Main Page | Modules | Alphabetical List | Data Structures | File List | Data Fields | Globals | Related Pages

sqlitehandler.h File Reference


Detailed Description

This handler allows you to use events with a sqlite database, see http://www.sqlite.org. Typically, you would use this handler to insert events into a database. You may also use this handler to perform queries and regex match the resulting rows using the 'match:' directive. This can be very useful by cross-correllating the current event with others in the database. You may have multiple regex's, each generating its own events. This avoids connecting for each regex, rather it is is read one time for all. You may optionally specify a subsitution string that behaves similar to 'sed' to customize the generated events. If you supply a substitution string, rather than copying the original complete matching string, the substitution string is used, replacing all occurances of the special charcters \[0-9] with the associated substring matches. Note: \0 matches the whole expression, while \1,\2 through \9 are substring matches 1, 2 through 9. An optional 'count:' directive is allowed which will generate the specified event if the row count is within the specified range. You may have multiple 'count:' directives. An optional 'complete:' directive will generate an event after a successful sql execution. An optional 'time:' directive will generate an event after a successful sql execution with the execution time in usec. Regex's are POSIX 1003.2 "extended" form. The sql and subst string replaces the following special symbols with their associated event data:
SymbolType
$v event's value
$v[0-9] the nth column where value is interpreted as a '|' delimited string
$n event's name
$s event's source
$p event's priority
$t event's timestamp as date string
$i event's timestamp as int

Wire keywords (standard handler keywords documented in Wire )

Insert Example:

// gonna insert events into 'alarm' table
set sql "insert into alarms (name, value, priority) values ('\$n', '\$v', \$p)"

// make the handler, assumes you have bound 'events' to list of events you care about.
create handler sqlite { 
  db: monitordb 
  sql: $sql 
  regevent: $events 
}

Query Example:

// assume that we have a logfileprobe watching /var/log/messages for 'su' to root messages
// and they all get logged the database 'alarms' table for all machines in the enterprise,
// see above insert example for how to store events in the database.

// cross correllate this 'su' event with others in the database, in this case
// we want to generate an alarm if we see more than 5 'su' messages in the
// last hour over ALL the machines in the enterprise
create handler sqlite { 
  db: monitordb 
  sql: "select priority from alarms where name='\$n' and date < julianday(datetime('now','localtime')) - 0.04166667"
  count: $su_alarm 6 10000000
  regevent: $su_event
}

Events Accepted:
TypeDescription
any Macro expand sql, then eval.
Complete Events Generated:
Event NameTypeDescription
complete AW_EVENT_TYPE_STRING Generate event on successful sql execution, value is sql
Time Events Generated:
Event NameTypeDescription
time AW_EVENT_TYPE_INT32 Generate event on successful sql execution, value is execution time in usec
Match Events Generated:
Event NameTypeDescription
match AW_EVENT_TYPE_STRING Matching row ('|' delimiting columns) or subst string
nomatch AW_EVENT_TYPE_STRING If no rows matched, value is sql
Count Events Generated:
Event NameTypeDescription
count AW_EVENT_TYPE_INT32 Number of rows returned from sql query

#include <stdio.h>
#include "awdb.h"
#include "sqlite3.h"
#include "regexmatch.h"
#include "monitor.h"
#include "wire.h"
#include "awsqlite.h"

Go to the source code of this file.

Data Structures

struct  aw_sqlitehandler_t
 Sqlite handler object. More...


Functions

aw_sqlitehandler_t * aw_create_sqlitehandler (const aw_sqlite_cinfo_t *cinfo, const byte_t *sql, const byte_t *desc, aw_db_cevents_t *cevents, u_int32_t nregexs, const aw_db_regex_t *regexs, u_int32_t ncounters, const aw_db_counter_t *counters, int32_t(*regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), int32_t(*regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index), const aw_alarm_sched_t *sched, aw_logger_t *elogger)
 Create a sqlite handler.

void aw_free_sqlitehandler (aw_sqlitehandler_t *h)
 Free handler and all associated resources.

aw_handler_t * aw_wire_sqlitehandler (aw_wire_mkhandler_args_t *args)
 Create a sqlitehandler using "wire". See header doc for keyword documentation.


Function Documentation

aw_sqlitehandler_t* aw_create_sqlitehandler (  const aw_sqlite_cinfo_t *  cinfo,
const byte_t *  sql,
const byte_t *  desc,
aw_db_cevents_t *  cevents,
u_int32_t  nregexs,
const aw_db_regex_t *  regexs,
u_int32_t  ncounters,
const aw_db_counter_t *  counters,
int32_t(*  regevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
int32_t(*  regmaskevent)(aw_handler_t *h, aw_address_t *eventid, u_int32_t index),
const aw_alarm_sched_t *  sched,
aw_logger_t *  elogger
) 
 

Create a sqlite handler.

aw_create_sqlitehandler

Parameters:
cinfo Connection info
sql Sql string to macro expand
desc Optional Description string
cevents Completion event
nregexs How many regex strings
regexs Array of regex strings/events
ncounters How many counters
counters Array of counters
regevent Function pointer for event registration
regmaskevent Function pointer for event mask registration
sched Run schedule
elogger Aware logger object
Returns:
Handler object

void aw_free_sqlitehandler (  aw_sqlitehandler_t *  h  ) 
 

Free handler and all associated resources.

aw_free_sqlitehandler

Parameters:
h The handler

aw_handler_t* aw_wire_sqlitehandler (  aw_wire_mkhandler_args_t *  args  ) 
 

Create a sqlitehandler using "wire". See header doc for keyword documentation.

aw_wire_sqlitehandler

Aware 0.11.1 Copyright (C) 1998-2005 Russell Leighton (russ@elegant-software.com)