Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 19 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,25 @@
The release notes on GitHub are taken from this file: the section whose
heading is the version number.

## 1.2.3

Interfaces
- **Interface** at the top of the traffic pages (Overview, Top 66, Traffic
details, Flow paths, Geo & networks, Flow records, detail): all
interfaces, or one, and the pages show only the traffic through it. It
starts on the default interface and is kept in the link. Findings,
Threat intel, Interface check and Settings stay on all traffic. One
interface over 7 or 30 days is read from the flow records (slower,
as far back as they are kept).
- Interface check: each interface can be named and tagged (✎) and one made
the default (★); saved to its iface line in Names as tag=… and default.
The page opens on the default interface.
- Interface check: the bits/s and packets/s charts are full width, one
above the other.
- Overview: the bandwidth of the chosen (or default, or busiest) interface
in bits/s, ingress green and egress blue, above the bandwidth by
application.

## 1.2.2

NetFlow and IPFIX sampling
Expand Down
33 changes: 25 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -517,10 +517,16 @@ If a device does not appear:
Flow numbers are estimates: sampled packets times the sampling rate.
traffic66 compares them with the device's own interface counters and shows
the difference on **Interface check**, with the likely cause when it is
larger than sampling alone explains. Each interface has a bits/s and a
packets/s chart with ingress (green) and egress (blue); the device's own
counters are dashed lines on the bits/s chart. Picking an interface in the
list shows its charts.
larger than sampling alone explains. Each interface has a full-width
bits/s chart and, under it, a packets/s chart, with ingress (green) and
egress (blue); the device's own counters are dashed lines on the bits/s
chart. Picking an interface in the list shows its charts.

Each row of the list has two buttons. **✎** gives the interface a name and
a short tag (such as *uplink*), shown next to its name everywhere. **☆**
makes it the default interface (**★**); there is one default. The pages
then open on it (see the **Interface** choice under [Using the web UI](#9-using-the-web-ui)), and the overview shows its
bandwidth. Both are saved at once to the `iface` line in Names.

![Interface check: traffic of every interface, and the flow estimate next to the device counter](docs/images/interfaces.png)

Expand Down Expand Up @@ -571,8 +577,9 @@ device 192.0.2.1 Core router
device 192.0.2.9 Branch firewall unsampled
device 192.0.2.20 Edge router sampling=1000

# interface names, by device address and ifIndex; speed in bits per second
iface 192.0.2.1 3 ISP uplink speed=1000000000
# interface names, by device address and ifIndex; speed in bits per second,
# tag= a short tag, default = the interface the pages open on (one only)
iface 192.0.2.1 3 ISP uplink speed=1000000000 tag=uplink default

