mirror of
https://github.com/optim-enterprises-bv/vault.git
synced 2025-10-31 18:48:08 +00:00
* VAULT-22481: Audit filter node (#24465) * Initial commit on adding filter nodes for audit * tests for audit filter * test: longer filter - more conditions * copywrite headers * Check interface for the right type * Add audit filtering feature (#24554) * Support filter nodes in backend factories and add some tests * More tests and cleanup * Attempt to move control of registration for nodes and pipelines to the audit broker (#24505) * invert control of the pipelines/nodes to the audit broker vs. within each backend * update noop audit test code to implement the pipeliner interface * noop mount path has trailing slash * attempting to make NoopAudit more friendly * NoopAudit uses known salt * Refactor audit.ProcessManual to support filter nodes * HasFiltering * rename the pipeliner * use exported AuditEvent in Filter * Add tests for registering and deregistering backends on the audit broker * Add missing licence header to one file, fix a typo in two tests --------- Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com> * Add changelog file * update bexpr datum to use a strong type * go docs updates * test path * PR review comments * handle scenarios/outcomes from broker.send * don't need to re-check the complete sinks * add extra check to deregister to ensure that re-registering non-filtered device sets sink threshold * Ensure that the multierror is appended before attempting to return it --------- Co-authored-by: Peter Wilson <peter.wilson@hashicorp.com>
48 lines
1.2 KiB
Go
48 lines
1.2 KiB
Go
// Copyright (c) HashiCorp, Inc.
|
|
// SPDX-License-Identifier: BUSL-1.1
|
|
|
|
package audit
|
|
|
|
import (
|
|
"context"
|
|
|
|
metrics "github.com/armon/go-metrics"
|
|
|
|
"github.com/hashicorp/eventlogger"
|
|
)
|
|
|
|
var _ eventlogger.Node = (*SinkWrapper)(nil)
|
|
|
|
// SinkWrapper is a wrapper for any kind of Sink Node that processes events
|
|
// containing an AuditEvent payload.
|
|
type SinkWrapper struct {
|
|
Name string
|
|
Sink eventlogger.Node
|
|
}
|
|
|
|
// Process simply wraps the Process method of this SinkWrapper's sink field by
|
|
// taking a measurement of the time elapsed since the provided Event was created
|
|
// once this method returns.
|
|
func (s *SinkWrapper) Process(ctx context.Context, e *eventlogger.Event) (*eventlogger.Event, error) {
|
|
defer func() {
|
|
auditEvent, ok := e.Payload.(*AuditEvent)
|
|
if ok {
|
|
metrics.MeasureSince([]string{"audit", s.Name, auditEvent.Subtype.MetricTag()}, e.CreatedAt)
|
|
}
|
|
}()
|
|
|
|
return s.Sink.Process(ctx, e)
|
|
}
|
|
|
|
// Reopen simply wraps the Reopen method of this SinkWrapper's sink field
|
|
// without doing any additional work.
|
|
func (s *SinkWrapper) Reopen() error {
|
|
return s.Sink.Reopen()
|
|
}
|
|
|
|
// Type simply wraps the Type method of this SinkWrapper's sink field without
|
|
// doing any additional work.
|
|
func (s *SinkWrapper) Type() eventlogger.NodeType {
|
|
return s.Sink.Type()
|
|
}
|