Simone Mainardi
|
b86378bca3
|
Implements ul/dl thpts in C and reworks the footer to use them
|
2019-09-03 18:56:23 +02:00 |
|
emanuele-f
|
8e6cd5962a
|
Fix blacklisted host alerts not generated when reading from PCAP dump
|
2019-09-03 17:50:08 +02:00 |
|
Simone Mainardi
|
a5b5510290
|
Adds bytes and packets throughput to NetworkInterface
|
2019-09-03 17:16:47 +02:00 |
|
emanuele-f
|
fbb66951b5
|
Add alert score on hosts
|
2019-09-03 13:36:27 +02:00 |
|
Simone Mainardi
|
3bfedf8f4c
|
Implements ThroughputStats and reworks GenericTrafficElement
|
2019-09-03 11:07:21 +02:00 |
|
Luca Deri
|
ffcfe398cc
|
Reworked flow stats defining InterarrivalStats
Fixed ms/timeval diffrence functions
|
2019-09-02 23:58:34 +02:00 |
|
emanuele-f
|
a0d8cd7595
|
Add l4_proto_to_id
|
2019-09-02 20:08:38 +02:00 |
|
Alfredo Cardigliano
|
3c930d0514
|
Code cleanup
|
2019-09-02 11:51:44 +02:00 |
|
emanuele-f
|
a58cd6a7d9
|
Add country flag in flow peers
|
2019-09-02 10:58:43 +02:00 |
|
emanuele-f
|
2d02de6cc1
|
Implement initial flow score support
|
2019-08-30 17:16:11 +02:00 |
|
Simone Mainardi
|
d2fc1f3b0b
|
Add proper axes labels to udp flow collection drops chart
|
2019-08-30 16:34:41 +02:00 |
|
Simone Mainardi
|
2e67a69cb7
|
Implements redis health and keys used monitoring
|
2019-08-30 16:19:33 +02:00 |
|
Simone Mainardi
|
24cf71a70d
|
Parses and charts UDP socket drops from nProbe
|
2019-08-30 12:54:41 +02:00 |
|
emanuele-f
|
e3ae0747c8
|
Properly handle disabled vs hidden graphs menu entries
Fixes #2710
|
2019-08-30 12:12:18 +02:00 |
|
Alfredo Cardigliano
|
13d032d185
|
Formatting IDS alerts
|
2019-08-29 11:20:41 +02:00 |
|
Simone Mainardi
|
6ae30f0604
|
Initial implementation of the Redis monitoring probe
|
2019-08-28 19:30:52 +02:00 |
|
emanuele-f
|
a37bb425ea
|
Add JA3 signature link in alerts
|
2019-08-28 18:41:17 +02:00 |
|
emanuele-f
|
b66b71fd7e
|
Implement alert on JA3 malicious signatures
Closes #2788
|
2019-08-28 18:33:13 +02:00 |
|
emanuele-f
|
a8cb972e7d
|
Implement ghost networks alerts
|
2019-08-28 16:42:18 +02:00 |
|
Simone Mainardi
|
1b189001f3
|
Fixes captive portal redirection URL not working
Fixes #2750
|
2019-08-27 18:17:44 +02:00 |
|
emanuele-f
|
3bf6ed1ecd
|
Add syn-vs-rst and misbehaving-vs-total-flows alerts
|
2019-08-27 16:33:53 +02:00 |
|
Simone Mainardi
|
606e681d8e
|
Fixes flow alerts exploration
Fixes #2782
|
2019-08-27 15:42:35 +02:00 |
|
Simone Mainardi
|
f96743569d
|
Adds alert menu also for view interfaces
|
2019-08-27 14:54:55 +02:00 |
|
Simone Mainardi
|
a0e4fe43da
|
Fixes missing alerts lists when only past alerts available
|
2019-08-27 14:54:19 +02:00 |
|
emanuele-f
|
300ea49b10
|
Little localization fix
|
2019-08-27 14:37:01 +02:00 |
|
emanuele-f
|
01c586119e
|
Remove ICMP ratio alert and enable ratio alerts by default in 5mins
|
2019-08-27 14:32:24 +02:00 |
|
