Simone Mainardi
c4ad235bf8
Fixes empty callbacks lists with alerts disabled
...
Fixes #3037
2019-11-04 18:38:20 +01:00
emanuele-f
675adcf90e
Migrate hosts disabled flow status preference to lua
...
By loading all the preferences at once in flow.lua setup() the
redis load is reduced and design is simpler.
2019-11-04 16:50:26 +01:00
emanuele-f
33949d31fd
Rework benchmark stats and charts
2019-10-31 17:48:53 +01:00
Alfredo Cardigliano
d10dfc7762
Deferred flow alerts insertion through a redis queue. Removed alerts DB select when printing flow details.
2019-10-31 12:53:23 +01:00
emanuele-f
e978a83151
Improve user scripts charts
...
Fixes #3020
2019-10-31 13:30:24 +01:00
emanuele-f
e238605f86
Fix latest run label
2019-10-25 17:51:29 +02:00
Alfredo Cardigliano
c7120e23f3
Hide periodic user scripts in pcap dump mode (unless --original-speed is specified)
2019-10-25 16:45:23 +02:00
emanuele-f
58a12f1241
Add user scripts benchmark charts
...
Implements #2999
2019-10-24 20:24:13 +02:00
emanuele-f
10aa5542f8
Rework alertEntity functions to avoid modules circular dependencies
...
Fixes #2975
2019-10-23 13:01:57 +02:00
Simone Mainardi
fca66af5e5
Adds speed and num calls to script duration information
2019-10-22 19:05:57 +02:00
emanuele-f
bb4f073b1a
Avoid triggering remote-to-remote alerts when disabled
2019-10-22 18:46:03 +02:00
emanuele-f
cbddac0562
Fix outside DHCP range alert
2019-10-22 17:16:45 +02:00
Alfredo Cardigliano
b816bfc2d6
Fix purge past alerts button
2019-10-22 16:56:06 +02:00
emanuele-f
ab0875155e
Remove AlertType typedef from C
2019-10-22 14:43:21 +02:00
emanuele-f
b3374651ce
Merge branch 'alerts_cleanup' into dev
2019-10-22 10:50:21 +02:00
emanuele-f
b3a8c6d49a
Migrate C flow status alerts to Lua user scripts
...
- Alerts and flow status cleanup
- Community flow user scripts migration
- Implement scripts filters by l7 proto and packet interface only
- Migrate flow2statusinfojson
- Lower flow periodic update to 30 seconds if there is flow activity
- Display flow scripts without a gui section
2019-10-22 10:42:22 +02:00
Simone Mainardi
1ec35c3042
Fixes and cleanup of disabled alerts
2019-10-22 10:33:42 +02:00
Simone Mainardi
43d0b89bd9
Prevens tons of unnecessary calls to alerts_api.trigger()
2019-10-17 18:54:13 +02:00
Simone Mainardi
f8443ff03d
Disk space reclaim and defrag of alerts db
2019-10-17 12:12:28 +02:00
Simone Mainardi
6fd7386c03
Fixes possible collisions when looking up flows by key
2019-10-16 19:04:10 +02:00
emanuele-f
873b96c20a
Split alert types definitions in multiple files
2019-10-16 12:04:07 +02:00
emanuele-f
7a14a9cf11
Improvements in status definition API
2019-10-16 10:33:19 +02:00
emanuele-f
9ea7ff01b8
Improve flow alert trigger logic and fix support for custom message
2019-10-15 18:36:41 +02:00
emanuele-f
b217909966
Split flow status definitions in multiple files
2019-10-15 17:28:45 +02:00
Simone Mainardi
b258f45858
Fixes deletion of old alerts when above a certain threshold
2019-10-14 18:03:16 +02:00
emanuele-f
7bd6feb622
Rename check_module -> user_script
2019-10-10 18:14:53 +02:00
Simone Mainardi
4ef7d35296
Benchmarks for hosts interface and network scripts
2019-10-10 11:54:31 +02:00
emanuele-f
ab0094c1c3
Unify syslog with user scripts API
2019-10-09 18:53:19 +02:00
emanuele-f
ffd3b4c1ee
Users scripts api changes and initial documentation
2019-10-09 15:12:28 +02:00
emanuele-f
ede9a7940a
Generalize periodic and flows callbacks
...
Now periodic callbacks are properly called even when alerts are disabled
The granularity filter and check_function has been replaced with a more generic hooks list
2019-10-07 19:05:43 +02:00
Simone Mainardi
aceb123ebb
Adds About/directories page listing custom scripts directories
2019-10-07 11:34:39 +02:00
emanuele-f
bee1efdded
Move callbacks scripts into separate tab
2019-10-04 10:48:13 +02:00
Simone Mainardi
d5df15d123
Fixes flow alerts missing from external alert endpoints
2019-10-03 16:37:59 +02:00
emanuele-f
1bf89fdb4d
Add server malicious JA3 signature check and improve alert information
...
Closes #2880
2019-09-24 13:30:32 +02:00
Simone Mainardi
3ea092093f
Adds generic probes tab to the alerts pages
2019-09-23 18:50:43 +02:00
emanuele-f
66827f9baa
Remove duplicate table in disabled-alerts
2019-09-23 13:05:51 +02:00
emanuele-f
6233606057
Fix disabled alerts bad interface selection
2019-09-23 12:33:01 +02:00
emanuele-f
f735749716
Add flow alert information into the flow defails
2019-09-18 15:10:41 +02:00
Simone Mainardi
b3d595653e
Initial implementation of lua flow callback scripts and blacklisted alerts
...
Partially implements #2842
2019-09-16 18:27:46 +02:00
Simone Mainardi
cc75605d0d
Adds hyperlink to engaged alerts historical timeseries
...
Implements #2850
2019-09-13 15:38:41 +02:00
Simone Mainardi
9fe404772d
Handles flow alerts and alert queues in view interfaces
...
Implements #2828
2019-09-10 15:48:39 +02:00
emanuele-f
b2a0956e0d
Fix host disabled flow status settings page error
2019-09-10 15:10:27 +02:00
emanuele-f
06f3077da8
Avoid excessive redis lookups for hosts when hosts cache is disabled
2019-09-09 12:42:35 +02:00
Alfredo Cardigliano
141622f151
Lua: created flow_consts module, getFlowStatusTypes has been replaced by flow_consts.flow_status_types, added flow.status_map to the Lua flow info
2019-09-04 22:20:51 +02:00
emanuele-f
d630cce58a
Fix script failures in SNMP message formatters
2019-09-04 15:36:46 +02:00
emanuele-f
b62e4183f0
Add ability to manually release an alert
2019-09-04 12:29:13 +02:00
emanuele-f
08e616a5d4
Fix "Could not retrieve alert information" on pcap dump interfaces
2019-09-03 18:59:19 +02:00
emanuele-f
3bf6ed1ecd
Add syn-vs-rst and misbehaving-vs-total-flows alerts
2019-08-27 16:33:53 +02:00
Simone Mainardi
606e681d8e
Fixes flow alerts exploration
...
Fixes #2782
2019-08-27 15:42:35 +02:00
emanuele-f
01c586119e
Remove ICMP ratio alert and enable ratio alerts by default in 5mins
2019-08-27 14:32:24 +02:00