Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 15 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,21 @@
The release notes on GitHub are taken from this file: the section whose
heading is the version number.

## 1.2.4

Interfaces
- The interfaces a device samples are told from the ones only seen as the
other end of its flows: by the sFlow data source, by flowDirection
(IPFIX 61) in NetFlow v9 and IPFIX, or else, without that field, as the
interface on at least 90% of the device's traffic.
- Interface check lists those other interfaces last, in smaller grey type,
under "Peer interfaces": their numbers hold only the traffic through the
sampled interface. Their charts say so.
- **Interface** above the pages lists only sampled interfaces, grouped by
device.
- Settings shows for each device the interfaces it samples, and whether its
NetFlow/IPFIX templates carry flowDirection.

## 1.2.3

Interfaces
Expand Down
22 changes: 19 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -528,6 +528,21 @@ makes it the default interface (**★**); there is one default. The pages
then open on it (see the **Interface** choice under [Using the web UI](#9-using-the-web-ui)), and the overview shows its
bandwidth. Both are saved at once to the `iface` line in Names.

Flow records name two interfaces: the one a packet came in on and the one
it left by. A device that samples only some interfaces therefore shows
the other ends of their flows too. Those **peer interfaces** are listed
last, in smaller grey type, under their own heading: their numbers hold
only the traffic that went through a sampled interface, not all of their
traffic. They are not offered under **Interface** above the pages.
traffic66 knows which interface sampled a flow from the sFlow data source,
or from the flowDirection field (IPFIX 61) of NetFlow v9 and IPFIX (ingress:
the input interface, egress: the output interface). Without that field, an
interface on at least 90% of a device's traffic is taken as the sampled
one; when there is none, no interface is marked. **Settings** shows, for
each device, the sampled interfaces and whether its templates carry
flowDirection. To see all of a device's traffic, sample every interface
inbound (see [Send flows from your devices](#4-send-flows-from-your-devices)).

![Interface check: traffic of every interface, and the flow estimate next to the device counter](docs/images/interfaces.png)

To get counters to compare with:
Expand Down Expand Up @@ -688,7 +703,7 @@ Pages:
| Findings | What needs attention: scans, password guessing, lateral movement, unusual uploads, floods and threat list traffic ([more](#findings)) |
| Threat intel | Hosts that talked to addresses on your threat lists, and how much they sent |
| Geo & networks | A world map of traffic by country, with lines from your networks; the networks (AS) traffic came from and went to, over time in bits/s and packets/s; traffic by country and by network |
| Settings | Devices, sampling, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |
| Settings | Devices, sampling, the interfaces each device samples and whether it sends flowDirection, loss, collectors, SNMP, the countries and networks database, the logo, and **Names** |
| Interface check | Traffic of every interface over time in bits/s and, below, packets/s, ingress (green) and egress (blue), with the device counters as dashed lines; how far the flow numbers are from the counters, worst first, with reasons; a name, a tag and the default for each interface |
| Flow records | How many flow records there were and when (a bar per interval), and the records themselves, newest first, page by page, with selectable columns. Opens on the last 15 minutes, updated every 5 seconds; opened from a value on another page (**Show its flow records**) it keeps that page's time range, and **Back to live** returns |
| Data cleanup | Deletes data older than 120, 90, 60, 30 or 7 days, or all of it, with how much each frees ([more](#13-data-backup-upgrade-uninstall)) |
Expand All @@ -703,8 +718,9 @@ server's date and time.
Above the traffic pages (Overview, Top 66, Traffic details, Flow paths,
Geo & networks, Flow records and the detail of a value) is **Interface**:
**All interfaces**, or one interface, so that these pages show only the
traffic through it (in or out). It starts on the default interface (★,
set on **Interface check**) and the choice is part of the link. Findings,
traffic through it (in or out). It lists the sampled interfaces, grouped
by device, and starts on the default interface (★, set on **Interface
check**) and the choice is part of the link. Findings,
Threat intel, Interface check and Settings always cover all traffic. For
one interface over 7 or 30 days the pages read the flow records rather
than the hourly and daily summaries, so they take longer and reach back
Expand Down
18 changes: 16 additions & 2 deletions docs/README.ar.md
Original file line number Diff line number Diff line change
Expand Up @@ -549,6 +549,19 @@ packets/s، فيهما الدخول (بالأخضر) والخروج (بالأز
[استخدام واجهة الويب](#9-using-the-web-ui))، وتعرض النظرة العامة عرض نطاقها الترددي.
ويُحفظ كلاهما فورًا في سطر `iface` في **الأسماء**.

