2021-10-04 15:14:52 +00:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
2022-06-23 09:51:43 +00:00
|
|
|
"bufio"
|
2021-10-04 15:14:52 +00:00
|
|
|
"fmt"
|
2022-06-23 09:51:43 +00:00
|
|
|
"io"
|
2021-10-04 15:14:52 +00:00
|
|
|
"os"
|
|
|
|
"os/exec"
|
|
|
|
"path/filepath"
|
|
|
|
|
|
|
|
log "github.com/sirupsen/logrus"
|
|
|
|
"github.com/spf13/cobra"
|
2022-10-13 10:28:24 +00:00
|
|
|
|
2022-10-17 07:24:07 +00:00
|
|
|
"github.com/crowdsecurity/crowdsec/pkg/hubtest"
|
2021-10-04 15:14:52 +00:00
|
|
|
)
|
|
|
|
|
2023-08-24 07:44:46 +00:00
|
|
|
func GetLineCountForFile(filepath string) (int, error) {
|
|
|
|
f, err := os.Open(filepath)
|
|
|
|
if err != nil {
|
|
|
|
return 0, err
|
|
|
|
}
|
|
|
|
defer f.Close()
|
|
|
|
lc := 0
|
|
|
|
fs := bufio.NewScanner(f)
|
|
|
|
for fs.Scan() {
|
|
|
|
lc++
|
|
|
|
}
|
|
|
|
return lc, nil
|
|
|
|
}
|
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
func runExplain(cmd *cobra.Command, args []string) error {
|
|
|
|
flags := cmd.Flags()
|
|
|
|
|
|
|
|
logFile, err := flags.GetString("file")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
dsn, err := flags.GetString("dsn")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
logLine, err := flags.GetString("log")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
logType, err := flags.GetString("type")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
opts := hubtest.DumpOpts{}
|
|
|
|
|
|
|
|
opts.Details, err = flags.GetBool("verbose")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
opts.SkipOk, err = flags.GetBool("failures")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2023-02-24 13:49:17 +00:00
|
|
|
opts.ShowNotOkParsers, err = flags.GetBool("only-successful-parsers")
|
|
|
|
opts.ShowNotOkParsers = !opts.ShowNotOkParsers
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
crowdsec, err := flags.GetString("crowdsec")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2023-09-11 13:18:04 +00:00
|
|
|
labels, err := flags.GetString("labels")
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
fileInfo, _ := os.Stdin.Stat()
|
|
|
|
|
|
|
|
if logType == "" || (logLine == "" && logFile == "" && dsn == "") {
|
|
|
|
printHelp(cmd)
|
|
|
|
fmt.Println()
|
|
|
|
fmt.Printf("Please provide --type flag\n")
|
|
|
|
os.Exit(1)
|
|
|
|
}
|
|
|
|
|
|
|
|
if logFile == "-" && ((fileInfo.Mode() & os.ModeCharDevice) == os.ModeCharDevice) {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("the option -f - is intended to work with pipes")
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
var f *os.File
|
|
|
|
|
2023-03-15 09:26:40 +00:00
|
|
|
// using empty string fallback to /tmp
|
|
|
|
dir, err := os.MkdirTemp("", "cscli_explain")
|
|
|
|
if err != nil {
|
|
|
|
return fmt.Errorf("couldn't create a temporary directory to store cscli explain result: %s", err)
|
|
|
|
}
|
2023-01-12 16:04:28 +00:00
|
|
|
tmpFile := ""
|
|
|
|
// we create a temporary log file if a log line/stdin has been provided
|
|
|
|
if logLine != "" || logFile == "-" {
|
|
|
|
tmpFile = filepath.Join(dir, "cscli_test_tmp.log")
|
|
|
|
f, err = os.Create(tmpFile)
|
|
|
|
if err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return err
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if logLine != "" {
|
|
|
|
_, err = f.WriteString(logLine)
|
|
|
|
if err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return err
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
} else if logFile == "-" {
|
|
|
|
reader := bufio.NewReader(os.Stdin)
|
|
|
|
errCount := 0
|
|
|
|
for {
|
|
|
|
input, err := reader.ReadBytes('\n')
|
|
|
|
if err != nil && err == io.EOF {
|
|
|
|
break
|
|
|
|
}
|
|
|
|
_, err = f.Write(input)
|
|
|
|
if err != nil {
|
|
|
|
errCount++
|
|
|
|
}
|
|
|
|
}
|
|
|
|
if errCount > 0 {
|
|
|
|
log.Warnf("Failed to write %d lines to tmp file", errCount)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
f.Close()
|
|
|
|
// this is the file that was going to be read by crowdsec anyway
|
|
|
|
logFile = tmpFile
|
|
|
|
}
|
|
|
|
|
|
|
|
if logFile != "" {
|
|
|
|
absolutePath, err := filepath.Abs(logFile)
|
|
|
|
if err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("unable to get absolute path of '%s', exiting", logFile)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
dsn = fmt.Sprintf("file://%s", absolutePath)
|
2023-08-24 07:44:46 +00:00
|
|
|
lineCount, err := GetLineCountForFile(absolutePath)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2023-01-12 16:04:28 +00:00
|
|
|
if lineCount > 100 {
|
2023-09-12 09:04:56 +00:00
|
|
|
log.Warnf("The log file contains %d lines. This may take a lot of resources.", lineCount)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
if dsn == "" {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("no acquisition (--file or --dsn) provided, can't run cscli test")
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
2023-03-15 09:26:40 +00:00
|
|
|
cmdArgs := []string{"-c", ConfigFilePath, "-type", logType, "-dsn", dsn, "-dump-data", dir, "-no-api"}
|
2023-09-11 13:18:04 +00:00
|
|
|
if labels != "" {
|
|
|
|
log.Debugf("adding labels %s", labels)
|
|
|
|
cmdArgs = append(cmdArgs, "-label", labels)
|
|
|
|
}
|
2023-01-12 16:04:28 +00:00
|
|
|
crowdsecCmd := exec.Command(crowdsec, cmdArgs...)
