Commit graph

4062 commits

Author SHA1 Message Date
Simone Mainardi
68246efd01 Decouples periodic hash table updates using a thread pool 2019-10-27 17:40:07 +01:00
Alfredo Cardigliano
6b60324544 Fix empty first/last seen with l7 metadata from Suricata 2019-10-27 15:42:43 +01:00
emanuele-f
930fdc9bd1 Fix flows script table 2019-10-25 18:41:37 +02:00
emanuele-f
e238605f86 Fix latest run label 2019-10-25 17:51:29 +02:00
Alfredo Cardigliano
c7120e23f3 Hide periodic user scripts in pcap dump mode (unless --original-speed is specified) 2019-10-25 16:45:23 +02:00
emanuele-f
8a2d3dafff Fix interface paused icon 2019-10-25 16:44:20 +02:00
Alfredo Cardigliano
1332ca1b0d Increased syn scan default limit 2019-10-25 15:13:24 +02:00
Alfredo Cardigliano
0d0394e862 Internals labels 2019-10-25 14:40:25 +02:00
Alfredo Cardigliano
96ef3c05e7 New alert when the number of idle entries in the hash tabel exceeds a configured threshold (implements #3005) 2019-10-25 14:29:37 +02:00
Simone Mainardi
f942ec3a1c Fixes wrong alerts sort column causing queries to fail
Fixes #3006
2019-10-25 14:11:49 +02:00
emanuele-f
1d5ff7c4e7 Remove global flow user scripts on/off 2019-10-25 13:12:47 +02:00
emanuele-f
f8ccfe24d8 Add flow scripts labels and descriptions 2019-10-25 12:16:19 +02:00
Alfredo Cardigliano
b42989154c Drawing active items in addition to idle in the internals chart 2019-10-25 12:14:53 +02:00
Alfredo Cardigliano
592aaf80e2 Displaying Active/Idle in the internals page 2019-10-25 12:02:13 +02:00
emanuele-f
0ea6856b44 Clean flow user scripts page 2019-10-25 11:30:06 +02:00
emanuele-f
58a12f1241 Add user scripts benchmark charts
Implements #2999
2019-10-24 20:24:13 +02:00
Alfredo Cardigliano
c29409673b Added alerts for TCP SYN Scan Host and Network as victims (implements #2963) 2019-10-24 16:59:33 +02:00
emanuele-f
8747af5f2b Reduce max queue length 2019-10-24 17:00:03 +02:00
emanuele-f
3882e2f26d Fix invalid failed exports key 2019-10-24 16:34:06 +02:00
emanuele-f
0d04eb2d5c Stop writing points if InfluxDB export is failing.
The dropped points are accounted and shown in the gui. Dropped points alert are generated as usual.

Fixes #2998
2019-10-24 16:09:01 +02:00
Alfredo Cardigliano
afbb34e262 TCP SYN Scan detection (implements #2963) 2019-10-24 15:35:26 +02:00
Simone Mainardi
955eed4b50 Reworks idling and purging of hash table entries to make it faster 2019-10-24 15:48:18 +02:00
emanuele-f
d1d789ea88 Improve category lists limits and reporting 2019-10-23 18:12:24 +02:00
emanuele-f
bb51396151 Fix bad categories lists limit check 2019-10-23 16:17:08 +02:00
Alfredo Cardigliano
858fa244c4 Hiding Active local host cache settings when Idle local host cache is disabled 2019-10-23 15:27:04 +02:00
emanuele-f
6fbc01b28e Remove redis hash access for user scripts disabled check 2019-10-23 14:41:10 +02:00
Simone Mainardi
60e657c0d2 Makes hash table state counters as gauges 2019-10-23 14:25:12 +02:00
Simone Mainardi
47f8525144 Adds chars and page for hash table states 2019-10-23 14:14:44 +02:00
Simone Mainardi
15e17a801a Implements per-state hash entry counters and writes them to ts 2019-10-23 13:09:02 +02:00
emanuele-f
10aa5542f8 Rework alertEntity functions to avoid modules circular dependencies
Fixes #2975
2019-10-23 13:01:57 +02:00
emanuele-f
19f820f1bc Add max rules limit for category lists
Fixes #2966
2019-10-23 11:53:21 +02:00
emanuele-f
4b29fa2af1 Only save the edited preferences in category lists
Fixes #2967
2019-10-23 11:37:04 +02:00
emanuele-f
0c96c49157 Avoid redis KEYS command for MUD 2019-10-23 11:24:33 +02:00
emanuele-f
373118f4cc Fix missing systemd interface cleanup on startup
This caused the timeseries export directory to fill up as reported in #2985
2019-10-23 10:54:54 +02:00
emanuele-f
76812f42af Add priority column in status overview 2019-10-22 19:52:05 +02:00
Simone Mainardi
fca66af5e5 Adds speed and num calls to script duration information 2019-10-22 19:05:57 +02:00
emanuele-f
bb4f073b1a Avoid triggering remote-to-remote alerts when disabled 2019-10-22 18:46:03 +02:00
emanuele-f
f136a19123 Fix flows script expert view 2019-10-22 17:52:53 +02:00
emanuele-f
f264311e73 Also show the disabled scripts in the overview page 2019-10-22 17:48:38 +02:00
Alfredo Cardigliano
3f7d8726aa Fix flow key in external alerta 2019-10-22 17:38:59 +02:00
emanuele-f
cbddac0562 Fix outside DHCP range alert 2019-10-22 17:16:45 +02:00
emanuele-f
201891562c Fix label 2019-10-22 17:10:35 +02:00
Alfredo Cardigliano
b816bfc2d6 Fix purge past alerts button 2019-10-22 16:56:06 +02:00
emanuele-f
6845b60744 Fix missing client ssl certificate and improve old ssl protocol info 2019-10-22 16:25:51 +02:00
Alfredo Cardigliano
8aa9f42123 external alert status_defs cleanup 2019-10-22 15:40:11 +02:00
emanuele-f
ac8d6f1110 Fix host MUD user script 2019-10-22 15:35:19 +02:00
Alfredo Cardigliano
d05777df1e External alerts API update and cleanup 2019-10-22 15:08:06 +02:00
Simone Mainardi
74c896ae73 Fixes validation error
Fixes #2964
2019-10-22 14:56:22 +02:00
emanuele-f
ab0875155e Remove AlertType typedef from C 2019-10-22 14:43:21 +02:00
Simone Mainardi
79157cc65d Fixes unnecessary checks when showing pie charts 2019-10-22 13:04:37 +02:00