mirror of
https://github.com/zeek/zeek.git
synced 2025-10-07 17:18:20 +00:00
Add pcap_file option to supervised nodes.
This allows to start Supervised nodes with a pcap_file argument rather than interface. This is based on changes from @J-Gras.
This commit is contained in:
parent
859ecc7b8b
commit
1882307cf3
7 changed files with 169 additions and 0 deletions
|
@ -0,0 +1,35 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
1300475167.096535 CHhAvVGS1DHFjwGM9 141.142.220.202 224.0.0.251 D dns
|
||||
1300475167.097012 ClEkJM2Vm5giqnMf4h fe80::217:f2ff:fed7:cf65 ff02::fb D dns
|
||||
1300475167.099816 C4J4Th3PJpwUYZZ6gc 141.142.220.50 224.0.0.251 D dns
|
||||
1300475168.853899 CmES5u32sYpV7JYN 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.854378 CP5puj4I8PtEU4qzYg 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.854837 C37jN32gN3y3AZzyf6 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.857956 C0LAHyvtKSQHyJxIl 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.858306 CFLRIC3zaTU1loLGxh 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.858713 C9rXSW3KSpTYvPrlI1 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.891644 C9mvWx3ezztgzcexV7 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.892037 CNnMIj2QSd84NKf7U3 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.892414 C7fIlMZDuRiqjpYbb 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.893988 CpmdRlaUoJLN3uIRa 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.894422 C1Xkzz2MaGtLrc1Tla 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.894787 CqlVyW1YwZ15RhTBc4 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.901749 CBA8792iHmnhPLksKa 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475168.902195 CGLPPc35OzDQij1XX8 141.142.220.118 141.142.2.2 Dd dns
|
||||
1300475169.899438 Cipfzj1BEnhejw8cGf 141.142.220.44 224.0.0.251 D dns
|
||||
1300475170.862384 CV5WJ42jPYbNW9JNWf 141.142.220.226 141.142.220.255 D dns
|
||||
1300475171.675372 CPhDKt12KQPUVbQz06 fe80::3074:17d5:2052:c324 ff02::1:3 D dns
|
||||
1300475171.677081 CAnFrb2Cvxr5T7quOc 141.142.220.226 224.0.0.252 D dns
|
||||
1300475173.116749 C8rquZ3DjgNW06JGLl fe80::3074:17d5:2052:c324 ff02::1:3 D dns
|
||||
1300475173.117362 CzrZOtXqhwwndQva3 141.142.220.226 224.0.0.252 D dns
|
||||
1300475173.153679 CaGCc13FffXe6RkQl9 141.142.220.238 141.142.220.255 D dns
|
||||
1300475168.652003 CtPZjS20MLrsMUOJi2 141.142.220.118 208.80.152.2 DdA -
|
||||
1300475168.902635 CiyBAq1bBLNaTiTAc 141.142.220.118 208.80.152.2 ShADad http
|
||||
1300475168.855305 C3eiCBGOLw3VtHfOj 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.855330 CwjjYJ2WqgTbAqiHl6 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.859163 Ck51lg1bScffFj34Ri 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.892913 CykQaM33ztNt0csB9a 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.892936 CtxTCR2Yer0FR1tIBg 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.895267 CLNN1k2QMum1aexUK7 141.142.220.118 208.80.152.3 ShADad http