تذكر سجلات التدفق واجهتين: التي دخلت منها الحزمة والتي خرجت منها. لذلك يعرض
الجهاز الذي يأخذ العينات من بعض واجهاته فقط الأطرافَ الأخرى لتدفقاتها أيضًا.
تُدرَج **واجهات الطرف الآخر** هذه في الآخر، بخط أصغر رمادي، تحت عنوان خاص بها:
فأرقامها لا تحوي إلا الحركة التي مرّت عبر واجهة مأخوذ منها العينات، لا كل
حركتها. ولا تُعرض ضمن **الواجهة** فوق الصفحات. يعرف traffic66 الواجهة التي أُخذت
منها عينة التدفق من مصدر بيانات sFlow، أو من الحقل flowDirection (IPFIX 61) في
NetFlow v9 وIPFIX (ingress: واجهة الدخول، egress: واجهة الخروج). وبدون هذا
الحقل، تُعدّ الواجهة الموجودة في 90% على الأقل من حركة الجهاز هي المأخوذ منها
العينات؛ وإن لم توجد فلا تُعلَّم أي واجهة. وتعرض **الإعدادات** لكل جهاز الواجهات
المأخوذ منها العينات (**العينات من**)، وهل تحمل قوالبه flowDirection (**مع
flowDirection (61)**). ولرؤية كل حركة الجهاز، خذ العينات من كل واجهة في اتجاه
الدخول (انظر [إرسال التدفقات من أجهزتك](#4-send-flows-from-your-devices)).

![مطابقة الواجهات: حركة كل واجهة، وتقدير التدفقات بجوار عدّاد الجهاز](images/interfaces.png)

للحصول على عدّادات للمقارنة:
Expand Down Expand Up @@ -690,7 +703,7 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
| الاكتشافات | ما يستدعي الانتباه: عمليات المسح، وتخمين كلمات المرور، والتحرك الجانبي، وعمليات الرفع غير المعتادة، والإغراق، وحركة قوائم التهديدات ([المزيد](#findings)) |
| معلومات التهديدات | المضيفات التي تواصلت مع عناوين في قوائم تهديداتك، وكم أرسلت |
| الجغرافيا والشبكات | خريطة العالم للحركة حسب الدولة، مع خطوط من شبكاتك؛ الشبكات (AS) التي جاءت منها الحركة وذهبت إليها، عبر الزمن بوحدة bits/s وpackets/s؛ والحركة حسب الدولة وحسب الشبكة |
| الإعدادات | الأجهزة، وأخذ العينات، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |
| الإعدادات | الأجهزة، وأخذ العينات، والواجهات التي يأخذ منها كل جهاز العينات وهل يرسل flowDirection، والفقد، والمستقبِلات، وSNMP، وقاعدة بيانات الدول والشبكات، والشعار، و**الأسماء** |
| مطابقة الواجهات | حركة كل واجهة عبر الزمن بوحدة bits/s، وتحتها packets/s، الدخول (بالأخضر) والخروج (بالأزرق)، مع عدّادات الجهاز خطوطًا متقطعة؛ ومدى ابتعاد أرقام التدفقات عن العدّادات، الأسوأ أولًا، مع الأسباب؛ واسم ووسم لكل واجهة، والواجهة الافتراضية |
| سجلات التدفق | كم سجل تدفق كان هناك ومتى (شريط لكل فترة)، والسجلات نفسها، الأحدث أولًا، صفحةً صفحة، مع أعمدة قابلة للاختيار. تُفتح على آخر 15 دقيقة، وتُحدَّث كل 5 ثوانٍ؛ وإذا فُتحت من قيمة في صفحة أخرى (**اعرض سجلات تدفقه**) فإنها تحتفظ بالنطاق الزمني لتلك الصفحة، ويعيدك **العودة إلى البث المباشر** |
| تنظيف البيانات | يحذف البيانات الأقدم من 120 أو 90 أو 60 أو 30 أو 7 أيام، أو كلها، مع مقدار ما يحرّره كل خيار ([المزيد](#13-data-backup-upgrade-uninstall)) |
Expand All @@ -705,7 +718,8 @@ curl -L https://www.spamhaus.org/drop/drop.txt -o <data directory>/threats/spamh
فوق صفحات الحركة (نظرة عامة، أعلى 66، تفاصيل الحركة، مسارات الحركة، الجغرافيا
والشبكات، سجلات التدفق، وتفاصيل أي قيمة) يوجد **الواجهة**: **كل الواجهات**، أو
واجهة واحدة، فلا تعرض هذه الصفحات إلا الحركة المارّة عبرها (دخولًا أو خروجًا).
ويبدأ على الواجهة الافتراضية (★، تُضبط في **مطابقة الواجهات**)، والاختيار جزء من
ويسرد الواجهات المأخوذ منها العينات مجمّعةً حسب الجهاز، ويبدأ على
الواجهة الافتراضية (★، تُضبط في **مطابقة الواجهات**)، والاختيار جزء من
الرابط. أما الاكتشافات ومعلومات التهديدات ومطابقة الواجهات والإعدادات فتغطي
دائمًا كل الحركة. ولواجهة واحدة على مدى 7 أو 30 يومًا تقرأ الصفحات سجلات التدفق
بدل الملخصات الساعية واليومية، فتستغرق وقتًا أطول ولا تعود إلى الوراء إلا بقدر
Expand Down
20 changes: 18 additions & 2 deletions docs/README.bn.md
Original file line number Diff line number Diff line change
Expand Up @@ -556,6 +556,21 @@ egress (নীল) থাকে; ডিভাইসের নিজের counte
([web UI ব্যবহার](#9-using-the-web-ui)-এ **ইন্টারফেস** বাছাই দেখুন), এবং সারসংক্ষেপ
এর bandwidth দেখায়। দুটোই সঙ্গে সঙ্গে **নাম**-এর `iface` লাইনে সংরক্ষিত হয়।

