|
1 |
| -package com.wizecore.graylog2.plugin; |
2 |
| - |
3 |
| -import java.util.Map; |
4 |
| - |
5 |
| -import org.graylog2.plugin.Message; |
6 |
| -import org.graylog2.syslog4j.SyslogConstants; |
7 |
| -import org.graylog2.syslog4j.SyslogIF; |
8 |
| - |
9 |
| -/** |
10 |
| - * Using CEF format |
11 |
| - */ |
12 |
| - |
13 |
| -/* |
14 |
| - * http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/ |
15 |
| - * |
16 |
| - * |
17 |
| - * CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension |
18 |
| -
|
19 |
| -CEF:0|ArcSight|Logger|5.0.0.5355.2|sensor:115|Logger Internal Event|1|\ |
20 |
| -cat=/Monitor/Sensor/Fan5 cs2=Current Value cnt=1 dvc=10.0.0.1 cs3=Ok \ |
21 |
| -cs1=null type=0 cs1Label=unit rt=1305034099211 cs3Label=Status cn1Label=value \ |
22 |
| -cs2Label=timeframe |
23 |
| - */ |
24 |
| -public class CEFSender implements MessageSender { |
25 |
| - |
26 |
| - @Override |
27 |
| - public void send(SyslogIF syslog, int level, Message msg) { |
28 |
| - StringBuilder out = new StringBuilder(); |
29 |
| - |
30 |
| - // Header: |
31 |
| - // CEF:Version|Device Vendor|Device Product|Device Version| |
32 |
| - out.append("CEF:0|Graylog|graylog-output-syslog:cefsender|2.3.1|"); |
33 |
| - |
34 |
| - // Device Event Class ID |
35 |
| - out.append("log:1"); |
36 |
| - out.append("|"); |
37 |
| - |
38 |
| - Map<String, Object> fields = msg.getFields(); |
39 |
| - Object fv = fields.get("act"); |
40 |
| - |
41 |
| - // Name |
42 |
| - String str = fv != null ? fv.toString() : null; |
43 |
| - if (str == null) { |
44 |
| - fv = fields.get("short_message"); |
45 |
| - str = fv != null ? fv.toString() : null; |
46 |
| - } |
47 |
| - if (str == null) { |
48 |
| - str = msg.getId(); |
49 |
| - } |
50 |
| - str = escape(str, false); |
51 |
| - out.append(str); |
52 |
| - |
53 |
| - // Severity |
54 |
| - // The valid integer values are 0-3=Low, 4-6=Medium, 7-8=High, and 9-10=Very-High. |
55 |
| - int cefLevel = 0; |
56 |
| - /** see {@link org.graylog2.syslog4j.SyslogConstants#LEVEL_INFO} */ |
57 |
| - switch (level) { |
58 |
| - case (SyslogConstants.LEVEL_DEBUG): |
59 |
| - cefLevel = 1; |
60 |
| - break; |
61 |
| - case (SyslogConstants.LEVEL_NOTICE): |
62 |
| - cefLevel = 2; |
63 |
| - break; |
64 |
| - case (SyslogConstants.LEVEL_INFO): |
65 |
| - cefLevel = 3; |
66 |
| - break; |
67 |
| - case (SyslogConstants.LEVEL_WARN): |
68 |
| - cefLevel = 6; |
69 |
| - break; |
70 |
| - case (SyslogConstants.LEVEL_ERROR): |
71 |
| - cefLevel = 7; |
72 |
| - break; |
73 |
| - case (SyslogConstants.LEVEL_CRITICAL): |
74 |
| - cefLevel = 8; |
75 |
| - break; |
76 |
| - case (SyslogConstants.LEVEL_ALERT): |
77 |
| - cefLevel = 9; |
78 |
| - break; |
79 |
| - case (SyslogConstants.LEVEL_EMERGENCY): |
80 |
| - cefLevel = 10; |
81 |
| - break; |
82 |
| - default: |
83 |
| - // FIXME: Unknown level |
84 |
| - cefLevel = 10; |
85 |
| - break; |
86 |
| - } |
87 |
| - out.append("|").append(cefLevel) .append("|"); |
88 |
| - |
89 |
| - // Extension |
90 |
| - boolean have = false; |
91 |
| - boolean haveExternalId = false; |
92 |
| - boolean haveMsg = false; |
| 1 | +package com.wizecore.graylog2.plugin; |
