Commit graph

5477 commits

Author SHA1 Message Date
MatteoBiscosi
8b60f05b14 Added vlans to flow details (#6663 and #6662) 2022-06-06 10:20:37 +02:00
MatteoBiscosi
07f3985a8a Added score to alert message 2022-06-01 11:31:02 +02:00
MatteoBiscosi
0006f0683f Updated ndpi flow risk info description 2022-06-01 11:10:19 +02:00
MatteoBiscosi
5e43b73059 Added check for flow risk info not nil 2022-06-01 10:49:10 +02:00
MatteoBiscosi
3509b3b74b Added dns fragmented alert 2022-05-31 18:34:22 +02:00
MatteoBiscosi
ad3ada6826 Added flow risk info to alert description 2022-05-31 17:16:12 +02:00
MatteoBiscosi
167cf6484a Updated ndpi flow risk alerts 2022-05-31 17:15:21 +02:00
MatteoBiscosi
91c9b5d04d Moved host mac reassociation alert 2022-05-31 11:31:42 +02:00
Alfredo Cardigliano
4fe46f0e6d Support match on 'all' alert for alert exclusion 2022-05-31 11:31:30 +02:00
Luca Deri
8e5cc88c8d Warning fix for #6578 2022-05-30 23:04:18 +02:00
Alfredo Cardigliano
a73d596503 Fix lookup for 'all' alert type exlusion 2022-05-30 19:04:16 +02:00
MatteoBiscosi
e4f5fae4e7 Removed empty protocol info 2022-05-30 18:05:55 +02:00
MatteoBiscosi
3867b03978 Added protocol information dumped even with no alerts (#6649) 2022-05-30 17:54:16 +02:00
MatteoBiscosi
44dc90f30c Generalized clickhouse json search 2022-05-30 16:50:05 +02:00
MatteoBiscosi
0b2589f616 Added error code filter to historical flow (#6610) 2022-05-30 15:22:45 +02:00
MatteoBiscosi
5f686624ab Added Error code filter to alerts (#6610) 2022-05-30 15:22:45 +02:00
Alfredo Cardigliano
f6cb982355 Fix alert_store housekeeping 2022-05-30 11:43:18 +02:00
Alfredo Cardigliano
21530068a9 Add get_table_name / get_write_table_name to alert store 2022-05-30 11:25:32 +02:00
Alfredo Cardigliano
502f4cd106 Delete alerts matching domain when adding exception 2022-05-27 16:50:25 +02:00
MatteoBiscosi
e2ad021161 Fixes external link (#6626) 2022-05-27 16:23:26 +02:00
Alfredo Cardigliano
32a520636b List exclusions for domains/certificates 2022-05-27 16:11:59 +02:00
Alfredo Cardigliano
83b3ae8bbc Add/remove domain/certificate exceptions 2022-05-27 15:32:50 +02:00
MatteoBiscosi
ee96f77bac Partially fixes external link prot in ntopng (#6626) 2022-05-27 13:04:59 +02:00
Alfredo Cardigliano
f7cf547a65 Rework alert_exclusions API 2022-05-27 12:55:30 +02:00
MatteoBiscosi
e9147aa37d Implemented connection failed alert (#6622) 2022-05-27 10:45:25 +02:00
Alfredo Cardigliano
957e0d777c Code cleanuip 2022-05-27 10:09:28 +02:00
Alfredo Cardigliano
ee7ef67ef7 Update preset 2022-05-27 09:19:25 +02:00
Luca Deri
6fb503ea75 Added sanity check for invalid recipient/endpoint configuration 2022-05-26 19:18:25 +02:00
Alfredo Cardigliano
7c2be78a36 Add alert_domain / alert_certificate 2022-05-26 17:57:53 +02:00
Alfredo Cardigliano
94b842284d Add safety check in flow_alert_store:insert with clickhouse 2022-05-26 16:34:13 +02:00
Luca Deri
f26ef05acb Fix for https://github.com/ntop/ntopng/issues/6578 (parameter 22) 2022-05-26 11:34:38 +02:00
Alfredo Cardigliano
48aee7d88f Fix string concatenation 2022-05-26 09:16:03 +02:00
MatteoBiscosi
7b99fc17b8 Added country to alert detail view 2022-05-25 13:22:39 +02:00
MatteoBiscosi
6921aa9dce Fixes external link url proto not correctly used (#6626) 2022-05-25 12:52:56 +02:00
MatteoBiscosi
0ac8da733f Fixed server name not used for server ips (#6623) 2022-05-25 11:29:08 +02:00
Alfredo Cardigliano
5b0e59b50c Fix hostname match in engaged alerts 2022-05-24 15:34:53 +02:00
MatteoBiscosi
72f814c36c Added vlan support to exclusion lists (#6510) 2022-05-24 12:22:24 +02:00
Luca Deri
bb84f56a5e Warning fix (#6578) 2022-05-24 08:49:21 +02:00
MatteoBiscosi
506426c3b8 Added vlan utility function 2022-05-23 18:24:02 +02:00
MatteoBiscosi
ffa48647ef Added ThreatFox malware list (#6341) 2022-05-20 17:54:21 +02:00
MatteoBiscosi
344946be8f Fixes non working info field filtering (#6564) 2022-05-20 16:25:02 +02:00
MatteoBiscosi
84dd3e4526 Unified aler and flow details page 2022-05-20 13:30:17 +02:00
MatteoBiscosi
08c9de2b7b Removed debug print 2022-05-20 11:36:31 +02:00
MatteoBiscosi
14e85b9888 Unified alert and flow details page style (#6565) 2022-05-20 11:30:44 +02:00
MatteoBiscosi
084b86c632 Fixes false positive in mirrored traffic 2022-05-20 11:30:44 +02:00
Alfredo Cardigliano
0aa9c899df Fix debug trace 2022-05-18 10:42:25 +02:00
MatteoBiscosi
65284b6929 Fixes Score Network alert (#6366) 2022-05-17 11:26:00 +02:00
MatteoBiscosi
c1e6f01d53 Fixes suspicious DGA domain nil value 2022-05-17 11:26:00 +02:00
MatteoBiscosi
7b51a4ca61 Added Fin Scan check (#5903) 2022-05-16 17:18:11 +02:00
MatteoBiscosi
7f81cc45a1 Added mirrore traffic toast (#6600) 2022-05-16 12:33:22 +02:00