5 ms·
Nice! I'm actually working on a similar project to push lsof and files from /proc into some postgres tables. Lets me do cool things like query log files across
by bpchaps 9y ago
Nice! I'm actually working on a similar project to push lsof and files from /proc into some postgres tables. Lets me do cool things like query log files across a ~6000 server infrastructure similar to:
SELECT distinct(l.name)
FROM lsof l, lsofer_runs r
WHERE l.lsofer_id = r.id
AND fd_type = 'REG'
AND l.fd ~ '[0-9][uw]'
AND l.name like '%log'
GROUP BY l.name, r.hostname
ORDER BY name
Best of luck!
- matthewaveryusa 9y agoso you're rewriting osquery? https://osquery.io/ https://osquery.io/
- bpchaps 9y agoHah, apparently.
- nthcolumn 9y agoI need this immediately.
- bpchaps 9y agoI'll see about getting it into a public repo soon and let you know.
- tyingq 9y agoHis description sounded like it would do joins across different hosts. Osquery looks to be single host at a time only.
- bpchaps 9y agoYep. I'm specifically writing it to find any log file that isn't being pushed into our third party logging service. It's a surprisingly difficult problem, especially considering the amount of tech sprawl that's accumulated. Since it's also a relatively low latency environment, it has to be written in a way that doesn't add too much load (without core isolation..).
- tyingq 9y agoYou could use the audit subsystem. https://www.linux.com/learn/customized-file-monitoring-auditd https://www.linux.com/learn/customized-file-monitoring-audit...
- bpchaps 9y agoDefinitely crossed my mind, but I'm working on hosts where installing auditd isn't really easy. Broken yum and apt all over the place makes installing new packages almost impossible. Same goes for lsof, but its installed in "enough" places. Kinda nightmarish, but it gives me a chance to write some fun code ;). Also, thanks for the article! Super interesting. Think that'd be better than implementing something on top of sysdig?
- tyingq 9y agoAuditd has the advantage of not being intermittent polling, which could miss something. Sounds like it isn't an option though.
- tyingq 9y agoAnother non polling option: http://www.brendangregg.com/blog/2014-07-25/opensnoop-for-linux.html http://www.brendangregg.com/blog/2014-07-25/opensnoop-for-li...
- bpchaps 9y ago+1 for anything by Brendan Gregg. I wasn't aware of the polling limitations of sysdig, but it definitely explains some things I've seen in the past. This is definitely going in my toolkit. Cheers! Edit: dammit, spelled his name wrong.
- kshvmdn 9y agoLooks very cool, is the code available anywhere? Would love to take a look.
- bpchaps 9y agoThe code is behind my company's GH, but here's a rewrite of the collector script: https://github.com/red-bin/lsofer/blob/master/lsofer.sh https://github.com/red-bin/lsofer/blob/master/lsofer.sh
- fomojola 9y agoIs this something you could do with Presto? You'd need to write a custom connector and it doesn't look like there is support for dynamically adding/removing catalogs (https://github.com/prestodb/presto/issues/2445 https://github.com/prestodb/presto/issues/2445) but it would presumably handle the heavy lifting for you.