#!/usr/bin/perl # # Copyright (C) 2011-2015 Cesnet z.s.p.o # # Use of this source is governed by a BSD-style license, see LICENSE file. use strict; use warnings; use FindBin qw($RealBin $RealScript); FindBin::again(); #------------------------------------------------------------------------------ # Warden 2.2 Client, Receiver, Example # # Simple use of warden-client receiver functionality to download new events # from # Warden server. This code illustrates how to integrate warden-client # receive functionality into local applications. #------------------------------------------------------------------------------ #------------------------------------------------------------------------------ # This code should developer add into his/her application. # Load Warden client library and use main module use lib "$RealBin/../lib"; use WardenClient; # Definition of requested event type. This attributes is also set on server # and must not change. my $requested_type = "portscan"; #------------------------------------------------------------------------------ # Simple code that prints out new events obtained from Warden server. print "+------------------------------------------------------------------------------------------------------------------------------------------+\n"; print "| id | hostname | service | detected | type | source_type | source | target_proto | target_port | attack_scale | note | priority | timeout |\n"; print "+------------------------------------------------------------------------------------------------------------------------------------------+\n"; # Download of new evetns from Warden server while (my @new_events = WardenClient::getNewEvents($requested_type)) { foreach my $event_ref (@new_events) { my @event = @$event_ref; print "| " . join(' | ', map { $_ || '' } @event) . " |" . "\n"; } print "+------------------------------------------------------------------------------------------------------------------------------------------+\n"; } print "+------------------------------------------------------------------------------------------------------------------------------------------+"; print "\n"; print "Last events in: " . scalar(localtime(time)) . "\n"; exit 0;