# # __main__.py # # This module is the entrypoint of the `logparse` shell command and also # contains single-use functions which don't fit elsewhere. # import logging, logging.handlers import argparse import os import glob import sys from subprocess import check_output from datetime import datetime import logparse import logparse.config from logparse.config import prefs, loadconf from logparse import formatting, mail, config, load_parsers global argparser def rotate(): # Rotate logs using systemd logrotate try: if not os.geteuid() == 0: if sys.stdin.isatty(): logger.warning("Not running as root, using sudo (may require password to be entered)") rotate_shell = check_output("sudo logrotate /etc/logrotate.conf", shell=True) else: raise PermissionError("Root priviliges are required to run logrotate but are not provided") else: rotate_shell = check_output("/usr/sbin/logrotate /etc/logrotate.conf", shell=True) logger.info("Rotated logfiles") logger.debug("logrotate output: " + rotate_shell) except Exception as e: logger.warning("Failed to rotate log files: " + str(e)) def rotate_sim(): # Simulate log rotation try: if not os.geteuid() == 0: logger.warning("Cannot run logrotate as root - you will see permission errors in the output below") sim_cmd = "logrotate -d /etc/logrotate.conf" logger.debug("Here is the output of `{0}` (simulated):".format(sim_cmd)) sim = check_output(sim_cmd, shell=True) logger.debug(sim) except Exception as e: logger.warning("Failed to get logrotate simulation: " + str(e)) def main(): # Get arguments global argparser argparser = argparse.ArgumentParser(description='grab logs of some common services and send them by email') argparser.add_argument('-t','--to', help='mail recipient (\"to\" address)', required=False) argparser.add_argument('-c', '--config', help='path to config file', required=False, default="/etc/logparse/logparse.conf") argparser.add_argument('-p', '--print', help='print HTML to stdout', required=False, dest='printout', action='store_true', default=False) argparser.add_argument('-d', '--destination', help='file to output HTML', required=False) argparser.add_argument('-f', '--overwrite', help='force overwrite an existing output file', required=False, action='store_true', default=False) argparser.add_argument('-v', '--verbose', help='verbose console/syslog output (for debugging)', required=False, default=False, action='store_true') argparser.add_argument('-r', '--rotate', help='force rotate log files using systemd logrotate (overrides --rotate and "rotate" in logparse.conf)', required=False, default=False, action='store_true') argparser.add_argument('-nr', '--no-rotate', help='do not rotate logfiles (overrides --rotate and logparse.conf)', required=False, default=False, action='store_true') argparser.add_argument('-s', '--simulate', help="test run logrotate (do not actually change files)", required=False, default=False, action="store_true") argparser.add_argument('-l', '--logs', help='services to analyse', required=False) argparser.add_argument('-nl', '--ignore-logs', help='skip these services (takes precedence over -l)', required=False) argparser.add_argument('-es', '--embed-styles', help='make CSS rules inline rather than linking the file', required=False, default=False, action='store_true') argparser.add_argument('-nh', '--plain', help='write/send plain text rather than HTML', required=False, default=False, action='store_true') argparser.add_argument('-q', '--quiet', help='no output to stdout', required=False, default=False, action='store_true') argparser.add_argument('-nm', '--no-mail', help="do not send email (overrides config file)", required=False, default=False, action="store_true") argparser.add_argument('-nw', '--no-write', help="do not write output file (overrides config file)", required=False, default=False, action="store_true") # Load config config.prefs = loadconf(argparser.parse_args().config) # Set up logging logger = logging.getLogger(__name__) loghandler = logging.handlers.SysLogHandler(address = '/dev/log') loghandler.setFormatter(logging.Formatter(fmt='logparse[' + str(os.getpid()) + ']: %(message)s')) loghandler.setLevel(logging.INFO) # don't spam syslog with debug