# File lib/fluent/plugin/in_syslog.rb, line 68 def initialize super require 'fluent/plugin/socket_util' end
# File lib/fluent/plugin/in_syslog.rb, line 101 def configure(conf) super if conf.has_key?('format') @parser = Plugin.new_parser(conf['format']) @parser.configure(conf) else conf['with_priority'] = true @parser = TextParser::SyslogParser.new @parser.configure(conf) @use_default = true end end
# File lib/fluent/plugin/in_syslog.rb, line 136 def run @loop.run(@blocking_timeout) rescue log.error "unexpected error", error: $!.to_s log.error_backtrace end
# File lib/fluent/plugin/in_syslog.rb, line 129 def shutdown @loop.watchers.each {|w| w.detach } @loop.stop @handler.close @thread.join end
# File lib/fluent/plugin/in_syslog.rb, line 115 def start callback = if @use_default method(:receive_data) else method(:receive_data_parser) end @loop = Coolio::Loop.new @handler = listen(callback) @loop.attach(@handler) @thread = Thread.new(&method(:run)) end
# File lib/fluent/plugin/in_syslog.rb, line 212 def emit(tag, time, record) router.emit(tag, time, record) rescue => e log.error "syslog failed to emit", error: e.to_s, error_class: e.class.to_s, tag: tag, record: Yajl.dump(record) end
# File lib/fluent/plugin/in_syslog.rb, line 200 def listen(callback) log.info "listening syslog socket on #{@bind}:#{@port} with #{@protocol_type}" if @protocol_type == :udp @usock = SocketUtil.create_udp_socket(@bind) @usock.bind(@bind, @port) SocketUtil::UdpHandler.new(@usock, log, @message_length_limit, callback) else # syslog family add "\n" to each message and this seems only way to split messages in tcp stream Coolio::TCPServer.new(@bind, @port, SocketUtil::TcpHandler, log, "\n", callback) end end
# File lib/fluent/plugin/in_syslog.rb, line 175 def receive_data(data, addr) @parser.parse(data) { |time, record| unless time && record log.warn "invalid syslog message", data: data return end pri = record.delete('pri'.freeze) facility = FACILITY_MAP[pri >> 3] priority = PRIORITY_MAP[pri & 0b111] record[@priority_key] = priority if @priority_key record[@facility_key] = facility if @facility_key record[@source_host_key] = addr[2] if @include_source_host tag = "#{@tag}.#{facility}.#{priority}" emit(tag, time, record) } rescue => e log.error data.dump, error: e.to_s log.error_backtrace end
# File lib/fluent/plugin/in_syslog.rb, line 145 def receive_data_parser(data, addr) m = SYSLOG_REGEXP.match(data) unless m log.warn "invalid syslog message: #{data.dump}" return end pri = m[1].to_i text = m[2] @parser.parse(text) { |time, record| unless time && record log.warn "pattern not match: #{text.inspect}" return end facility = FACILITY_MAP[pri >> 3] priority = PRIORITY_MAP[pri & 0b111] record[@priority_key] = priority if @priority_key record[@facility_key] = facility if @facility_key record[@source_host_key] = addr[2] if @include_source_host tag = "#{@tag}.#{facility}.#{priority}" emit(tag, time, record) } rescue => e log.error data.dump, error: e.to_s log.error_backtrace end