Documentation ¶
Index ¶
- Constants
- Variables
- func AddTags(ms MapStr, tags []string) error
- func Bytes_Htohl(b []byte) uint32
- func Bytes_Ntohl(b []byte) uint32
- func Bytes_Ntohll(b []byte) uint64
- func Bytes_Ntohs(b []byte) uint16
- func DumpInCSVFormat(fields []string, rows [][]string) string
- func Ipv4_Ntoa(ip uint32) string
- func IsLoopback(ip_str string) (bool, error)
- func LoadGeoIPData(config Geoip) *libgeo.GeoIP
- func LocalIpAddrs() ([]net.IP, error)
- func LocalIpAddrsAsStrings(include_loopbacks bool) ([]string, error)
- func MergeFields(ms, fields MapStr, underRoot bool) error
- func ReadString(s []byte) (string, error)
- type Cache
- func (c *Cache) CleanUp() int
- func (c *Cache) Delete(k Key) Value
- func (c *Cache) Entries() map[Key]Value
- func (c *Cache) Get(k Key) Value
- func (c *Cache) Put(k Key, v Value) Value
- func (c *Cache) PutIfAbsent(k Key, v Value) Value
- func (c *Cache) PutIfAbsentWithTimeout(k Key, v Value, timeout time.Duration) Value
- func (c *Cache) PutWithTimeout(k Key, v Value, timeout time.Duration) Value
- func (c *Cache) Replace(k Key, v Value) Value
- func (c *Cache) ReplaceWithTimeout(k Key, v Value, timeout time.Duration) Value
- func (c *Cache) Size() int
- func (c *Cache) StartJanitor(interval time.Duration)
- func (c *Cache) StopJanitor()
- type CmdlineTuple
- type Config
- func (c *Config) Bool(name string, idx int) (bool, error)
- func (c *Config) Child(name string, idx int) (*Config, error)
- func (c *Config) CountField(name string) (int, error)
- func (c *Config) Float(name string, idx int) (float64, error)
- func (c *Config) HasField(name string) bool
- func (c *Config) Int(name string, idx int) (int64, error)
- func (c *Config) Merge(from interface{}) error
- func (c *Config) Path() string
- func (c *Config) PathOf(field string) string
- func (c *Config) SetBool(name string, idx int, value bool) error
- func (c *Config) SetChild(name string, idx int, value *Config) error
- func (c *Config) SetFloat(name string, idx int, value float64) error
- func (c *Config) SetInt(name string, idx int, value int64) error
- func (c *Config) SetString(name string, idx int, value string) error
- func (c *Config) String(name string, idx int) (string, error)
- func (c *Config) Unpack(to interface{}) error
- type Endpoint
- type EventMetadata
- type Eventer
- type Geoip
- type HashableIpPortTuple
- type HashableTcpTuple
- type IpPortTuple
- type Key
- type MapStr
- func (m MapStr) Clone() MapStr
- func (m MapStr) CopyFieldsTo(to MapStr, key string) error
- func (m MapStr) Delete(key string) error
- func (m MapStr) EnsureCountField() error
- func (m MapStr) EnsureTimestampField(now func() time.Time) error
- func (m MapStr) HasKey(key string) (bool, error)
- func (m MapStr) String() string
- func (m MapStr) StringToPrint() string
- func (m MapStr) Update(d MapStr)
- type NetString
- type RemovalListener
- type TcpTuple
- type Time
- type Value
- type WorkerSignal
Constants ¶
const ( EventMetadataKey = "_event_metadata" FieldsKey = "fields" TagsKey = "tags" )
const ( OK_STATUS = "OK" ERROR_STATUS = "Error" SERVER_ERROR_STATUS = "Server Error" CLIENT_ERROR_STATUS = "Client Error" )
standardized status values
const MaxIpPortTupleRawSize = 16 + 16 + 2 + 2
const MaxTcpTupleRawSize = 16 + 16 + 2 + 2 + 4
const TsLayout = "2006-01-02T15:04:05.000Z"
TsLayout is the layout to be used in the timestamp marshaling/unmarshaling everywhere. The timezone must always be UTC.
