Main Page | Modules | Alphabetical List | Data Structures | File List | Data Fields | Globals | Related Pages

sfilterhandler.h File Reference


Detailed Description

This handler acts as a regex based string filter. Those events that are received with a string value that match a supplied regex will be copied and sent to the associated copy address. You may have variable numbers of regex filters which allow you to filter an event stream into channels of events based on matching. You may optionally specify a subsitution string that behaves similar to 'sed' to customize the generated events.

If you supply a substitution string, rather than copying the original complete matching string, the substitution string is used, replacing all occurances of the special charcters \[0-9] with the associated substring matches. Note: \0 matches the whole expression, while \1,\2 through \9 are substring matches 1, 2 through 9. For example, say you are getting events from a logfileprobe which is generating alert events from a packet filter (e.g., Snort). You want the denial of service alerts to go to a particular downstream event handler, further you want to format the string nicely, pulling out the from and to IP:PORT. You might use a regex like: "DOS.* ([0-9]*\.[0-9]*\.[0-9]*\.[0-9]*:[0-9]*) -> ([0-9]*\.[0-9]*\.[0-9]*\.[0-9]*:[0-9]*)". This has 2 substrings, one for each IP:PORT. The substitution string might be: "DOS\t\1\t\2" which would result in a tab delimited record having the 'from' IP:PORT substring followed by the 'to' IP:PORT substring.

Substitution strings will be macro expanded for macros before event generation. The macro processing replaces the following special symbols with their associated event data:

SymbolType
$v event's value
$v[0-9] the nth column where value is interpreted as a '|' delimited string
$n event's name
$s event's source
$p event's priority
$t event's timestamp as date string
$i event's timestamp as int

The name: option changes the regex match from evaluating the event's value to evaluating the event's name, thus allowing you to break an event stream into channels of events based on event name.

The source: option changes the regex match from evaluating the event's value to evaluating the event's source, thus allowing you to break an event stream into channels of events based on event source.

Regex's are POSIX 1003.2 "extended" form.

Wire keywords (standard handler keywords documented in Wire ):

You my have multiple filter: lines. Matches are applied in the order they are declared.

Value example:


// $snortevents is a list bound to all events generated by
// snort alerts. This filter will breakup the stream of events
// into channels by type of alert. 
set webattack create event { name: "web attack"  priority: 1 }
set dos create event { name: "denial of service"  priority: 1 }
set porn create event { name: "porn"  priority: 1 }

// filter
create handler sfilter { 
 filter: $webattack "web-application" ""
 filter: $dos "-dos" ""
 filter: $porn "kickass-porn" ""
 regevent: $snortevents
}

// alert webmaster of web attack
create handler execp { 
 cmd: "mail -s \"Web attack alert: \$n\" webmaster"
 input: "Web attack alert:\n \$n \$v\n\n"
 regevent: $webattack
}

// alert network admin of dos
create handler execp { 
 cmd: "mail -s \"Denial of service attack alert: \$n\" netadmin"
 input: "Denial of service attack alert:\n \$n \$v\n\n"
 regevent: $dos
}

// keep log of porn surfed to use as blackmail later :)
set logger create hlogger { filename: /log/booty.log rotate: daily }
create handler log { logger: $logger regevent: $porn }

Name example:

// Assume that you have given your events
// meaningful names, for example, the event
// for noconnect: used in your probe of your
// mail server is "noconnect mailserver".
// Similary, all event names for probes of
// particular machines have the machine's name
// as part of the event name.

// Further assume that you have given meaningful
// priorities to events, where priorities in the
// range of 90-100 are very serious and require
// immediate attention.

// Finally, assume that you want to dispatch alerts
// to different people depending on which machine
// generated the alert (e.g., DNS server "down"
// event generates an alert to the network engineer
// while a database "down" alert goes to a DBA).

