3 'j@shddlZddlZddlZddlmZmZmZmZGdddeZGdddeeZ GdddeeZ dS) N)Plugin PluginOptIndependentPlugin CosPluginc@s(eZdZdZdZd ZddZdd Zd S) LogsBasez System logslogssystemhardwarestoragecsJd}d|g}g}j|rtj|ddd}|j}xtjd|tjtjBdD]}yP|d}|jd rt j |j d j d }|r|t j |7}n|t j |7}WqTtk r} zjd | WYdd} ~ XqTXqTWx0|jD]$} | jd r|t j | j d 7}qWWdQRXx>|D]6}jj|s<q"j|} |jd| 7}q"Wx<|D]4} | jdr~| d d} j| rbj| qbWjddddddddddddg jdjddddtfdd d0D} | rFjd#rFjd$d%gd&d'jd(d)d*jd+d,d*jd-rFjd.d/gdS)1Nz/etc/rsyslog.confz/etc/syslog.confrzUTF-8)encodingz-(include\((\s*)?file=([\"'`]([^'\"]*)[\"'`])))patternstringflagszecho z $`zError parsing include(): z$IncludeConfigz^\S+\s+(-?\/.*$)\s+-z/var/log/auth.log*z/var/log/boot.logz/var/log/dist-upgradez/var/log/installerz/var/log/kern.log*z/var/log/messages*z/var/log/secure*z/var/log/syslog*z /var/log/udevz/etc/rsyslog.dzjournalctl --disk-usagez/var/logTs) recursiveZ extra_optsc3s |]}jj|dVqdS)z log/journal/N) path_exists path_join).0p)self/usr/lib/python3.6/logs.py Vsz!LogsBase.setup../var/runzsystemd-journaldZ journal_fullZ journal_alld)tagsZprioritythisZjournal_since_boot)Zbootr ZlastZjournal_last_bootall_logsz/var/log/journal/*z/run/log/journal/*)rr)ropenrreadrefindallIM startswithosgetenvsplitstripglob ExceptionZ _log_debug splitlinesZdo_regex_find_allZ path_isfileZ add_copy_specadd_cmd_outputZadd_dir_listinganyZ is_service add_journal get_option)rZrsyslogZconfsrZconfZcontentmatchZ_entZenvcerrlineconfigiZjournalr)rrsetupst  & $           zLogsBase.setupcCs|jddddS)Nz /etc/rsyslog*z (ActionLibdbiPassword |pwd=)(.*)z \1[********])Zdo_path_regex_sub)rrrrpostproccszLogsBase.postprocN)rr r )__name__ __module__ __qualname__Z short_desc plugin_nameprofilesr:r;rrrrrs Mrc@seZdZdZdZdZdS)IndependentLogsa This plugin will collect logs traditionally considered to be "system" logs, meaning those such as /var/log/messages, rsyslog, and journals that are not limited to unit-specific entries. Note that the --since option will apply to journal collections by this plugin as well as the typical application to log files. Most users can expect typical journal collections to include the "full" journal, as well as journals limited to this boot and the previous boot. rrr r N)rr r )r<r=r>__doc__r?r@rrrrrAks rAcs,eZdZeddddgZfddZZS)CosLogszlog-daysrz"the number of days logs to collect)namedefaultZdesccsDtj|jdr |jdn |jdd}|jd|dddS)Nr"zjournalctl -o exportzlog-daysrrdays)Zsince)superr:r4r1r3)rrF) __class__rrr:s     z CosLogs.setup)r<r=r>rZ option_listr: __classcell__rr)rHrrC{s rC) r.r*r%Zsos.report.pluginsrrrrrrArCrrrr s \