Variables ¶
var ErrorFieldsIsNotMapStr = errors.New("the value stored in fields is not a MapStr")
var ErrorTagsIsNotStringArray = errors.New("the value stored in tags is not a []string")
Functions ¶
func AddTags ¶
AddTag appends a tag to the tags field of ms. If the tags field does not exist then it will be created. If the tags field exists and is not a []string then an error will be returned. It does not deduplicate the list of tags.
func Bytes_Htohl ¶
func Bytes_Ntohl ¶
func Bytes_Ntohll ¶
func Bytes_Ntohs ¶
func DumpInCSVFormat ¶
DumpInCSVFormat takes a set of fields and rows and returns a string representing the CSV representation for the fields and rows.
func IsLoopback ¶
IsLoopback check if a particular IP notation corresponds to a loopback interface.
func LoadGeoIPData ¶
func LoadGeoIPData(config Geoip) *libgeo.GeoIP
func LocalIpAddrs ¶
LocalIpAddrs finds the IP addresses of the hosts on which the shipper currently runs on.
func LocalIpAddrsAsStrings ¶
LocalIpAddrsAsStrings finds the IP addresses of the hosts on which the shipper currently runs on and returns them as an array of strings.
func MergeFields ¶
MergeFields merges the top-level keys and values in each source hash (it does not perform a deep merge). If the same key exists in both, the value in fields takes precedence. If underRoot is true then the contents of the fields MapStr is merged with the value of the 'fields' key in ms.
An error is returned if underRoot is true and the value of ms.fields is not a MapStr.
func ReadString ¶
ReadString extracts the first null terminated string from a slice of bytes.
Types ¶
type Cache ¶
Cache is a semi-persistent mapping of keys to values. Elements added to the cache are store until they are explicitly deleted or are expired due time- based eviction based on last access time.
Expired elements are not visible through classes methods, but they do remain stored in the cache until CleanUp() is invoked. Therefore CleanUp() must be invoked periodically to prevent the cache from becoming a memory leak. If you want to start a goroutine to perform periodic clean-up then see StartJanitor().
Cache does not support storing nil values. Any attempt to put nil into the cache will cause a panic.
func NewCache ¶
NewCache creates and returns a new Cache. d is the length of time after last access that cache elements expire. initialSize is the initial allocation size used for the Cache's underlying map.
func NewCacheWithRemovalListener ¶
func NewCacheWithRemovalListener(d time.Duration, initialSize int, l RemovalListener) *Cache
NewCacheWithRemovalListener creates and returns a new Cache and register a RemovalListener callback function. d is the length of time after last access that cache elements expire. initialSize is the initial allocation size used for the Cache's underlying map. l is the callback function that will be invoked when cache elements are removed from the map on CleanUp.
func (*Cache) CleanUp ¶
CleanUp performs maintenance on the cache by removing expired elements from the cache. If a RemoveListener is registered it will be invoked for each element that is removed during this clean up operation. The RemovalListener is invoked on the caller's goroutine.
func (*Cache) Delete ¶
Delete a key from the map and return the value or nil if the key does not exist. The RemovalListener is not notified for explicit deletions.
func (*Cache) Get ¶
Get the current value associated with a key or nil if the key is not present. The last access time of the element is updated.
func (*Cache) Put ¶
Put writes the given key and value to the map replacing any existing value if it exists. The previous value associated with the key returned or nil if the key was not present.
func (*Cache) PutIfAbsent ¶
PutIfAbsent writes the given key and value to the cache only if the key is absent from the cache. Nil is returned if the key-value pair were written, otherwise the old value is returned.
func (*Cache) PutIfAbsentWithTimeout ¶
PutIfAbsentWithTimeout writes the given key and value to the cache only if the key is absent from the cache. Nil is returned if the key-value pair were written, otherwise the old value is returned. The cache expiration time will be overwritten by timeout of the key being inserted.
func (*Cache) PutWithTimeout ¶
PutWithTimeout writes the given key and value to the map replacing any existing value if it exists. The previous value associated with the key returned or nil if the key was not present. The cache expiration time will be overwritten by timeout of the key being inserted.
func (*Cache) Replace ¶
Replace overwrites the value for a key only if the key exists. The old value is returned if the value is updated, otherwise nil is returned.
func (*Cache) ReplaceWithTimeout ¶
ReplaceWithTimeout overwrites the value for a key only if the key exists. The old value is returned if the value is updated, otherwise nil is returned. The cache expiration time will be overwritten by timeout of the key being inserted.
func (*Cache) Size ¶
Size returns the number of elements in the cache. The number includes both active elements and expired elements that have not been cleaned up.
func (*Cache) StartJanitor ¶
StartJanitor starts a goroutine that will periodically invoke the cache's CleanUp() method.
func (*Cache) StopJanitor ¶
func (c *Cache) StopJanitor()
StopJanitor stops the goroutine created by StartJanitor.
type CmdlineTuple ¶
type CmdlineTuple struct {
Src, Dst []byte
}
Source and destination process names, as found by the proc module.
