emanuele-f
|
35e3a2f20c
|
Do not compute DNS ratio in nEdge
nEdge does not see the DNS replies so DNS ratio is incorrect
|
2019-09-30 11:28:15 +02:00 |
|
Simone Mainardi
|
79b69c2e6f
|
Flattens out the structure of lua flow callbacks
|
2019-09-17 18:22:55 +02:00 |
|
Simone Mainardi
|
661f897898
|
Implements instrumentation to monitor lua flow callbacks
|
2019-09-17 17:42:54 +02:00 |
|
Simone Mainardi
|
909408168b
|
Improves flow check lua scripts loading efficiency
|
2019-09-17 14:24:29 +02:00 |
|
Simone Mainardi
|
e2c9e729a4
|
Implements flow check modules enable/disable prefs
|
2019-09-17 11:57:29 +02:00 |
|
Simone Mainardi
|
b3d595653e
|
Initial implementation of lua flow callback scripts and blacklisted alerts
Partially implements #2842
|
2019-09-16 18:27:46 +02:00 |
|
Simone Mainardi
|
83f5e68239
|
Reworks flow.lua callback code
|
2019-09-12 16:15:04 +02:00 |
|
Simone Mainardi
|
288d3a51ec
|
Optimizes flow lua by avoiding unnecessary calls
|
2019-09-12 16:02:13 +02:00 |
|
Simone Mainardi
|
968e21d984
|
Implements flow lua callbacks in the periodic activities thread
|
2019-09-12 15:36:41 +02:00 |
|
emanuele-f
|
e4f1d1f5d3
|
Avoid flow.lua overhead if all the modules are disabled
|
2019-09-11 14:52:26 +02:00 |
|
emanuele-f
|
5a57be4879
|
Fix invalid granularity filter
|
2019-09-06 10:29:10 +02:00 |
|
emanuele-f
|
d9a44d615a
|
Implement generic flow callbacks
|
2019-09-05 19:11:11 +02:00 |
|
emanuele-f
|
a8cb972e7d
|
Implement ghost networks alerts
|
2019-08-28 16:42:18 +02:00 |
|
emanuele-f
|
3bf6ed1ecd
|
Add syn-vs-rst and misbehaving-vs-total-flows alerts
|
2019-08-27 16:33:53 +02:00 |
|
emanuele-f
|
01c586119e
|
Remove ICMP ratio alert and enable ratio alerts by default in 5mins
|
2019-08-27 14:32:24 +02:00 |
|
emanuele-f
|
b3bdfcff32
|
Cleanup of the too-many-drops interface alert
|
2019-08-27 13:04:53 +02:00 |
|
emanuele-f
|
eb3542d7e7
|
Address too much ratio alerts generated after host deserialization
|
2019-08-27 11:02:28 +02:00 |
|
emanuele-f
|
57e623da04
|
Implement ICMP and HTTP requests vs replies ratio alert
|
2019-08-27 10:33:08 +02:00 |
|
emanuele-f
|
5dd88985f4
|
Improve and fix DNS replies/requests ratio
|
2019-08-27 09:57:59 +02:00 |
|
emanuele-f
|
d1caa6fbf1
|
Temporary disable request_reply_ratio to prevent too much alerts generation
|
2019-08-26 18:52:41 +02:00 |
|
emanuele-f
|
a0761db1e8
|
Implement replies/requests ratio alert
|
2019-08-26 18:38:34 +02:00 |
|
emanuele-f
|
b0ba13f0bc
|
Syn/flow flood alerts now use their own alert type
|
2019-08-26 17:36:27 +02:00 |
|
emanuele-f
|
e92641920d
|
Implement syn/flow flood victim alerts on local networks
|
2019-08-26 16:42:23 +02:00 |
|
emanuele-f
|
abdc3d54a3
|
Handle alert config default values
Closes #2747
|
2019-08-23 19:23:05 +02:00 |
|
emanuele-f
|
