|
11 | 11 |
|
12 | 12 | import org.elasticsearch.ingest.IngestDocument; |
13 | 13 | import org.elasticsearch.test.ESTestCase; |
| 14 | +import org.junit.runners.model.TestClass; |
14 | 15 |
|
| 16 | +import java.io.IOException; |
| 17 | +import java.net.URISyntaxException; |
| 18 | +import java.net.URL; |
| 19 | +import java.nio.file.Files; |
| 20 | +import java.nio.file.Paths; |
15 | 21 | import java.time.Instant; |
16 | 22 | import java.time.ZoneId; |
17 | 23 | import java.time.ZonedDateTime; |
18 | 24 | import java.util.HashMap; |
19 | 25 | import java.util.List; |
20 | 26 | import java.util.Map; |
| 27 | +import java.util.Objects; |
21 | 28 |
|
22 | 29 | import static java.util.Map.entry; |
23 | 30 | import static org.hamcrest.Matchers.aMapWithSize; |
24 | 31 | import static org.hamcrest.Matchers.containsInAnyOrder; |
25 | 32 | import static org.hamcrest.Matchers.equalTo; |
26 | 33 |
|
27 | 34 | public class CefProcessorTests extends ESTestCase { |
28 | | - |
| 35 | + private static String readCefMessageFile(String fileName) throws IOException, URISyntaxException { |
| 36 | + URL resource = TestClass.class.getResource("/" + fileName); |
| 37 | + return Files.readString(Paths.get(Objects.requireNonNull(resource).toURI())); |
| 38 | + } |
29 | 39 | private IngestDocument document; |
30 | 40 |
|
31 | | - public void testParse() { |
| 41 | + public void testParse() throws IOException, URISyntaxException { |
32 | 42 | String message; |
33 | 43 | List<String> headers; |
34 | 44 | Map<String, String> extensions; |
35 | 45 | { |
36 | | - message = "CEF:0|vendor|product|version|class|name|severity|"; |
| 46 | + message = readCefMessageFile("basic_cef_message.txt"); |
37 | 47 | headers = CefParser.parseHeaders(message); |
38 | 48 | extensions = CefParser.parseExtensions(headers.removeLast()); |
39 | 49 | assertThat(headers, equalTo(List.of("CEF:0", "vendor", "product", "version", "class", "name", "severity"))); |
40 | 50 | assertThat(extensions, aMapWithSize(0)); |
41 | 51 | } |
42 | 52 | { |
43 | | - message = "CEF:1|vendor|product|version|class|name|severity|someExtension=someValue"; |
| 53 | + message = readCefMessageFile("cef_message_with_extension.txt"); |
44 | 54 | headers = CefParser.parseHeaders(message); |
45 | 55 | extensions = CefParser.parseExtensions(headers.removeLast()); |
46 | 56 | assertThat(headers, equalTo(List.of("CEF:1", "vendor", "product", "version", "class", "name", "severity"))); |
47 | 57 | assertThat(extensions, equalTo(Map.of("someExtension", "someValue"))); |
48 | 58 | } |
49 | 59 | { |
50 | | - message = "CEF:1|vendor|product\\|pipe|version space|class\\\\slash|name|severity|ext1=some value ext2=pipe|value "; |
| 60 | + message = readCefMessageFile("cef_message_with_escaped_pipe.txt"); |
51 | 61 | headers = CefParser.parseHeaders(message); |
52 | 62 | extensions = CefParser.parseExtensions(headers.removeLast()); |
53 | 63 | assertThat(headers, equalTo(List.of("CEF:1", "vendor", "product|pipe", "version space", "class\\slash", "name", "severity"))); |
|
0 commit comments