Commit graph

262 commits

Author SHA1 Message Date
Luca Deri
65afdd5d57 Added sanity check for VLAN Ids 2024-07-26 17:40:52 +02:00
Matteo Biscosi
c98f761d93 Added sankey to probes/exporters page 2024-07-26 17:04:57 +02:00
Luca Deri
96e8909ae7 Added nProbe reset check 2024-07-24 17:29:38 +02:00
Matteo Biscosi
ad275ef6da Fixes duplicated interface shown (#8539) 2024-07-22 16:41:48 +02:00
Luca Deri
6212d3c262 Modified initialiation 2024-07-19 19:46:49 +02:00
Luca Deri
15fba3f7ac Compilation fixes 2024-07-19 18:07:40 +02:00
Matteo Biscosi
0addcb479c Removed debug trace 2024-07-19 17:36:39 +02:00
Luca Deri
fe09def805 Attribute rename 2024-07-19 17:23:46 +02:00
Luca Deri
e020843d42 Code cleanup 2024-07-19 16:29:39 +02:00
Matteo Biscosi
a214b5f43b Fixes uuid_num not correctly parsed 2024-07-18 16:58:33 +02:00
Matteo Biscosi
b4b9253472 Fixes flow exporters issues 2024-07-18 10:24:20 +02:00
Matteo Biscosi
d306ed5f5f Added uuid_num and unique_source_id to exporters and probes 2024-07-17 11:41:43 +02:00
Alfredo Cardigliano
7eacf56555 Parse UNIQUE_SOURCE_ID 2024-07-17 07:18:05 +00:00
Matteo Biscosi
4603c5d882 Added probe ip to devices map 2024-07-16 16:53:48 +02:00
Matteo Biscosi
6d0c53ffc6 Added flows and drops ts to netflow/sflow exporters 2024-07-09 15:13:05 +02:00
Matteo Biscosi
4d8fe2f9f8 Added drops/flows and probes info to view interface 2024-07-09 10:52:02 +02:00
Luca Deri
f675579512 Added nprobe UUID support 2024-07-07 11:01:39 +02:00
Matteo Biscosi
1635df72aa Added Flows and Drops ts to exporters 2024-07-04 15:44:19 +02:00
Alfredo Cardigliano
104a65a957 Comment out debug print 2024-06-03 09:09:55 +02:00
Matteo Biscosi
d795bf3474 Added NAT info in clickhouse (#8384) 2024-05-10 10:22:55 -04:00
Matteo Biscosi
98f085113e Fixes incorrect code 2024-05-08 09:28:34 -04:00
Luca Deri
3d117a9e16 Added support for SIP CallID in flow key 2024-05-04 11:27:38 +02:00
Luca Deri
db38a5d2d5 DHCP (via ZMQ) Fixes for #7972
The symbolic hostname will use the DHCP name before the DNS resolved name
2024-05-02 21:46:03 +02:00
Luca Deri
bc372d0d93 Cosmetic fixes 2024-04-30 12:28:51 +02:00
Luca Deri
e19a557beb Disabed UDP swap also for ZMQ interfaces 2024-04-25 14:27:37 +02:00
Luca Deri
093c7f8e51 Disabled flow swap for UDP flows that might lead to false positives 2024-04-25 12:12:36 +02:00
Luca Deri
e8cca77633 Updated logic for swapping collected flows so that it is consistent with Flow::check_swap() 2024-04-25 11:02:58 +02:00
Alfredo Cardigliano
7c936f9d09 Remove deprecated private cloud support 2024-03-15 10:03:25 +01:00
Nicolò Maio
2d150103b7
Add TCP flow connection state (#8210)
* Add TCP flow connection state (#8140)

* Add Major and Minor connection states (#8140)

* Remove ZMQ connection state parsing. (#8140)

* Update doc with major and minor conn states. (#8140)
2024-02-28 14:45:49 +01:00
Luca Deri
c60170366b Further JA4 fixes 2024-02-20 16:25:09 +01:00
Nicolo Maio
9165d05e40 Add JA4C 2024-02-20 11:48:13 +01:00
Luca Deri
3aadd4e8be Added tracings
Added details parameter to NetworkInterface::lua() and subclasses
2024-02-15 07:10:24 +01:00
Nicolo Maio
ed479a8b09 Add SMTP_MAIL_FROM, SMTP_RCPT_TO mapping + L7_PROTO_RISK_NAME dump on syslog. 2024-01-30 17:52:33 +01:00
Nicolo Maio
d0eb93ec1a Implement the FLOW_END_REASON parser. 2024-01-30 14:23:32 +01:00
Luca Deri
55870e97b9 (C) Update 2024-01-12 11:44:18 +01:00
Luca Deri
c00c4b9360 Added flow source support 2024-01-11 12:43:25 +01:00
Luca Deri
e54fa3cb91 Fix in cloud license VLAN handling 2023-09-21 10:22:50 +02:00
Luca Deri
43d8e20c98 Fix for handling process information in cloud mode 2023-09-19 18:49:21 +02:00
Luca Deri
0bc208cefa Enhanced Cloud mode and VS 2023-09-18 23:14:56 +02:00
Luca Deri
ceb850d952 Implemented automatic detection of cloud-generated local hosts 2023-09-15 00:41:52 +02:00
Luca Deri
c2ea5a5cb5 Improved VLAN mapping in cloud-mode 2023-09-14 11:39:07 +02:00
Luca Deri
2d10109388 Implemented VLAB maooing 2023-09-13 23:29:48 +02:00
Luca Deri
74d693017b Initial changes for flow support in cloud mode 2023-09-12 23:59:23 +02:00
Luca
6f61a22ec4 Cleaned up ParsedFlow code 2023-08-07 23:19:20 +02:00
Alfredo Cardigliano
0edd399d2e Keep track of active probes 2023-06-12 16:45:48 +02:00
Alfredo Cardigliano
e07dbb55f8 Change/fix source_id which is 32-bit in zmq messages v2 2023-06-09 17:24:06 +02:00
Alfredo Cardigliano
227e0867eb Subscribe to control messages topic. Rework 'pro' message handles 2023-06-09 15:54:03 +02:00
Alfredo Cardigliano
5935bce2a9 Do not compile cloud support on nedge 2023-06-09 09:40:36 +02:00
Alfredo Cardigliano
56f54a33b2 Add support for cloud keys generation 2023-06-08 13:01:48 +02:00
Luca Deri
0324a16684 Added check for ignoring old nProbe versions 2023-06-01 13:08:15 +02:00