If you supply a substitution string, rather than copying the original complete matching string, the substitution string is used, replacing all occurances of the special charcters \[0-9] with the associated substring matches. Note: \0 matches the whole expression, while \1,\2 through \9 are substring matches 1, 2 through 9. For example, say you are getting events from a logfileprobe which is generating alert events from a packet filter (e.g., Snort). You want the denial of service alerts to go to a particular downstream event handler, further you want to format the string nicely, pulling out the from and to IP:PORT. You might use a regex like: "DOS.* ([0-9]*\.[0-9]*\.[0-9]*\.[0-9]*:[0-9]*) -> ([0-9]*\.[0-9]*\.[0-9]*\.[0-9]*:[0-9]*)". This has 2 substrings, one for each IP:PORT. The substitution string might be: "DOS\t\1\t\2" which would result in a tab delimited record having the 'from' IP:PORT substring followed by the 'to' IP:PORT substring.
Substitution strings will be macro expanded for macros before event generation. The macro processing replaces the following special symbols with their associated event data:
| Symbol | Type |
|---|---|
| $v | event's value |
| $v[0-9] | the nth column where value is interpreted as a '|' delimited string |
| $n | event's name |
| $s | event's source |
| $p | event's priority |
| $t | event's timestamp as date string |
| $i | event's timestamp as int |
The name: option changes the regex match from evaluating the event's value to evaluating the event's name, thus allowing you to break an event stream into channels of events based on event name.
The source: option changes the regex match from evaluating the event's value to evaluating the event's source, thus allowing you to break an event stream into channels of events based on event source.
Regex's are POSIX 1003.2 "extended" form.
Wire keywords (standard handler keywords documented in Wire ):
Value example:
// $snortevents is a list bound to all events generated by
// snort alerts. This filter will breakup the stream of events
// into channels by type of alert.
set webattack create event { name: "web attack" priority: 1 }
set dos create event { name: "denial of service" priority: 1 }
set porn create event { name: "porn" priority: 1 }
// filter
create handler sfilter {
filter: $webattack "web-application" ""
filter: $dos "-dos" ""
filter: $porn "kickass-porn" ""
regevent: $snortevents
}
// alert webmaster of web attack
create handler execp {
cmd: "mail -s \"Web attack alert: \$n\" webmaster"
input: "Web attack alert:\n \$n \$v\n\n"
regevent: $webattack
}
// alert network admin of dos
create handler execp {
cmd: "mail -s \"Denial of service attack alert: \$n\" netadmin"
input: "Denial of service attack alert:\n \$n \$v\n\n"
regevent: $dos
}
// keep log of porn surfed to use as blackmail later :)
set logger create hlogger { filename: /log/booty.log rotate: daily }
create handler log { logger: $logger regevent: $porn }
Name example:
// Assume that you have given your events
// meaningful names, for example, the event
// for noconnect: used in your probe of your
// mail server is "noconnect mailserver".
// Similary, all event names for probes of
// particular machines have the machine's name
// as part of the event name.
// Further assume that you have given meaningful
// priorities to events, where priorities in the
// range of 90-100 are very serious and require
// immediate attention.
// Finally, assume that you want to dispatch alerts
// to different people depending on which machine
// generated the alert (e.g., DNS server "down"
// event generates an alert to the network engineer
// while a database "down" alert goes to a DBA).
// You setup an rfilterhandler to filter the
// high priority events...
set high-priority-events create event { name: dispatch }
// filter
create handler rfilter {
priority:
filter $high-priority-events 90 100
regevent: $allevents
}
// Now, filter the stream of high priority events
// by name, the output stream of each will generate
// an alert to the appropriate person
set netadmin-alert create event { name: "net-admin" }
set dbadmin-alert create event { name: "db-admin" }
set mailadmin-alert create event { name: "mail-admin" }
// filter
create handler sfilter {
name:
filter $netadmin-alert "dns|gw|firewall" ""
filter $dbadmin-alert "oracle" ""
filter $mailadmin-alert "mail" ""
regevent: $high-priority-events
}
// alert network admin
create handler execp {
cmd: "mail -s \"High priority alert: $n\" netadmin"
input: "High priority alert:\n $n $v\n\n"
regevent: $netadmin-alert
}
// alert dba
create handler execp {
cmd: "mail -s \"High priority alert: $n\" dba"
input: "High priority alert:\n $n $v\n\n"
regevent: $dbadmin-alert
}
// alert sys admin
create handler execp {
cmd: "mail -s \"High priority alert: $n\" sysadmin"
input: "High priority alert:\n $n $v\n\n"
regevent: $mailadmin-alert
}
Events accepted when filtering value:
| Type | Description |
|---|---|
| AW_EVENT_TYPE_STRING | Apply regex test to event, if match then generate a copy |
| Event Name | Type | Description |
|---|---|---|
| copy | AW_EVENT_TYPE_STRING | Copy of original event that passed the filter if no substitution, else regex substituted string |
| Type | Description |
|---|---|
| any | Apply regex test to event name, if match then generate a copy |
| Event Name | Type | Description |
|---|---|---|
| copy | any | Copy of original event that passed the filter if no substitution, else regex substituted name |
#include "monitor.h"
#include "wire.h"
#include "regexmatch.h"
Go to the source code of this file.
Data Structures | |
| struct | aw_sfilter_pattern_filter_t |
| Event to generate w/range match (internal). More... | |
| struct | aw_sfilter_regex_filter_t |
| Event to generate w/regx match (user supplied). More... | |
| struct | aw_sfilterhandler_t |
| Sfilter handler object. More... | |
Functions | |
| aw_sfilterhandler_t * | aw_create_sfilterhandler (u_int32_t nfilters, aw_sfilter_regex_filter_t *filters, u_int32_t alternate, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *logger) |
| Create a string filter handler. | |
| void | aw_free_sfilterhandler (aw_sfilterhandler_t *h) |
| Free handler and all associated resources. | |
| aw_handler_t * | aw_wire_sfilterhandler (aw_wire_mkhandler_args_t *args) |
| Create a sfilterhandler using "wire". See header doc for keyword documentation. | |
|
||||||||||||||||||||||||||||||||
|
Create a string filter handler. aw_create_sfilterhandler
|
|
|
Free handler and all associated resources. aw_free_sfilterhandler
|
|
|
Create a sfilterhandler using "wire". See header doc for keyword documentation. aw_wire_sfilterhandler |