Files
librenms-librenms/includes/polling/applications/portactivity.inc.php
Zane C. Bowers-Hadley 0bbcde1227 add the ability for storing app data to prevent spamming of the event log via via component usage (#14087)
* initial work on add the ability to save/fetch app data

* update to use get_app_data for ZFS

* update the poller for the new app_data stuff

* ZFS now logs changes to pools

* add schema update for app_data stuff

* small formatting fix

* add a missing \

* now adds a column

* sql-schema is no longer used, so remove the file that was added here

* misc cleanups

* rename the method in database/migrations/2022_07_03_1947_add_app_data.php

* hopefully fix the migration bit

* add the column to misc/db_schema.yaml

* more misc small DB fixes

* update the test as the json column uses collat of utf8mb4_bin

* revert the last change and try manually setting it to what is expected

* remove a extra ;

* update suricata as well

* correct the instance -> instances in one location to prevent the old instance list from being stomped

* remove a extra ;

* update fail2ban to use it as well

* remove two unused functions as suricata and fail2ban no longer use components

* style cleanup

* postgres poller updated to use it

* update html side of the postgres bits

* chronyd now uses app data bits now as well

* portactivity now uses it as well

* style fix

* sort the returned arrays from app_data

* correct log message for port activity

* collocation change

* try re-ordering it

* add in the new data column to the tests

* remove a extra ,

* hmm... ->collate('utf8mb4_unicode_ci') is not usable as apparently collate does not exist

* change the column type from json to longtext

* mv chronyd stuff while I sort out the rest of the tests... damn thing is always buggy

* hmm... fix a missing line then likely move stuff back

* style fix

* add fillable

* add the expexcted data for fail2ban json

* escape a " I missed

* add data for portactivity

* add suricata app data

* add app data to zfs legacy test

* put the moved tests back into place and update zfs-v1 test

* add app data for chronyd test

* add app data for fail2ban legacy test

* update zfs v1 app data

* add some notes on application dev work

* add Developing/Application-Notes.md to mkdocs.yml

* add data column to it

* added various suggestions from bennet-esyoil

* convert from isset to sizeof

* type fix

* fully remove the old save app data function and move it into a helper function... the other still needs cleaned up prior to removal

* update docs

* get_app_data is fully removed now as well

* a few style fixes

* add $casts

* update chronyd test

* attempt to fix the data

* more doc cleanup and try changing the cast

* style fix

* revert the changes to the chronyd test

* apply a few of murrant's suggestions

* document working with ->data as json and non-josn

* remove two no-longer used in this PR exceptions

* ->data now operates transparently

* style fix

* update data tests

* fix json

* test fix

* update the app notes to reflect how app data now works

* app test fix

* app data fix for linux_lsi

* json fix

* minor doc cleanup

* remove duplicate querty and use json_decode instead

* style fix

* modelize the app poller

* use a anon func instead of foreach

* test update

* style cleanup

* style cleanup

* another test cleanup

* more test cleanup

* reverse the test changes and add in some more glue code

* revert one of the test changes

* another small test fix

* Make things use models
Left some array access, but those will still work just fine.

* missed chronyd and portactivity

* rename poll to avoid make it any confusion

* Remove extra save and fix timestamp

* save any changes made to app->data

* nope, that was not it

* What are magic methods and how do they work?