|
||||
1300475168.724007 CUM0KZ3MLUfNB0cl11 141.142.220.118 208.80.152.118 ShADad http
|
||||
1300475169.780331 CFSwNi4CNGxcuffo49 141.142.220.235 173.192.163.128 ^h -
|
|
@ -0,0 +1,3 @@
|
|||
### BTest baseline data generated by btest-diff. Do not edit. Use "btest -U/-u" to update. Requires BTest >= 0.63.
|
||||
is_supervisor, T
|
||||
PASS (got error), node with name 'grault' has interface and pcap_file set
|
70
testing/btest/supervisor/config-cluster-pcap.zeek
Normal file
70
testing/btest/supervisor/config-cluster-pcap.zeek
Normal file
|
@ -0,0 +1,70 @@
|
|||
# @TEST-DOC: Test support for pcap_file on Supervisor::ClusterEndpoint and Supervisor::NodeConfig
|
||||
#
|
||||
# @TEST-PORT: MANAGER_PORT
|
||||
# @TEST-PORT: WORKER_PORT
|
||||
# @TEST-EXEC: btest-bg-run zeek zeek -j %INPUT
|
||||
# @TEST-EXEC: btest-bg-wait 45
|
||||
# @TEST-EXEC: mv zeek/worker/conn.log zeek/worker/conn.log.orig
|
||||
# @TEST-EXEC: zeek-cut ts uid id.orig_h id.resp_h history service < zeek/worker/conn.log.orig > zeek/worker/conn.log
|
||||
# @TEST-EXEC: TEST_DIFF_CANONIFIER= btest-diff zeek/worker/conn.log
|
||||
|
||||
redef Log::default_rotation_interval = 0sec;
|
||||
|
||||
@if ( Supervisor::is_supervisor() )
|
||||
|
||||
redef SupervisorControl::enable_listen = T;
|
||||
|
||||
event zeek_init()
|
||||
{
|
||||
local cluster: table[string] of Supervisor::ClusterEndpoint;
|
||||
cluster["manager"] = [$role=Supervisor::MANAGER, $host=127.0.0.1,
|
||||
$p=to_port(getenv("MANAGER_PORT"))];
|
||||
cluster["worker"] = [$role=Supervisor::WORKER, $host=127.0.0.1,
|
||||
$p=to_port(getenv("WORKER_PORT")),
|
||||
$pcap_file=(getenv("TRACES") + "/wikipedia.trace")];
|
||||
|
||||
for ( n, ep in cluster )
|
||||
{
|
||||
local sn = Supervisor::NodeConfig($name = n);
|
||||
sn$cluster = cluster;
|
||||
sn$directory = n;
|
||||
sn$stdout_file = "stdout";
|
||||
sn$stderr_file = "stderr";
|
||||
|
||||
if ( ep?$pcap_file )
|
||||
sn$pcap_file = ep$pcap_file;
|
||||
|
||||
local res = Supervisor::create(sn);
|
||||
|
||||
if ( res != "" )
|
||||
print fmt("failed to create node %s: %s", n, res);
|
||||
}
|
||||
}
|
||||
|
||||
global ready_for_shutdown = F;
|
||||
|
||||
# Immediately terminate the supervisor once we get a report about the worker
|
||||
# starting for a second time.
|
||||
event Supervisor::node_status(node: string, pid: count)
|
||||
{
|
||||
if ( node != "worker" )
|
||||
return;
|
||||
|
||||
if ( ready_for_shutdown )
|
||||
terminate();
|
||||
|
||||
ready_for_shutdown = T;
|
||||
}
|
||||
|
||||
@else
|
||||
|
||||
redef Log::enable_local_logging = T;
|
||||
redef Log::enable_remote_logging = F;
|
||||
|
||||
# Even though we run with a pcap_file, we will not terminate
|
||||
# once fully read, trigger terminate() directly.
|
||||
event Pcap::file_done(path: string)
|
||||
{
|
||||
terminate();
|
||||
}
|
||||
@endif
|
|
@ -0,0 +1,19 @@
|
|||
# @TEST-DOC: Creating a node with inteface and pcap_file fails.
|
||||
# @TEST-EXEC: zeek -j -b %INPUT >out
|
||||
# @TEST-EXEC: btest-diff out
|
||||
|
||||
# Providing interface and pcap_file is an error.
|
||||
|
||||
event zeek_init()
|
||||
{
|
||||
print "is_supervisor", Supervisor::is_supervisor();
|
||||
local sn = Supervisor::NodeConfig(
|
||||
$name="grault",
|
||||
$interface="lo",
|
||||
$pcap_file="/dev/null",
|
||||
);
|
||||
local res = Supervisor::create(sn);
|
||||
|
||||
print res != "" ? "PASS (got error)" : " FAIL (no error)", res;
|
||||
terminate();
|
||||
}
|
Loading…
Add table
Add a link
Reference in a new issue