Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
140 changes: 140 additions & 0 deletions pkg/acquisition/schemas/appsec.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,140 @@
$schema: https://json-schema.org/draft/2020-12/schema
title: CrowdSec AppSec datasource
description: >
Schema for appsec acquisition entries consumed by CrowdSec. Every field
mirrors pkg/acquisition/modules/appsec.Configuration and the embedded
configuration.DataSourceCommonCfg.
type: object
additionalProperties: false
properties:
source:
type: string
const: appsec
description: >
Must be appsec to bind this acquisition entry to the AppSec WAF datasource.
mode:
type: string
enum: [tail]
default: tail
description: >
Acquisition mode (only tail streaming is supported).
labels:
type: object
minProperties: 1
description: >
Labels attached to emitted events (for example type: appsec).
additionalProperties:
type: string
properties:
type:
type: string
description: Parser/collection selector; strongly recommended.
log_level:
type: string
enum: [panic, fatal, error, warn, warning, info, debug, trace]
description: >
Overrides the module logger level for this datasource.
name:
type: string
description: >
Friendly identifier for the datasource entry; defaults to listen_addr
and path (or listen_socket) when omitted.
use_time_machine:
type: boolean
default: false
description: >
Replays past events when supported by the acquisition module.
unique_id:
type: string
description: >
Stable identifier injected by cscli/crowdsec auto-run (usually not user set).
transform:
type: string
description: >
expr program applied to events before they enter the pipeline.
listen_addr:
type: string
default: "127.0.0.1:7422"
description: >
Address:port to bind the AppSec HTTP listener on. Mutually exclusive
with listen_socket.
listen_socket:
type: string
description: >
Unix socket path to bind the AppSec listener on, instead of listen_addr.
cert_file:
type: string
description: TLS certificate file for the AppSec listener.
key_file:
type: string
description: TLS key file for the AppSec listener.
path:
type: string
default: "/"
description: >
HTTP path the bouncer posts requests to; a leading / is added if missing.
routines:
type: integer
minimum: 1
default: 1
description: >
Number of parallel appsec runner goroutines.
appsec_config:
type: string
description: >
Single appsec-config item (or glob pattern) to load. Mutually exclusive
with appsec_configs and appsec_config_path.
appsec_configs:
type: array
minItems: 1
items:
type: string
minLength: 1
description: >
List of appsec-config items (or glob patterns) to load. Mutually
exclusive with appsec_config and appsec_config_path.
appsec_config_path:
type: string
description: >
Path to an appsec-config file to load directly. Mutually exclusive
with appsec_config and appsec_configs.
auth_cache_duration:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
default: 1m
description: >
How long a validated bouncer API key is cached before being re-checked
against LAPI.
auth_timeout:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
default: 200ms
description: >
Timeout for the LAPI round-trip that validates a bouncer API key. 0
disables the timeout.
body_read_timeout:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
default: 1s
description: >
Timeout for reading the bouncer request body. 0 disables the timeout.
required:
- source
allOf:
- description: >
Exactly one appsec-config source must be provided, matching the
UnmarshalConfig checks.
not:
anyOf:
- required: [appsec_config, appsec_configs]
- required: [appsec_config_path, appsec_configs]
- anyOf:
- required: [appsec_config]
- required: [appsec_configs]
- required: [appsec_config_path]
examples:
- source: appsec
listen_addr: 127.0.0.1:7422
appsec_config: crowdsecurity/vpatch-generic-rules
labels:
type: appsec
126 changes: 126 additions & 0 deletions pkg/acquisition/schemas/cloudwatch.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,126 @@
$schema: https://json-schema.org/draft/2020-12/schema
title: CrowdSec Cloudwatch datasource
description: >
Schema for cloudwatch acquisition entries consumed by CrowdSec. Every field
mirrors pkg/acquisition/modules/cloudwatch.Configuration and the embedded
configuration.DataSourceCommonCfg.
type: object
additionalProperties: false
properties:
source:
type: string
const: cloudwatch
description: >
Must be cloudwatch to bind this acquisition entry to the Cloudwatch
datasource.
mode:
type: string
enum: [tail, cat]
default: tail
description: >
Acquisition mode (tail streams logs, cat performs a finite read).
labels:
type: object
minProperties: 1
description: >
Labels attached to emitted events (for example type: cloudwatch).
additionalProperties:
type: string
properties:
type:
type: string
description: Parser/collection selector; strongly recommended.
log_level:
type: string
enum: [panic, fatal, error, warn, warning, info, debug, trace]
description: >
Overrides the module logger level for this datasource.
name:
type: string
description: Friendly identifier for the datasource entry.
use_time_machine:
type: boolean
default: false
description: >
Replays past events when supported by the acquisition module.
unique_id:
type: string
description: >
Stable identifier injected by cscli/crowdsec auto-run (usually not user set).
transform:
type: string
description: >
expr program applied to events before they enter the pipeline.
group_name:
type: string
minLength: 1
description: The Cloudwatch log group to monitor.
stream_regexp:
type: string
format: regex
description: >
Regular expression used to select streams within the log group.
