explain.go 3.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111
  1. package main
  2. import (
  3. "fmt"
  4. "os"
  5. "os/exec"
  6. "path/filepath"
  7. "github.com/crowdsecurity/crowdsec/pkg/cstest"
  8. log "github.com/sirupsen/logrus"
  9. "github.com/spf13/cobra"
  10. )
  11. func NewExplainCmd() *cobra.Command {
  12. /* ---- HUB COMMAND */
  13. var logFile string
  14. var dsn string
  15. var logLine string
  16. var logType string
  17. var details bool
  18. var cmdExplain = &cobra.Command{
  19. Use: "explain",
  20. Short: "Explain log pipeline",
  21. Long: `
  22. Explain log pipeline
  23. `,
  24. Example: `
  25. cscli explain --file ./myfile.log --type nginx
  26. cscli explain --log "Sep 19 18:33:22 scw-d95986 sshd[24347]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=1.2.3.4" --type syslog
  27. cscli explain -dsn "file://myfile.log" --type nginx
  28. `,
  29. Args: cobra.ExactArgs(0),
  30. DisableAutoGenTag: true,
  31. Run: func(cmd *cobra.Command, args []string) {
  32. if logType == "" || (logLine == "" && logFile == "" && dsn == "") {
  33. cmd.Help()
  34. fmt.Println()
  35. fmt.Printf("Please provide --type flag\n")
  36. os.Exit(1)
  37. }
  38. // we create a temporary log file if a log line has been provided
  39. if logLine != "" {
  40. logFile = "./cscli_test_tmp.log"
  41. f, err := os.Create(logFile)
  42. if err != nil {
  43. log.Fatal(err)
  44. }
  45. defer f.Close()
  46. _, err = f.WriteString(logLine)
  47. if err != nil {
  48. log.Fatal(err)
  49. }
  50. }
  51. if logFile != "" {
  52. absolutePath, err := filepath.Abs(logFile)
  53. if err != nil {
  54. log.Fatalf("unable to get absolue path of '%s', exiting", logFile)
  55. }
  56. dsn = fmt.Sprintf("file://%s", absolutePath)
  57. }
  58. if dsn == "" {
  59. log.Fatal("no acquisition (--file or --dsn) provided, can't run cscli test.")
  60. }
  61. cmdArgs := []string{"-c", ConfigFilePath, "-type", logType, "-dsn", dsn, "-dump-data", "./", "-no-api"}
  62. crowdsecCmd := exec.Command("crowdsec", cmdArgs...)
  63. output, err := crowdsecCmd.CombinedOutput()
  64. if err != nil {
  65. fmt.Println(string(output))
  66. log.Fatalf("fail to run crowdsec for test: %v", err)
  67. }
  68. // rm the temporary log file if only a log line was provided
  69. if logLine != "" {
  70. if err := os.Remove(logFile); err != nil {
  71. log.Fatalf("unable to remove tmp log file '%s': %+v", logFile, err)
  72. }
  73. }
  74. parserDumpFile := filepath.Join("./", cstest.ParserResultFileName)
  75. bucketStateDumpFile := filepath.Join("./", cstest.BucketPourResultFileName)
  76. parserDump, err := cstest.LoadParserDump(parserDumpFile)
  77. if err != nil {
  78. log.Fatalf("unable to load parser dump result: %s", err)
  79. }
  80. bucketStateDump, err := cstest.LoadBucketPourDump(bucketStateDumpFile)
  81. if err != nil {
  82. log.Fatalf("unable to load bucket dump result: %s", err)
  83. }
  84. if err := cstest.DumpTree(*parserDump, *bucketStateDump, details); err != nil {
  85. log.Fatalf(err.Error())
  86. }
  87. },
  88. }
  89. cmdExplain.PersistentFlags().StringVarP(&logFile, "file", "f", "", "Log file to test")
  90. cmdExplain.PersistentFlags().StringVarP(&dsn, "dsn", "d", "", "DSN to test")
  91. cmdExplain.PersistentFlags().StringVarP(&logLine, "log", "l", "", "Lgg line to test")
  92. cmdExplain.PersistentFlags().StringVarP(&logType, "type", "t", "", "Type of the acquisition to test")
  93. cmdExplain.PersistentFlags().BoolVarP(&details, "verbose", "v", false, "Display individual changes")
  94. return cmdExplain
  95. }