// You setup an rfilterhandler to filter the 
// high priority events...

set high-priority-events create event { name: dispatch }

// filter
create handler rfilter { 
 priority:
 filter $high-priority-events 90 100
 regevent: $allevents
}

// Now, filter the stream of high priority events
// by name, the output stream of each will generate
// an alert to the appropriate person

set netadmin-alert create event { name: "net-admin" }
set dbadmin-alert create event { name: "db-admin" }
set mailadmin-alert create event { name: "mail-admin" }

// filter
create handler sfilter { 
 name:
 filter $netadmin-alert "dns|gw|firewall" ""
 filter $dbadmin-alert "oracle" ""
 filter $mailadmin-alert "mail" ""
 regevent: $high-priority-events
}

// alert network admin 
create handler execp { 
 cmd: "mail -s \"High priority alert: $n\" netadmin"
 input: "High priority alert:\n $n $v\n\n"
 regevent: $netadmin-alert
}

// alert dba
create handler execp { 
 cmd: "mail -s \"High priority alert: $n\" dba"
 input: "High priority alert:\n $n $v\n\n"
 regevent: $dbadmin-alert
}

// alert sys admin 
create handler execp { 
 cmd: "mail -s \"High priority alert: $n\" sysadmin"
 input: "High priority alert:\n $n $v\n\n"
 regevent: $mailadmin-alert
}


Events accepted when filtering value:
TypeDescription
AW_EVENT_TYPE_STRING Apply regex test to event, if match then generate a copy
Events generated when filtering value:
Event NameTypeDescription
copy AW_EVENT_TYPE_STRING Copy of original event that passed the filter if no substitution, else regex substituted string
Events accepted when filtering name:
TypeDescription
any Apply regex test to event name, if match then generate a copy
Events generated when filtering source:
Event NameTypeDescription
copy any Copy of original event that passed the filter if no substitution, else regex substituted name

#include "monitor.h"
#include "wire.h"
#include "regexmatch.h"

Go to the source code of this file.

Data Structures

struct  aw_sfilter_pattern_filter_t
 Event to generate w/range match (internal). More...

struct  aw_sfilter_regex_filter_t
 Event to generate w/regx match (user supplied). More...

struct  aw_sfilterhandler_t
 Sfilter handler object. More...


Functions

aw_sfilterhandler_t * aw_create_sfilterhandler (u_int32_t nfilters, aw_sfilter_regex_filter_t *filters, u_int32_t alternate, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *logger)
 Create a string filter handler.

void aw_free_sfilterhandler (aw_sfilterhandler_t *h)
 Free handler and all associated resources.

aw_handler_t * aw_wire_sfilterhandler (aw_wire_mkhandler_args_t *args)
 Create a sfilterhandler using "wire". See header doc for keyword documentation.


Function Documentation

aw_sfilterhandler_t* aw_create_sfilterhandler (  u_int32_t  nfilters,
aw_sfilter_regex_filter_t *  filters,
u_int32_t  alternate,
int32_t(*  regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
int32_t(*  regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
const aw_alarm_sched_t *  sched,
aw_logger_t *  logger
) 
 

Create a string filter handler.

aw_create_sfilterhandler

Parameters:
nfilters How many filters
filters Event filters, if range match is true, generate event
alternate If 1 indicates you want to filter on name, if 2 on source rather than value
regevent Function pointer for event registration
regmaskevent Function pointer for event mask registration
sched Run schedule
logger Logger object
Returns:
Handler object

void aw_free_sfilterhandler (  aw_sfilterhandler_t *  h  ) 
 

Free handler and all associated resources.

aw_free_sfilterhandler

Parameters:
h The handler

aw_handler_t* aw_wire_sfilterhandler (  aw_wire_mkhandler_args_t *  args  ) 
 

Create a sfilterhandler using "wire". See header doc for keyword documentation.

aw_wire_sfilterhandler

Aware 0.11.1 Copyright (C) 1998-2005 Russell Leighton (russ@elegant-software.com)