|
|
|
|
output, err := crowdsecCmd.CombinedOutput()
|
|
|
|
if err != nil {
|
|
|
|
fmt.Println(string(output))
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("fail to run crowdsec for test: %v", err)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
// rm the temporary log file if only a log line/stdin was provided
|
|
|
|
if tmpFile != "" {
|
|
|
|
if err := os.Remove(tmpFile); err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("unable to remove tmp log file '%s': %+v", tmpFile, err)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
parserDumpFile := filepath.Join(dir, hubtest.ParserResultFileName)
|
|
|
|
bucketStateDumpFile := filepath.Join(dir, hubtest.BucketPourResultFileName)
|
|
|
|
|
|
|
|
parserDump, err := hubtest.LoadParserDump(parserDumpFile)
|
|
|
|
if err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("unable to load parser dump result: %s", err)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
bucketStateDump, err := hubtest.LoadBucketPourDump(bucketStateDumpFile)
|
|
|
|
if err != nil {
|
2023-02-20 14:05:42 +00:00
|
|
|
return fmt.Errorf("unable to load bucket dump result: %s", err)
|
2023-01-12 16:04:28 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
hubtest.DumpTree(*parserDump, *bucketStateDump, opts)
|
|
|
|
|
2023-03-15 09:26:40 +00:00
|
|
|
if err := os.RemoveAll(dir); err != nil {
|
|
|
|
return fmt.Errorf("unable to delete temporary directory '%s': %s", dir, err)
|
|
|
|
}
|
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2021-10-04 15:14:52 +00:00
|
|
|
func NewExplainCmd() *cobra.Command {
|
2023-01-12 16:04:28 +00:00
|
|
|
cmdExplain := &cobra.Command{
|
2021-10-04 15:14:52 +00:00
|
|
|
Use: "explain",
|
|
|
|
Short: "Explain log pipeline",
|
|
|
|
Long: `
|
|
|
|
Explain log pipeline
|
|
|
|
`,
|
|
|
|
Example: `
|
|
|
|
cscli explain --file ./myfile.log --type nginx
|
|
|
|
cscli explain --log "Sep 19 18:33:22 scw-d95986 sshd[24347]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=1.2.3.4" --type syslog
|
2021-12-02 14:55:50 +00:00
|
|
|
cscli explain --dsn "file://myfile.log" --type nginx
|
2022-06-23 09:51:43 +00:00
|
|
|
tail -n 5 myfile.log | cscli explain --type nginx -f -
|
2021-10-04 15:14:52 +00:00
|
|
|
`,
|
|
|
|
Args: cobra.ExactArgs(0),
|
|
|
|
DisableAutoGenTag: true,
|
2023-01-12 16:04:28 +00:00
|
|
|
RunE: runExplain,
|
|
|
|
}
|
2021-10-04 15:14:52 +00:00
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
flags := cmdExplain.Flags()
|
2021-10-04 15:14:52 +00:00
|
|
|
|
2023-01-12 16:04:28 +00:00
|
|
|
flags.StringP("file", "f", "", "Log file to test")
|
|
|
|
flags.StringP("dsn", "d", "", "DSN to test")
|
|
|
|
flags.StringP("log", "l", "", "Log line to test")
|
|
|
|
flags.StringP("type", "t", "", "Type of the acquisition to test")
|
2023-09-11 13:18:04 +00:00
|
|
|
flags.String("labels", "", "Additional labels to add to the acquisition format (key:value,key2:value2)")
|
2023-01-12 16:04:28 +00:00
|
|
|
flags.BoolP("verbose", "v", false, "Display individual changes")
|
|
|
|
flags.Bool("failures", false, "Only show failed lines")
|
2023-02-24 13:49:17 +00:00
|
|
|
flags.Bool("only-successful-parsers", false, "Only show successful parsers")
|
2023-01-12 16:04:28 +00:00
|
|
|
flags.String("crowdsec", "crowdsec", "Path to crowdsec")
|
2021-10-04 15:14:52 +00:00
|
|
|
|
|
|
|
return cmdExplain
|
|
|
|
}
|