From patchwork Tue Nov 5 22:36:18 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Robin Roevens X-Patchwork-Id: 8206 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) client-signature RSA-PSS (4096 bits)) (Client CN "mail01.haj.ipfire.org", Issuer "R11" (verified OK)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4Xjjqy4bpbz3x5y for ; Tue, 5 Nov 2024 22:36:46 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [172.28.1.201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) client-signature ECDSA (secp384r1)) (Client CN "mail02.haj.ipfire.org", Issuer "E6" (verified OK)) by mail01.ipfire.org (Postfix) with ESMTPS id 4Xjjqp5dc2z4bK; Tue, 5 Nov 2024 22:36:38 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [127.0.0.1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4Xjjqp29gbz34Kw; Tue, 5 Nov 2024 22:36:38 +0000 (UTC) Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "R11" (verified OK)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4Xjjqm23Hnz342Q for ; Tue, 5 Nov 2024 22:36:36 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4Xjjql15PLz1Zd for ; Tue, 5 Nov 2024 22:36:35 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=B4j7SNqU; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1730846195; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=0++LWyXMwyI8RNCLyRCrGDMC9GS+cYTSv+qr8/9EQHg=; b=GHMtkWNb+A08Z8YtwO3QPeiTiS5VSjzA2xsgdQDKS2K5OisFZtdnRI2zmyvaev0bS2XdTn 2jSMpGK4qBoy7RoHHHBO80L/RvxLHFwmyP5Jgo3iO1yLr5him0THyrwHiOd5kyqTbq/ACL QRSWmZ/is7Gx+dSmk64tNouUWH8YUWuJq57zgohmy7KK59WAwOKqfQ8s/XamqgFqdDqJpA zAHqvG5AkkY9WyeRb59eoNbzKScjS4JZWoeVH8xUGVrd+bHSyiUzoONCo7rEAWjJggry8H FxhOK5hSd5al2zlYm0XkyTd3J7rds1F5o27MCpH7ngYcZC/gDsVHtLAw5E6FzQ== ARC-Seal: i=1; s=202003rsa; d=lists.ipfire.org; t=1730846195; a=rsa-sha256; cv=none; b=HjPjynQaHUHJp1JoENCrXt4XXA9LkUNpA+9lOs2kNUNyxVgVG6FSjm3h5DzEtXI0tBTOKD Cfn8p2+Wpo+LQNl4LCPngVBI2hp6mhSQgtsEpoD60oaXH1J/iuaznmhGaTfym2xSUHIqbR 7vpF668ypJriOUC8Q9ZZcUihd0J6mLDLFmy60llYIysGOea8tmumzHjBS+vYTqJ2Yzb9Vq CRpln1vLlYEKnBlA3naKvl9K7yPyyGfii1e/+ZmQ24LPjfrIsEWcvff0o0w905cACZO7oh eHnwxapRfjuchYwHqYFWnGHZ8WwRVlPlybOSxDx7/XJoryU3r5lwPbigXcDhHw== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=B4j7SNqU; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org Received: from mail01.disroot.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 0441124CD6 for ; Tue, 5 Nov 2024 23:36:34 +0100 (CET) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id qOQJyoJ_xwy6 for ; Tue, 5 Nov 2024 23:36:29 +0100 (CET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1730846189; bh=kSwt/DzvgO2+XOy44PDIKQduuxHbi22o2lwetU0/KpA=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=B4j7SNqUifkYG0Q5lti0bTYMZCpjbGqG/Wo382PhaYQB3Te9y0HWTHUUSHZwlEY6G nrAUcRIkSDaeKwiGDoSDsPsd/lNw4ytZz7C2Jpph0PaGRatvp+Ng4ac3pdlQI5wNYn YQt5ijICa20UK2EYnYGjcoh1O1OLJGt+RHBROc7uCMsAacXlAHeTyvkW700gfo1mvM lSpdc0BGLI5wXCXVMBRLPrcNVBSVHCjLvIYRngZLy/HU/6IMcIErHC+F8pSVKuI7s7 fELgG1E4g1k8PVmmhyiQvRy53MhgUS2tl6nezu9WdUg6Cbp1ZVo+9/spAMUPo8ubnp YaqZudUptsa5w== From: Robin Roevens To: development@lists.ipfire.org Subject: [PATCH 2/2] zabbix_agentd: Add IPS throughput and guardian blocked IP count items Date: Tue, 5 Nov 2024 23:36:18 +0100 Message-ID: <20241105223618.4086546-2-robin.roevens@disroot.org> In-Reply-To: <20241105223618.4086546-1-robin.roevens@disroot.org> References: <20241105223618.4086546-1-robin.roevens@disroot.org> MIME-Version: 1.0 X-Rspamd-Action: no action X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4Xjjql15PLz1Zd X-Spamd-Result: default: False [0.55 / 11.00]; BAYES_HAM(-3.00)[99.99%]; SPF_REPUTATION_SPAM(2.06)[0.68799890087892]; RBL_VIRUSFREE_BOTNET(2.00)[178.21.23.139:from]; RBL_SENDERSCORE_REPUT_9(-1.00)[178.21.23.139:from]; MID_CONTAINS_FROM(1.00)[]; NEURAL_HAM(-1.00)[-0.999]; R_MISSING_CHARSET(0.50)[]; BAD_REP_POLICIES(0.10)[]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.01)[]; IP_REPUTATION_HAM(-0.00)[asn: 50673(0.00), country: NL(-0.00), ip: 178.21.23.139(0.00)]; RCVD_TLS_LAST(0.00)[]; TO_DN_SOME(0.00)[]; MIME_TRACE(0.00)[0:+]; R_DKIM_ALLOW(0.00)[disroot.org:s=mail]; RCPT_COUNT_TWO(0.00)[2]; ARC_NA(0.00)[]; FUZZY_RATELIMITED(0.00)[rspamd.com]; DMARC_POLICY_ALLOW(0.00)[disroot.org,reject]; DKIM_TRACE(0.00)[disroot.org:+]; TO_MATCH_ENVRCPT_SOME(0.00)[]; RCVD_COUNT_TWO(0.00)[2]; FROM_EQ_ENVFROM(0.00)[]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; R_SPF_ALLOW(0.00)[+a]; DKIM_REPUTATION(0.00)[0]; MISSING_XM_UA(0.00)[]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; FROM_HAS_DN(0.00)[] Message-ID-Hash: ZJKX5QK24Q2WIDDNJQLA7ELWKIVEMX6X X-Message-ID-Hash: ZJKX5QK24Q2WIDDNJQLA7ELWKIVEMX6X X-MailFrom: robin.roevens@disroot.org X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.8 Precedence: list List-Id: IPFire development talk Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: - Adds Zabbix Agent userparameter `ipfire.ips.throughput.get` for the agent to get details about IPS throughput bypassed/scanned/whitelisted in bytes (JSON) - Adds Zabbix Agent userparameter `ipfire.guardian.blocked.count` for the agent to get the number of currently blocked IP's by Addon: Guardian. Signed-off-by: Robin Roevens --- config/zabbix_agentd/userparameter_ipfire.conf | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/config/zabbix_agentd/userparameter_ipfire.conf b/config/zabbix_agentd/userparameter_ipfire.conf index cc0bd9f8e..c8ead1608 100644 --- a/config/zabbix_agentd/userparameter_ipfire.conf +++ b/config/zabbix_agentd/userparameter_ipfire.conf @@ -11,4 +11,12 @@ UserParameter=ipfire.dhcpd.clients,grep -s -E 'lease|bind' /var/state/dhcp/dhcpd # Number of Captive Portal clients UserParameter=ipfire.captive.clients,awk -F ',' 'length($2) == 17 {sum += 1} END {if (length(sum) == 0) print 0; else print sum}' /var/ipfire/captive/clients # Services list and state -UserParameter=ipfire.services.get,sudo /var/ipfire/zabbix_agentd/scripts/ipfire_services.pl \ No newline at end of file +UserParameter=ipfire.services.get,sudo /var/ipfire/zabbix_agentd/scripts/ipfire_services.pl +# IPS throughput bypassed/scanned/whitelisted in bytes/type (JSON) +UserParameter=ipfire.ips.throughput.get,sudo /usr/local/bin/getipstat -xm | awk 'BEGIN{ORS="";print "{"}/Chain IPS/{f=1}/BYPASSED/&&f{printf "\"bypassed\":%s",$2}/SCANNED/&&f{printf ",\"scanned\":%s",$2}/WHITELISTED/&&f{printf ",\"whitelisted\":%s",$2}/^$/{f=0}END{print "}"}' +# Addon: Guardian: Number of currently blocked IP's +UserParameter=ipfire.guardian.blocked.count,sudo /usr/local/bin/getipstat | awk 'BEGIN{ORS="";c=0}/Chain GUARDIAN/{f=1}/DROP/&&f{c++}/^$/{f=0}END{print c}' +# +# Allow item key to be called with (unused) parameters. This allows the #SINGLETON method of discovering this item only when specific service is active +Alias=ipfire.ips.throughput.get[]:ipfire.ips.throughput.get +Alias=ipfire.guardian.blocked.count[]:ipfire.guardian.blocked.count \ No newline at end of file