredo Cardigliano
|
bc26f3f5eb
|
Exclude no (empty or zero) mitre from results
|
2024-08-12 15:19:31 +02:00 |
|
Luca Deri
|
7928a423bf
|
Fixed invalid formatting
|
2024-08-09 21:27:18 +02:00 |
|
Luca Deri
|
b6e167c2fc
|
Cleaup
|
2024-08-09 12:50:19 +02:00 |
|
Luca Deri
|
d7873670dd
|
Unified formatting of historical and live flows
|
2024-08-09 12:01:56 +02:00 |
|
Luca Deri
|
dbfa98bab9
|
Fixed invalid historical flow formatting
|
2024-08-09 12:00:52 +02:00 |
|
Alfredo Cardigliano
|
c6ec914ebd
|
Add safety checks
|
2024-08-09 11:49:38 +02:00 |
|
Alfredo Cardigliano
|
3c654f7a3e
|
Enable host ja4 fingerprint in place of ja3
|
2024-08-09 10:36:01 +02:00 |
|
Matteo Biscosi
|
7c90337921
|
Added traces in case of empty schema (#8609)
|
2024-08-09 09:37:48 +02:00 |
|
Alfredo Cardigliano
|
b882c225f7
|
Fix supported filter types
|
2024-08-09 09:11:25 +02:00 |
|
Alfredo Cardigliano
|
548c9aeec5
|
Remove obsolete JA3 support
|
2024-08-09 09:08:32 +02:00 |
|
Matteo Biscosi
|
4b1b37103a
|
Changed alert msg and added support to zmq only interface alerts
|
2024-08-08 17:25:35 +02:00 |
|
Matteo Biscosi
|
46fff4d8e3
|
Updated checks documentation (#8463)
|
2024-08-08 17:25:35 +02:00 |
|
Alfredo Cardigliano
|
5398e9d888
|
Add mitre info to historical flow and flow alert
|
2024-08-08 12:45:57 +02:00 |
|
Luca Deri
|
1477437b7c
|
Improvements for no exporter/probe activity
|
2024-08-07 18:06:51 +02:00 |
|
Luca Deri
|
16b5a8ccc1
|
Implemented no exporter/probe activity (#8608)
|
2024-08-07 18:06:51 +02:00 |
|
Alfredo Cardigliano
|
a4d28d59f2
|
Fix #8589
|
2024-08-07 16:03:53 +02:00 |
|
Alfredo Cardigliano
|
b09688beee
|
Add new alert no_exporter_activity
|
2024-08-07 13:05:48 +02:00 |
|
Alfredo Cardigliano
|
939df53237
|
Add Top Mitre in flow and host alerts. Optimize alert Tops computation. Add Security report.
|
2024-08-07 11:17:06 +02:00 |
|
Luca Deri
|
05ce90a5dd
|
Cleanup
|
2024-08-06 17:53:17 +02:00 |
|
Alfredo Cardigliano
|
0b16d384b6
|
Fix mitre info in flow alerts custom queries
|
2024-08-06 17:45:17 +02:00 |
|
Alfredo Cardigliano
|
7e284e971b
|
Fix mitre rendering in host alerts custom queries
|
2024-08-06 17:42:56 +02:00 |
|
Alfredo Cardigliano
|
287c3e1806
|
Handle mitre filters in queries
|
2024-08-06 16:58:52 +02:00 |
|
Alfredo Cardigliano
|
6d7e24e06a
|
Add list of filters for mitre ids and categories
|
2024-08-06 16:44:50 +02:00 |
|
Alfredo Cardigliano
|
abee29d8d7
|
Add mitre tables by id. Fix host alerts format in case of aggragations
|
2024-08-06 16:20:09 +02:00 |
|
DGabri
|
75d5afbb58
|
Reverted back to old formatting function
|
2024-08-06 15:37:47 +02:00 |
|
Alfredo Cardigliano
|
d141cc86e8
|
Read i18n for mitre even with no alert id (in case of aggregations)
|
2024-08-06 15:25:36 +02:00 |
|
Alfredo Cardigliano
|
c951b410b5
|
Cleanup code
|
2024-08-06 15:18:56 +02:00 |
|
DGabri
|
fb9d305fde
|
Added mitre info in flow alerts page
|
2024-08-06 12:46:44 +02:00 |
|
DGabri
|
db8b08d69b
|
Fixed double entry in table
|
2024-08-06 12:40:17 +02:00 |
|
DGabri
|
53027bde72
|
Added mitre info in host alert table. To implement filters
|
2024-08-06 12:31:01 +02:00 |
|
Alfredo Cardigliano
|
f6ed085c1a
|
Fix i18n for column names
|
2024-08-06 12:10:54 +02:00 |
|
Alfredo Cardigliano
|
a308d6c623
|
Fix host custom queries
|
2024-08-06 11:40:34 +02:00 |
|
Alfredo Cardigliano
|
c4b9fa94d4
|
Move tags titles to db_search.tags
|
2024-08-06 09:54:59 +02:00 |
|
Alfredo Cardigliano
|
d981c8d315
|
Add mitre titles and tags
|
2024-08-06 09:50:32 +02:00 |
|
Luca Deri
|
dddd30c6db
|
Removed tracing
Indent
|
2024-08-05 22:40:42 +02:00 |
|
Alfredo Cardigliano
|
206b86544f
|
Fix corner cases in alert_elephant_flow.format
|
2024-08-05 18:00:22 +02:00 |
|
Luca Deri
|
e522eebf6b
|
Enhanced collector stats
|
2024-08-05 17:37:00 +02:00 |
|
Alfredo Cardigliano
|
895a1f7832
|
Use host_alerts_view for reading host alerts (it includes mitre data)
|
2024-08-05 16:49:38 +02:00 |
|
DGabri
|
1b32535735
|
FIxed port
|
2024-08-05 16:02:16 +02:00 |
|
DGabri
|
31349dac7c
|
Disabled assets inventory pref. #8591
|
2024-08-05 10:27:24 +02:00 |
|
DGabri
|
9495b20509
|
Fixed: #8519
|
2024-08-05 10:22:20 +02:00 |
|
Alfredo Cardigliano
|
ef48b5f964
|
Fix: Use post scripts in case of alerts on flow-end
|
2024-08-02 16:32:24 +02:00 |
|
Matteo Biscosi
|
63ebb9071a
|
Removed same info stored
|
2024-08-02 12:10:23 +02:00 |
|
Matteo Biscosi
|
ffa80bb51a
|
Added blacklist info to alert_json
|
2024-08-02 12:10:06 +02:00 |
|
Matteo Biscosi
|
87457ac068
|
Fixes host details tooltip
|
2024-08-02 11:34:17 +02:00 |
|
Alfredo Cardigliano
|
fa0bf68576
|
Add missing paths
|
2024-08-01 18:01:56 +02:00 |
|
Alfredo Cardigliano
|
5c55790981
|
Code cleanup
|
2024-08-01 12:06:13 +02:00 |
|
Matteo Biscosi
|
9b2216bb03
|
Disabled snmp_info button in snmp trap alert
|
2024-07-31 18:47:57 +02:00 |
|
Matteo Biscosi
|
a7ab748ae2
|
Removed sflowdev timeseries and unified to flowdev
|
2024-07-31 16:25:25 +02:00 |
|