From patchwork Thu Jul 30 19:15:54 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Robin Roevens X-Patchwork-Id: 10077 Return-Path: Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by web04.haj.ipfire.org (Postfix) with ESMTPS id 4hB0HR5XCTz3wqJ for ; Thu, 30 Jul 2026 19:53:07 +0000 (UTC) Received: from mail02.haj.ipfire.org (mail02.haj.ipfire.org [IPv6:2001:678:b28::201]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519) (Client CN "mail02.haj.ipfire.org", Issuer "YE1" (not verified)) by mail01.ipfire.org (Postfix) with ESMTPS id 4hB0HF634rz47H for ; Thu, 30 Jul 2026 19:52:57 +0000 (UTC) Received: from mail02.haj.ipfire.org (localhost [IPv6:::1]) by mail02.haj.ipfire.org (Postfix) with ESMTP id 4hB0GK3NSYz36Wk for ; Thu, 30 Jul 2026 19:52:09 +0000 (UTC) X-Original-To: development@lists.ipfire.org Received: from mail01.ipfire.org (mail01.haj.ipfire.org [172.28.1.202]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (secp384r1 raw public key) server-digest SHA384 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mail01.haj.ipfire.org", Issuer "YR2" (not verified)) by mail02.haj.ipfire.org (Postfix) with ESMTPS id 4hB0GG6NF9z2xJ0 for ; Thu, 30 Jul 2026 19:52:06 +0000 (UTC) Received: from layka.disroot.org (layka.disroot.org [178.21.23.139]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bit raw public key) server-digest SHA256) (Client did not present a certificate) by mail01.ipfire.org (Postfix) with ESMTPS id 4hB0G64nKlz2V for ; Thu, 30 Jul 2026 19:51:58 +0000 (UTC) Authentication-Results: mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=FOS0nepR; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org ARC-Seal: i=1; a=rsa-sha256; d=lists.ipfire.org; s=202003rsa; cv=none; t=1785441118; b=Kcf7PWuGR+W6oA3IU4HS5x2G795Rok8UdgTHPUAKCSndSJS0KoHiAzei4aC8Ncv8EhLqHP P5JULHQyEchc/ZLs6eqqa5yleqUU0+J/Zf+fdh0DjkfoamUMJH4YFDZoMRSrr7OtXS33zA 0RpWbdul1OPxjtOL9s2321ycsbGiCdpLSaOLCq9RdyWeXrt6Pa6WOkms3lyVk/8FOt80W6 wIXrkKdNhW5FeLVxNsflDKdJc1tKznSxH0CMSoGkRPuKjF2IKlI79ieIkiGnaP+jwuMfBZ 9FQ24pvWe2F6VMbUxguoRlHEI3TfvR88RYW31dx/vYeSWCLqa6XjC3hbieJLAw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=lists.ipfire.org; s=202003rsa; t=1785441118; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=SE8Jk+gmJJFdc1+LmbaKUYv3LC8aiABQ403MrvEA5Wc=; b=Eve8QNoLrC7IwtpzqQRM9ioTfM0rVejHnskTi5Gb4WQAc/6zPtnD1T5k/VcfqbTlPcvlhM UNv/uhI+UnatcTMTYsKb7j3JTQc1cn6FzCgdKsBoEJAFM6DfEp9bO21o6gch0ZuPIxdiqB Fg6wfcQ3IlJYILW0rsdvoQ+2U36FiPXGPyRbW/XoBxcRbX4tXI/tfr1k3LCKXwUhqWURFU +gvOM6cr33wXcaUT8HAIvyqZKKvHtQgIW+2VlXYHhez4+UOWTVA5VqPcPfhp0coajb4z7Q U3D+J0OIm4x/E8aJEQUuWcY9iaNwWGPLVwIlENM3JDwq+/66wEjsQRfIH0LYaw== ARC-Authentication-Results: i=1; mail01.ipfire.org; dkim=pass header.d=disroot.org header.s=mail header.b=FOS0nepR; spf=pass (mail01.ipfire.org: domain of robin.roevens@disroot.org designates 178.21.23.139 as permitted sender) smtp.mailfrom=robin.roevens@disroot.org; dmarc=pass (policy=reject) header.from=disroot.org Received: from mail01.layka.lan (localhost [127.0.0.1]) by disroot.org (Postfix) with ESMTP id 12ABC41B43 for ; Thu, 30 Jul 2026 21:51:58 +0200 (CEST) X-Virus-Scanned: SPAM Filter at disroot.org Received: from layka.disroot.org ([127.0.0.1]) by localhost (disroot.org [127.0.0.1]) (amavis, port 10024) with ESMTP id vuV46lxNh64i for ; Thu, 30 Jul 2026 21:51:57 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=disroot.org; s=mail; t=1785441117; bh=wCjAXcjEHTM1CntbDAzR6ptpi/9ADPbh5PjTrkGyZgg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=FOS0nepRXboMxhRyzibxJtZrZPYBPjNnn0lyIYjHVb+eUgX4018zouqWsxjEROBLU