explain.go 3.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128
  1. package main
  2. import (
  3. "bufio"
  4. "fmt"
  5. "os"
  6. "os/exec"
  7. "path/filepath"
  8. "github.com/crowdsecurity/crowdsec/pkg/cstest"
  9. log "github.com/sirupsen/logrus"
  10. "github.com/spf13/cobra"
  11. )
  12. func NewExplainCmd() *cobra.Command {
  13. /* ---- HUB COMMAND */
  14. var logFile string
  15. var dsn string
  16. var logLine string
  17. var logType string
  18. var opts cstest.DumpOpts
  19. var cmdExplain = &cobra.Command{
  20. Use: "explain",
  21. Short: "Explain log pipeline",
  22. Long: `
  23. Explain log pipeline
  24. `,
  25. Example: `
  26. cscli explain --file ./myfile.log --type nginx
  27. cscli explain --log "Sep 19 18:33:22 scw-d95986 sshd[24347]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=1.2.3.4" --type syslog
  28. cscli explain --dsn "file://myfile.log" --type nginx
  29. `,
  30. Args: cobra.ExactArgs(0),
  31. DisableAutoGenTag: true,
  32. Run: func(cmd *cobra.Command, args []string) {
  33. if logType == "" || (logLine == "" && logFile == "" && dsn == "") {
  34. printHelp(cmd)
  35. fmt.Println()
  36. fmt.Printf("Please provide --type flag\n")
  37. os.Exit(1)
  38. }
  39. // we create a temporary log file if a log line has been provided
  40. if logLine != "" {
  41. logFile = "./cscli_test_tmp.log"
  42. f, err := os.Create(logFile)
  43. if err != nil {
  44. log.Fatal(err)
  45. }
  46. defer f.Close()
  47. _, err = f.WriteString(logLine)
  48. if err != nil {
  49. log.Fatal(err)
  50. }
  51. }
  52. if logFile != "" {
  53. absolutePath, err := filepath.Abs(logFile)
  54. if err != nil {
  55. log.Fatalf("unable to get absolue path of '%s', exiting", logFile)
  56. }
  57. dsn = fmt.Sprintf("file://%s", absolutePath)
  58. lineCount := getLineCountForFile(absolutePath)
  59. if lineCount > 100 {
  60. log.Warnf("log file contains %d lines. This may take lot of resources.", lineCount)
  61. }
  62. }
  63. if dsn == "" {
  64. log.Fatal("no acquisition (--file or --dsn) provided, can't run cscli test.")
  65. }
  66. cmdArgs := []string{"-c", ConfigFilePath, "-type", logType, "-dsn", dsn, "-dump-data", "./", "-no-api"}
  67. crowdsecCmd := exec.Command("crowdsec", cmdArgs...)
  68. output, err := crowdsecCmd.CombinedOutput()
  69. if err != nil {
  70. fmt.Println(string(output))
  71. log.Fatalf("fail to run crowdsec for test: %v", err)
  72. }
  73. // rm the temporary log file if only a log line was provided
  74. if logLine != "" {
  75. if err := os.Remove(logFile); err != nil {
  76. log.Fatalf("unable to remove tmp log file '%s': %+v", logFile, err)
  77. }
  78. }
  79. parserDumpFile := filepath.Join("./", cstest.ParserResultFileName)
  80. bucketStateDumpFile := filepath.Join("./", cstest.BucketPourResultFileName)
  81. parserDump, err := cstest.LoadParserDump(parserDumpFile)
  82. if err != nil {
  83. log.Fatalf("unable to load parser dump result: %s", err)
  84. }
  85. bucketStateDump, err := cstest.LoadBucketPourDump(bucketStateDumpFile)
  86. if err != nil {
  87. log.Fatalf("unable to load bucket dump result: %s", err)
  88. }
  89. cstest.DumpTree(*parserDump, *bucketStateDump, opts)
  90. },
  91. }
  92. cmdExplain.PersistentFlags().StringVarP(&logFile, "file", "f", "", "Log file to test")
  93. cmdExplain.PersistentFlags().StringVarP(&dsn, "dsn", "d", "", "DSN to test")
  94. cmdExplain.PersistentFlags().StringVarP(&logLine, "log", "l", "", "Log line to test")
  95. cmdExplain.PersistentFlags().StringVarP(&logType, "type", "t", "", "Type of the acquisition to test")
  96. cmdExplain.PersistentFlags().BoolVarP(&opts.Details, "verbose", "v", false, "Display individual changes")
  97. cmdExplain.PersistentFlags().BoolVar(&opts.SkipOk, "failures", false, "Only show failed lines")
  98. return cmdExplain
  99. }
  100. func getLineCountForFile(filepath string) int {
  101. f, err := os.Open(filepath)
  102. if err != nil {
  103. log.Fatalf("unable to open log file %s", filepath)
  104. }
  105. defer f.Close()
  106. lc := 0
  107. fs := bufio.NewScanner(f)
  108. for fs.Scan() {
  109. lc++
  110. }
  111. return lc
  112. }