d1c5275302
|
Move suppressed alerts flag to C to reduce Redis load
|
2019-08-20 11:54:25 +02:00 |
|
emanuele-f
|
c183a577be
|
Alerts API cleanup and JSON migration
|
2019-07-29 15:17:22 +02:00 |
|
emanuele-f
|
988e3eaab6
|
Move alerts configuration under the triangle icon
|
2019-07-26 10:59:38 +02:00 |
|
emanuele-f
|
4fc1fea405
|
Fix remote hosts global alerts config
|
2019-07-25 14:45:23 +02:00 |
|
emanuele-f
|
c9bf1e78cc
|
Implement alerts release on shutdown
|
2019-07-19 13:58:10 +02:00 |
|
emanuele-f
|
749a64e789
|
Release alerts on idle hosts
|
2019-07-19 10:54:05 +02:00 |
|
Simone Mainardi
|
824027da2a
|
Implements lua calls of idle hosts with triggered alerts
|
2019-07-18 18:15:23 +02:00 |
|
Simone Mainardi
|
0fd3be6b79
|
Implements hosts purge mark algorithm
|
2019-07-18 15:19:36 +02:00 |
|
Simone Mainardi
|
be85b2ebc8
|
Implements algorithm to purge hosts only after checking their alerts
|
2019-07-18 13:34:45 +02:00 |
|
emanuele-f
|
c5e597ea75
|
Fix alert config on local hosts
|
2019-07-17 19:05:01 +02:00 |
|
emanuele-f
|
6ea7055761
|
Fix engaged alerts on remote hosts
|
2019-07-17 18:46:19 +02:00 |
|
emanuele-f
|
2e537a0c94
|
Alert changes after review
|
2019-07-17 12:51:47 +02:00 |
|
emanuele-f
|
c117f20e19
|
Initial rework for in-memory alerts
|
2019-07-16 19:25:09 +02:00 |
|
emanuele-f
|
0071a3522b
|
Fix missing detected host alerts
|
2019-07-16 11:43:58 +02:00 |
|
Simone Mainardi
|
cc97be85ca
|
Fixes host alerts key generation
|
2019-07-15 22:54:09 +02:00 |
|
emanuele-f
|
746509316d
|
Fix entity global alert config read
|
2019-07-15 14:29:17 +02:00 |
|
emanuele-f
|
5e40e47cce
|
Implement expired alerts release
This is necessary to handle the case where a previously configured alert config is deleted
|
2019-07-15 13:09:18 +02:00 |
|
Simone Mainardi
|
86e2b7108b
|
Enforces minimum when configuring flood alerts
|
2019-07-15 12:56:31 +02:00 |
|
Simone Mainardi
|
e890786d91
|
Allows alert modules to be run only at given periodicities
|
2019-07-15 12:26:50 +02:00 |
|
Simone Mainardi
|
26f2e264c4
|
Allows alerts to be configured only at given periodicity (gui)
|
2019-07-15 12:14:17 +02:00 |
|
Simone Mainardi
|
fb891bbf2f
|
Finishes implementation of new flood checks in lua
|
2019-07-12 19:14:30 +02:00 |
|
emanuele-f
|
8a8157a015
|
Handle possibly nil tables
|
2019-07-12 12:53:09 +02:00 |
|
emanuele-f
|
5e0b8b496e
|
Remove autorelease logic based on periodicity and update database schema
|
2019-07-12 12:46:21 +02:00 |
|
emanuele-f
|
e26a7949ac
|
Rework network threshold alerts definition
|
2019-07-11 19:35:34 +02:00 |
|
emanuele-f
|
f6ff3ad010
|
Rework interface threshold alerts definition
|
2019-07-11 19:11:33 +02:00 |
|
emanuele-f
|
b16136f5b4
|
Rework host threshold alerts definition
|
2019-07-11 19:11:33 +02:00 |
|