Flow record-এ দুটি interface থাকে: যেটি দিয়ে packet এসেছে এবং যেটি দিয়ে
বেরিয়েছে। তাই যে ডিভাইস শুধু কিছু interface স্যাম্পল করে, সেটি তাদের flow-এর
অন্য প্রান্তগুলোও দেখায়। এই **বিপরীত ইন্টারফেস** তালিকার শেষে, ছোট ধূসর লেখায়,
নিজস্ব শিরোনামের নিচে দেখানো হয়: তাদের সংখ্যায় শুধু সেই ট্রাফিক থাকে যা কোনো
স্যাম্পল করা interface দিয়ে গেছে, তাদের সব ট্রাফিক নয়। পেজগুলোর ওপরের
**ইন্টারফেস**-এ এগুলো দেওয়া হয় না। কোন interface একটি flow স্যাম্পল করেছে,
traffic66 তা জানে sFlow-এর data source থেকে, অথবা NetFlow v9 ও IPFIX-এর
flowDirection field (IPFIX 61) থেকে (ingress: input interface, egress: output
interface)। এই field না থাকলে, যে interface ডিভাইসের অন্তত 90% ট্রাফিকে আছে
সেটিকে স্যাম্পল করা ধরা হয়; এমন কোনোটি না থাকলে কোনো interface চিহ্নিত হয় না।
**সেটিংস** প্রতিটি ডিভাইসের **স্যাম্পল ইন্টারফেস** দেখায়, এবং তার template
**flowDirection (61) সহ** কি না। ডিভাইসের সব ট্রাফিক দেখতে প্রতিটি interface
inbound স্যাম্পল করুন ([আপনার ডিভাইস থেকে flow
পাঠান](#4-send-flows-from-your-devices) দেখুন)।

![ইন্টারফেস মিলানো: প্রতিটি interface-এর ট্রাফিক, আর ডিভাইসের counter-এর পাশে flow-এর অনুমান](images/interfaces.png)

