|
1 | | -package com.wizecore.graylog2.plugin; |
2 | | - |
3 | | -import java.util.Map; |
4 | | - |
5 | | -import org.graylog2.plugin.Message; |
6 | | -import org.graylog2.syslog4j.SyslogConstants; |
7 | | -import org.graylog2.syslog4j.SyslogIF; |
8 | | - |
9 | | -/** |
10 | | - * Using CEF format |
11 | | - */ |
12 | | - |
13 | | -/* |
14 | | - * http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/ |
15 | | - * |
16 | | - * |
17 | | - * CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension |
18 | | -
|
19 | | -CEF:0|ArcSight|Logger|5.0.0.5355.2|sensor:115|Logger Internal Event|1|\ |
20 | | -cat=/Monitor/Sensor/Fan5 cs2=Current Value cnt=1 dvc=10.0.0.1 cs3=Ok \ |
21 | | -cs1=null type=0 cs1Label=unit rt=1305034099211 cs3Label=Status cn1Label=value \ |
22 | | -cs2Label=timeframe |
23 | | - */ |
24 | | -public class CEFSender implements MessageSender { |
25 | | - |
26 | | - @Override |
27 | | - public void send(SyslogIF syslog, int level, Message msg) { |
28 | | - StringBuilder out = new StringBuilder(); |
29 | | - |
30 | | - // Header: |
31 | | - // CEF:Version|Device Vendor|Device Product|Device Version| |
32 | | - out.append("CEF:0|Graylog|graylog-output-syslog:cefsender|2.3.1|"); |
33 | | - |
34 | | - // Device Event Class ID |
35 | | - out.append("log:1"); |
36 | | - out.append("|"); |
37 | | - |
38 | | - Map<String, Object> fields = msg.getFields(); |
39 | | - Object fv = fields.get("act"); |
40 | | - |
41 | | - // Name |
42 | | - String str = fv != null ? fv.toString() : null; |
43 | | - if (str == null) { |
44 | | - fv = fields.get("short_message"); |
45 | | - str = fv != null ? fv.toString() : null; |
46 | | - } |
47 | | - if (str == null) { |
48 | | - str = msg.getId(); |
49 | | - } |
50 | | - str = escape(str, false); |
51 | | - out.append(str); |
52 | | - |
53 | | - // Severity |
54 | | - // The valid integer values are 0-3=Low, 4-6=Medium, 7-8=High, and 9-10=Very-High. |
55 | | - int cefLevel = 0; |
56 | | - /** see {@link org.graylog2.syslog4j.SyslogConstants#LEVEL_INFO} */ |
57 | | - switch (level) { |
58 | | - case (SyslogConstants.LEVEL_DEBUG): |
59 | | - cefLevel = 1; |
60 | | - break; |
61 | | - case (SyslogConstants.LEVEL_NOTICE): |
62 | | - cefLevel = 2; |
63 | | - break; |
64 | | - case (SyslogConstants.LEVEL_INFO): |
65 | | - cefLevel = 3; |
66 | | - break; |
67 | | - case (SyslogConstants.LEVEL_WARN): |
68 | | - cefLevel = 6; |
69 | | - break; |
70 | | - case (SyslogConstants.LEVEL_ERROR): |
71 | | - cefLevel = 7; |
72 | | - break; |
73 | | - case (SyslogConstants.LEVEL_CRITICAL): |
74 | | - cefLevel = 8; |
75 | | - break; |
76 | | - case (SyslogConstants.LEVEL_ALERT): |
77 | | - cefLevel = 9; |
78 | | - break; |
79 | | - case (SyslogConstants.LEVEL_EMERGENCY): |
80 | | - cefLevel = 10; |
81 | | - break; |
82 | | - default: |
83 | | - // FIXME: Unknown level |
84 | | - cefLevel = 10; |
85 | | - break; |
86 | | - } |
87 | | - out.append("|").append(cefLevel) .append("|"); |
88 | | - |
89 | | - // Extension |
90 | | - boolean have = false; |
91 | | - boolean haveExternalId = false; |
92 | | - boolean haveMsg = false; |
| 1 | +package com.wizecore.graylog2.plugin; |