* fix two typos

* update linux_lsi test

* change quote type

Co-authored-by: Tony Murray <murraytony@gmail.com>
2022-07-22 16:01:55 -05:00

136 lines
6.9 KiB
PHP

<?php
use LibreNMS\Exceptions\JsonAppException;
use LibreNMS\RRD\RrdDefinition;
$name = 'portactivity';
try {
$returned = json_app_get($device, 'portactivity', 1);
} catch (JsonAppException $e) { // Only doing the generic one as this has no non-JSON return
echo PHP_EOL . $name . ':' . $e->getCode() . ':' . $e->getMessage() . PHP_EOL;
update_application($app, $e->getCode() . ':' . $e->getMessage(), []); // Set empty metrics and error message
return;
}
$ports = $returned['data'];
$ports_rrd_def = RrdDefinition::make()
->addDataset('total_conns', 'GAUGE', 0)
->addDataset('total_to', 'GAUGE', 0)
->addDataset('total_from', 'GAUGE', 0)
->addDataset('totalLISTEN', 'GAUGE', 0)
->addDataset('totalCLOSED', 'GAUGE', 0)
->addDataset('totalSYN_SENT', 'GAUGE', 0)
->addDataset('totalSYN_RECEIVED', 'GAUGE', 0)
->addDataset('totalESTABLISHED', 'GAUGE', 0)
->addDataset('totalCLOSE_WAIT', 'GAUGE', 0)
->addDataset('totalFIN_WAIT_1', 'GAUGE', 0)
->addDataset('totalCLOSING', 'GAUGE', 0)
->addDataset('totalLAST_ACK', 'GAUGE', 0)
->addDataset('totalFIN_WAIT_2', 'GAUGE', 0)
->addDataset('totalTIME_WAIT', 'GAUGE', 0)
->addDataset('totalUNKNOWN', 'GAUGE', 0)
->addDataset('totalother', 'GAUGE', 0)
->addDataset('toLISTEN', 'GAUGE', 0)
->addDataset('toCLOSED', 'GAUGE', 0)
->addDataset('toSYN_SENT', 'GAUGE', 0)
->addDataset('toSYN_RECEIVED', 'GAUGE', 0)
->addDataset('toESTABLISHED', 'GAUGE', 0)
->addDataset('toCLOSE_WAIT', 'GAUGE', 0)
->addDataset('toFIN_WAIT_1', 'GAUGE', 0)
->addDataset('toCLOSING', 'GAUGE', 0)
->addDataset('toLAST_ACK', 'GAUGE', 0)
->addDataset('toFIN_WAIT_2', 'GAUGE', 0)
->addDataset('toTIME_WAIT', 'GAUGE', 0)
->addDataset('toUNKNOWN', 'GAUGE', 0)
->addDataset('toother', 'GAUGE', 0)
->addDataset('fromLISTEN', 'GAUGE', 0)
->addDataset('fromCLOSED', 'GAUGE', 0)
->addDataset('fromSYN_SENT', 'GAUGE', 0)
->addDataset('fromSYN_RECEIVED', 'GAUGE', 0)
->addDataset('fromESTABLISHED', 'GAUGE', 0)
->addDataset('fromCLOSE_WAIT', 'GAUGE', 0)
->addDataset('fromFIN_WAIT_1', 'GAUGE', 0)
->addDataset('fromCLOSING', 'GAUGE', 0)
->addDataset('fromLAST_ACK', 'GAUGE', 0)
->addDataset('fromFIN_WAIT_2', 'GAUGE', 0)
->addDataset('fromTIME_WAIT', 'GAUGE', 0)
->addDataset('fromUNKNOWN', 'GAUGE', 0)
->addDataset('fromother', 'GAUGE', 0);
//
// update the RRD files for each port
//
$ports_keys = array_keys($ports);
$ports_keys_int = 0;
while (isset($ports[$ports_keys[$ports_keys_int]])) {
$rrd_name = ['app', $name, $app->app_id, $ports_keys[$ports_keys_int]];
$fields = [
'total_conns' => $ports[$ports_keys[$ports_keys_int]]['total_conns'],
'total_to' => $ports[$ports_keys[$ports_keys_int]]['total_to'],
'total_from' => $ports[$ports_keys[$ports_keys_int]]['total_from'],
'totalLISTEN' => $ports[$ports_keys[$ports_keys_int]]['total']['LISTEN'],
'totalCLOSED' => $ports[$ports_keys[$ports_keys_int]]['total']['CLOSED'],
'totalSYN_SENT' => $ports[$ports_keys[$ports_keys_int]]['total']['SYN_SENT'],
'totalSYN_RECEIVED' => $ports[$ports_keys[$ports_keys_int]]['total']['SYN_RECEIVED'],
'totalESTABLISHED' => $ports[$ports_keys[$ports_keys_int]]['total']['ESTABLISHED'],
'totalCLOSE_WAIT' => $ports[$ports_keys[$ports_keys_int]]['total']['CLOSE_WAIT'],
