multiple config per target

This commit is contained in:
Pierre Dubouilh
2026-08-28 00:34:23 +02:00
committed by Pierre Dubouilh
parent 43392ace03
commit ac17c11158
2 changed files with 24 additions and 24 deletions
+16 -16
View File
@@ -24,40 +24,40 @@ async fn run() -> Result<()> {
let invalid_statuses_ref = invalid_statuses_parsed.as_ref(); let invalid_statuses_ref = invalid_statuses_parsed.as_ref();
// generic parser // generic parser
let generic_path = args.generic_logpath.as_ref(); let generic_paths = &args.generic_logpath;
let generic_ip_re = args.generic_ip.as_ref(); let generic_ip_re = args.generic_ip.as_ref();
let generic_positive = args.generic_positive.as_ref(); let generic_positive = args.generic_positive.as_ref();
let generic_negative = args.generic_negative.as_ref(); let generic_negative = args.generic_negative.as_ref();
if let Some(p) = generic_path { for p in generic_paths {
ml.add_file(&p).await?; ml.add_file(&p).await?;
log!("starting with generic parsing at {:?}", &p); log!("starting with generic parsing at {:?}", &p);
} }
// sshd // sshd
let sshd_logpath = args.sshd_logpath.as_ref(); let sshd_logpaths = &args.sshd_logpath;
if let Some(p) = sshd_logpath { for p in sshd_logpaths {
ml.add_file(&p).await?; ml.add_file(&p).await?;
log!("starting with sshd parsing at {:?}", &p); log!("starting with sshd parsing at {:?}", &p);
} }
// common log format // common log format
let clf_logpath = args.clf_logpath.as_ref(); let clf_logpaths = &args.clf_logpath;
if let Some(p) = clf_logpath { for p in clf_logpaths {
ml.add_file(&p).await?; ml.add_file(&p).await?;
log!("starting with clf parsing at {:?}", &p); log!("starting with clf parsing at {:?}", &p);
} }
// json // json
let json_logpath = args.json_logpath.as_ref(); let json_logpaths = &args.json_logpath;
if let Some(p) = json_logpath { for p in json_logpaths {
ml.add_file(&p).await?; ml.add_file(&p).await?;
log!("starting with json parsing at {:?}", &p); log!("starting with json parsing at {:?}", &p);
} }
if json_logpath.is_none() if json_logpaths.is_empty()
&& clf_logpath.is_none() && clf_logpaths.is_empty()
&& sshd_logpath.is_none() && sshd_logpaths.is_empty()
&& generic_path.is_none() && generic_paths.is_empty()
{ {
bail!("no log files to parse, see --help"); bail!("no log files to parse, see --help");
} }
@@ -70,13 +70,13 @@ async fn run() -> Result<()> {
let path_buf = Some(line.source().to_path_buf()); let path_buf = Some(line.source().to_path_buf());
let path = path_buf.as_ref(); let path = path_buf.as_ref();
let (target, ret) = if path == sshd_logpath { let (target, ret) = if path.is_some_and(|p| sshd_logpaths.contains(p)) {
("sshd", sshd::parse(payload)?) ("sshd", sshd::parse(payload)?)
} else if path == clf_logpath { } else if path.is_some_and(|p| clf_logpaths.contains(p)) {
("clf", clf::parse(payload, invalid_statuses_ref)?) ("clf", clf::parse(payload, invalid_statuses_ref)?)
} else if path == json_logpath { } else if path.is_some_and(|p| json_logpaths.contains(p)) {
("json", json::parse(payload, invalid_statuses_ref)?) ("json", json::parse(payload, invalid_statuses_ref)?)
} else if path == generic_path { } else if path.is_some_and(|p| generic_paths.contains(p)) {
( (
"generic", "generic",
generic::parse(payload, generic_ip_re, generic_positive, generic_negative)?, generic::parse(payload, generic_ip_re, generic_positive, generic_negative)?,
+8 -8
View File
@@ -110,21 +110,21 @@ pub struct Args {
#[clap(short, long)] #[clap(short, long)]
pub verbose: bool, pub verbose: bool,
/// path of sshd logfile /// path of sshd logfile, can be repeated
#[clap(short, long, value_parser = resolve_path)] #[clap(short, long, value_parser = resolve_path)]
pub sshd_logpath: Option<PathBuf>, pub sshd_logpath: Vec<PathBuf>,
/// path of Common-Log-Format logfile (Apache, etc..) /// path of Common-Log-Format logfile (Apache, etc..), can be repeated
#[clap(short, long, value_parser = resolve_path)] #[clap(short, long, value_parser = resolve_path)]
pub clf_logpath: Option<PathBuf>, pub clf_logpath: Vec<PathBuf>,
/// path of JSON logfile (works with Caddy) /// path of JSON logfile (works with Caddy), can be repeated
#[clap(short, long, value_parser = resolve_path)] #[clap(short, long, value_parser = resolve_path)]
pub json_logpath: Option<PathBuf>, pub json_logpath: Vec<PathBuf>,
/// generic parser log file path /// generic parser log file path, can be repeated
#[clap(long, value_parser = resolve_path, requires_all = ["generic_ip", "generic_match"])] #[clap(long, value_parser = resolve_path, requires_all = ["generic_ip", "generic_match"])]
pub generic_logpath: Option<PathBuf>, pub generic_logpath: Vec<PathBuf>,
/// generic parser ip regex /// generic parser ip regex
#[clap(long, value_parser = parse_regex, requires = "generic_logpath")] #[clap(long, value_parser = parse_regex, requires = "generic_logpath")]