explain.go 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117
  1. package main
  2. import (
  3. "fmt"
  4. "os"
  5. "os/exec"
  6. "path/filepath"
  7. "github.com/crowdsecurity/crowdsec/pkg/cstest"
  8. "github.com/crowdsecurity/crowdsec/pkg/types"
  9. log "github.com/sirupsen/logrus"
  10. "github.com/spf13/cobra"
  11. )
  12. func NewExplainCmd() *cobra.Command {
  13. /* ---- HUB COMMAND */
  14. var logFile string
  15. var dsn string
  16. var logLine string
  17. var logType string
  18. var opts cstest.DumpOpts
  19. var cmdExplain = &cobra.Command{
  20. Use: "explain",
  21. Short: "Explain log pipeline",
  22. Long: `
  23. Explain log pipeline
  24. `,
  25. Example: `
  26. cscli explain --file ./myfile.log --type nginx
  27. cscli explain --log "Sep 19 18:33:22 scw-d95986 sshd[24347]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=1.2.3.4" --type syslog
  28. cscli explain --dsn "file://myfile.log" --type nginx
  29. `,
  30. Args: cobra.ExactArgs(0),
  31. DisableAutoGenTag: true,
  32. Run: func(cmd *cobra.Command, args []string) {
  33. if logType == "" || (logLine == "" && logFile == "" && dsn == "") {
  34. printHelp(cmd)
  35. fmt.Println()
  36. fmt.Printf("Please provide --type flag\n")
  37. os.Exit(1)
  38. }
  39. var f *os.File
  40. // we create a temporary log file if a log line has been provided
  41. if logLine != "" {
  42. logFile = "./cscli_test_tmp.log"
  43. f, err := os.Create(logFile) // nolint: govet
  44. if err != nil {
  45. log.Fatal(err)
  46. }
  47. defer f.Close()
  48. _, err = f.WriteString(logLine)
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. }
  53. if logFile != "" {
  54. absolutePath, err := filepath.Abs(logFile)
  55. if err != nil {
  56. log.Fatalf("unable to get absolute path of '%s', exiting", logFile)
  57. }
  58. dsn = fmt.Sprintf("file://%s", absolutePath)
  59. lineCount := types.GetLineCountForFile(absolutePath)
  60. if lineCount > 100 {
  61. log.Warnf("log file contains %d lines. This may take lot of resources.", lineCount)
  62. }
  63. }
  64. if dsn == "" {
  65. log.Fatal("no acquisition (--file or --dsn) provided, can't run cscli test.")
  66. }
  67. cmdArgs := []string{"-c", ConfigFilePath, "-type", logType, "-dsn", dsn, "-dump-data", "./", "-no-api"}
  68. crowdsecCmd := exec.Command("crowdsec", cmdArgs...)
  69. output, err := crowdsecCmd.CombinedOutput()
  70. if err != nil {
  71. fmt.Println(string(output))
  72. log.Fatalf("fail to run crowdsec for test: %v", err)
  73. }
  74. // rm the temporary log file if only a log line was provided
  75. if logLine != "" {
  76. f.Close()
  77. if err := os.Remove(logFile); err != nil {
  78. log.Fatalf("unable to remove tmp log file '%s': %+v", logFile, err)
  79. }
  80. }
  81. parserDumpFile := filepath.Join("./", cstest.ParserResultFileName)
  82. bucketStateDumpFile := filepath.Join("./", cstest.BucketPourResultFileName)
  83. parserDump, err := cstest.LoadParserDump(parserDumpFile)
  84. if err != nil {
  85. log.Fatalf("unable to load parser dump result: %s", err)
  86. }
  87. bucketStateDump, err := cstest.LoadBucketPourDump(bucketStateDumpFile)
  88. if err != nil {
  89. log.Fatalf("unable to load bucket dump result: %s", err)
  90. }
  91. cstest.DumpTree(*parserDump, *bucketStateDump, opts)
  92. },
  93. }
  94. cmdExplain.PersistentFlags().StringVarP(&logFile, "file", "f", "", "Log file to test")
  95. cmdExplain.PersistentFlags().StringVarP(&dsn, "dsn", "d", "", "DSN to test")
  96. cmdExplain.PersistentFlags().StringVarP(&logLine, "log", "l", "", "Log line to test")
  97. cmdExplain.PersistentFlags().StringVarP(&logType, "type", "t", "", "Type of the acquisition to test")
  98. cmdExplain.PersistentFlags().BoolVarP(&opts.Details, "verbose", "v", false, "Display individual changes")
  99. cmdExplain.PersistentFlags().BoolVar(&opts.SkipOk, "failures", false, "Only show failed lines")
  100. return cmdExplain
  101. }