2 * collectd - src/snort.c
3 * Copyright (C) 2013 Kris Nielander
5 * This program is free software; you can redistribute it and/or modify it
6 * under the terms of the GNU General Public License as published by the
7 * Free Software Foundation; only version 2 of the License is applicable.
9 * This program is distributed in the hope that it will be useful, but
10 * WITHOUT ANY WARRANTY; without even the implied warranty of
11 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
12 * General Public License for more details.
14 * You should have received a copy of the GNU General Public License along
15 * with this program; if not, write to the Free Software Foundation, Inc.,
16 * 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
19 * Kris Nielander <nielander@fox-it.com>
21 * This plugin is based on the snmp plugin by Florian octo Forster.
26 #include "plugin.h" /* plugin_register_*, plugin_dispatch_values */
27 #include "common.h" /* auxiliary functions */
34 struct metric_definition_s {
39 struct metric_definition_s *next;
41 typedef struct metric_definition_s metric_definition_t;
43 struct instance_definition_s {
46 metric_definition_t **metric_list;
50 struct instance_definition_s *next;
52 typedef struct instance_definition_s instance_definition_t;
55 static metric_definition_t *metric_head = NULL;
57 static int snort_read_submit(instance_definition_t *id, metric_definition_t *md,
60 /* Registration variables */
62 value_list_t vl = VALUE_LIST_INIT;
64 DEBUG("snort plugin: plugin_instance=%s type=%s value=%s", id->name,
71 parse_value(buf, &value, md->data_source_type);
77 sstrncpy(vl.host, hostname_g, sizeof (vl.host));
78 sstrncpy(vl.plugin, "snort", sizeof(vl.plugin));
79 sstrncpy(vl.plugin_instance, id->name, sizeof(vl.plugin_instance));
80 sstrncpy(vl.type, md->type, sizeof(vl.type));
83 vl.interval = id->interval;
85 DEBUG("snort plugin: -> plugin_dispatch_values (&vl);");
86 plugin_dispatch_values(&vl);
91 static int snort_read_buffer (instance_definition_t *id,
92 char const *buffer, size_t buffer_size)
101 /* mmap, char pointers */
104 /* Set the start value count. */
107 /* Set the pointer to the last line of the file and count the fields.
108 (Skip the last two characters of the buffer: `\n' and `\0') */
109 for (p_end = (buffer + buffer_size) - 2; p_end > buffer; --p_end){
112 } else if (*p_end == '\n'){
118 if (metrics_num == 1){
119 ERROR("snort plugin: last line of `%s' does not contain enough values.", id->path);
124 ERROR("snort plugin: last line of `%s' is a comment.", id->path);
128 /* Copy the line to the buffer */
131 /* Create a list of all values */
132 metrics = calloc (metrics_num, sizeof (*metrics));
133 if (metrics == NULL) {
134 ERROR ("snort plugin: calloc failed.");
141 while (buf_ptr != NULL) {
142 char *next = strchr (buf_ptr, ',');
147 metrics[i] = buf_ptr;
151 assert (i == metrics_num);
154 id->last = TIME_T_TO_CDTIME_T(strtol(*metrics, NULL, 0));
156 /* Register values */
157 for (i = 0; i < id->metric_list_len; ++i){
158 metric_definition_t *md = id->metric_list[i];
160 if (md->index >= metrics_num) {
161 ERROR ("snort plugin: Metric \"%s\": Request for index %i when "
162 "only %i fields are available.",
163 md->name, md->index, metrics_num);
167 snort_read_submit(id, md, metrics[md->index]);
170 /* Free up resources */
176 static int snort_read(user_data_t *ud){
177 instance_definition_t *id;
183 /* mmap, char pointers */
187 DEBUG("snort plugin: snort_read (instance = %s)", id->name);
189 fd = open(id->path, O_RDONLY);
191 ERROR("snort plugin: Unable to open `%s'.", id->path);
195 if ((fstat(fd, &sb) != 0) || (!S_ISREG(sb.st_mode))){
196 ERROR("snort plugin: `%s' is not a file.", id->path);
201 if (sb.st_size == 0){
202 ERROR("snort plugin: `%s' is empty.", id->path);
207 p_start = mmap(/* addr = */ NULL, sb.st_size, PROT_READ, MAP_SHARED, fd,
209 if (p_start == MAP_FAILED){
210 ERROR("snort plugin: mmap error");
215 snort_read_buffer (id, p_start, (size_t) sb.st_size);
217 /* Done with mmap and file pointer */
219 munmap(p_start, sb.st_size);
223 static void snort_metric_definition_destroy(void *arg){
224 metric_definition_t *md;
230 if (md->name != NULL)
231 DEBUG("snort plugin: Destroying metric definition `%s'.", md->name);
238 static int snort_config_add_metric_index(metric_definition_t *md, oconfig_item_t *ci){
239 if ((ci->values_num != 1) || (ci->values[0].type != OCONFIG_TYPE_NUMBER)){
240 WARNING("snort plugin: `Index' needs exactly one integer argument.");
244 md->index = (int)ci->values[0].value.number;
246 WARNING("snort plugin: `Index' must be higher than 0.");
254 static int snort_config_add_metric(oconfig_item_t *ci){
255 metric_definition_t *md;
256 const data_set_t *ds;
260 md = (metric_definition_t *)malloc(sizeof(*md));
263 memset(md, 0, sizeof(*md));
266 status = cf_util_get_string (ci, &md->name);
272 for (i = 0; i < ci->children_num; ++i){
273 oconfig_item_t *option = ci->children + i;
276 if (strcasecmp("Type", option->key) == 0)
277 status = cf_util_get_string(option, &md->type);
278 else if (strcasecmp("Index", option->key) == 0)
279 status = snort_config_add_metric_index(md, option);
