osquery-1/osquery/dispatcher/distributed_runner.cpp

63 lines
1.8 KiB
C++
Raw Normal View History

/**
* Copyright (c) 2014-present, Facebook, Inc.
2015-09-07 18:09:06 +00:00
* All rights reserved.
*
* This source code is licensed as defined on the LICENSE file found in the
* root directory of this source tree.
2015-09-07 18:09:06 +00:00
*/
2018-08-02 15:57:02 +00:00
#include <chrono>
2016-09-12 23:53:42 +00:00
#include <osquery/database.h>
#include <osquery/distributed.h>
#include <osquery/flags.h>
2016-09-12 23:53:42 +00:00
#include <osquery/system.h>
#include <osquery/utils/system/time.h>
#include <osquery/dispatcher/distributed_runner.h>
#include <osquery/utils/conversions/tryto.h>
2015-09-07 18:09:06 +00:00
namespace osquery {
FLAG(uint64,
2015-10-02 18:33:50 +00:00
distributed_interval,
2015-09-07 18:09:06 +00:00
60,
2015-10-02 18:33:50 +00:00
"Seconds between polling for new queries (default 60)")
2015-09-07 18:09:06 +00:00
2015-10-02 18:33:50 +00:00
DECLARE_bool(disable_distributed);
2015-09-07 18:09:06 +00:00
DECLARE_string(distributed_plugin);
2016-09-12 23:53:42 +00:00
const size_t kDistributedAccelerationInterval = 5;
2015-09-07 18:09:06 +00:00
void DistributedRunner::start() {
auto dist = Distributed();
while (!interrupted()) {
2015-09-07 18:09:06 +00:00
dist.pullUpdates();
if (dist.getPendingQueryCount() > 0) {
dist.runQueries();
}
std::string accelerate_checkins_expire_str = "-1";
Status status = getDatabaseValue(kPersistentSettings,
"distributed_accelerate_checkins_expire",
accelerate_checkins_expire_str);
if (!status.ok() || getUnixTime() > tryTo<unsigned long int>(
accelerate_checkins_expire_str, 10)
.takeOr(0ul)) {
2018-08-02 15:57:02 +00:00
pause(std::chrono::seconds(FLAGS_distributed_interval));
2016-09-12 23:53:42 +00:00
} else {
2018-08-02 15:57:02 +00:00
pause(std::chrono::seconds(kDistributedAccelerationInterval));
2016-09-12 23:53:42 +00:00
}
2015-09-07 18:09:06 +00:00
}
}
Status startDistributed() {
if (!FLAGS_disable_distributed) {
2015-09-07 18:09:06 +00:00
Dispatcher::addService(std::make_shared<DistributedRunner>());
return Status(0, "OK");
} else {
return Status(1, "Distributed query service not enabled.");
}
}
} // namespace osquery