Q1VO4tUEMGT06KWhuSwai8veV/CGdfi6PXAowly0jy6Q0S7xkQEU6Lcd/+YFKFfNT1 h3L4NRbQDnVvVHMZkTuKcs0Dkc2jL1oQ98NGXXeOwiQbucdcDlPCh+57xln74xyF86 9IUYx3WL1+0hvC5V+lzxEytU7aoqW6IlNsqVwrNCofVi015rKtgHTkSxOb5JUQ2f+I MoEF39gNyuZsOQiRlpdH0tVVTuVrFt7prX/sA8mPqr+4MOgAak1yZyck7rlxm/aumO jmUtLVNnYNVmA== Received: from chojin.roevenslambrechts.be (chojin.roevenslambrechts.be [192.168.0.50]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) (no client certificate requested) (Authenticated sender) by hachiman (MailScanner Milter) with SMTP id B36AE585FE0; Thu, 30 Jul 2026 21:51:54 +0200 (CEST) From: Robin Roevens To: development@lists.ipfire.org Cc: Robin Roevens Subject: [PATCH 3/5] Set zabbix_pending flag when storing new event in DB Date: Thu, 30 Jul 2026 21:15:54 +0200 Message-ID: <20260730195148.3278295-4-robin.roevens@disroot.org> In-Reply-To: <20260730195148.3278295-1-robin.roevens@disroot.org> References: <20260730195148.3278295-1-robin.roevens@disroot.org> Precedence: list List-Id: List-Subscribe: , List-Unsubscribe: , List-Post: List-Help: Sender: Mail-Followup-To: MIME-Version: 1.0 X-RoevensLambrechts-MailScanner-ID: B36AE585FE0.AD543 X-RoevensLambrechts-MailScanner: Found to be clean X-RoevensLambrechts-MailScanner-From: robin.roevens@disroot.org X-RoevensLambrechts-MailScanner-Watermark: 1786045915.98205@BLDBXlrhaWWAluiUOm3hAA X-Rspamd-Server: mail01.haj.ipfire.org X-Rspamd-Queue-Id: 4hB0G64nKlz2V X-Rspamd-Action: no action X-Spamd-Result: default: False [-5.63 / 11.00]; BAYES_HAM(-3.00)[100.00%]; R_DKIM_ALLOW(-1.65)[disroot.org:s=mail]; MID_CONTAINS_FROM(1.00)[]; DKIM_REPUTATION(-0.92)[-0.92153870218341]; SPF_REPUTATION_HAM(-0.65)[-0.65402885146808]; DMARC_POLICY_ALLOW(-0.50)[disroot.org,reject]; R_MISSING_CHARSET(0.50)[]; R_SPF_ALLOW(-0.20)[+a]; MIME_GOOD(-0.10)[text/plain]; MX_GOOD(-0.10)[disroot.org]; RCPT_COUNT_TWO(0.00)[2]; ASN(0.00)[asn:50673, ipnet:178.21.23.0/24, country:NL]; IP_REPUTATION_HAM(0.00)[asn: 50673(0.00), country: NL(-0.01), ip: 178.21.23.139(0.00)]; ARC_NA(0.00)[]; TO_DN_SOME(0.00)[]; MIME_TRACE(0.00)[0:+]; RCVD_COUNT_THREE(0.00)[3]; RCVD_TLS_LAST(0.00)[]; TO_MATCH_ENVRCPT_SOME(0.00)[]; MISSING_XM_UA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; DKIM_TRACE(0.00)[disroot.org:+]; ARC_SIGNED(0.00)[lists.ipfire.org:s=202003rsa:i=1]; PREVIOUSLY_DELIVERED(0.00)[development@lists.ipfire.org]; FROM_HAS_DN(0.00)[] When sending to zabbix is enabled, we need to set the zabbix_pending flag set on each new event written to the database. Signed-off-by: Robin Roevens --- src/suricata-reporter.in | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/src/suricata-reporter.in b/src/suricata-reporter.in index 83e4e97..78bb04d 100644 --- a/src/suricata-reporter.in +++ b/src/suricata-reporter.in @@ -314,9 +314,14 @@ class Reporter(object): """ Writes a single event to the database """ + # Determine whether this event should be marked for Zabbix delivery + zabbix_pending = 1 if self.config.getboolean('zabbix', 'enabled', fallback=False) else 0 + # Write the event to the database - self.db.execute("INSERT INTO alerts(timestamp, event) VALUES(?, ?)", - (event.timestamp.timestamp(), event.json)) + self.db.execute( + "INSERT INTO alerts(timestamp, event, zabbix_pending) VALUES(?, ?, ?)", + (event.timestamp.timestamp(), event.json, zabbix_pending) + ) # Commit it straight away self.db.commit()