| 2 | + |
| 3 | +import java.util.Map; |
| 4 | + |
| 5 | +import org.graylog2.plugin.Message; |
| 6 | +import org.graylog2.syslog4j.SyslogConstants; |
| 7 | +import org.graylog2.syslog4j.SyslogIF; |
| 8 | + |
| 9 | +/** |
| 10 | + * Using CEF format |
| 11 | + */ |
| 12 | + |
| 13 | +/* |
| 14 | + * http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/ |
| 15 | + * |
| 16 | + * |
| 17 | + * CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension |
| 18 | +
|
| 19 | +CEF:0|ArcSight|Logger|5.0.0.5355.2|sensor:115|Logger Internal Event|1|\ |
| 20 | +cat=/Monitor/Sensor/Fan5 cs2=Current Value cnt=1 dvc=10.0.0.1 cs3=Ok \ |
| 21 | +cs1=null type=0 cs1Label=unit rt=1305034099211 cs3Label=Status cn1Label=value \ |
| 22 | +cs2Label=timeframe |
| 23 | + */ |
| 24 | +public class CEFSender implements MessageSender { |
| 25 | + |
| 26 | + @Override |
| 27 | + public void send(SyslogIF syslog, int level, Message msg) { |
| 28 | + StringBuilder out = new StringBuilder(); |
| 29 | + |
| 30 | + // Header: |
| 31 | + // CEF:Version|Device Vendor|Device Product|Device Version| |
| 32 | + out.append("CEF:0|Graylog|graylog-output-syslog:cefsender|2.3.1|"); |
| 33 | + |
| 34 | + // Device Event Class ID |
| 35 | + out.append("log:1"); |
| 36 | + out.append("|"); |
| 37 | + |
| 38 | + Map<String, Object> fields = msg.getFields(); |
| 39 | + Object fv = fields.get("act"); |
| 40 | + |
| 41 | + // Name |
| 42 | + String str = fv != null ? fv.toString() : null; |
| 43 | + if (str == null) { |
| 44 | + fv = fields.get("short_message"); |
| 45 | + str = fv != null ? fv.toString() : null; |
| 46 | + } |
| 47 | + if (str == null) { |
| 48 | + str = msg.getId(); |
| 49 | + } |
| 50 | + str = escape(str, false); |
| 51 | + out.append(str); |
| 52 | + |
| 53 | + // Severity |
| 54 | + // The valid integer values are 0-3=Low, 4-6=Medium, 7-8=High, and 9-10=Very-High. |
| 55 | + int cefLevel = 0; |
| 56 | + /** see {@link org.graylog2.syslog4j.SyslogConstants#LEVEL_INFO} */ |
| 57 | + switch (level) { |
| 58 | + case (SyslogConstants.LEVEL_DEBUG): |
| 59 | + cefLevel = 1; |
| 60 | + break; |
| 61 | + case (SyslogConstants.LEVEL_NOTICE): |
| 62 | + cefLevel = 2; |
| 63 | + break; |
| 64 | + case (SyslogConstants.LEVEL_INFO): |
| 65 | + cefLevel = 3; |
| 66 | + break; |
| 67 | + case (SyslogConstants.LEVEL_WARN): |
| 68 | + cefLevel = 6; |
| 69 | + break; |
| 70 | + case (SyslogConstants.LEVEL_ERROR): |
| 71 | + cefLevel = 7; |
| 72 | + break; |
| 73 | + case (SyslogConstants.LEVEL_CRITICAL): |
| 74 | + cefLevel = 8; |
| 75 | + break; |
| 76 | + case (SyslogConstants.LEVEL_ALERT): |
| 77 | + cefLevel = 9; |
| 78 | + break; |
| 79 | + case (SyslogConstants.LEVEL_EMERGENCY): |
| 80 | + cefLevel = 10; |
| 81 | + break; |
| 82 | + default: |
| 83 | + // FIXME: Unknown level |
| 84 | + cefLevel = 10; |
| 85 | + break; |
| 86 | + } |
| 87 | + out.append("|").append(cefLevel) .append("|"); |
| 88 | + |
| 89 | + // Extension |
| 90 | + boolean have = false; |
| 91 | + boolean haveExternalId = false; |
| 92 | + boolean haveMsg = false; |
93 | 93 | boolean haveStart = false; |
94 | | - for (String k: fields.keySet()) { |
