-- -- (C) 2013-17 - ntop.org -- dirs = ntop.getDirs() package.path = dirs.installdir .. "/scripts/lua/modules/?.lua;" .. package.path local shaper_utils if ntop.isPro() then package.path = dirs.installdir .. "/scripts/lua/pro/modules/?.lua;" .. package.path shaper_utils = require("shaper_utils") end require "lua_utils" require "historical_utils" require "flow_utils" require "voip_utils" local json = require ("dkjson") sendHTTPHeader('text/html; charset=iso-8859-1') ntop.dumpFile(dirs.installdir .. "/httpdocs/inc/header.inc") warn_shown = 0 function displayProc(proc) print("
| ") if(ifstats.sprobe) then print('Source Id') else print('VLAN ID') end print(" | " .. flow["vlan"].. " | |||
|---|---|---|---|---|
| Flow Peers [ Client / Server ] | ") print(flowinfo2hostname(flow,"cli",ifstats.vlan)) if(flow["cli.systemhost"] == true) then print(" ") end print("") if(flow["cli.port"] > 0) then print(":" .. flow["cli.port"].."") end if(flow["cli.mac"] ~= nil and flow["cli.mac"]~= "" and flow["cli.mac"] ~= "00:00:00:00:00:00") then print(" [ " .. flow["cli.mac"].." ]") end print(" \n") print("") print(flowinfo2hostname(flow,"srv",ifstats.vlan)) if(flow["srv.systemhost"] == true) then print(" ") end print("") if(flow["srv.port"] > 0) then print(":" .. flow["srv.port"].. "") end if(flow["srv.mac"] ~= nil and flow["srv.mac"]~= "" and flow["srv.mac"] ~= "00:00:00:00:00:00") then print(" [ " .. flow["srv.mac"].." ]") end print(" | |||
| Protocol | ") if(ifstats.inline and flow["verdict.pass"]) then print("") else print(" | ")
end
if(flow["verdict.pass"] == false) then print(" | ')
print("||
| Flow Shapers | ") c = flowinfo2hostname(flow,"cli",ifstats.vlan) s = flowinfo2hostname(flow,"srv",ifstats.vlan) cli_max_rate = shaper_utils.getShaperMaxRate(ifstats.id, flow["shaper.cli2srv_ingress"]) if(cli_max_rate == "") then cli_max_rate = -1 end srv_max_rate =shaper_utils.getShaperMaxRate(ifstats.id, flow["shaper.cli2srv_egress"]) if(srv_max_rate == "") then srv_max_rate = -1 end max_rate = getFlowMaxRate(cli_max_rate, srv_max_rate) print(""..c.." "..s.." | "..shaper_utils.shaperRateToString(max_rate).." | "..c.." "..s.." | "..shaper_utils.shaperRateToString(max_rate).." | ") print("") end print("
| First / Last Seen | " .. formatEpoch(flow["seen.first"]) .. " [" .. secondsToTime(os.time()-flow["seen.first"]) .. " ago]" .. " | \n")
print("" .. formatEpoch(flow["seen.last"]) .. " [" .. secondsToTime(os.time()-flow["seen.last"]) .. " ago]" .. " | ||
| Total Traffic | Total: " .. bytesToSize(flow["bytes"]) .. " | ") if((ifstats.type ~= "zmq") and ((flow["proto.l4"] == "TCP") or (flow["proto.l4"] == "UDP")) and (flow["goodput_bytes"] > 0)) then print("Goodput: " .. bytesToSize(flow["goodput_bytes"]) .. " (") pctg = round(((flow["goodput_bytes"]*100)/flow["bytes"]), 2) if(pctg < 50) then pctg = ""..pctg.."" elseif(pctg < 60) then pctg = ""..pctg.."" end print(pctg.."") print(" %) | \n") end print(" | |
| Client Server: " .. formatPackets(flow["cli2srv.packets"]) .. " / ".. bytesToSize(flow["cli2srv.bytes"]) .. " | Client Server: " .. formatPackets(flow["srv2cli.packets"]) .. " / ".. bytesToSize(flow["srv2cli.bytes"]) .. " | |||
| ")
cli2srv = round((flow["cli2srv.bytes"] * 100) / flow["bytes"], 0)
cli_name = shortHostName(ntop.getResolvedAddress(flow["cli.ip"]))
srv_name = shortHostName(ntop.getResolvedAddress(flow["srv.ip"]))
if(flow["cli.port"] > 0) then
cli_name = cli_name .. ":" .. flow["cli.port"]
srv_name = srv_name .. ":" .. flow["srv.port"]
end
print(' ')
print(" | ||||
| Network Latency Breakdown | ")
cli2srv = round(((flow["tcp.nw_latency.client"] * 100) / s), 0)
c = string.format("%.3f", flow["tcp.nw_latency.client"])
print(' ')
s = string.format("%.3f", flow["tcp.nw_latency.server"])
print(' ')
print(" | |||
| Application Latency | "..msToTime(flow["tcp.appl_latency"]).." | |||
| Packet Inter-Arrival Time [ Min / Avg / Max ] | Client Server: ") print(msToTime(flow["interarrival.cli2srv"]["min"]).." / "..msToTime(flow["interarrival.cli2srv"]["avg"]).." / "..msToTime(flow["interarrival.cli2srv"]["max"])) print(" | \n") if(flow["srv2cli.packets"] < 2) then print("") else print(" | Client Server: ") print(msToTime(flow["interarrival.srv2cli"]["min"]).." / "..msToTime(flow["interarrival.srv2cli"]["avg"]).." / "..msToTime(flow["interarrival.srv2cli"]["max"])) end print(" | |
| This looks like an idle flow with periodic transmissions just to keep it alive. | ||||
