Skip to content
GitLab
Explore
Sign in
Primary navigation
Search or go to…
Project
W
Warden
Manage
Activity
Members
Labels
Plan
Issues
Issue boards
Milestones
Wiki
Code
Merge requests
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Package registry
Container registry
Model registry
Operate
Environments
Terraform modules
Monitor
Incidents
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Terms and privacy
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Pavel Valach
Warden
Commits
0163d76a
Commit
0163d76a
authored
4 years ago
by
Rajmund Hruška
Browse files
Options
Downloads
Patches
Plain Diff
Filer: Filter keys in sent events. (Redmine issue: #6799)
parent
52fcd05b
Branches
Branches containing commit
No related tags found
No related merge requests found
Changes
3
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
warden_filer/test_warden_filer.py
+83
-0
83 additions, 0 deletions
warden_filer/test_warden_filer.py
warden_filer/warden_filer.cfg.dist
+2
-0
2 additions, 0 deletions
warden_filer/warden_filer.cfg.dist
warden_filer/warden_filer.py
+13
-2
13 additions, 2 deletions
warden_filer/warden_filer.py
with
98 additions
and
2 deletions
warden_filer/test_warden_filer.py
0 → 100755
+
83
−
0
View file @
0163d76a
#!/usr/bin/python
"""
Warden3 Filer Test Suite
"""
import
unittest2
as
unittest
import
warden_filer
idea_raw_1
=
{
'
ID
'
:
'
4dd7cf5e-4a95-49f6-8f04-947de998012c
'
,
'
Format
'
:
'
IDEA0
'
,
'
DetectTime
'
:
'
2016-06-21T13:08:27Z
'
,
'
WinStartTime
'
:
'
2016-06-21T11:55:02Z
'
,
'
WinEndTime
'
:
'
2016-06-21T12:00:02Z
'
,
'
Source
'
:
[
{
'
IP4
'
:
[
'
188.14.166.39
'
]
}
],
'
Target
'
:
[
{
'
IP4
'
:
[
'
195.113.165.128/25
'
]
}
],
'
_TO_DELETE
'
:
{
'
key1
'
:
'
value
'
,
'
key2
'
:
2
},
'
Node
'
:
[
{
'
Type
'
:
[
'
Relay
'
],
'
Name
'
:
'
cz.cesnet.mentat.warden_filer
'
}
],
'
_CESNET
'
:
{
'
StorageTime
'
:
'
2016-06-21T14:00:07Z
'
}
}
idea_filtered_1
=
{
'
ID
'
:
'
4dd7cf5e-4a95-49f6-8f04-947de998012c
'
,
'
Format
'
:
'
IDEA0
'
,
'
DetectTime
'
:
'
2016-06-21T13:08:27Z
'
,
'
WinStartTime
'
:
'
2016-06-21T11:55:02Z
'
,
'
WinEndTime
'
:
'
2016-06-21T12:00:02Z
'
,
'
Source
'
:
[
{
'
IP4
'
:
[
'
188.14.166.39
'
]
}
],
'
Target
'
:
[
{
'
IP4
'
:
[
'
195.113.165.128/25
'
]
}
],
'
Node
'
:
[
{
'
Type
'
:
[
'
Relay
'
],
'
Name
'
:
'
cz.cesnet.mentat.warden_filer
'
}
]
}
class
Warden3FilerTest
(
unittest
.
TestCase
):
"""
Warden3 Filer unit tests
"""
def
test_filter_by_regexp
(
self
):
regexp
=
'
^_+
'
filtered
=
warden_filer
.
filter_by_regexp
(
idea_raw_1
,
regexp
)
self
.
assertEquals
(
filtered
,
idea_filtered_1
)
event
=
{
'
ID
'
:
'
1
'
,
'
Node
'
:
{
'
_INTERNAL
'
:
'
data
'
}
}
filtered
=
warden_filer
.
filter_by_regexp
(
event
,
regexp
)
# only first level keys are filtered
self
.
assertEquals
(
filtered
,
event
)
if
__name__
==
"
__main__
"
:
unittest
.
main
()
This diff is collapsed.
Click to expand it.
warden_filer/warden_filer.cfg.dist
+
2
−
0
View file @
0163d76a
...
...
@@ -27,6 +27,8 @@
// "tag": null,
// "notag": ["Honeypot"]
//},
// Optional regexp filter for keys, matched keys are removed from events
//"key_filter" : "^_+",
// Optional information about detector to be prepended into Idea Node array
//"node": {
// "Name": "cz.example.warden.test_sender",
...
...
This diff is collapsed.
Click to expand it.
warden_filer/warden_filer.py
+
13
−
2
View file @
0163d76a
...
...
@@ -17,6 +17,7 @@ import signal
import
resource
import
atexit
import
argparse
import
re
from
os
import
path
,
mkdir
from
random
import
choice
,
randint
;
...
...
@@ -249,7 +250,14 @@ def get_dir_list(sdir, owait_poll_time, owait_timeout, nfchunk, oneshot):
nflist
=
sdir
.
get_incoming
()
return
nflist
def
filter_by_regexp
(
event
,
regexp
):
"""
:param dict event: event where the keys should be filtered.
:param regexp: regular expression defining keys which should be left out.
:return: dictionary which does NOT contain keys matching regexp.
:rtype: dict
"""
return
{
k
:
event
.
get
(
k
)
for
k
in
event
.
keys
()
if
not
re
.
match
(
regexp
,
k
)}
def
sender
(
config
,
wclient
,
sdir
,
oneshot
):
poll_time
=
config
.
get
(
"
poll_time
"
,
5
)
...
...
@@ -258,6 +266,8 @@ def sender(config, wclient, sdir, oneshot):
node
=
config
.
get
(
"
node
"
,
None
)
done_dir
=
config
.
get
(
"
done_dir
"
,
None
)
conf_filt
=
config
.
get
(
"
filter
"
,
{})
# If no filter for keys is set then the filter which matches nothing is used
key_filter
=
config
.
get
(
"
key_filter
"
,
"
a^
"
)
filt
=
{}
# Extract filter explicitly to be sure we have right param names for match_event
for
s
in
(
"
cat
"
,
"
nocat
"
,
"
tag
"
,
"
notag
"
,
"
group
"
,
"
nogroup
"
):
...
...
@@ -301,7 +311,8 @@ def sender(config, wclient, sdir, oneshot):
if
node
:
nodelist
=
event
.
setdefault
(
"
Node
"
,
[])
nodelist
.
insert
(
0
,
node
)
events
.
append
(
event
)
# filter keys based on regular expression before appending to the list
events
.
append
(
filter_by_regexp
(
event
,
key_filter
))
nf_sent
.
append
(
nf
)
except
Exception
as
e
:
Error
(
message
=
"
Error loading event
"
,
exc
=
sys
.
exc_info
(),
file
=
str
(
nf
),
...
...
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment