#include <exception>
-#include <osquery/flags.h>
#include <osquery/logger.h>
#include <osquery/utils/config/default_paths.h>
namespace fs = boost::filesystem;
-/**
- * This is the mode that Glog uses for logfiles.
- * Must be at the top level (i.e. outside of the `osquery` namespace).
- */
-DECLARE_int32(logfile_mode);
-
namespace osquery {
-FLAG(string,
- logger_path,
- OSQUERY_LOG_HOME,
- "Directory path for ERROR/WARN/INFO and results logging");
-/// Legacy, backward compatible "osquery_log_dir" CLI option.
-FLAG_ALIAS(std::string, osquery_log_dir, logger_path);
-
-FLAG(int32, logger_mode, 0640, "Decimal mode for log files (default '0640')");
-
const std::string kFilesystemLoggerFilename = "osqueryd.results.log";
const std::string kFilesystemLoggerSnapshots = "osqueryd.snapshots.log";
Status FilesystemLoggerPlugin::setUp() {
- log_path_ = fs::path(FLAGS_logger_path);
-
- // Ensure that the Glog status logs use the same mode as our results log.
- // Glog 0.3.4 does not support a logfile mode.
- // FLAGS_logfile_mode = FLAGS_logger_mode;
-
// Ensure that we create the results log here.
return logStringToFile("", kFilesystemLoggerFilename, true);
}
Status FilesystemLoggerPlugin::logStringToFile(const std::string& s,
const std::string& filename,
bool empty) {
- WriteLock lock(mutex_);
- Status status;
- try {
- status = writeTextFile((log_path_ / filename).string(),
- (empty) ? "" : s + '\n',
- FLAGS_logger_mode);
- } catch (const std::exception& e) {
- return Status(1, e.what());
- }
- return status;
+ return Status(1, "Not supported.");
}
Status FilesystemLoggerPlugin::logStatus(
// Stop the internal Glog facilities.
google::ShutdownGoogleLogging();
- // The log dir is used for status logging and the filesystem results logs.
- if (isWritable(log_path_.string()).ok()) {
- FLAGS_log_dir = log_path_.string();
- FLAGS_logtostderr = false;
- } else {
- // If we cannot write logs to the filesystem, fallback to stderr.
- // The caller (flags/options) might 'also' be logging to stderr using
- // debug, verbose, etc.
- FLAGS_logtostderr = true;
- }
- // Restart the Glog facilities using the name `init` was provided.
google::InitGoogleLogging(name.c_str());
// We may violate Glog global object assumptions. So set names manually.
(basename + ".WARNING.").c_str());
google::SetLogDestination(google::GLOG_ERROR, (basename + ".ERROR.").c_str());
- // Store settings for logging to stderr.
- bool log_to_stderr = FLAGS_logtostderr;
- bool also_log_to_stderr = FLAGS_alsologtostderr;
- int stderr_threshold = FLAGS_stderrthreshold;
- FLAGS_alsologtostderr = false;
- FLAGS_logtostderr = false;
- FLAGS_stderrthreshold = 5;
-
// Now funnel the intermediate status logs provided to `init`.
logStatus(log);
-
- // The filesystem logger cheats and uses Glog to log to the filesystem so
- // we can return failure here and stop the custom log sink.
- // Restore settings for logging to stderr.
- FLAGS_logtostderr = log_to_stderr;
- FLAGS_alsologtostderr = also_log_to_stderr;
- FLAGS_stderrthreshold = stderr_threshold;
}
}