95 | | - Object v = fields.get(k); |
96 | | - if (!k.equals("message") && !k.equals("full_message") && !k.equals("short_message")) { |
| 94 | + for (String k: fields.keySet()) { |
| 95 | + Object v = fields.get(k); |
| 96 | + if (!k.equals("message") && !k.equals("full_message") && !k.equals("short_message")) { |
97 | 97 | String s = v != null ? v.toString() : "null"; |
98 | | - s = escape(s, true); |
99 | | - if (have) { |
100 | | - out.append(" "); |
| 98 | + s = escape(s, true); |
| 99 | + if (have) { |
| 100 | + out.append(" "); |
| 101 | + } |
| 102 | + out.append(k).append('=').append(s); |
| 103 | + have = true; |
| 104 | + |
| 105 | + if (!haveExternalId && k.equals("externalId")) { |
| 106 | + haveExternalId = true; |
| 107 | + } |
| 108 | + |
| 109 | + if (!haveMsg && k.equals("msg")) { |
| 110 | + haveMsg = true; |
101 | 111 | } |
102 | | - out.append(k).append('=').append(s); |
103 | | - have = true; |
104 | | - |
105 | | - if (!haveExternalId && k.equals("externalId")) { |
106 | | - haveExternalId = true; |
107 | | - } |
108 | | - |
109 | | - if (!haveMsg && k.equals("msg")) { |
110 | | - haveMsg = true; |
111 | | - } |
112 | | - |
113 | | - if (!haveStart && k.equals("start")) { |
114 | | - haveStart = true; |
115 | | - } |
116 | | - } |
117 | | - } |
118 | | - |
119 | | - if (!haveStart) { |
120 | | - out.append(" start=").append(msg.getTimestamp().getMillis()); |
121 | | - } |
122 | | - |
123 | | - if (!haveMsg) { |
124 | | - out.append(" msg=").append(escape(msg.getMessage(), true)); |
125 | | - } |
126 | | - |
127 | | - if (!haveExternalId) { |
128 | | - out.append(" externalId=").append(msg.getId()); |
| 112 | + |
| 113 | + if (!haveStart && k.equals("start")) { |
| 114 | + haveStart = true; |
| 115 | + } |
| 116 | + } |
| 117 | + } |
| 118 | + |
| 119 | + if (!haveStart) { |
| 120 | + out.append(" start=").append(msg.getTimestamp().getMillis()); |
| 121 | + } |
| 122 | + |
| 123 | + if (!haveMsg) { |
| 124 | + out.append(" msg=").append(escape(msg.getMessage(), true)); |
129 | 125 | } |
130 | 126 |
|
131 | | - syslog.log(level, out.toString()); |
132 | | - } |
133 | | - |
134 | | - public String escape(String s, boolean extension) { |
135 | | - s = s.replace("\\", "\\\\"); |
| 127 | + if (!haveExternalId) { |
| 128 | + out.append(" externalId=").append(msg.getId()); |
| 129 | + } |
| 130 | + |
| 131 | + syslog.log(level, out.toString()); |
| 132 | + } |
| 133 | + |
| 134 | + public String escape(String s, boolean extension) { |
| 135 | + s = s.replace("\\", "\\\\"); |
136 | 136 | if (extension) { |
137 | 137 | s = s.replace("=", "\\="); |
138 | 138 | s = s.replace("\r", ""); |
139 | | - s = s.replace("\n", "\\n"); |
140 | | - } else { |
141 | | - s = s.replace("|", "\\|"); |
142 | | - s = s.replace("\r", ""); |
143 | | - s = s.replace("\n", ""); |
144 | | - } |
145 | | - return s; |
146 | | - } |
147 | | -} |
| 139 | + s = s.replace("\n", "\\n"); |
| 140 | + } else { |
| 141 | + s = s.replace("|", "\\|"); |
| 142 | + s = s.replace("\r", ""); |
| 143 | + s = s.replace("\n", ""); |
| 144 | + } |
| 145 | + return s; |
| 146 | + } |
| 147 | +} |
0 commit comments