إنتقل إلى المحتوى الرئيسي

Dashboard

Your PiRogue runs a Grafana dashboard that shows, in near real time, the network connections of the connected devices and the security alerts raised by Suricata.

Overview of the PiRogue dashboard
Overview of the PiRogue dashboard
Data retention

The PiRogue keeps 5 days of history. Older data is automatically deleted. To keep it, see Export data.

Use the time picker at the top right to choose the period displayed by every panel.

General statistics​

Five figures summarize the selected period:

  • Connected devices: the number of different devices that connected to the PiRogue
  • Security alerts: the number of alerts raised by Suricata rules, which may indicate an intrusion attempt, malicious activity or a policy violation
  • Network I/O: the amount of data exchanged between the devices and the Internet
  • Network flows: the number of communication sessions between the devices and remote servers
  • Contacted domains: the number of different domain names contacted

World map​

The location of the servers the devices communicated with. A quick way to spot a country you did not expect.

Network flows​

One row per network flow:

ColumnMeaning
TimeWhen the flow started
CategoryThe type of traffic, as classified by NFStream
ApplicationThe application that generated the flow
DomainThe name of the contacted server
Source / DestinationThe IP addresses of both ends of the flow
CountryWhere the remote server is located
VolumeThe amount of data exchanged

Sort and filter this list to find patterns: which application talks the most, which domain appears only at night, and so on.

Security alerts​

One row per alert raised by Suricata:

ColumnMeaning
TimeWhen the alert was raised. Click it to open the details of the alert
SeverityHow urgent the detected threat is
CategoryThe type of threat
SignatureThe name of the rule that matched
Source / DestinationThe IP addresses involved. Depending on the rule, the source is the origin of the threat or the destination is the target

To understand exactly why an alert fired, look up its signature: see Suricata rules.