Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    New widget for havp

    Scheduled Pinned Locked Moved pfSense Packages
    24 Posts 3 Posters 9.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      Roodawakening
      last edited by

      @matrix200:

      Roodawakening,
      Check out the following thread :
      http://forum.pfsense.org/index.php/topic,16291.0.html

      So do you see anything in the widget now?

      Yes…I attempted to download the EICAR "viruses" (*.com, *.zip, etc.) and each attempt was neatly displaced in the widget. As was previously mentioned, it would be nice to have dates associated with each error so it's clear when HAVP flagged a suspicious file but the raw functionality is there. Great job, Matrix200, and thanks for helping me get this going.

      "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
      –Virgil, Aeneid, Book 6

      Rob

      1 Reply Last reply Reply Quote 0
      • R Offline
        Roodawakening
        last edited by

        Matrix200,

        Here's a screenshot of my Dashboard:

        "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
        –Virgil, Aeneid, Book 6

        Rob

        1 Reply Last reply Reply Quote 0
        • R Offline
          Roodawakening
          last edited by

          Matrix200…

          Just another suggestion/"wishlist": Is there any way to incorporate the dates of virus definitions into the widget? How about a button to update the definitions so users don't have to do it manually through the package itself? I'm not a programmer so I don't know if these suggestions are feasible.

          Anyway...I do like the widget and appreciate the time and effort you've put into it.

          "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
          –Virgil, Aeneid, Book 6

          Rob

          1 Reply Last reply Reply Quote 0
          • M Offline
            matrix200
            last edited by

            Roodawakening,

            Ok to answer your questions :
            1. I am not sure adding datetime is such a good idea since as you can see I am very much constrained in width of the line that I can use.
            We are looking into ways to make the widget more usable though and hopefully will come up with something soon.

            2. I am not sure what you mean with your second suggestion.
            The updates are done automatically through the havp configuration so there is no need to do that manually.
            Widget's job is to display virus alerts similarly to what snort widget does so I am not sure what is that you expect.

            Current network "hardware" :
            Running 2.2RC in Virtualbox 4.2.16.

            Retired:
            ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

            1 Reply Last reply Reply Quote 0
            • jimpJ Offline
              jimp Rebel Alliance Developer Netgate
              last edited by

              @matrix200:

              Ok to answer your questions :
              1. I am not sure adding datetime is such a good idea since as you can see I am very much constrained in width of the line that I can use.
              We are looking into ways to make the widget more usable though and hopefully will come up with something soon.

              You might be able to make Column #1 the Date and Virus name on two lines:

              | Date
              Virus | URL |

              That should give it plenty of room to wrap the URL as needed.
              Or alternately:

              | Date | Virus
              URL |

              That way you could dedicate more width to column #2.

              Edit: The tables apparently are white-on-white, not sure why, I'll look into it. Just highlight the text and you'll see what I originally put.

              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

              Need help fast? Netgate Global Support!

              Do not Chat/PM for help!

              1 Reply Last reply Reply Quote 0
              • M Offline
                matrix200
                last edited by

                Jim-p, thanks for the suggestion.
                I actually like the second one (that is date and then virus/url on the second column).
                I also think this could be great idea for Snort widget too.

                Current network "hardware" :
                Running 2.2RC in Virtualbox 4.2.16.

                Retired:
                ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                1 Reply Last reply Reply Quote 0
                • M Offline
                  matrix200
                  last edited by

                  Ok I have prepared the new version that looks like that :

                  Let me know if this is more useful.

                  Current network "hardware" :
                  Running 2.2RC in Virtualbox 4.2.16.

                  Retired:
                  ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                  1 Reply Last reply Reply Quote 0
                  • R Offline
                    Roodawakening
                    last edited by

                    @matrix200:

                    Ok I have prepared the new version that looks like that :

                    Let me know if this is more useful.

                    Excellent. I find it more useful because now I know when a particular alert was received. I often due EICAR test files to make sure HAVP is working correctly (because, fortunately, I have no true virus files to flag) and it's nice to know on what date (and time) my test was successful.

                    How do I download the new version?

                    Thanks…

                    "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
                    –Virgil, Aeneid, Book 6

                    Rob

                    1 Reply Last reply Reply Quote 0
                    • jimpJ Offline
                      jimp Rebel Alliance Developer Netgate
                      last edited by

                      @Roodawakening:

                      How do I download the new version?

                      I'll put it in the Dashboard package and update it in the next few days, then just update the Dashboard when you see a new version.

                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                      Need help fast? Netgate Global Support!

                      Do not Chat/PM for help!

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        matrix200
                        last edited by

                        Ok just to let everybody know the new version with the new look has been released.
                        Thanks to Jim-P as always :)
                        Please use this thread to report any issues with it.

                        Current network "hardware" :
                        Running 2.2RC in Virtualbox 4.2.16.

                        Retired:
                        ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                        1 Reply Last reply Reply Quote 0
                        • R Offline
                          Roodawakening
                          last edited by

                          For whatever reason, the times and dates never change. I attempt to download EICAR test viruses, HAVP blocks them, but only those from two weeks ago show up.

                          "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
                          –Virgil, Aeneid, Book 6

                          Rob

                          1 Reply Last reply Reply Quote 0
                          • M Offline
                            matrix200
                            last edited by

                            Hmm, this probably means that logging has been turned off so nothing new gets added to the log.
                            Can you make sure the havp logging is on in the UI?

                            Current network "hardware" :
                            Running 2.2RC in Virtualbox 4.2.16.

                            Retired:
                            ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                            1 Reply Last reply Reply Quote 0
                            • R Offline
                              Roodawakening
                              last edited by

                              @matrix200:

                              Hmm, this probably means that logging has been turned off so nothing new gets added to the log.
                              Can you make sure the havp logging is on in the UI?

                              I thought that was the problem, too, but look…

                              "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
                              –Virgil, Aeneid, Book 6

                              Rob

                              1 Reply Last reply Reply Quote 0
                              • M Offline
                                matrix200
                                last edited by

                                From my experience if both syslog and logfile are checked only syslog works.
                                Can you try disabling syslog and try again?

                                Current network "hardware" :
                                Running 2.2RC in Virtualbox 4.2.16.

                                Retired:
                                ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                                1 Reply Last reply Reply Quote 0
                                • R Offline
                                  Roodawakening
                                  last edited by

                                  That fixed it but I had to disable Syslog in both the 'HTTP Proxy' and 'Settings' tabs found under Services–>Antivirus

                                  Anyways…thanks for your work.

                                  "The descent to hell is easy. The gates stand open day and night. But to reclimb the slope and escape to the upper air: This is labor."
                                  –Virgil, Aeneid, Book 6

                                  Rob

                                  1 Reply Last reply Reply Quote 0
                                  • M Offline
                                    matrix200
                                    last edited by

                                    Yeah, this is a bug in havp which dvserg should fix.

                                    Current network "hardware" :
                                    Running 2.2RC in Virtualbox 4.2.16.

                                    Retired:
                                    ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                                    1 Reply Last reply Reply Quote 0
                                    • M Offline
                                      matrix200
                                      last edited by

                                      Ok I found a bug in the widget that would cause sorting by date to mess up.
                                      This happens if you have widget open for a while but there are no updates.
                                      There is a fix that will be released when the next dashboard version is out.
                                      My apologies

                                      Current network "hardware" :
                                      Running 2.2RC in Virtualbox 4.2.16.

                                      Retired:
                                      ALIX2C2 , 4 gigabyte disk cf card running 2.0 (official release).

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.