misp-dashboard/zmq_subscriber.py

63 lines
1.8 KiB
Python
Raw Normal View History

#!/usr/bin/env python3.5
2017-10-20 16:55:07 +02:00
import time, datetime
import zmq
2017-12-04 16:44:44 +01:00
import logging
import redis
import configparser
import argparse
import os
import sys
import json
configfile = os.path.join(os.environ['DASH_CONFIG'], 'config.cfg')
cfg = configparser.ConfigParser()
cfg.read(configfile)
2017-12-04 16:44:44 +01:00
logging.basicConfig(filename='logs/logs.log', filemode='w', level=logging.INFO)
logger = logging.getLogger(__name__)
2017-11-06 18:40:44 +01:00
ZMQ_URL = cfg.get('RedisGlobal', 'zmq_url')
CHANNEL = cfg.get('RedisLog', 'channel')
2017-11-30 08:17:53 +01:00
LISTNAME = cfg.get('RedisLIST', 'listName')
2017-11-30 08:17:53 +01:00
serv_list = redis.StrictRedis(
host=cfg.get('RedisGlobal', 'host'),
port=cfg.getint('RedisGlobal', 'port'),
2017-11-30 08:17:53 +01:00
db=cfg.getint('RedisLIST', 'db'))
###############
## MAIN LOOP ##
###############
2017-11-30 08:17:53 +01:00
def put_in_redis_list(zmq_name, content):
2017-11-30 16:04:03 +01:00
content = content.decode('utf8')
2017-11-30 08:17:53 +01:00
to_add = {'zmq_name': zmq_name, 'content': content}
2017-11-30 16:04:03 +01:00
serv_list.lpush(LISTNAME, json.dumps(to_add))
2017-12-04 16:44:44 +01:00
logger.debug('Pushed: {}'.format(json.dumps(to_add)))
2017-10-13 15:03:09 +02:00
def main(zmqName):
context = zmq.Context()
socket = context.socket(zmq.SUB)
socket.connect(ZMQ_URL)
socket.setsockopt_string(zmq.SUBSCRIBE, '')
2017-10-13 15:03:09 +02:00
while True:
try:
content = socket.recv()
content.replace(b'\n', b'') # remove \n...
2017-11-30 08:17:53 +01:00
put_in_redis_list(zmqName, content)
except KeyboardInterrupt:
return
2017-10-13 15:03:09 +02:00
if __name__ == "__main__":
2017-12-04 11:14:25 +01:00
parser = argparse.ArgumentParser(description='A zmq subscriber. It subscribes to a ZNQ then redispatch it to the misp-dashboard')
2017-10-27 08:49:47 +02:00
parser.add_argument('-n', '--name', required=False, dest='zmqname', help='The ZMQ feed name', default="MISP Standard ZMQ")
parser.add_argument('-u', '--url', required=False, dest='zmqurl', help='The URL to connect to', default=ZMQ_URL)
args = parser.parse_args()
main(args.zmqname)