Commit graph

5513 commits

Author SHA1 Message Date
Alfredo Cardigliano
72dca21d3d Fix getExtraFlowInfoURL 2022-06-15 17:38:50 +02:00
MatteoBiscosi
98f39db18b Added traffic direction filter to alerts (#6666) 2022-06-14 16:21:40 +02:00
Alfredo Cardigliano
d1bdb99aaf Rename process chart id 2022-06-14 15:30:47 +02:00
Alfredo Cardigliano
e2916e79a2 Add issuerdn to info 2022-06-14 15:06:39 +02:00
Alfredo Cardigliano
0ea7052640 Add flow alert info URL value 2022-06-14 14:56:20 +02:00
Alfredo Cardigliano
7068b089d4 Remove html from alert name 2022-06-14 12:36:50 +02:00
Alfredo Cardigliano
27abbe4448 Use github.com for connectivity check. Add pref to configure the url. 2022-06-14 11:18:54 +02:00
MatteoBiscosi
f341dff696 Removed duplicated require 2022-06-13 19:25:43 +02:00
Alfredo Cardigliano
d27344fd6e Add support for deleting all alert exclusions by type 2022-06-13 15:26:07 +02:00
Luca Deri
9c5ed484c7 Additional checks 2022-06-10 18:09:40 +02:00
Alfredo Cardigliano
df2829d409 Improve iec_invalid_transition format function (#6682) 2022-06-10 16:17:08 +02:00
MatteoBiscosi
a20d2dba58 Changed interface thpt alert 2022-06-10 11:45:31 +02:00
MatteoBiscosi
b7a61835ba Fixes dns large packets alert incorrectly triggered (#6674) 2022-06-10 10:34:03 +02:00
MatteoBiscosi
873a1d2252 Fixes table expected error 2022-06-09 19:05:25 +02:00
MatteoBiscosi
048d97c2d4 Removed shorten string from confidence 2022-06-09 18:24:44 +02:00
MatteoBiscosi
ba20719d4a Fixes suspicious dga domain url not formatted 2022-06-09 18:19:03 +02:00
MatteoBiscosi
9622209308 Minor fixes to alerts 2022-06-09 18:12:04 +02:00
MatteoBiscosi
4895a3f7d3 Unified tstamp formatting (#6676) 2022-06-09 17:37:50 +02:00
Alfredo Cardigliano
80210f92ae Tags cleanup. Lint update. 2022-06-09 17:12:17 +02:00
MatteoBiscosi
12e9863eae Fixes wrong confidence color 2022-06-09 16:25:58 +02:00
Alfredo Cardigliano
8f596d095f Cleanup more debugger 2022-06-09 15:09:25 +02:00
MatteoBiscosi
8214173ecd Various changes to alerts (#6675) 2022-06-09 12:26:25 +02:00
MatteoBiscosi
e8b63b76f2 Possibly fixes issue #6677 2022-06-09 11:52:15 +02:00
Alfredo Cardigliano
8ddf0e6998 Store cli/srv location in alerts 2022-06-09 11:27:41 +02:00
MatteoBiscosi
ad23d309ee Sliced application guessed label 2022-06-09 11:19:57 +02:00
Alfredo Cardigliano
f633292e83 Add cli/srv location to flow alerts 2022-06-09 10:40:33 +02:00
MatteoBiscosi
4d037e911b Possible fix for #6670 2022-06-08 17:59:10 +02:00
MatteoBiscosi
2885659195 Added traffic direction and remove cli and srv location (#6665) 2022-06-08 13:44:23 +02:00
MatteoBiscosi
021086e44f Added dpi and guessed badge to flow list and details 2022-06-08 10:51:19 +02:00
MatteoBiscosi
4b7edebc71 Added confidence filter to alerts 2022-06-07 18:40:02 +02:00
MatteoBiscosi
69b9e6337e Removed debug print 2022-06-07 18:01:15 +02:00
MatteoBiscosi
b40d26f2e8 Changed confidence from string to number 2022-06-07 17:59:42 +02:00
MatteoBiscosi
9bdded81e8 Added confidence filter 2022-06-07 13:33:27 +02:00
Luca Deri
9d364c69b4 Fixed TCP with no answer alert definition 2022-06-07 13:11:35 +02:00
MatteoBiscosi
8b00fd67a9 Added confidence to historical Flows 2022-06-07 13:01:38 +02:00
MatteoBiscosi
68671222bd Added DHCP starvation alert (#6659) 2022-06-06 17:39:12 +02:00
MatteoBiscosi
8b60f05b14 Added vlans to flow details (#6663 and #6662) 2022-06-06 10:20:37 +02:00
MatteoBiscosi
07f3985a8a Added score to alert message 2022-06-01 11:31:02 +02:00
MatteoBiscosi
0006f0683f Updated ndpi flow risk info description 2022-06-01 11:10:19 +02:00
MatteoBiscosi
5e43b73059 Added check for flow risk info not nil 2022-06-01 10:49:10 +02:00
MatteoBiscosi
3509b3b74b Added dns fragmented alert 2022-05-31 18:34:22 +02:00
MatteoBiscosi
ad3ada6826 Added flow risk info to alert description 2022-05-31 17:16:12 +02:00
MatteoBiscosi
167cf6484a Updated ndpi flow risk alerts 2022-05-31 17:15:21 +02:00
MatteoBiscosi
91c9b5d04d Moved host mac reassociation alert 2022-05-31 11:31:42 +02:00
Alfredo Cardigliano
4fe46f0e6d Support match on 'all' alert for alert exclusion 2022-05-31 11:31:30 +02:00
Luca Deri
8e5cc88c8d Warning fix for #6578 2022-05-30 23:04:18 +02:00
Alfredo Cardigliano
a73d596503 Fix lookup for 'all' alert type exlusion 2022-05-30 19:04:16 +02:00
MatteoBiscosi
e4f5fae4e7 Removed empty protocol info 2022-05-30 18:05:55 +02:00
MatteoBiscosi
3867b03978 Added protocol information dumped even with no alerts (#6649) 2022-05-30 17:54:16 +02:00
MatteoBiscosi
44dc90f30c Generalized clickhouse json search 2022-05-30 16:50:05 +02:00