| TCP Packet Analysis | ||||
| Client Server / Client Server | ||||
| Retransmissions | ".. formatPackets(flow["cli2srv.retransmissions"]) .." / ".. formatPackets(flow["srv2cli.retransmissions"]) .." | |||
| Out of Order | ".. formatPackets(flow["cli2srv.out_of_order"]) .." / ".. formatPackets(flow["srv2cli.out_of_order"]) .." | |||
| Lost | ".. formatPackets(flow["cli2srv.lost"]) .." / ".. formatPackets(flow["srv2cli.lost"]) .." | |||
| SSL Certificate | ") print(""..flow["protos.ssl.certificate"].." ") if(flow["category"] ~= nil) then print(" "..getCategoryIcon(flow["protos.ssl.certificate"], flow["category"])) end historicalProtoHostHref(ifid, nil, nil, nil, flow["protos.ssl.certificate"]) print(" | |||
| ".. ''.. "Max (Estimated) TCP Throughput | Client Server: ") print(bitsToSize(flow["tcp.max_thpt.cli2srv"])) print(" | Client Server: ") print(bitsToSize(flow["tcp.max_thpt.srv2cli"])) print(" | ||
| Throughput Trend | "..flow["cli.ip"].." "..flow["srv.ip"]..": ") print(flow["cli2srv.trend"]) print(" | "..flow["cli.ip"].." "..flow["srv.ip"]..": ") print(flow["srv2cli.trend"]) print(" | ||
| TCP Flags | Client Server: ") printTCPFlags(flow["cli2srv.tcp_flags"]) print(" | Client Server: ") printTCPFlags(flow["srv2cli.tcp_flags"]) print(" | ||
| ") flow_completed = false flow_reset = false flows_syn_seen = false resetter = "" if(hasbit(flags,0x01)) then flow_completed = true end if(hasbit(flags,0x02)) then flows_syn_seen = true end if(hasbit(flags,0x04)) then flow_completed = true flow_reset = true if(hasbit(flow["cli2srv.tcp_flags"],0x04)) then resetter = "client" else resetter = "server" end end local flow_msg="" if flow_reset == true then flow_msg = flow_msg.." This flow has been reset" if resetter ~= nil and resetter ~= "" then flow_msg = flow_msg.." by "..resetter end flow_msg = flow_msg.."." elseif flow_completed == true then flow_msg = flow_msg.." This flow is completed and will expire soon." else flow_msg = flow_msg.." This flow is active." if flows_syn_seen == false then flow_msg = flow_msg.." However, flow begin has not been seen: peer roles (client/server) might be inaccurate." end end print(flow_msg) print(" | ||||
| ICMP Info | ".. getICMPTypeCode(icmp) .. " | |||
| Flow Status | "..getFlowStatus(flow["flow.status"]).." | |||
| Actual / Peak Throughput | ") if (throughput_type == "bps") then print("" .. bitsToSize(8*flow["throughput_bps"]) .. " ") elseif (throughput_type == "pps") then print("" .. pktsToSize(flow["throughput_bps"]) .. " ") end if (throughput_type == "bps") then print(" / " .. bitsToSize(8*flow["top_throughput_bps"]) .. " ") elseif (throughput_type == "pps") then print(" / " .. pktsToSize(flow["top_throughput_bps"]) .. " ") end print(" | 0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0") print(" | ||
| ') width = 1024 height = 200 url = ntop.getHttpPrefix().."/lua/sprobe_flow_data.lua?flow_key="..flow_key dofile(dirs.installdir .. "/scripts/lua/inc/sprobe.lua") print(' | ||||
| Client Process Information | ||||
| Server Process Information | ||||
| DNS Query | ") if(string.ends(flow["protos.dns.last_query"], "arpa")) then print(flow["protos.dns.last_query"]) else print(""..flow["protos.dns.last_query"].." ") end if(flow["category"] ~= nil) then print(" "..getCategoryIcon(flow["protos.dns.last_query"], flow["category"])) end print(" | |||
| BitTorrent hash | ".. flow["bittorrent_hash"].." | |||
| SSH Signature | Client: "..flow["protos.ssh.client_signature"].." | Server: "..flow["protos.ssh.server_signature"].." | ||
| HTTP | HTTP Method | "..flow["protos.http.last_method"].." | ||
| Server Name | ") if(flow["host_server_name"] ~= nil and flow["host_server_name"] ~= "") then s = flow["host_server_name"] else s = flowinfo2hostname(flow,"srv",ifstats.vlan) end print(""..s.." ") if(flow["category"] ~= nil) then print(" "..getCategoryIcon(flow["host_server_name"], flow["category"])) end print(" | |||
| URL | ") if(flow["protos.http.last_url"] ~= "") then print(""..shortenString(flow["protos.http.last_url"]).." ") else print(shortenString(flow["protos.http.last_url"])) end print(" | |||
| Response Code | "..flow["protos.http.last_return_code"].." | |||
| Server Name | "..flow["host_server_name"].." | |||
| Profile Name | "..flow["profile"].." | |||
| Dump Flow Traffic | ") print [[ ') print(" | |||
| Additional Flow Elements | ||||
| " .. getFlowKey(key) .. " | " .. handleCustomFlowField(key, value) .. " | |||