281 WARNING("snort plugin: Option `%s' not allowed here.", option->key);
290 snort_metric_definition_destroy(md);
294 /* Verify all necessary options have been set. */
295 if (md->type == NULL){
296 WARNING("snort plugin: Option `Type' must be set.");
298 } else if (md->index == 0){
299 WARNING("snort plugin: Option `Index' must be set.");
304 snort_metric_definition_destroy(md);
308 /* Retrieve the data source type from the types db. */
309 ds = plugin_get_ds(md->type);
311 ERROR ("snort plugin: Failed to look up type \"%s\". "
312 "It may not be defined in the types.db file. "
313 "Please read the types.db(5) manual page for more details.",
315 snort_metric_definition_destroy(md);
317 } else if (ds->ds_num != 1) {
318 ERROR ("snort plugin: The type \"%s\" has %i data sources. "
319 "Only types with a single data soure are supported.",
320 ds->type, ds->ds_num);
323 md->data_source_type = ds->ds->type;
326 DEBUG("snort plugin: md = { name = %s, type = %s, data_source_type = %d, index = %d }",
327 md->name, md->type, md->data_source_type, md->index);
329 if (metric_head == NULL)
332 metric_definition_t *last;
334 while (last->next != NULL)
342 static void snort_instance_definition_destroy(void *arg){
343 instance_definition_t *id;
349 if (id->name != NULL)
350 DEBUG("snort plugin: Destroying instance definition `%s'.", id->name);
354 sfree(id->metric_list);
358 static int snort_config_add_instance_collect(instance_definition_t *id, oconfig_item_t *ci){
359 metric_definition_t *metric;
362 if (ci->values_num < 1){
363 WARNING("snort plugin: The `Collect' config option needs at least one argument.");
367 /* Verify string arguments */
368 for (i = 0; i < ci->values_num; ++i)
369 if (ci->values[i].type != OCONFIG_TYPE_STRING){
370 WARNING("snort plugin: All arguments to `Collect' must be strings.");
374 id->metric_list = (metric_definition_t **)malloc(sizeof(metric_definition_t *) * ci->values_num);
375 if (id->metric_list == NULL)
378 for (i = 0; i < ci->values_num; ++i){
379 for (metric = metric_head; metric != NULL; metric = metric->next)
380 if (strcasecmp(ci->values[i].value.string, metric->name) == 0)
384 WARNING("snort plugin: `Collect' argument not found `%s'.", ci->values[i].value.string);
388 DEBUG("snort plugin: id { name=%s md->name=%s }", id->name, metric->name);
390 id->metric_list[i] = metric;
391 id->metric_list_len++;
398 static int snort_config_add_instance(oconfig_item_t *ci){
400 instance_definition_t* id;
404 /* Registration variables */
405 char cb_name[DATA_MAX_NAME_LEN];
407 struct timespec cb_interval;
409 if ((ci->values_num != 1) || (ci->values[0].type != OCONFIG_TYPE_STRING)){
410 WARNING("snort plugin: The `Instance' config option needs exactly one string argument.");
414 id = (instance_definition_t *)malloc(sizeof(*id));
417 memset(id, 0, sizeof(*id));
419 id->name = strdup(ci->values[0].value.string);
420 if (id->name == NULL){
425 /* Use default interval. */
426 id->interval = plugin_get_interval();
428 for (i = 0; i < ci->children_num; ++i){
429 oconfig_item_t *option = ci->children + i;
432 if (strcasecmp("Path", option->key) == 0)
433 status = cf_util_get_string(option, &id->path);
434 else if (strcasecmp("Collect", option->key) == 0)
435 status = snort_config_add_instance_collect(id, option);
436 else if (strcasecmp("Interval", option->key) == 0)
437 cf_util_get_cdtime(option, &id->interval);
439 WARNING("snort plugin: Option `%s' not allowed here.", option->key);
448 snort_instance_definition_destroy(id);
452 /* Verify all necessary options have been set. */
453 if (id->path == NULL){
454 WARNING("snort plugin: Option `Path' must be set.");
456 } else if (id->metric_list == NULL){
457 WARNING("snort plugin: Option `Collect' must be set.");
462 snort_instance_definition_destroy(id);
466 DEBUG("snort plugin: id = { name = %s, path = %s }", id->name, id->path);
468 ssnprintf (cb_name, sizeof (cb_name), "snort-%s", id->name);
469 memset(&cb_data, 0, sizeof(cb_data));
471 cb_data.free_func = snort_instance_definition_destroy;
472 CDTIME_T_TO_TIMESPEC(id->interval, &cb_interval);
473 status = plugin_register_complex_read(NULL, cb_name, snort_read, &cb_interval, &cb_data);
476 ERROR("snort plugin: Registering complex read function failed.");
477 snort_instance_definition_destroy(id);
485 static int snort_config(oconfig_item_t *ci){
487 for (i = 0; i < ci->children_num; ++i){
488 oconfig_item_t *child = ci->children + i;
489 if (strcasecmp("Metric", child->key) == 0)
490 snort_config_add_metric(child);
491 else if (strcasecmp("Instance", child->key) == 0)
492 snort_config_add_instance(child);
494 WARNING("snort plugin: Ignore unknown config option `%s'.", child->key);
498 } /* int snort_config */
500 static int snort_shutdown(void){
501 metric_definition_t *metric_this;
502 metric_definition_t *metric_next;
504 metric_this = metric_head;
507 while (metric_this != NULL){
508 metric_next = metric_this->next;
509 snort_metric_definition_destroy(metric_this);
510 metric_this = metric_next;
516 void module_register(void){
517 plugin_register_complex_config("snort", snort_config);
518 plugin_register_shutdown("snort", snort_shutdown);