তুলনার জন্য counter পেতে:
Expand Down Expand Up @@ -702,7 +717,7 @@ application, দেশ, ডিভাইস — ক্লিক করা যা
| সন্দেহজনক কার্যকলাপ | কীসে নজর দিতে হবে: scan, পাসওয়ার্ড অনুমান, lateral movement, অস্বাভাবিক upload, flood আর threat list-এর ট্রাফিক ([আরও](#findings)) |
| হুমকির তথ্য | যেসব host আপনার threat list-এর address-এর সাথে কথা বলেছে, এবং কতটা পাঠিয়েছে |
| ভূগোল ও নেটওয়ার্ক | দেশ অনুযায়ী ট্রাফিকের বিশ্ব মানচিত্র, আপনার নেটওয়ার্ক থেকে রেখা সহ; যেসব নেটওয়ার্ক (AS) থেকে ট্রাফিক এসেছে ও যেখানে গেছে, সময়ের সাথে bits/s ও packets/s-এ; দেশ ও নেটওয়ার্ক অনুযায়ী ট্রাফিক |
| সেটিংস | ডিভাইস, sampling, loss, collector, SNMP, দেশ ও নেটওয়ার্ক ডেটাবেস, লোগো, এবং **নাম** |
| সেটিংস | ডিভাইস, sampling, প্রতিটি ডিভাইস কোন interface স্যাম্পল করে ও flowDirection পাঠায় কি না, loss, collector, SNMP, দেশ ও নেটওয়ার্ক ডেটাবেস, লোগো, এবং **নাম** |
| ইন্টারফেস মিলানো | সময়ের সাথে প্রতিটি interface-এর ট্রাফিক bits/s-এ এবং, নিচে, packets/s-এ, ingress (সবুজ) ও egress (নীল), ডিভাইসের counter ড্যাশ রেখা হিসেবে; flow-এর সংখ্যা counter থেকে কতটা দূরে, সবচেয়ে খারাপগুলো আগে, কারণসহ; প্রতিটি interface-এর জন্য একটি নাম, একটি ট্যাগ ও ডিফল্ট |
| ফ্লো রেকর্ড | কতগুলো flow record ছিল এবং কখন (প্রতি interval-এ একটি bar), আর record-গুলো নিজেই, নতুনগুলো আগে, পেজ ধরে ধরে, বেছে নেওয়া যায় এমন column সহ। শেষ 15 মিনিট দিয়ে খোলে, প্রতি 5 সেকেন্ডে আপডেট হয়; অন্য পেজের কোনো value থেকে (**এর ফ্লো রেকর্ড দেখুন**) খুললে সেই পেজের সময়সীমা রাখে, আর **লাইভে ফিরুন** আবার লাইভে নিয়ে যায় |
| ডেটা পরিষ্কার | 120, 90, 60, 30 বা 7 দিনের চেয়ে পুরোনো ডেটা, বা সব ডেটা মুছে দেয়, প্রতিটিতে কতটা জায়গা খালি হয় তা সহ ([আরও](#13-data-backup-upgrade-uninstall)) |
Expand All @@ -717,7 +732,8 @@ application, দেশ, ডিভাইস — ক্লিক করা যা
ট্রাফিক পেজগুলোর (সারসংক্ষেপ, শীর্ষ 66, ট্রাফিকের বিস্তারিত, ট্রাফিকের পথ, ভূগোল ও
নেটওয়ার্ক, ফ্লো রেকর্ড এবং কোনো value-এর বিস্তারিত) ওপরে **ইন্টারফেস** আছে:
**সব ইন্টারফেস**, অথবা একটি interface, যাতে এই পেজগুলো শুধু সেটির মধ্য দিয়ে
যাওয়া ট্রাফিক (আগত বা বহির্গামী) দেখায়। এটি ডিফল্ট interface (★, **ইন্টারফেস
যাওয়া ট্রাফিক (আগত বা বহির্গামী) দেখায়। এতে স্যাম্পল ইন্টারফেসগুলো ডিভাইস অনুযায়ী
দলে দেখানো হয়, এবং এটি ডিফল্ট interface (★, **ইন্টারফেস
মিলানো**-তে ঠিক করা) দিয়ে শুরু হয় এবং বাছাইটি লিংকের অংশ। সন্দেহজনক কার্যকলাপ,
হুমকির তথ্য, ইন্টারফেস মিলানো ও সেটিংস সবসময় সব ট্রাফিক দেখায়। 7 বা 30 দিনের
জন্য একটি interface বাছলে পেজগুলো ঘণ্টা ও দিনের summary-র বদলে flow record
Expand Down
Loading
Loading