messages if argparser.parse_args().quiet or config.prefs.getboolean("logparse", "quiet"): logging.basicConfig(level=logging.CRITICAL) elif argparser.parse_args().verbose or config.prefs.getboolean("logparse", "verbose"): logging.basicConfig(level=logging.DEBUG) logger.debug("Verbose mode turned on") else: logging.basicConfig(level=logging.INFO) logger.addHandler(loghandler) logger.debug([x for x in config.prefs.sections()]) logger.debug(config.prefs.get("logparse", "output")) logger.debug("Config test: " + config.prefs.get("logparse", "output")) # Time analysis global start start = datetime.now() logger.info("Beginning log analysis at {0} {1}".format(start.strftime(formatting.DATEFMT), start.strftime(formatting.TIMEFMT))) logger.debug("This is {0} version {1}, running on Python {2}".format(logparse.__name__, logparse.__version__, sys.version.replace('\n', ''))) # Write header formatting.init_var() if argparser.parse_args().plain: output = formatting.PlaintextOutput(linewidth=config.prefs.getint("plain", "linewidth")) output.append_header() else: output = formatting.HtmlOutput() output.append_header(config.prefs.get("html", "header")) # Find parsers loader = load_parsers.ParserLoader("logparse.parsers") parser_names = set([x.name for x in loader.parsers]) if argparser.parse_args().logs: parser_names = parser_names.intersection(set(argparser.parse_args().logs.split())) elif config.prefs.get("logparse", "parsers"): parser_names = parser_names.intersection(set(config.prefs.get("logparse", "parsers").split())) if argparser.parse_args().ignore_logs: parser_names = parser_names.difference(set(argparser.parse_args().ignore_logs.split())) elif config.prefs.get("logparse", "ignore-parsers"): parser_names = parser_names.difference(set(config.prefs.get("logparse", "ignore-parsers").split())) # Execute parsers logger.debug("Queued the following parsers: " + str(loader.parsers)) for parser in loader.parsers: if parser.name in parser_names: output.append_section(parser.parse_log()) # Write HTML footer output.append_footer() if (argparser.parse_args().destination or config.prefs.get("logparse", "output")) and not argparser.parse_args().no_write: if argparser.parse_args().destination: dest_path = argparser.parse_args().destination else: dest_path = config.prefs.get("logparse", "output") logger.debug("Outputting to {0}".format(dest_path)) if (argparser.parse_args().embed_styles or config.prefs.getboolean("html", "embed-styles")) and not (argparser.parse_args().plain or config.prefs.getboolean("plain", "plain")): output.embed_css(config.prefs.get("html", "css")) if (not os.path.isfile(dest_path)) and not (argparser.parse_args().overwrite or config.prefs.getboolean("logparse", "overwrite")): output.write(dest_path) elif logging.root.level == logging.CRITICAL: pass else: logger.warning("Destination file already exists") if input("Would you like to overwrite {0}? (y/n) [n] ".format(dest_path)) == 'y': output.write(dest_path) else: logger.warning("No output written") if (str(argparser.parse_args().to) or str(config.prefs.get("mail", "to"))) and not argparser.parse_args().no_mail: if str(argparser.parse_args().to): to = argparser.parse_args().to else: to = config.prefs.get("mail", "to") mail.sendmail( mailbin=config.prefs.get("mail", "mailbin"), body=(output.embed_css(config.prefs.get("html", "css")) if isinstance(output, formatting.HtmlOutput) else output.content), recipient=to, subject=formatting.fsubject(config.prefs.get("mail", "subject")), html=isinstance(output, formatting.HtmlOutput), sender=config.prefs.get("mail", "from")) if not argparser.parse_args().no_rotate: if argparser.parse_args().simulate or config.prefs.getboolean("logparse", "rotate"): rotate_sim() elif config.prefs.getboolean("logparse", "rotate") or argparser.parse_args().rotate: rotate() else: logger.debug("User doesn't want to rotate logs") else: logger.debug("User doesn't want to rotate logs") # Print end message finish = datetime.now() logger.info("Finished parsing logs at {0} {1} (total time: {2})".format(finish.strftime(formatting.DATEFMT), finish.strftime(formatting.TIMEFMT), finish - start)) if argparser.parse_args().printout: output.print_stdout() return