| 2 | + |
| 3 | +import java.util.Map; |
| 4 | + |
| 5 | +import org.graylog2.plugin.Message; |
| 6 | +import org.graylog2.syslog4j.SyslogConstants; |
| 7 | +import org.graylog2.syslog4j.SyslogIF; |
| 8 | + |
| 9 | +/** |
| 10 | + * Using CEF format |
| 11 | + */ |
| 12 | + |
| 13 | +/* |
| 14 | + * http://blog.rootshell.be/2011/05/11/ossec-speaks-arcsight/ |
| 15 | + * |
| 16 | + * |
| 17 | + * CEF:Version|Device Vendor|Device Product|Device Version|Signature ID|Name|Severity|Extension |
| 18 | +
|
| 19 | +CEF:0|ArcSight|Logger|5.0.0.5355.2|sensor:115|Logger Internal Event|1|\ |
| 20 | +cat=/Monitor/Sensor/Fan5 cs2=Current Value cnt=1 dvc=10.0.0.1 cs3=Ok \ |
| 21 | +cs1=null type=0 cs1Label=unit rt=1305034099211 cs3Label=Status cn1Label=value \ |
| 22 | +cs2Label=timeframe |
| 23 | + */ |
| 24 | +public class CEFSender implements MessageSender { |
| 25 | + |
| 26 | + @Override |
| 27 | + public void send(SyslogIF syslog, int level, Message msg) { |
| 28 | + StringBuilder out = new StringBuilder(); |
| 29 | + |
| 30 | + // Header: |
| 31 | + // CEF:Version|Device Vendor|Device Product|Device Version| |
| 32 | + out.append("CEF:0|Graylog|graylog-output-syslog:cefsender|2.3.1|"); |
| 33 | + |
| 34 | + // Device Event Class ID |
| 35 | + out.append("log:1"); |
| 36 | + out.append("|"); |
| 37 | + |
| 38 | + Map<String, Object> fields = msg.getFields(); |
| 39 | + Object fv = fields.get("act"); |
| 40 | + |
| 41 | + // Name |
| 42 | + String str = fv != null ? fv.toString() : null; |
| 43 | + if (str == null) { |
| 44 | + fv = fields.get("short_message"); |
| 45 | + str = fv != null ? fv.toString() : null; |
| 46 | + } |
| 47 | + if (str == null) { |
| 48 | + str = msg.getId(); |
| 49 | + } |
| 50 | + str = escape(str, false); |
| 51 | + out.append(str); |
| 52 | + |
| 53 | + // Severity |
| 54 | + // The valid integer values are 0-3=Low, 4-6=Medium, 7-8=High, and 9-10=Very-High. |
| 55 | + int cefLevel = 0; |
| 56 | + /** see {@link org.graylog2.syslog4j.SyslogConstants#LEVEL_INFO} */ |
| 57 | + switch (level) { |
| 58 | + case (SyslogConstants.LEVEL_DEBUG): |
| 59 | + cefLevel = 1; |
| 60 | + break; |
| 61 | + case (SyslogConstants.LEVEL_NOTICE): |
| 62 | + cefLevel = 2; |
| 63 | + break; |
| 64 | + case (SyslogConstants.LEVEL_INFO): |
| 65 | + cefLevel = 3; |
| 66 | + break; |
| 67 | + case (SyslogConstants.LEVEL_WARN): |
| 68 | + cefLevel = 6; |
| 69 | + break; |
| 70 | + case (SyslogConstants.LEVEL_ERROR): |
| 71 | + cefLevel = 7; |
| 72 | + break; |
| 73 | + case (SyslogConstants.LEVEL_CRITICAL): |
| 74 | + cefLevel = 8; |
| 75 | + break; |
| 76 | + case (SyslogConstants.LEVEL_ALERT): |
| 77 | + cefLevel = 9; |
| 78 | + break; |
| 79 | + case (SyslogConstants.LEVEL_EMERGENCY): |
| 80 | + cefLevel = 10; |
| 81 | + break; |
| 82 | + default: |
| 83 | + // FIXME: Unknown level |
| 84 | + cefLevel = 10; |
| 85 | + break; |
| 86 | + } |
| 87 | + out.append("|").append(cefLevel) .append("|"); |
| 88 | + |
| 89 | + // Extension |
| 90 | + boolean have = false; |
| 91 | + boolean haveExternalId = false; |
| 92 | + boolean haveMsg = false; |
93 | 93 | boolean haveStart = false;
|
94 |