'totalFIN_WAIT_1' => $ports[$ports_keys[$ports_keys_int]]['total']['FIN_WAIT_1'],
'totalCLOSING' => $ports[$ports_keys[$ports_keys_int]]['total']['CLOSING'],
'totalLAST_ACK' => $ports[$ports_keys[$ports_keys_int]]['total']['LAST_ACK'],
'totalFIN_WAIT_2' => $ports[$ports_keys[$ports_keys_int]]['total']['FIN_WAIT_2'],
'totalTIME_WAIT' => $ports[$ports_keys[$ports_keys_int]]['total']['TIME_WAIT'],
'totalUNKNOWN' => $ports[$ports_keys[$ports_keys_int]]['total']['UNKNOWN'],
'totalother' => $ports[$ports_keys[$ports_keys_int]]['total']['other'],
'toLISTEN' => $ports[$ports_keys[$ports_keys_int]]['to']['LISTEN'],
'toCLOSED' => $ports[$ports_keys[$ports_keys_int]]['to']['CLOSED'],
'toSYN_SENT' => $ports[$ports_keys[$ports_keys_int]]['to']['SYN_SENT'],
'toSYN_RECEIVED' => $ports[$ports_keys[$ports_keys_int]]['to']['SYN_RECEIVED'],
'toESTABLISHED' => $ports[$ports_keys[$ports_keys_int]]['to']['ESTABLISHED'],
'toCLOSE_WAIT' => $ports[$ports_keys[$ports_keys_int]]['to']['CLOSE_WAIT'],
'toFIN_WAIT_1' => $ports[$ports_keys[$ports_keys_int]]['to']['FIN_WAIT_1'],
'toCLOSING' => $ports[$ports_keys[$ports_keys_int]]['to']['CLOSING'],
'toLAST_ACK' => $ports[$ports_keys[$ports_keys_int]]['to']['LAST_ACK'],
'toFIN_WAIT_2' => $ports[$ports_keys[$ports_keys_int]]['to']['FIN_WAIT_2'],
'toTIME_WAIT' => $ports[$ports_keys[$ports_keys_int]]['to']['TIME_WAIT'],
'toUNKNOWN' => $ports[$ports_keys[$ports_keys_int]]['to']['UNKNOWN'],
'toother' => $ports[$ports_keys[$ports_keys_int]]['to']['other'],
'fromLISTEN' => $ports[$ports_keys[$ports_keys_int]]['from']['LISTEN'],
'fromCLOSED' => $ports[$ports_keys[$ports_keys_int]]['from']['CLOSED'],
'fromSYN_SENT' => $ports[$ports_keys[$ports_keys_int]]['from']['SYN_SENT'],
'fromSYN_RECEIVED' => $ports[$ports_keys[$ports_keys_int]]['from']['SYN_RECEIVED'],
'fromESTABLISHED' => $ports[$ports_keys[$ports_keys_int]]['from']['ESTABLISHED'],
'fromCLOSE_WAIT' => $ports[$ports_keys[$ports_keys_int]]['from']['CLOSE_WAIT'],
'fromFIN_WAIT_1' => $ports[$ports_keys[$ports_keys_int]]['from']['FIN_WAIT_1'],
'fromCLOSING' => $ports[$ports_keys[$ports_keys_int]]['from']['CLOSING'],
'fromLAST_ACK' => $ports[$ports_keys[$ports_keys_int]]['from']['LAST_ACK'],
'fromFIN_WAIT_2' => $ports[$ports_keys[$ports_keys_int]]['from']['FIN_WAIT_2'],
'fromTIME_WAIT' => $ports[$ports_keys[$ports_keys_int]]['from']['TIME_WAIT'],
'fromUNKNOWN' => $ports[$ports_keys[$ports_keys_int]]['from']['UNKNOWN'],
'fromother' => $ports[$ports_keys[$ports_keys_int]]['from']['other'],
];
$tags = ['name' => $name, 'app_id' => $app->app_id, 'rrd_def' => $ports_rrd_def, 'rrd_name' => $rrd_name];
data_update($device, 'app', $tags, $fields);
$ports_keys_int++;
}
// check for added or removed instances
$old_ports = $app->data['ports'] ?? [];
$added_ports = array_diff($ports_keys, $old_ports);
$removed_ports = array_diff($old_ports, $ports_keys);
// if we have any source instances, save and log
if (count($added_ports) > 0 || count($removed_ports) > 0) {
$app->data = ['ports' => $ports_keys];
$log_message = 'Portactivity Port Change:';
$log_message .= count($added_ports) > 0 ? ' Added ' . implode(',', $added_ports) : '';
$log_message .= count($removed_ports) > 0 ? ' Removed ' . implode(',', $added_ports) : '';
log_event($log_message, $device, 'application');
}
update_application($app, 'OK', data_flatten($ports));