# host names shown instead of addresses
host 10.10.3.27 Finance PC
Expand Down Expand Up @@ -674,15 +681,15 @@ Pages:

| Page | What it answers |
|---|---|
| Overview | How much traffic now, by application (**Total**, or only **Inbound** or **Outbound** traffic of your networks), compared with the same time yesterday (ranges up to a day), last week (up to a week) or the days before (longer ranges), when there is data then; open findings; direction and protocol; top clients and services |
| Overview | The bandwidth of the chosen interface (or the default, or else the busiest) in bits/s, ingress and egress as seen by the interface; how much traffic now, by application (**Total**, or only **Inbound** or **Outbound** traffic of your networks), compared with the same time yesterday (ranges up to a day), last week (up to a week) or the days before (longer ranges), when there is data then; open findings; direction and protocol; top clients and services |
| Top 66 | Opens on **Table**, one table of the top 66: by default conversations (client, server, service, country). Every column heading sorts; number columns (traffic, packets, average packet size, flows) rank all traffic in the range, so the smallest average packet size finds scanners and floods. **Group by** switches to applications, networks, segments, devices, encapsulation and VLAN. **Talkers** shows the top 30 clients and servers side by side with traffic, packets and flow records, above a row for all traffic |
| Traffic details | Two ring charts. **Servers and clients**: the inner ring is the 8 busiest servers, the outer ring the clients of each; **Clients inside** turns it round (clients inside, the servers each uses outside), since one side often explains more than the other. **Services**: one ring of the busiest services. Point at a segment for its traffic; click it like any value |
| Flow paths | Which host uses which application towards which country: the 8 busiest hosts, the rest as Other. **Client → server** shows client → service → server; **By network** shows networks instead of hosts. Long names are shortened to 22 characters; point at one for the full name |
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Geo & networks | A world map of traffic by country, with lines from your networks; the networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Settings | Devices, sampling, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |
| Interface check | Traffic of every interface over time in bits/s and packets/s, ingress (green) and egress (blue), with the device counters as dashed lines; how far the flow numbers are from the counters, worst first, with reasons |
| Interface check | Traffic of every interface over time in bits/s and, below, packets/s, ingress (green) and egress (blue), with the device counters as dashed lines; how far the flow numbers are from the counters, worst first, with reasons; a name, a tag and the default for each interface |
| Flow records | How many flow records there were and when (a bar per interval), and the records themselves, newest first, page by page, with selectable columns. Opens on the last 15 minutes, updated every 5 seconds; opened from a value on another page (**Show its flow records**) it keeps that page's time range, and **Back to live** returns |
| Data cleanup | Deletes data older than 120, 90, 60, 30 or 7 days, or all of it, with how much each frees ([more](#13-data-backup-upgrade-uninstall)) |
| Offline pcap analysis | Packet captures (pcap, pcapng) analysed apart from the live data ([more](#offline-pcap-analysis)) |
Expand All @@ -693,6 +700,16 @@ intel, Geo & networks), setup and data (Settings, Flow records, Data
cleanup) and Offline pcap analysis. Under the logo are the version and the
server's date and time.

Above the traffic pages (Overview, Top 66, Traffic details, Flow paths,
Geo & networks, Flow records and the detail of a value) is **Interface**:
**All interfaces**, or one interface, so that these pages show only the
traffic through it (in or out). It starts on the default interface (★,
set on **Interface check**) and the choice is part of the link. Findings,
Threat intel, Interface check and Settings always cover all traffic. For
one interface over 7 or 30 days the pages read the flow records rather
than the hourly and daily summaries, so they take longer and reach back
as far as flow records are kept (30 days by default).

Above the pages: time range (15 minutes to 30 days, or **Custom…** for any
start and end, also further back than 30 days), automatic refresh every 30
seconds, and **Copy link**, which copies a link to exactly the current view
Expand Down
30 changes: 23 additions & 7 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -539,9 +539,15 @@ softflowd -i eth0 -n 192.0.2.50:2055 -v 9 -t maxlife=60
أرقام التدفقات تقديرية: عدد الحزم المأخوذة عينةً مضروبًا في معدّل أخذ
العينات. يقارنها traffic66 بعدّادات الواجهات في الجهاز نفسه ويعرض الفرق في
**مطابقة الواجهات**، مع السبب المرجّح حين يكون الفرق أكبر مما يفسّره أخذ
العينات وحده. لكل واجهة مخطط بوحدة bits/s وآخر بوحدة packets/s فيهما الدخول
(بالأخضر) والخروج (بالأزرق)؛ وتظهر عدّادات الجهاز نفسه خطوطًا متقطعة على مخطط
bits/s. واختيار واجهة من القائمة يعرض مخططاتها.
العينات وحده. لكل واجهة مخطط بوحدة bits/s بعرض الصفحة كاملًا، وتحته مخطط بوحدة
packets/s، فيهما الدخول (بالأخضر) والخروج (بالأزرق)؛ وتظهر عدّادات الجهاز نفسه
خطوطًا متقطعة على مخطط bits/s. واختيار واجهة من القائمة يعرض مخططاتها.

