1 |
|
#!/usr/bin/perl -w |
2 |
|
|
3 |
+ |
# |
4 |
+ |
# i-scream central monitoring system |
5 |
+ |
# Copyright (C) 2000-2002 i-scream |
6 |
+ |
# |
7 |
+ |
# This program is free software; you can redistribute it and/or |
8 |
+ |
# modify it under the terms of the GNU General Public License |
9 |
+ |
# as published by the Free Software Foundation; either version 2 |
10 |
+ |
# of the License, or (at your option) any later version. |
11 |
+ |
# |
12 |
+ |
# This program is distributed in the hope that it will be useful, |
13 |
+ |
# but WITHOUT ANY WARRANTY; without even the implied warranty of |
14 |
+ |
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
15 |
+ |
# GNU General Public License for more details. |
16 |
+ |
# |
17 |
+ |
# You should have received a copy of the GNU General Public License |
18 |
+ |
# along with this program; if not, write to the Free Software |
19 |
+ |
# Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA. |
20 |
+ |
# |
21 |
+ |
|
22 |
|
# ----------------------------------------------------------- |
23 |
|
# Perl i-scream Host. |
24 |
|
# http://www.i-scream.org.uk |
53 |
|
$pidfile |
54 |
|
$retry_wait |
55 |
|
$ostype |
56 |
+ |
$key |
57 |
|
@data |
58 |
|
); |
59 |
|
|
81 |
|
&write_pid(); |
82 |
|
|
83 |
|
&tcp_configure(); |
84 |
+ |
&send_tcp_heartbeat(); |
85 |
|
&send_udp_packet(); |
86 |
|
|
87 |
|
$last_udp_time = time; |
161 |
|
|
162 |
|
print $sock "LASTMODIFIED\n"; |
163 |
|
$response = <$sock>; |
164 |
< |
if (!$response) { |
165 |
< |
print "The i-scream server did not return anything for the LASTMODIFIED command.\n"; |
164 |
> |
if (!$response || $response eq "ERROR\n") { |
165 |
> |
print "The i-scream server did not provide the LASTMODIFIED value.\n"; |
166 |
|
close($sock); |
167 |
|
wait_then_retry(); |
168 |
|
next; |
169 |
|
} |
170 |
< |
chop $response; |
170 |
> |
chomp $response; |
171 |
|
$last_modified = $response; |
172 |
|
|
173 |
|
print "Config last modified: ". (scalar localtime $last_modified/1000) . "\n"; |
174 |
|
|
175 |
|
print $sock "FILELIST\n"; |
176 |
|
$response = <$sock>; |
177 |
< |
if (!$response) { |
177 |
> |
if (!$response || $response eq "ERROR\n") { |
178 |
|
print "The i-scream server did not provide a configuration file list.\n"; |
179 |
|
close($sock); |
180 |
|
wait_then_retry(); |
181 |
|
next; |
182 |
|
} |
183 |
< |
chop $response; |
183 |
> |
chomp $response; |
184 |
|
$file_list = $response; |
185 |
|
|
186 |
|
print "File list obtained: $file_list\n"; |
187 |
|
|
188 |
|
print $sock "FQDN\n"; |
189 |
|
$response = <$sock>; |
190 |
< |
if (!$response) { |
190 |
> |
if (!$response || $response eq "ERROR\n") { |
191 |
|
print "The i-scream server did not tell us our FQDN.\n"; |
192 |
|
close($sock); |
193 |
|
wait_then_retry(); |
194 |
|
next; |
195 |
|
} |
196 |
< |
chop $response; |
196 |
> |
chomp $response; |
197 |
|
$fqdn = $response; |
198 |
|
|
199 |
|
print "FQDN returned: $fqdn\n"; |
200 |
|
|
201 |
|
print $sock "UDPUpdateTime\n"; |
202 |
|
$response = <$sock>; |
203 |
< |
if (!$response) { |
203 |
> |
if (!$response || $response eq "ERROR\n") { |
204 |
|
print "The i-scream server did not give us a UDPUpdateTime.\n"; |
205 |
|
close($sock); |
206 |
|
wait_then_retry(); |
207 |
|
next; |
208 |
|
} |
209 |
< |
chop $response; |
209 |
> |
chomp $response; |
210 |
|
$udp_update_time = $response; |
211 |
|
|
212 |
|
print $sock "TCPUpdateTime\n"; |
213 |
|
$response = <$sock>; |
214 |
< |
if (!$response) { |
214 |
> |
if (!$response || $response eq "ERROR\n") { |
215 |
|
print "The i-scream server did not give us a TCPUpdateTime.\n"; |
216 |
|
close($sock); |
217 |
|
wait_then_retry(); |
218 |
|
next; |
219 |
|
} |
220 |
< |
chop $response; |
220 |
> |
chomp $response; |
221 |
|
$tcp_update_time = $response; |
222 |
|
|
223 |
|
print "UDP packet period: $udp_update_time seconds.\nTCP heartbeat period: $tcp_update_time seconds.\n"; |
241 |
|
wait_then_retry(); |
242 |
|
next; |
243 |
|
} |
244 |
< |
chop $response; |
224 |
< |
$response =~ /^(.*);(.*);(.*)/; |
244 |
> |
chomp $response; |
245 |
|
if ($response eq "ERROR") { |
246 |
|
print "There are no active configured filters for your host.\n"; |
247 |
|
close($sock); |
248 |
|
wait_then_retry(); |
249 |
|
next; |
250 |
|
} |
251 |
+ |
$response =~ /^(.*);(.*);(.*)/; |
252 |
|
($filter_addr, $udp_port, $tcp_port) = ($1, $2, $3); |
253 |
|
unless (defined($filter_addr) && defined($udp_port) && defined($tcp_port)) { |
254 |
|
print "Failed: Filter address response from server did not make sense: $response\n"; |
307 |
|
push(@data, "packet.attributes.date $date"); |
308 |
|
push(@data, "packet.attributes.type data"); |
309 |
|
push(@data, "packet.attributes.ip $ip"); |
310 |
+ |
push(@data, "packet.attributes.key $key"); |
311 |
|
|
312 |
|
# sort the data |
313 |
|
@data = sort(grep(!/^$/, grep(/^packet\./, @data))); |
395 |
|
&tcp_configure(); |
396 |
|
return; |
397 |
|
} |
398 |
+ |
|
399 |
+ |
print $sock "KEY\n"; |
400 |
+ |
$key = <$sock>; |
401 |
|
|
402 |
|
print $sock "ENDHEARTBEAT\n"; |
403 |
|
$response = <$sock>; |