Commit graph

8209 commits

Author SHA1 Message Date
Luca Deri
8e5cc88c8d Warning fix for #6578 2022-05-30 23:04:18 +02:00
Alfredo Cardigliano
a73d596503 Fix lookup for 'all' alert type exlusion 2022-05-30 19:04:16 +02:00
MatteoBiscosi
e4f5fae4e7 Removed empty protocol info 2022-05-30 18:05:55 +02:00
MatteoBiscosi
3867b03978 Added protocol information dumped even with no alerts (#6649) 2022-05-30 17:54:16 +02:00
MatteoBiscosi
44dc90f30c Generalized clickhouse json search 2022-05-30 16:50:05 +02:00
MatteoBiscosi
0b2589f616 Added error code filter to historical flow (#6610) 2022-05-30 15:22:45 +02:00
MatteoBiscosi
5f686624ab Added Error code filter to alerts (#6610) 2022-05-30 15:22:45 +02:00
Alfredo Cardigliano
f6cb982355 Fix alert_store housekeeping 2022-05-30 11:43:18 +02:00
Alfredo Cardigliano
21530068a9 Add get_table_name / get_write_table_name to alert store 2022-05-30 11:25:32 +02:00
MatteoBiscosi
503f461b4a Fixed url in http flows (#6626) 2022-05-30 10:47:02 +02:00
Alfredo Cardigliano
502f4cd106 Delete alerts matching domain when adding exception 2022-05-27 16:50:25 +02:00
MatteoBiscosi
e2ad021161 Fixes external link (#6626) 2022-05-27 16:23:26 +02:00
Alfredo Cardigliano
32a520636b List exclusions for domains/certificates 2022-05-27 16:11:59 +02:00
Alfredo Cardigliano
83b3ae8bbc Add/remove domain/certificate exceptions 2022-05-27 15:32:50 +02:00
MatteoBiscosi
ee96f77bac Partially fixes external link prot in ntopng (#6626) 2022-05-27 13:04:59 +02:00
Alfredo Cardigliano
f7cf547a65 Rework alert_exclusions API 2022-05-27 12:55:30 +02:00
MatteoBiscosi
e9147aa37d Implemented connection failed alert (#6622) 2022-05-27 10:45:25 +02:00
Alfredo Cardigliano
957e0d777c Code cleanuip 2022-05-27 10:09:28 +02:00
Alfredo Cardigliano
ee7ef67ef7 Update preset 2022-05-27 09:19:25 +02:00
Luca Deri
6fb503ea75 Added sanity check for invalid recipient/endpoint configuration 2022-05-26 19:18:25 +02:00
Alfredo Cardigliano
7c2be78a36 Add alert_domain / alert_certificate 2022-05-26 17:57:53 +02:00
Alfredo Cardigliano
94b842284d Add safety check in flow_alert_store:insert with clickhouse 2022-05-26 16:34:13 +02:00
Alfredo Cardigliano
98ba752369 Move edit/check/filter.lua to add/alert/exclusion.lua 2022-05-26 15:07:34 +02:00
Luca Deri
f26ef05acb Fix for https://github.com/ntop/ntopng/issues/6578 (parameter 22) 2022-05-26 11:34:38 +02:00
Alfredo Cardigliano
48aee7d88f Fix string concatenation 2022-05-26 09:16:03 +02:00
MatteoBiscosi
7b99fc17b8 Added country to alert detail view 2022-05-25 13:22:39 +02:00
MatteoBiscosi
6921aa9dce Fixes external link url proto not correctly used (#6626) 2022-05-25 12:52:56 +02:00
MatteoBiscosi
0ac8da733f Fixed server name not used for server ips (#6623) 2022-05-25 11:29:08 +02:00
Alfredo Cardigliano
5b0e59b50c Fix hostname match in engaged alerts 2022-05-24 15:34:53 +02:00
MatteoBiscosi
72f814c36c Added vlan support to exclusion lists (#6510) 2022-05-24 12:22:24 +02:00
Luca Deri
bb84f56a5e Warning fix (#6578) 2022-05-24 08:49:21 +02:00
MatteoBiscosi
784609a9f0 Fixes csv download (#6618) 2022-05-23 19:25:32 +02:00
MatteoBiscosi
506426c3b8 Added vlan utility function 2022-05-23 18:24:02 +02:00
MatteoBiscosi
ffa48647ef Added ThreatFox malware list (#6341) 2022-05-20 17:54:21 +02:00
MatteoBiscosi
6134c9b810 Removed no more needed dependencies 2022-05-20 17:53:04 +02:00
MatteoBiscosi
344946be8f Fixes non working info field filtering (#6564) 2022-05-20 16:25:02 +02:00
MatteoBiscosi
84dd3e4526 Unified aler and flow details page 2022-05-20 13:30:17 +02:00
MatteoBiscosi
08c9de2b7b Removed debug print 2022-05-20 11:36:31 +02:00
MatteoBiscosi
14e85b9888 Unified alert and flow details page style (#6565) 2022-05-20 11:30:44 +02:00
MatteoBiscosi
084b86c632 Fixes false positive in mirrored traffic 2022-05-20 11:30:44 +02:00
Alfredo Cardigliano
cf813db892 Fix label for inactive hosts (hide vlan 0) 2022-05-18 10:48:28 +02:00
Alfredo Cardigliano
0aa9c899df Fix debug trace 2022-05-18 10:42:25 +02:00
MatteoBiscosi
65284b6929 Fixes Score Network alert (#6366) 2022-05-17 11:26:00 +02:00
MatteoBiscosi
c1e6f01d53 Fixes suspicious DGA domain nil value 2022-05-17 11:26:00 +02:00
Luca Deri
2380d80642 Added DHCP MAC stats 2022-05-16 23:30:50 +02:00
MatteoBiscosi
7b51a4ca61 Added Fin Scan check (#5903) 2022-05-16 17:18:11 +02:00
MatteoBiscosi
7f81cc45a1 Added mirrore traffic toast (#6600) 2022-05-16 12:33:22 +02:00
MatteoBiscosi
bde099b236 Fixes url not correct (#6601) 2022-05-16 11:30:36 +02:00
Luca Deri
b0158f89c2 Reworked MAC/IP Reassociation alert used to detect spoofind and MITM (Man In The Middle) Attacks 2022-05-15 19:17:18 +02:00
Luca Deri
cdbb0e5380 Implements #6598 2022-05-15 16:57:48 +02:00