في كل صف من القائمة زرّان. يمنح **✎** الواجهة اسمًا ووسمًا قصيرًا (مثل *uplink*)
يظهر بجوار اسمها في كل مكان. ويجعلها **☆** الواجهة الافتراضية (**★**)؛ وهناك
واجهة افتراضية واحدة فقط. بعدها تُفتح الصفحات عليها (انظر خيار **الواجهة** في
[استخدام واجهة الويب](#9-using-the-web-ui))، وتعرض النظرة العامة عرض نطاقها الترددي.
ويُحفظ كلاهما فورًا في سطر `iface` في **الأسماء**.

![مطابقة الواجهات: حركة كل واجهة، وتقدير التدفقات بجوار عدّاد الجهاز](images/interfaces.png)

Expand Down Expand Up @@ -592,8 +598,9 @@ device 192.0.2.1 Core router
device 192.0.2.9 Branch firewall unsampled
device 192.0.2.20 Edge router sampling=1000

# interface names, by device address and ifIndex; speed in bits per second
iface 192.0.2.1 3 ISP uplink speed=1000000000
# interface names, by device address and ifIndex; speed in bits per second,
# tag= a short tag, default = the interface the pages open on (one only)
iface 192.0.2.1 3 ISP uplink speed=1000000000 tag=uplink default

# host names shown instead of addresses
host 10.10.3.27 Finance PC
Expand Down Expand Up @@ -676,15 +683,15 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh

| الصفحة | ما الذي تجيب عنه |
|---|---|
| نظرة عامة | حجم الحركة الآن حسب التطبيق (**الإجمالي**، أو حركة شبكاتك في اتجاه **وارد** أو **صادر** فقط)، مقارنةً بالوقت نفسه أمس (للنطاقات حتى يوم)، أو بالأسبوع الماضي (حتى أسبوع)، أو بالأيام السابقة (للنطاقات الأطول)، متى توفرت بيانات لتلك الفترة؛ الاكتشافات المفتوحة؛ الاتجاه والبروتوكول؛ أبرز العملاء والخدمات |
| نظرة عامة | عرض النطاق الترددي للواجهة المختارة (أو الافتراضية، وإلا فالأكثر نشاطًا) بوحدة bits/s، الدخول والخروج كما تراهما الواجهة؛ حجم الحركة الآن حسب التطبيق (**الإجمالي**، أو حركة شبكاتك في اتجاه **وارد** أو **صادر** فقط)، مقارنةً بالوقت نفسه أمس (للنطاقات حتى يوم)، أو بالأسبوع الماضي (حتى أسبوع)، أو بالأيام السابقة (للنطاقات الأطول)، متى توفرت بيانات لتلك الفترة؛ الاكتشافات المفتوحة؛ الاتجاه والبروتوكول؛ أبرز العملاء والخدمات |
| أعلى 66 | تُفتح على **جدول**، وهو جدول واحد لأعلى 66: افتراضيًا المحادثات (العميل والخادم والخدمة والدولة). كل عنوان عمود يفرز؛ والأعمدة الرقمية (حركة المرور، الحزم، متوسط الحزمة، التدفقات) تعيد اختيار أعلى 66 من كل حركة المرور في الفترة، لذا يكشف أصغر متوسط حزمة عمليات المسح والإغراق. ويبدّل **التجميع حسب** إلى التطبيقات والشبكات والمقاطع والأجهزة وأنواع التغليف وشبكات VLAN. أما **أكثر الأطراف نشاطًا** فيعرض أعلى 30 عميلًا وخادمًا جنبًا إلى جنب مع الحركة والحزم وسجلات التدفق، فوق صف لكل الحركة |
| تفاصيل الحركة | مخططان حلقيان. **الخوادم والعملاء**: الحلقة الداخلية أكثر 8 خوادم نشاطًا، والخارجية عملاء كل منها؛ ويعكس **العملاء في الداخل** ذلك (العملاء في الداخل، والخوادم التي يستخدمها كل منهم في الخارج)، إذ كثيرًا ما يفسّر أحد الطرفين أكثر من الآخر. **الخدمات**: حلقة واحدة لأكثر الخدمات نشاطًا. مرّر المؤشر على جزء لترى حركته، وانقر عليه كأي قيمة |
| مسارات الحركة | أي مضيف يستخدم أي تطبيق نحو أي دولة: أكثر 8 مضيفات نشاطًا، والباقي ضمن «أخرى». ويعرض **العميل ← الخادم** العميل ← الخدمة ← الخادم؛ ويعرض **حسب المقطع** الشبكات بدل المضيفات. تُختصر الأسماء الطويلة إلى 22 حرفًا؛ مرّر المؤشر على أحدها لترى الاسم كاملًا |
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| الجغرافيا والشبكات | خريطة العالم للحركة حسب الدولة، مع خطوط من شبكاتك؛ الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| الإعدادات | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن بوحدة bits/s وpackets/s، الدخول (بالأخضر) والخروج (بالأزرق)، مع عدّادات الجهاز خطوطًا متقطعة؛ ومدى ابتعاد أرقام التدفقات عن العدّادات، الأسوأ أولًا، مع الأسباب |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن بوحدة bits/s، وتحتها packets/s، الدخول (بالأخضر) والخروج (بالأزرق)، مع عدّادات الجهاز خطوطًا متقطعة؛ ومدى ابتعاد أرقام التدفقات عن العدّادات، الأسوأ أولًا، مع الأسباب؛ واسم ووسم لكل واجهة، والواجهة الافتراضية |
| سجلات التدفق | كم سجل تدفق كان هناك ومتى (شريط لكل فترة)، والسجلات نفسها، الأحدث أولًا، صفحةً صفحة، مع أعمدة قابلة للاختيار. تُفتح على آخر 15 دقيقة، وتُحدَّث كل 5 ثوانٍ؛ وإذا فُتحت من قيمة في صفحة أخرى (**اعرض سجلات تدفقه**) فإنها تحتفظ بالنطاق الزمني لتلك الصفحة، ويعيدك **العودة إلى البث المباشر** |
| تنظيف البيانات | يحذف البيانات الأقدم من 120 أو 90 أو 60 أو 30 أو 7 أيام، أو كلها، مع مقدار ما يحرّره كل خيار ([المزيد](#13-data-backup-upgrade-uninstall)) |
| تحليل pcap دون اتصال | تحليل ملفات التقاط الحزم (pcap وpcapng) بمعزل عن البيانات الحية ([المزيد](#تحليل-pcap-دون-اتصال)) |
Expand All @@ -695,6 +702,15 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
تنظيف البيانات)، وتحليل pcap دون اتصال. وتحت الشعار يظهر الإصدار
وتاريخ الخادم ووقته.