emanuele-f
|
b3bdfcff32
|
Cleanup of the too-many-drops interface alert
|
2019-08-27 13:04:53 +02:00 |
|
emanuele-f
|
eb3542d7e7
|
Address too much ratio alerts generated after host deserialization
|
2019-08-27 11:02:28 +02:00 |
|
emanuele-f
|
57e623da04
|
Implement ICMP and HTTP requests vs replies ratio alert
|
2019-08-27 10:33:08 +02:00 |
|
emanuele-f
|
5dd88985f4
|
Improve and fix DNS replies/requests ratio
|
2019-08-27 09:57:59 +02:00 |
|
Simone Mainardi
|
348b9e5a56
|
Adds HASSH hyperlinks and application name when eBPF is available
|
2019-08-26 21:53:43 +02:00 |
|
emanuele-f
|
a0761db1e8
|
Implement replies/requests ratio alert
|
2019-08-26 18:38:34 +02:00 |
|
emanuele-f
|
b0ba13f0bc
|
Syn/flow flood alerts now use their own alert type
|
2019-08-26 17:36:27 +02:00 |
|
Simone Mainardi
|
11aa854cba
|
Handles hosts HASSH fingerprints
|
2019-08-26 16:55:39 +02:00 |
|
Simone Mainardi
|
0353edb2a6
|
Adds ssh HASSH signatures into flows
|
2019-08-26 15:22:47 +02:00 |
|
emanuele-f
|
abdc3d54a3
|
Handle alert config default values
Closes #2747
|
2019-08-23 19:23:05 +02:00 |
|
Simone Mainardi
|
81f93ad882
|
Implements Icinga2 check plugin for host and host flow alerts
|
2019-08-23 14:53:12 +02:00 |
|
emanuele-f
|
16b839828d
|
Reduce alerts drop message severity
|
2019-08-23 14:29:48 +02:00 |
|
emanuele-f
|
de7a5a49d8
|
Implement optimized hasAlerts to reduce alerts page load time
|
2019-08-23 13:00:52 +02:00 |
|
Simone Mainardi
|
c8fb20bed9
|
Makes alert database tables rowid as autoincrement
|
2019-08-23 10:31:56 +02:00 |
|
emanuele-f
|
2814a94077
|
Report curl error while a list download fails
Fixes #2777
|
2019-08-23 09:52:58 +02:00 |
|
Simone Mainardi
|
061eb632a6
|
Initial implementation of the icinga2 checker plugin
|
2019-08-22 17:16:14 +02:00 |
|
emanuele-f
|
f43f4b7dd9
|
Add engaged alerts type exclusion filter
Fixes #2780
|
2019-08-22 16:30:45 +02:00 |
|
emanuele-f
|
7534fa4636
|
Fix ifid handling in disabled alerts
|
2019-08-22 15:53:29 +02:00 |
|
emanuele-f
|
65b2bd6ffb
|
Fix missing alerts filters when a filter is in place
|
2019-08-22 15:25:54 +02:00 |
|
emanuele-f
|
3a3e4c6880
|
Properly handle alert filters dropdowns
Closes #2778
|
2019-08-22 15:13:54 +02:00 |
|
emanuele-f
|
e2a0299857
|
Add past alerts and flow alerts to host details
|
2019-08-22 12:50:11 +02:00 |
|
emanuele-f
|
1032af0d8f
|
Add network engage_alerts timeseries
|
2019-08-21 17:07:58 +02:00 |
|
emanuele-f
|
69cd896a9f
|
Implement engaged alerts and flow alerts timeseries
|
2019-08-21 16:57:14 +02:00 |
|
emanuele-f
|
2b2a74af79
|
Fix bad time resolution of values for some host exported timeseries
- active_flows.as_client
- active_flows.as_server
- total_flows.as_client
- total_flows.as_server
- contacts.as_client
- contacts.as_server
- DNS, TCP, ICMP stats
Fixes #2776
|
2019-08-21 15:37:17 +02:00 |
|