2021-08-25 09:43:29 +00:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
|
|
|
"context"
|
|
|
|
"crypto/tls"
|
|
|
|
"encoding/json"
|
|
|
|
"fmt"
|
|
|
|
"io/ioutil"
|
|
|
|
"net/http"
|
|
|
|
"os"
|
|
|
|
"strings"
|
|
|
|
|
2021-09-03 10:24:59 +00:00
|
|
|
"github.com/crowdsecurity/crowdsec/pkg/protobufs"
|
2021-08-25 09:43:29 +00:00
|
|
|
"github.com/hashicorp/go-hclog"
|
|
|
|
plugin "github.com/hashicorp/go-plugin"
|
|
|
|
|
|
|
|
"gopkg.in/yaml.v2"
|
|
|
|
)
|
|
|
|
|
|
|
|
var logger hclog.Logger = hclog.New(&hclog.LoggerOptions{
|
|
|
|
Name: "splunk-plugin",
|
2022-03-10 12:56:46 +00:00
|
|
|
Level: hclog.LevelFromString("INFO"),
|
2021-08-25 09:43:29 +00:00
|
|
|
Output: os.Stderr,
|
|
|
|
JSONFormat: true,
|
|
|
|
})
|
|
|
|
|
|
|
|
type PluginConfig struct {
|
|
|
|
Name string `yaml:"name"`
|
|
|
|
URL string `yaml:"url"`
|
|
|
|
Token string `yaml:"token"`
|
|
|
|
LogLevel *string `yaml:"log_level"`
|
|
|
|
}
|
|
|
|
|
|
|
|
type Splunk struct {
|
|
|
|
PluginConfigByName map[string]PluginConfig
|
|
|
|
Client http.Client
|
|
|
|
}
|
|
|
|
|
|
|
|
type Payload struct {
|
|
|
|
Event string `json:"event"`
|
|
|
|
}
|
|
|
|
|
2021-09-03 10:24:59 +00:00
|
|
|
func (s *Splunk) Notify(ctx context.Context, notification *protobufs.Notification) (*protobufs.Empty, error) {
|
2021-08-25 09:43:29 +00:00
|
|
|
if _, ok := s.PluginConfigByName[notification.Name]; !ok {
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, fmt.Errorf("splunk invalid config name %s", notification.Name)
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
cfg := s.PluginConfigByName[notification.Name]
|
2022-03-10 12:56:46 +00:00
|
|
|
|
2021-08-25 09:43:29 +00:00
|
|
|
if cfg.LogLevel != nil && *cfg.LogLevel != "" {
|
|
|
|
logger.SetLevel(hclog.LevelFromString(*cfg.LogLevel))
|
|
|
|
}
|
2022-03-10 12:56:46 +00:00
|
|
|
|
2021-08-25 09:43:29 +00:00
|
|
|
logger.Info(fmt.Sprintf("received notify signal for %s config", notification.Name))
|
|
|
|
|
|
|
|
p := Payload{Event: notification.Text}
|
|
|
|
data, err := json.Marshal(p)
|
|
|
|
if err != nil {
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, err
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
req, err := http.NewRequest("POST", cfg.URL, strings.NewReader(string(data)))
|
|
|
|
if err != nil {
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, err
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
req.Header.Add("Authorization", fmt.Sprintf("Splunk %s", cfg.Token))
|
|
|
|
logger.Debug(fmt.Sprintf("posting event %s to %s", string(data), req.URL))
|
|
|
|
resp, err := s.Client.Do(req)
|
|
|
|
if err != nil {
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, err
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
if resp.StatusCode != 200 {
|
|
|
|
content, err := ioutil.ReadAll(resp.Body)
|
|
|
|
if err != nil {
|
2022-06-22 13:53:53 +00:00
|
|
|
return &protobufs.Empty{}, fmt.Errorf("got non 200 response and failed to read error %s", err)
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, fmt.Errorf("got non 200 response %s", string(content))
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
respData, err := ioutil.ReadAll(resp.Body)
|
|
|
|
if err != nil {
|
2022-06-22 13:53:53 +00:00
|
|
|
return &protobufs.Empty{}, fmt.Errorf("failed to read response body got error %s", err)
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
logger.Debug(fmt.Sprintf("got response %s", string(respData)))
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, nil
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
|
2021-09-03 10:24:59 +00:00
|
|
|
func (s *Splunk) Configure(ctx context.Context, config *protobufs.Config) (*protobufs.Empty, error) {
|
2021-08-25 09:43:29 +00:00
|
|
|
d := PluginConfig{}
|
|
|
|
err := yaml.Unmarshal(config.Config, &d)
|
|
|
|
s.PluginConfigByName[d.Name] = d
|
2021-09-03 10:24:59 +00:00
|
|
|
return &protobufs.Empty{}, err
|
2021-08-25 09:43:29 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func main() {
|
|
|
|
var handshake = plugin.HandshakeConfig{
|
|
|
|
ProtocolVersion: 1,
|
|
|
|
MagicCookieKey: "CROWDSEC_PLUGIN_KEY",
|
|
|
|
MagicCookieValue: os.Getenv("CROWDSEC_PLUGIN_KEY"),
|
|
|
|
}
|
|
|
|
|
|
|
|
tr := &http.Transport{
|
|
|
|
TLSClientConfig: &tls.Config{InsecureSkipVerify: true},
|
|
|
|
}
|
|
|
|
client := &http.Client{Transport: tr}
|
|
|
|
|
|
|
|
sp := &Splunk{PluginConfigByName: make(map[string]PluginConfig), Client: *client}
|
|
|
|
plugin.Serve(&plugin.ServeConfig{
|
|
|
|
HandshakeConfig: handshake,
|
|
|
|
Plugins: map[string]plugin.Plugin{
|
2021-09-03 10:24:59 +00:00
|
|
|
"splunk": &protobufs.NotifierPlugin{
|
2021-08-25 09:43:29 +00:00
|
|
|
Impl: sp,
|
|
|
|
},
|
|
|
|
},
|
|
|
|
GRPCServer: plugin.DefaultGRPCServer,
|
|
|
|
Logger: logger,
|
|
|
|
})
|
|
|
|
}
|