فوق صفحات الحركة (نظرة عامة، أعلى 66، تفاصيل الحركة، مسارات الحركة، الجغرافيا
والشبكات، سجلات التدفق، وتفاصيل أي قيمة) يوجد **الواجهة**: **كل الواجهات**، أو
واجهة واحدة، فلا تعرض هذه الصفحات إلا الحركة المارّة عبرها (دخولًا أو خروجًا).
ويبدأ على الواجهة الافتراضية (★، تُضبط في **مطابقة الواجهات**)، والاختيار جزء من
الرابط. أما الاكتشافات ومعلومات التهديدات ومطابقة الواجهات والإعدادات فتغطي
دائمًا كل الحركة. ولواجهة واحدة على مدى 7 أو 30 يومًا تقرأ الصفحات سجلات التدفق
بدل الملخصات الساعية واليومية، فتستغرق وقتًا أطول ولا تعود إلى الوراء إلا بقدر
مدة الاحتفاظ بسجلات التدفق (30 يومًا افتراضيًا).

فوق الصفحات: النطاق الزمني (من 15 دقيقة إلى 30 يومًا، أو **مخصص…** لأي
بداية ونهاية، حتى أبعد من 30 يومًا)، وتحديث تلقائي كل 30 ثانية، و**نسخ
الرابط** الذي ينسخ رابطًا إلى العرض الحالي بالضبط (الصفحة والنطاق الزمني
Expand Down
Loading
Loading