- Add DeviceDetailModal with 8 tabs (Info, Flows, Apps, Encryption, Servers, Password Leaks, IP Reputation, VPN & Events) - Make device cards in AgentDetailModal clickable (nested modal drill-down) - Expand fetchDeviceDetails backend to query all 10 correlated tables (devices, flows, intel_device_discovery, intel_encryption_audit, intel_server_discovery, intel_unencrypted_passwords, intel_ip_reputation, intel_vpn_detection, events, mac_bandwidth) - Smart combined app/domain display: prioritize actual domain names over port-only labels (Port 443 -> scontent.fcgk42-1.fna.fbcdn.net) - Update Flows tab: domain shown in teal monospace, protocols in purple, port-only entries muted - Add 10 new TypeScript interfaces for device detail data types - Add MAC address fallback queries (by MAC when IP yields no results) - Fix fmtBytes for very large values
39 lines
1.6 KiB
JavaScript
39 lines
1.6 KiB
JavaScript
const db = require('../backend/database').getDB();
|
|
|
|
// Check all flows - how many have domain vs just port
|
|
const stats = db.prepare(`
|
|
SELECT
|
|
COUNT(*) as total,
|
|
SUM(CASE WHEN domain IS NOT NULL THEN 1 ELSE 0 END) as with_domain,
|
|
SUM(CASE WHEN app_label IS NOT NULL AND app_label NOT LIKE 'Port %' THEN 1 ELSE 0 END) as named_app,
|
|
SUM(CASE WHEN app_label LIKE 'Port %' THEN 1 ELSE 0 END) as port_only,
|
|
SUM(CASE WHEN app_label IS NULL AND domain IS NULL THEN 1 ELSE 0 END) as both_null
|
|
FROM flows
|
|
`).get();
|
|
console.log('Flow stats:', stats);
|
|
|
|
// What are the unique domain values?
|
|
const uniqueDomains = db.prepare(`SELECT DISTINCT domain FROM flows WHERE domain IS NOT NULL LIMIT 20`).all();
|
|
console.log('\nUnique domains in DB:', uniqueDomains.length);
|
|
uniqueDomains.forEach(r => console.log(' ', r.domain));
|
|
|
|
// What devices have domain data, and how many?
|
|
console.log('\n\nDevices with domain+app data:');
|
|
const devDomains = db.prepare(`
|
|
SELECT src_ip, src_mac,
|
|
COUNT(*) total_flows,
|
|
SUM(CASE WHEN domain IS NOT NULL THEN 1 ELSE 0 END) domain_flows,
|
|
SUM(CASE WHEN app_label IS NOT NULL AND app_label NOT LIKE 'Port %' THEN 1 ELSE 0 END) named_flows,
|
|
GROUP_CONCAT(DISTINCT domain) sample_domains
|
|
FROM flows
|
|
WHERE domain IS NOT NULL OR (app_label IS NOT NULL AND app_label NOT LIKE 'Port %')
|
|
GROUP BY src_ip
|
|
ORDER BY domain_flows DESC
|
|
LIMIT 10
|
|
`).all();
|
|
devDomains.forEach(r => {
|
|
const {sample_domains, ...rest} = r;
|
|
console.log(JSON.stringify(rest));
|
|
if (sample_domains) console.log(' domains:', sample_domains.split(',').slice(0,3).join(', '));
|
|
});
|