Commit graph

7198 commits

Author SHA1 Message Date
Luca Deri
ed938dc6c1 Fixed DNS report 2021-02-28 13:00:10 +01:00
gabryon99
1a4c7c2388 put the date on two lines (#5065) 2021-02-28 12:23:52 +01:00
Simone Mainardi
9d43be52c7 Reworks client/server heuristic for ZMQ interfaces 2021-02-27 21:01:19 +01:00
Matteo Biscosi
be9b5b8405 Removed mac address from flow alert msg
Changed remote to local alert description
2021-02-26 19:12:04 +01:00
Alfredo Cardigliano
47b3c8a969 Check low goodput for established connections (e.g. do not generate alerts for connection reset with 0 goodput) (#5068) 2021-02-26 16:39:15 +01:00
Matteo Biscosi
4be03c9627 Reviewed alert description and alert table width 2021-02-26 16:22:11 +01:00
Luca Deri
1f4c3114cf Some strings have been made shorter 2021-02-26 16:19:11 +01:00
Matteo Biscosi
39d3618351 Fixes flow alerts table column width and description 2021-02-26 16:10:48 +01:00
Alfredo Cardigliano
4f0ac39efe Add more protocols to be filtered (#5068) 2021-02-26 15:36:37 +01:00
Matteo Biscosi
fa5088d49b Removed useless description from some flow alert 2021-02-26 12:58:06 +01:00
Matteo Biscosi
e521ce6cdc Removed incorrect scripts from flow interfaces
This alerts shouldn't be used in flow interfaces but only in packets one because the flow interfaces doesn't have/have incorrect informations regaring these fields
2021-02-26 12:35:16 +01:00
Luca Deri
5d136ac51c Name fix 2021-02-26 12:26:33 +01:00
Matteo Biscosi
56a3cb9875 Added contacts behaviour rrd timeseries 2021-02-26 11:40:54 +01:00
Simone Mainardi
36e26cd0fc Cleanup old ip reassignment / remote to remote alerts code
Fixes #5038
2021-02-26 11:36:21 +01:00
Simone Mainardi
def8cadbca Fixes some ip reassignment alerts not triggering 2021-02-26 11:34:40 +01:00
Alfredo Cardigliano
d90fb8f8a5 Fix html tag stripping 2021-02-26 11:32:29 +01:00
Simone Mainardi
76006d6250 Fixes IP reassignment code that is now per-interface
Implements #5038
2021-02-26 11:21:04 +01:00
Alfredo Cardigliano
db0633fc9f Map alert severity to syslog messages 2021-02-26 10:28:18 +01:00
Matteo Biscosi
41163ac7f6 Implements low risk alert type must be further split
Implements #5066
2021-02-25 19:09:17 +01:00
Simone Mainardi
7228b6b08e Reworks Lua after flow status bitmap extension to 128 bits 2021-02-25 18:55:21 +01:00
gabryon99
0df58e5a2f nowrap for protocol and type columns in alert table (#5065) 2021-02-25 16:34:48 +01:00
Luca Deri
6bfe31d5bd Fixed HTML issue 2021-02-25 15:44:00 +01:00
Alfredo Cardigliano
b6c083c8bb Use a more standard date format 2021-02-25 15:27:28 +01:00
Alfredo Cardigliano
de67f9b13f Cleanup 2021-02-25 15:00:04 +01:00
Alfredo Cardigliano
bd55990961 Add support for syslog format RFC 5424 2021-02-25 14:50:23 +01:00
Matteo Biscosi
6a4c6cf30c Implements noisy low goodput alert
Implements #5068
2021-02-25 12:21:29 +01:00
Matteo Biscosi
dbfdec34fe Implements Local Host behaviour analysis and it's alert
Alert in case the host has an unexpected behaviour
2021-02-25 12:04:05 +01:00
gabryon99
7a1a9be9af fixed filter menu in hosts map (#5064) 2021-02-25 11:35:56 +01:00
Matteo Biscosi
a89e46f32c Fixed mispelled OS timeseries name 2021-02-25 11:02:34 +01:00
Matteo Biscosi
49ae038c3f Implements #5038 cleanup IP reassigment code
Removed debug print and used setPref instead of setCache
2021-02-25 11:00:09 +01:00
gabryon99
932954151a updated email regex used for the telemetry field (#5056) 2021-02-25 10:57:59 +01:00
Matteo Biscosi
ef3eb09d3b Removed rrd fname from OSes schema 2021-02-25 10:55:22 +01:00
Alfredo Cardigliano
1c988036c1 Add host to the syslog export 2021-02-25 09:41:00 +01:00
Simone Mainardi
e369aa0a85 Implements alert filters for all engaged alerts 2021-02-24 10:29:59 +01:00
Alfredo Cardigliano
a4b6be18b4 Update locale for malicious signatures 2021-02-24 10:18:40 +01:00
gabryon99
08f2e68f0b add raw exclusion list for user script page (#5002) 2021-02-23 21:16:08 +01:00
Simone Mainardi
981f7a0572 Removes experimental code for timeseries delta 2021-02-23 19:09:07 +01:00
Alfredo Cardigliano
db9adb9060 Add support for Malicious JA3 signature using nDPI (#5045) 2021-02-23 18:35:19 +01:00
Simone Mainardi
6a02355395 Fixes failing syslog 2021-02-23 17:03:32 +01:00
Simone Mainardi
e82f318742 Adds exclusion filter for SNMP device alerts 2021-02-23 15:48:21 +01:00
Simone Mainardi
af90ee08c9 Removes a debug flag 2021-02-23 15:38:20 +01:00
Simone Mainardi
696bcb33e5 Implements alert exclusions for hosts, interfaces, local networks 2021-02-23 15:36:14 +01:00
gabryon99
11e56489a6 fixed typo for threshold cross 2021-02-23 13:42:32 +01:00
gabryon99
6f229ffd01 add threshold_cross template 2021-02-23 12:58:33 +01:00
Luca Deri
a3990cd904 Added Some IPFIX stanndard fields collected by ntopng/nProbe in pass throught mode 2021-02-23 12:33:07 +01:00
Simone Mainardi
6b75045a86 Always return rendered user script templates in order 2021-02-23 11:20:56 +01:00
Simone Mainardi
15d4672f7e Loads plugins templates from /modules when no template is found 2021-02-23 10:55:41 +01:00
Matteo Biscosi
c62c2c232e Removed useless requires for enchanting performances
Removed, where it was possible, the lua requires, with the objective of enchanting the performances of periodic activities
2021-02-23 10:51:50 +01:00
Simone Mainardi
454f5c07ba Fixes deletetion of user script configs leaving stale pools 2021-02-22 18:52:42 +01:00
Luca Deri
f1c87e533f Simplified housekeeping.lua 2021-02-22 18:03:25 +01:00