Mutually exclusive in practice with stream_name.
stream_name:
type: string
description: >
Exact stream name to follow within the log group.
describelogstreams_limit:
type: integer
minimum: 1
description: >
Batch size for the DescribeLogStreams pagination.
getlogeventspages_limit:
type: integer
minimum: 1
description: >
Batch size for the GetLogEvents pagination.
poll_new_stream_interval:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: >
Frequency at which new streams are discovered within the log group.
max_stream_age:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: >
Only monitor streams that have been updated within this duration.
poll_stream_interval:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: Frequency at which each stream is polled.
stream_read_timeout:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: >
Stop monitoring a stream that hasn't been updated within this
duration; it may be reopened later.
aws_api_timeout:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: Timeout applied to AWS API calls.
aws_profile:
type: string
description: Named AWS profile to use for credentials.
prepend_cloudwatch_timestamp:
type: boolean
description: >
Prepend the Cloudwatch event timestamp to the log line.
aws_config_dir:
type: string
description: >
Directory containing an AWS config/credentials pair, used instead of
aws_region and the default credential chain.
aws_region:
type: string
description: >
AWS region to use; required unless aws_config_dir is set.
required:
- source
- group_name
examples:
- source: cloudwatch
group_name: /my/log/group
aws_region: eu-west-1
labels:
type: cloudwatch
114 changes: 114 additions & 0 deletions pkg/acquisition/schemas/file.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,114 @@
$schema: https://json-schema.org/draft/2020-12/schema
title: CrowdSec File datasource
description: >
Schema for file acquisition entries consumed by CrowdSec. Every field
mirrors pkg/acquisition/modules/file.Configuration and the embedded
configuration.DataSourceCommonCfg.
type: object
additionalProperties: false
properties:
source:
type: string
const: file
description: >
Must be file to bind this acquisition entry to the File datasource.
mode:
type: string
enum: [tail, cat]
default: tail
description: >
Acquisition mode (tail streams new lines, cat reads the file(s) once).
labels:
type: object
minProperties: 1
description: >
Labels attached to emitted events (for example type: syslog).
additionalProperties:
type: string
properties:
type:
type: string
description: Parser/collection selector; strongly recommended.
log_level:
type: string
enum: [panic, fatal, error, warn, warning, info, debug, trace]
description: >
Overrides the module logger level for this datasource.
name:
type: string
description: Friendly identifier for the datasource entry.
use_time_machine:
type: boolean
default: false
description: >
Replays past events when supported by the acquisition module.
unique_id:
type: string
description: >
Stable identifier injected by cscli/crowdsec auto-run (usually not user set).
transform:
type: string
description: >
expr program applied to events before they enter the pipeline.
filenames:
type: array
minItems: 1
items:
type: string
minLength: 1
description: >
Glob patterns of files to read/tail. At least one of filenames or
filename is required.
filename:
type: string
minLength: 1
description: >
Single glob pattern, appended to filenames when set.
exclude_regexps:
type: array
minItems: 1
items:
type: string
minLength: 1
format: regex
description: >
Regular expressions used to exclude matched files from acquisition.
force_inotify:
type: boolean
default: false
description: >
Force an inotify watch on the parent directory even for non-glob
patterns.
max_buffer_size:
type: integer
minimum: 1
description: >
Maximum size, in bytes, of a scanned line; defaults to bufio's
MaxScanTokenSize when unset.
poll_without_inotify:
type: boolean
description: >
Fall back to polling instead of inotify (auto-detected on some
filesystems such as network shares when unset).
discovery_poll_enable:
type: boolean
default: false
description: >
Periodically re-glob patterns to discover newly created files matching
them, in addition to inotify-based discovery.
discovery_poll_interval:
type: string
pattern: "^[0-9]+(ns|us|ms|s|m|h)$"
description: >
Interval between discovery polls when discovery_poll_enable is true.
required:
- source
anyOf:
- required: [filenames]
- required: [filename]
examples:
- source: file
filenames:
- /var/log/nginx/access.log
labels:
type: nginx
Loading
Loading