| - for (String k: fields.keySet()) { |
95 |
| - Object v = fields.get(k); |
96 |
| - if (!k.equals("message") && !k.equals("full_message") && !k.equals("short_message")) { |
| 94 | + for (String k: fields.keySet()) { |
| 95 | + Object v = fields.get(k); |
| 96 | + if (!k.equals("message") && !k.equals("full_message") && !k.equals("short_message")) { |
97 | 97 | String s = v != null ? v.toString() : "null";
|
98 |
| - s = escape(s, true); |
99 |
| - if (have) { |
100 |
| - out.append(" "); |
| 98 | + s = escape(s, true); |
| 99 | + if (have) { |
| 100 | + out.append(" "); |
| 101 | + } |
| 102 | + out.append(k).append('=').append(s); |
| 103 | + have = true; |
| 104 | + |
| 105 | + if (!haveExternalId && k.equals("externalId")) { |
| 106 | + haveExternalId = true; |
| 107 | + } |
| 108 | + |
| 109 | + if (!haveMsg && k.equals("msg")) { |
| 110 | + haveMsg = true; |
101 | 111 | }
|
102 |
| - out.append(k).append('=').append(s); |
103 |
| - have = true; |
104 |
| - |
105 |
| - if (!haveExternalId && k.equals("externalId")) { |
106 |
| - haveExternalId = true; |
107 |
| - } |
108 |
| - |
109 |
| - if (!haveMsg && k.equals("msg")) { |
110 |
| - haveMsg = true; |
111 |
| - } |
112 |
| - |
113 |
| - if (!haveStart && k.equals("start")) { |
114 |
| - haveStart = true; |
115 |
| - } |
116 |
| - } |
117 |
| - } |
118 |
| - |
119 |
| - if (!haveStart) { |
120 |
| - out.append(" start=").append(msg.getTimestamp().getMillis()); |
121 |
| - } |
122 |
| - |
123 |
| - if (!haveMsg) { |
124 |
| - out.append(" msg=").append(escape(msg.getMessage(), true)); |
125 |
| - } |
126 |
| - |
127 |
| - if (!haveExternalId) { |
128 |
| - out.append(" externalId=").append(msg.getId()); |
| 112 | + |
| 113 | + if (!haveStart && k.equals("start")) { |
| 114 | + haveStart = true; |
| 115 | + } |
| 116 | + } |
| 117 | + } |
| 118 | + |
| 119 | + if (!haveStart) { |
| 120 | + out.append(" start=").append(msg.getTimestamp().getMillis()); |
| 121 | + } |
| 122 | + |
| 123 | + if (!haveMsg) { |
| 124 | + out.append(" msg=").append(escape(msg.getMessage(), true)); |
129 | 125 | }
|
130 | 126 |
|
131 |
| - syslog.log(level, out.toString()); |
132 |
| - } |
133 |
| - |
134 |
| - public String escape(String s, boolean extension) { |
135 |
| - s = s.replace("\\", "\\\\"); |
| 127 | + if (!haveExternalId) { |
| 128 | + out.append(" externalId=").append(msg.getId()); |
| 129 | + } |
| 130 | + |
| 131 | + syslog.log(level, out.toString()); |
| 132 | + } |
| 133 | + |
| 134 | + public String escape(String s, boolean extension) { |
| 135 | + s = s.replace("\\", "\\\\"); |
136 | 136 | if (extension) {
|
137 | 137 | s = s.replace("=", "\\=");
|
138 | 138 | s = s.replace("\r", "");
|
139 |
| - s = s.replace("\n", "\\n"); |
140 |
| - } else { |
141 |
| - s = s.replace("|", "\\|"); |
142 |
| - s = s.replace("\r", ""); |
143 |
| - s = s.replace("\n", ""); |
144 |
| - } |
145 |
| - return s; |
146 |
| - } |
147 |
| -} |
| 139 | + s = s.replace("\n", "\\n"); |
| 140 | + } else { |
| 141 | + s = s.replace("|", "\\|"); |
| 142 | + s = s.replace("\r", ""); |
| 143 | + s = s.replace("\n", ""); |
| 144 | + } |
| 145 | + return s; |
| 146 | + } |
| 147 | +} |
0 commit comments