Page MenuHomePhabricator

fastnetmon misreports attack type and protocol
Closed, ResolvedPublic

Description

Since about Dec 1st*, fastnetmon seems to only ever report Attack type: unknown and Attack protocol: tcp, regardless of the kind of traffic that triggers it.

Details

Event Timeline

Restricted Application added a subscriber: Aklapper. · View Herald Transcript
jcrespo triaged this task as Medium priority.Dec 26 2019, 10:59 AM

Known issue: https://github.com/pavel-odintsov/fastnetmon/issues/787#issuecomment-570740316
I don't see it being solved anytime soon.

Also added a "limitations" section to the doc: https://wikitech.wikimedia.org/wiki/Netflow#Limitations

Change 562387 had a related patch set uploaded (by CDanis; owner: CDanis):
[operations/puppet@production] fastnetmon: remove UDP and ICMP limits

https://gerrit.wikimedia.org/r/562387

Change 562387 merged by CDanis:
[operations/puppet@production] fastnetmon: remove UDP and ICMP limits

https://gerrit.wikimedia.org/r/562387

CDanis changed the task status from Open to Stalled.Jan 9 2020, 3:11 PM

Believe this has been worked around for now.

CDanis claimed this task.