Henri DF
c9806407e8
Priority level internal handling
...
Handle internally as ints, then translate as appropriate in outputs
2016-03-30 14:38:18 -07:00
Henri DF
d6dee28bbe
Output simplification
...
The Output is now chosen globally (for all rules), on the command line.
2016-03-30 14:27:19 -07:00
Henri DF
f44bd06f1d
Remove unused/unimplemented options
2016-03-30 13:20:31 -07:00
Henri DF
5f0123317a
Remove function outputs from grammar
2016-03-30 13:00:51 -07:00
Henri DF
a9fc4d2b09
Merge pull request #18 from draios/priorities
...
Priorities
2016-03-30 12:55:49 -07:00
Henri DF
aef0be3027
Add priorities to all outputs
...
For now, all are WARNING. Will need to refine/adjust over time.
2016-03-30 12:54:46 -07:00
Henri DF
6158168a97
Grammar support for priorities
2016-03-29 21:35:07 -07:00
Henri DF
7fcd0b98a0
Merge pull request #17 from draios/implicit-time
...
Implicit time
2016-03-29 19:56:01 -07:00
Henri DF
38957d3b14
Add timestamp in function outputs
2016-03-29 19:54:15 -07:00
Henri DF
97d7b125ba
Implicit time in output formats
...
As pointed out by Loris, timestamping output messages should be a
responsibility of the output/collection system.
So as a first step towards this, add timestamps automatically for output
formats, and remove them from rules.
2016-03-29 19:47:57 -07:00
Henri DF
bc7f955127
rules: fix error in zookeeper_port
2016-03-29 19:47:18 -07:00
Henri DF
2d6c6d7d2d
Merge pull request #16 from draios/more-service-rules
...
More service rules
2016-03-29 19:36:44 -07:00
Henri DF
cfb6e56877
Merge pull request #15 from draios/error-handling-improvements
...
Minor error handling improvements
2016-03-29 19:32:56 -07:00
Henri DF
aea9b0054b
Minor error handling improvements
2016-03-29 19:31:34 -07:00
Henri DF
08afde0858
Add mysql rules
2016-03-29 22:16:15 +00:00
Henri DF
1e003fc0a6
Add more services to rules file
...
(HBase, Kafka, Memcached, MongoDB)
2016-03-29 22:16:15 +00:00
Henri DF
1d1a14acf9
Tweak comments in rules file
2016-03-29 22:16:15 +00:00
Henri DF
019e76114e
Merge pull request #14 from draios/fast-ins
...
Use new sysdig support for fast processing of in-exprs
2016-03-29 14:59:24 -07:00
Henri DF
faf36cd8d7
Use new sysdig support for fast processing of in-exprs
2016-03-24 14:25:48 -07:00
Henri DF
85772a387b
Merge pull request #13 from draios/paren-optimization
...
Optimization: don't nest at every boolean op
2016-03-18 13:11:34 -07:00
Henri DF
aa31d0a0fb
Optimization: don't nest at every boolean op
2016-03-18 13:10:07 -07:00
Henri DF
bbcedef54a
Some tweaks to rules
2016-03-18 13:09:17 -07:00
Henri DF
9043c89a9b
Nice formatting when printing ASTs
2016-03-16 13:00:03 -07:00
Henri DF
6a504c924c
Add a bunch of rules for service ports
2016-03-11 14:38:16 -08:00
Henri DF
773bc3f5d0
rules tweaks
2016-03-10 16:59:37 -08:00
Henri DF
44adb46529
Rules tweaks
2016-03-08 19:02:45 +00:00
Henri DF
7104d52466
minor cmakefile cleanup
2016-03-07 17:27:20 -08:00
Henri DF
8c7cc61793
fix luajit dependency
2016-03-07 17:19:28 -08:00
Henri DF
b8a16aab85
fix re.lua permissions
2016-03-08 01:15:43 +00:00
Henri DF
f4c7bb8f72
un-hardcode LUA_INCLUDE in cmake file
2016-03-08 01:15:43 +00:00
Henri DF
972c84707f
Mo rules
2016-03-07 16:35:13 -08:00
Henri DF
a14087dc94
.gitignore
2016-03-06 15:16:13 -08:00
Henri DF
79e4af09ca
Merge pull request #12 from draios/build-lpeg
...
Build lpeg
2016-03-04 17:55:58 -08:00
Henri DF
8c6bb8a236
Set Lua cpath along with path
2016-03-04 17:54:18 -08:00
Henri DF
cc4837312e
Pull lpeg and build it
2016-03-04 17:52:01 -08:00
Henri DF
9bbe692137
Some more progress on rules
2016-03-03 16:14:14 -08:00
Henri DF
e7adc4e1f5
Remove cruft from CMakeLists.txt
2016-03-03 16:13:32 -08:00
Henri DF
331042858f
Initial version of outputs.lua
2016-03-03 16:13:08 -08:00
Henri DF
7593aac4c9
.gitignore
2016-03-03 16:11:57 -08:00
Henri DF
5f681b1bd8
Signal handlers and clean(er) exit
2016-03-04 00:11:09 +00:00
Henri DF
a921e25385
Tweaks to base.txt
2016-03-04 00:10:57 +00:00
Henri DF
b700a85b05
Add ssh alert
2016-03-04 00:10:48 +00:00
Henri DF
ea158baa8d
Fix error string
2016-03-02 22:24:12 +00:00
Henri DF
9c4bfecd40
Progress on base rules
2016-03-02 22:24:12 +00:00
Henri DF
33ad92e98b
Fix typo-bug in lua code
2016-03-01 22:01:45 -08:00
Henri DF
f0da1c724b
formats.cpp: print lua error string (like elsewherE)
2016-03-01 22:01:14 -08:00
Henri DF
a52441dcaa
Some updates to base rules file
2016-03-01 20:10:52 -08:00
Henri DF
8343d23c3f
remove debugging print from rules_loader.lua
2016-03-01 20:10:34 -08:00
Henri DF
2eb02a9597
Merge pull request #11 from draios/digwatch_fields
...
Digwatch fields
2016-03-01 13:55:00 -08:00
Henri DF
26fcf3415d
Add digwatch.fields() to Lua API
2016-03-01 21:54:20 +00:00