type Config ¶
func NewConfigFrom ¶
type EventMetadata ¶
type EventMetadata struct { Fields MapStr FieldsUnderRoot bool `config:"fields_under_root"` Tags []string }
EventMetadata contains fields and tags that can be added to an event via configuration.
type HashableIpPortTuple ¶
type HashableIpPortTuple [MaxIpPortTupleRawSize]byte
type HashableTcpTuple ¶
type HashableTcpTuple [MaxTcpTupleRawSize]byte
type IpPortTuple ¶
type IpPortTuple struct { Ip_length int Src_ip, Dst_ip net.IP Src_port, Dst_port uint16 // contains filtered or unexported fields }
func NewIpPortTuple ¶
func (*IpPortTuple) ComputeHashebles ¶
func (t *IpPortTuple) ComputeHashebles()
func (*IpPortTuple) Hashable ¶
func (t *IpPortTuple) Hashable() HashableIpPortTuple
Hashable returns a hashable value that uniquely identifies the IP-port tuple.
func (*IpPortTuple) RevHashable ¶
func (t *IpPortTuple) RevHashable() HashableIpPortTuple
Hashable returns a hashable value that uniquely identifies the IP-port tuple after swapping the source and destination.
func (*IpPortTuple) String ¶
func (t *IpPortTuple) String() string
type MapStr ¶
type MapStr map[string]interface{}
Commonly used map of things, used in JSON creation and the like.
func ConvertToGenericEvent ¶
func MapStrUnion ¶
MapStrUnion creates a new MapStr containing the union of the key-value pairs of the two maps. If the same key is present in both, the key-value pairs from dict2 overwrite the ones from dict1.
func MarshallUnmarshall ¶
func (MapStr) EnsureCountField ¶
EnsureCountField sets the 'count' field to 1 if count does not already exist.
func (MapStr) EnsureTimestampField ¶
Checks if a timestamp field exists and if it doesn't it adds one by using the injected now() function as a time source.
func (MapStr) StringToPrint ¶
type NetString ¶
type NetString []byte
NetString store the byte length of the data that follows, making it easier to unambiguously pass text and byte data between programs that could be sensitive to values that could be interpreted as delimiters or terminators (such as a null character).
func (NetString) MarshalText ¶
MarshalText exists to implement encoding.TextMarshaller interface to treat []byte as raw string by other encoders/serializers (e.g. JSON)
type RemovalListener ¶
RemovalListener is the callback function type that can be registered with the cache to receive notification of the removal of expired elements.
type TcpTuple ¶
type TcpTuple struct { Ip_length int Src_ip, Dst_ip net.IP Src_port, Dst_port uint16 Stream_id uint32 // contains filtered or unexported fields }
func TcpTupleFromIpPort ¶
func TcpTupleFromIpPort(t *IpPortTuple, tcp_id uint32) TcpTuple
func (*TcpTuple) ComputeHashebles ¶
func (t *TcpTuple) ComputeHashebles()
func (*TcpTuple) Hashable ¶
func (t *TcpTuple) Hashable() HashableTcpTuple
Hashable() returns a hashable value that uniquely identifies the TCP tuple.
func (TcpTuple) IpPort ¶
func (t TcpTuple) IpPort() *IpPortTuple
Returns a pointer to the equivalent IpPortTuple.
type Time ¶
Time is an abstraction for the time.Time type
func MustParseTime ¶
MustParseTime is a convenience equivalent of the ParseTime function that panics in case of errors.
func (Time) MarshalJSON ¶
MarshalJSON implements json.Marshaler interface. The time is a quoted string in the JsTsLayout format.
func (*Time) UnmarshalJSON ¶
UnmarshalJSON implements js.Unmarshaler interface. The time is expected to be a quoted string in TsLayout format.
type WorkerSignal ¶
type WorkerSignal struct { Done chan struct{} // contains filtered or unexported fields }
WorkerSignal ensure all events have been treated before closing Go routines
func NewWorkerSignal ¶
func NewWorkerSignal() *WorkerSignal
func (*WorkerSignal) AddEvent ¶
func (ws *WorkerSignal) AddEvent(delta int)
func (*WorkerSignal) DoneEvent ¶
func (ws *WorkerSignal) DoneEvent()
func (*WorkerSignal) Init ¶
func (ws *WorkerSignal) Init()
func (*WorkerSignal) Stop ¶
func (ws *WorkerSignal) Stop()
func (*WorkerSignal) WorkerFinished ¶
func (ws *WorkerSignal) WorkerFinished()
func (*WorkerSignal) WorkerStart ¶
func (ws *WorkerSignal) WorkerStart()