Commit graph

413 commits

Author SHA1 Message Date
Nicolo Maio
9b1da73e4c Minor fix. (#6922) 2023-03-23 14:38:00 +00:00
Nicolo Maio
d4c67d4efc Fix sql op and add comment. (#6922) 2023-03-23 14:32:03 +00:00
Nicolo Maio
fc135e1661 Add filter on 2nd and lower flow risk.(#6922) 2023-03-23 14:08:37 +00:00
Alfredo Cardigliano
0a86bd4196 Comment out unneeded condition 2023-03-22 15:06:28 +01:00
Nicolo Maio
ee057fb525 Fix alert Suspicious DGA Domain filter. (#7226) 2023-03-22 11:41:07 +00:00
Nicolo Maio
7d7fe03575 Fix top DGA domain name filter value. (#7226) 2023-03-22 09:14:51 +00:00
Nicolo Maio
09f0bb10fb Minor fix. (#7226) 2023-03-21 15:55:50 +00:00
Nicolo Maio
260caf0b49 Add top domain name dropdown menu and alert filter. (#7226) 2023-03-21 15:38:00 +00:00
Matteo Biscosi
00e25ccd46 Added direct download with clickhouse alerts (#6852) 2023-03-21 11:21:47 +00:00
Matteo Biscosi
9ccda97dc6 Fixes ja3 filter not correctly working 2023-03-07 16:25:38 +00:00
Nicolò Maio
8d5959b7d6
Adding JA3. (#6908) (#7285) 2023-03-07 16:15:55 +01:00
Matteo Biscosi
e7f9086165 Added community id column on historical flows and alerts (#6908) 2023-02-16 18:17:49 +01:00
MatteoBiscosi
0264fb8992 Removed ip resolution when formatting alerts (#7209) 2023-02-08 13:06:36 +01:00
Alfredo Cardigliano
d6e926e9c9 Improve interface report 2023-02-03 15:26:42 +01:00
MatteoBiscosi
254bf31d23 Fixes vlan not properly working 2023-02-03 10:51:25 +01:00
Alfredo Cardigliano
cbc7eadbd8 Fix engaged alerts reported in all tab 2023-02-02 11:00:47 +01:00
Alfredo Cardigliano
16748e5f03 Add global top alerts stats 2023-01-20 16:52:05 +01:00
Alfredo Cardigliano
8631013266 Restore check for engaged alerts to be displayed if started before the displayed interval 2023-01-13 18:26:42 +01:00
Luca Deri
15786b1a00 Changes required to support multiple ntopng instances dumping flows into the same ClickHouse database 2023-01-11 20:00:03 +01:00
Alfredo Cardigliano
a9f4463f8e Add Flow Risk (Bitmap) Filter in alerts (#7077) 2023-01-02 11:15:01 +01:00
Luca Deri
21101c43f1 Added detection of periodic flows and exported it as flow risk in both flows and alerts 2022-12-30 19:48:26 +01:00
Luca Deri
4f1451c021 Handled where clause in historical queries 2022-12-29 21:44:53 +01:00
Luca Deri
587cde6f27 Firxed alert store queries when group_by is used 2022-12-28 21:23:37 +01:00
Luca Deri
d596c5ee16 Improved alert analyser 2022-12-28 18:00:57 +01:00
Alfredo Cardigliano
4feb9ef4d9 Cleanup debug print 2022-12-23 18:57:09 +01:00
Alfredo Cardigliano
bc8fb50ce7 Improve Engaged Time Report in Chart (#7066) 2022-12-23 18:55:52 +01:00
MatteoBiscosi
e0b08d6878 Correctly formatted flow tuple with vlans 2022-12-19 10:38:30 +01:00
Alfredo Cardigliano
754e1dd7f4 Add top VLAN and Network flow alerts (#6999) 2022-12-05 06:39:38 -05:00
MatteoBiscosi
692ae0bfcc Added critical and emergency status to alerts 2022-10-19 10:18:51 +02:00
MatteoBiscosi
52c316d214 Removed non standard connotations (#6878) 2022-10-17 15:53:36 +02:00
MatteoBiscosi
93077fc7b0 Fixes label cut algorithm not working (#6869) 2022-09-12 11:03:55 +02:00
MatteoBiscosi
a7ffcbbd2f Fixes incorrect self named 2022-08-26 15:19:35 +02:00
Alfredo Cardigliano
18073ecb2c Add Flow Exporter column (and filter) to flow alerts (implement #6822) 2022-08-24 09:39:39 +02:00
Alfredo Cardigliano
f7abded777 Account system stats in the All page for engaged 2022-08-23 15:18:25 +02:00
Luca Deri
cdb4c15fa0 Fixed print format 2022-08-22 18:13:09 +02:00
Luca Deri
cb47fe4237 Added missing formatter 2022-08-22 18:10:13 +02:00
Alfredo Cardigliano
fa68eadef0 Add supprot for filtering alerts on probe ip and interface (#6809) 2022-08-22 16:39:35 +02:00
Alfredo Cardigliano
acd7ac4671 Store exporter and interface info for flow alerts with sqlite 2022-08-22 16:02:25 +02:00
Alfredo Cardigliano
8f991db0f3 Show System alerts in interfaces also with SQLite (fix #6498) 2022-08-02 11:20:17 +02:00
MatteoBiscosi
3f214341ea Added traceback in case of nil score 2022-07-20 13:14:49 +02:00
Alfredo Cardigliano
77c80a0190 Safety check 2022-07-19 11:11:50 +02:00
MatteoBiscosi
d4eb7a10ce Added check for alerts 2022-07-15 17:10:52 +02:00
Alfredo Cardigliano
7928c96dea Filter domains when showing alert exclusion options 2022-06-29 10:23:14 +02:00
Alfredo Cardigliano
3b12ca84e2 Show server name in place of URL when disabling alerts by domain 2022-06-28 19:04:41 +02:00
Alfredo Cardigliano
ca820b4a36 Code cleanup. Add issuerdn and domain name to alert exclusion in flow details. 2022-06-28 18:36:51 +02:00
MatteoBiscosi
ddc8fa447e Added check for duplicated protocol label (#6731) 2022-06-28 15:34:05 +02:00
MatteoBiscosi
4fc3b32e84 Fixes incorrect field printed 2022-06-27 13:27:26 +02:00
Alfredo Cardigliano
55d00b8f66 Get issuerDN from risk info in case of tls_certificate_selfsigned 2022-06-21 17:07:46 +02:00
Alfredo Cardigliano
4413f41b65 Cleanup code for json field lookup 2022-06-17 09:56:50 +02:00
Alfredo Cardigliano
72dca21d3d Fix getExtraFlowInfoURL 2022-06-15 17:38:50 +02:00