1
0

syslog-stat.pl 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199
  1. #!/usr/bin/perl
  2. #
  3. # Copyright (C) Roman Dmitiriev, rnd@rajven.ru
  4. #
  5. use utf8;
  6. use English;
  7. use base;
  8. use FindBin '$Bin';
  9. use lib "$Bin";
  10. use strict;
  11. use Time::Local;
  12. use FileHandle;
  13. use eyelib::config;
  14. use eyelib::main;
  15. use eyelib::mysql;
  16. use Data::Dumper;
  17. use DBI;
  18. use Time::Local;
  19. use Date::Parse;
  20. use Getopt::Long;
  21. use IO::Socket::UNIX qw( SOCK_STREAM );
  22. use Proc::Daemon;
  23. use Cwd;
  24. my $pf = '/var/run/syslog-stat.pid';
  25. my $socket_path='/var/run/syslog-ng.socket';
  26. my $daemon = Proc::Daemon->new(
  27. pid_file => $pf,
  28. work_dir => $HOME_DIR
  29. );
  30. # are you running? Returns 0 if not.
  31. my $pid = $daemon->Status($pf);
  32. my $daemonize = 1;
  33. GetOptions(
  34. 'daemon!' => \$daemonize,
  35. "help" => \&usage,
  36. "reload" => \&reload,
  37. "restart" => \&restart,
  38. "start" => \&run,
  39. "status" => \&status,
  40. "stop" => \&stop
  41. ) or &usage;
  42. exit(0);
  43. sub stop {
  44. if ($pid) {
  45. print "Stopping pid $pid...";
  46. if ($daemon->Kill_Daemon($pf)) {
  47. print "Successfully stopped.\n";
  48. } else {
  49. print "Could not find $pid. Was it running?\n";
  50. }
  51. } else {
  52. print "Not running, nothing to stop.\n";
  53. }
  54. }
  55. sub status {
  56. if ($pid) {
  57. print "Running with pid $pid.\n";
  58. } else {
  59. print "Not running.\n";
  60. }
  61. }
  62. sub run {
  63. if (!$pid) {
  64. print "Starting...";
  65. if ($daemonize) {
  66. # when Init happens, everything under it runs in the child process.
  67. # this is important when dealing with file handles, due to the fact
  68. # Proc::Daemon shuts down all open file handles when Init happens.
  69. # Keep this in mind when laying out your program, particularly if
  70. # you use filehandles.
  71. $daemon->Init;
  72. }
  73. setpriority(0,0,19);
  74. $SPID=~s/\.pl$/\.pid/;
  75. write_to_file($SPID,$$);
  76. my %trash_patterns = (
  77. 'Receive illegal destination ip packet 255.0.0.0 ,drop it' =>'1',
  78. 'Receive illegal destination ip packet 0.0.0.0 ,drop it' =>'1',
  79. 'SD Normal' =>'1',
  80. 'SD Abnormal' =>'1',
  81. 'source:0.0.0.0 destination:0.0.0.0 user:admin cmd:login' =>'1',
  82. 'FAN\'S speed level - 1 changed to level - 0.' => '1',
  83. 'FAN\'S speed level - 0 changed to level - 1.' => '1',
  84. "Environment-I-FANS-SPEED-CHNG: FAN'S speed level"=>'1'
  85. );
  86. my %warning_patterns = (
  87. 'SHUTDOWN-CTRL' => '1',
  88. 'PORT_FLOW' => '1',
  89. 'System ColdStart' => '1',
  90. 'Deny user/' => '1',
  91. 'LOOP-BACK-DETECTED' => 'loop',
  92. 'Find loop' =>'loop',
  93. 'SYS-5-LOOP' => 'loop',
  94. 'drifting from' => 'loop',
  95. 'Port-security has reached' => '1',
  96. 'Unauthenticated IP-MAC' => '1',
  97. 'FAN_FAILED' => '0',
  98. 'has the same IP Address' => '1',
  99. 'Loop detected on port e0' => 'loop',
  100. 'loopguard' => 'zyxel_loop',
  101. 'without management command' => '1',
  102. 'System cold start' =>'1',
  103. 'topology changes' => '1',
  104. 'HMON-0-power'=>'1',
  105. 'On battery power in response to an input power problem'=>'1',
  106. 'No longer on battery power'=>'1',
  107. 'Environment-W-PS-STAT-CHNG'=>'1',
  108. 'System warm start' => '1'
  109. );
  110. while (1) {
  111. eval {
  112. my $db = DBI->connect("dbi:mysql:database=$DBNAME;host=$DBHOST","$DBUSER","$DBPASS");
  113. if ( !defined $dbh ) { die "Cannot connect to mySQL server: $DBI::errstr\n"; }
  114. open(SYSLOG,$socket_path) || die("Error open fifo socket $socket_path: $!");
  115. while (my $logline = <SYSLOG>) {
  116. next unless defined $logline;
  117. chomp($logline);
  118. my ($timestamp,$host_ip,$message) = split (/\|/, $logline);
  119. next if (!$message);
  120. $message =~ s/\r/ /g;
  121. $message =~ s/\\015//g;
  122. $message =~ s/\\012//g;
  123. next if (!$message);
  124. next if (!$host_ip);
  125. if (time()-$last_refresh_config>=60) { init_option($db); }
  126. log_debug("Raw message: $message");
  127. #is trash messages?
  128. my $trash = 0;
  129. foreach my $pattern (keys %trash_patterns) {
  130. next if (!$pattern);
  131. if ($message=~/$pattern/i) {
  132. log_debug("Trash pattern: $pattern");
  133. $trash = 1;
  134. last;
  135. }
  136. }
  137. next if ($trash);
  138. my $hostname=$host_ip;
  139. my $netdev = get_device_by_ip($db,$host_ip);
  140. my $id = 0;
  141. if ($netdev) {
  142. $hostname = $netdev->{device_name};
  143. $id = $netdev->{id};
  144. } else {
  145. log_debug("Host with $host_ip is not found in netdevices!");
  146. }
  147. my $q_msg=$db->quote($message);
  148. my $ssql="INSERT INTO remote_syslog(device_id,ip,message) values('".$id."','".$host_ip."',".$q_msg.")";
  149. do_sql($db,$ssql);
  150. foreach my $pattern (keys %warning_patterns) {
  151. next if (!$pattern);
  152. if ($message=~/$pattern/i) {
  153. log_info("Warning pattern $pattern found! Send email.",1);
  154. sendEmail("Syslog warning for $hostname [".$host_ip."]!",$host_ip." ".$message);
  155. last;
  156. }
  157. }
  158. }
  159. close(SYSLOG);
  160. };
  161. if ($@) { log_error("Exception found: $@"); sleep(60); }
  162. }
  163. } else {
  164. print "Already Running with pid $pid\n";
  165. }
  166. }
  167. sub usage {
  168. print "usage: syslog-monitord.pl (start|stop|status|restart)\n";
  169. exit(0);
  170. }
  171. sub reload {
  172. print "reload process not implemented.\n";
  173. }
  174. sub restart {
  175. stop;
  176. run;
  177. }