oraclehandler.h File Reference
Detailed Description
This handler allows you to use events with a oracle database,
see http://www.oracle.com.
Typically, you would use this handler to insert events into a database.
You may also use this handler to perform queries and regex match the resulting
rows using the 'match:' directive. This can be very useful by cross-correllating the current event
with others in the database. You may have multiple regex's, each generating its own events. This avoids
connecting for each regex, rather it is is read one time for all.
You may optionally specify a subsitution string that behaves similar to 'sed' to
customize the generated events.
If you supply a substitution string, rather than copying the original complete matching string, the
substitution string is used, replacing all occurances of the special charcters \[0-9]
with the associated substring matches. Note: \0 matches the whole expression, while
\1,\2 through \9 are substring matches 1, 2 through 9.
An optional 'count:' directive is allowed which will generate the specified
event if the row count is within the specified range. You may have multiple
'count:' directives.
An optional 'complete:' directive will generate an event after a successful
sql execution.
An optional 'time:' directive will generate an event after a successful
sql execution with the execution time in usec.
Regex's are POSIX 1003.2 "extended" form.
The sql and subst string replaces the following special symbols with their
associated event data:
| Symbol | Type |
|---|
| $v | event's value |
| $v[0-9] | the nth column where value is interpreted as a '|' delimited string |
| $n | event's name |
| $s | event's source |
| $p | event's priority |
| $t | event's timestamp as date string |
| $i | event's timestamp as int |
Wire keywords (standard handler keywords documented in Wire )
- user: user (user name)
- passwd: passwd (password)
- db: name of db (database name)
- sql: sql string (macro expand format using event info)
- complete: event (optional)
- time: event (optional)
- match: match-event nomatch-event regexp subst send match-event if regex matches, else send nomatch-event, if either match-event or nomatch-event are empty strings they are ignored (optional)
- count: count-event min max (optional, if row count is in [min,max] the generate count-event)
Insert Example:
// gonna insert events into 'alarm' table
set sql "insert into alarms (name, value, priority, timestamp) values ('\$n', '\$v', \$p, SYSDATE)"
// make the handler, assumes you have bound 'events' to list of events you care about.
create handler oracle {
user: russ passwd: "aware" db: monitordb
sql: $sql
regevent: $events
}
Query Example:
// assume that we have a logfileprobe watching /var/log/messages for 'su' to root messages
// and they all get logged the database 'alarms' table for all machines in the enterprise,
// see above insert example for how to store events in the database.
// cross correllate this 'su' event with others in the database, in this case
// we want to generate an alarm if we see more than 5 'su' messages in the
// last hour over ALL the machines in the enterprise
create handler oracle {
user: russ passwd: "aware" db: monitordb
sql: "select priority from alarms where name='\$n' and timestamp - to_date('00:00', 'MI:SS') > sysdate - to_date('01:00', 'HH:MI')"
count: $su_alarm 6 10000000
regevent: $su_event
}
Events Accepted:
| Type | Description |
| any |
Macro expand sql, then eval. |
Complete Events Generated:
| Event Name | Type | Description |
| complete |
AW_EVENT_TYPE_STRING |
Generate event on successful sql execution, value is sql |
Time Events Generated:
| Event Name | Type | Description |
| time |
AW_EVENT_TYPE_INT32 |
Generate event on successful sql execution, value is execution time in usec |
Match Events Generated:
| Event Name | Type | Description |
| match |
AW_EVENT_TYPE_STRING |
Matching row ('|' delimiting columns) or subst string |
| nomatch |
AW_EVENT_TYPE_STRING |
If no rows matched, value is sql |
Count Events Generated:
| Event Name | Type | Description |
| count |
AW_EVENT_TYPE_INT32 |
Number of rows returned from sql query |
#include <stdio.h>
#include "awdb.h"
#include "monitor.h"
#include "wire.h"
#include "awora.h"
Go to the source code of this file.
|
Data Structures |
| struct | aw_oraclehandler_t |
| | Oracle handler object. More...
|
Functions |
| aw_oraclehandler_t * | aw_create_oraclehandler (aw_ora_cinfo_t *cinfo, byte_t *sql, byte_t *desc, aw_db_cevents_t *cevents, u_int32_t nregexs, aw_db_regex_t *regexs, u_int32_t ncounters, aw_db_counter_t *counters, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *elogger) |
| | Create a oracle handler.
|
| void | aw_free_oraclehandler (aw_oraclehandler_t *h) |
| | Free handler and all associated resources.
|
| aw_handler_t * | aw_wire_oraclehandler (aw_wire_mkhandler_args_t *args) |
| | Create a oraclehandler using "wire". See header doc for keyword documentation.
|
Function Documentation
| aw_oraclehandler_t* aw_create_oraclehandler |
( |
aw_ora_cinfo_t * |
cinfo, |
|
|
byte_t * |
sql, |
|
|
byte_t * |
desc, |
|
|
aw_db_cevents_t * |
cevents, |
|
|
u_int32_t |
nregexs, |
|
|
aw_db_regex_t * |
regexs, |
|
|
u_int32_t |
ncounters, |
|
|
aw_db_counter_t * |
counters, |
|
|
int32_t(* |
regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), |
|
|
int32_t(* |
regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), |
|
|
const aw_alarm_sched_t * |
sched, |
|
|
aw_logger_t * |
elogger |
|
) |
|
|
|
|
Create a oracle handler.
aw_create_oraclehandler
- Parameters:
-
| cinfo | Connection info |
| sql | Sql string to macro expand |
| desc | Optional Description string |
| cevents | Completion event |
| nregexs | How many regex strings |
| regexs | Array of regex strings/events |
| ncounters | How many counters |
| counters | Array of counters |
| regevent | Function pointer for event registration |
| regmaskevent | Function pointer for event mask registration |
| sched | Run schedule |
| elogger | Aware logger object |
- Returns:
- Handler object
|
|
|
Free handler and all associated resources.
aw_free_oraclehandler
- Parameters:
-
|
|
|
Create a oraclehandler using "wire". See header doc for keyword documentation.
aw_wire_oraclehandler |
Aware 0.11.1 Copyright (C) 1998-2005 Russell Leighton (russ@elegant-software.com)