2018-12-26 01:29:39 +01:00
|
|
|
// +build !nofilter
|
|
|
|
|
2018-12-25 03:17:14 +01:00
|
|
|
package filtering
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
|
|
|
"os"
|
|
|
|
|
|
|
|
"github.com/araddon/qlbridge/datasource"
|
|
|
|
"github.com/araddon/qlbridge/expr"
|
|
|
|
"github.com/araddon/qlbridge/value"
|
|
|
|
"github.com/araddon/qlbridge/vm"
|
|
|
|
)
|
|
|
|
|
|
|
|
type ExprValue struct {
|
2018-12-26 01:29:39 +01:00
|
|
|
node expr.Node
|
|
|
|
expression string
|
2018-12-25 03:17:14 +01:00
|
|
|
}
|
|
|
|
|
|
|
|
func (e *ExprValue) String() string {
|
2018-12-26 01:29:39 +01:00
|
|
|
if e.node != nil {
|
|
|
|
return e.node.String()
|
2018-12-25 03:17:14 +01:00
|
|
|
} else {
|
|
|
|
return "<Empty Expression>"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
func (e *ExprValue) Set(value string) error {
|
2018-12-25 03:52:53 +01:00
|
|
|
if value == "" {
|
2018-12-26 01:29:39 +01:00
|
|
|
e.node = nil
|
|
|
|
e.expression = value
|
2018-12-25 03:52:53 +01:00
|
|
|
return nil
|
|
|
|
}
|
2018-12-25 03:17:14 +01:00
|
|
|
ast, err := expr.ParseExpression(value)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2018-12-26 01:29:39 +01:00
|
|
|
e.node = ast
|
|
|
|
e.expression = value
|
2018-12-25 03:17:14 +01:00
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2019-01-09 16:55:58 +01:00
|
|
|
// Validate answers the question whether to include a log line or not.
|
|
|
|
func (e *ExprValue) Validate(logLine map[string]interface{}) bool {
|
2018-12-26 01:29:39 +01:00
|
|
|
if e.node == nil {
|
2018-12-25 03:52:53 +01:00
|
|
|
return true
|
|
|
|
}
|
2019-01-09 16:55:58 +01:00
|
|
|
line := translateMap(logLine)
|
2018-12-25 03:17:14 +01:00
|
|
|
context := datasource.NewContextSimpleNative(line)
|
2018-12-26 01:29:39 +01:00
|
|
|
val, ok := vm.Eval(context, e.node)
|
2018-12-25 03:17:14 +01:00
|
|
|
if !ok || val == nil { // errors when evaluating
|
|
|
|
return false
|
|
|
|
}
|
2018-12-26 01:54:30 +01:00
|
|
|
if bv, isBool := val.(value.BoolValue); isBool {
|
|
|
|
return bv.Val()
|
2018-12-25 03:17:14 +01:00
|
|
|
}
|
2018-12-26 01:54:30 +01:00
|
|
|
fmt.Fprintln(os.Stderr, "WARNING: The 'where' expression doesn't return a boolean")
|
|
|
|
return false
|
2018-12-25 03:17:14 +01:00
|
|
|
}
|
2019-01-09 16:39:06 +01:00
|
|
|
|
|
|
|
func translateMap(lineInput map[string]interface{}) map[string]interface{} {
|
|
|
|
lineOutput := make(map[string]interface{})
|
|
|
|
lineOutput["prog"] = lineInput["app_name"]
|
|
|
|
lineOutput["msg"] = lineInput["message"]
|
|
|
|
lineOutput["facility"] = lineInput["facility"]
|
|
|
|
lineOutput["host"] = lineInput["hostname"]
|
|
|
|
lineOutput["time"] = lineInput["timestamp"]
|
|
|
|
lineOutput["sev"] = lineInput["severity"]
|
|
|
|
return lineOutput
|
|
|
|
}
|