wazuh-kibana-app/server/controllers/wazuh-elastic.js

340 lines
12 KiB
JavaScript
Raw Normal View History

/*
* Wazuh app - Class for Wazuh-Elastic functions
* Copyright (C) 2018 Wazuh, Inc.
*
* This program is free software; you can redistribute it and/or modify
* it under the terms of the GNU General Public License as published by
* the Free Software Foundation; either version 2 of the License, or
* (at your option) any later version.
*
* Find more information about this on the LICENSE file.
*/
2018-04-22 13:41:10 +00:00
import ElasticWrapper from '../lib/elastic-wrapper';
import fs from 'fs';
import yml from 'js-yaml';
import path from 'path';
import { AgentsVisualizations, OverviewVisualizations, RulesetVisualizations } from '../integration-files/visualizations/index'
2018-04-22 13:41:10 +00:00
export default class WazuhElastic {
constructor(server){
this.wzWrapper = new ElasticWrapper(server);
}
2017-10-27 08:10:17 +00:00
async getTimeStamp(req,reply) {
try {
const data = await this.wzWrapper.getWazuhVersionIndexAsSearch();
if(data.hits &&
data.hits.hits[0] &&
data.hits.hits[0]._source &&
data.hits.hits[0]._source.installationDate &&
data.hits.hits[0]._source.lastRestart){
return reply({
installationDate: data.hits.hits[0]._source.installationDate,
lastRestart : data.hits.hits[0]._source.lastRestart
});
} else {
throw new Error('Could not fetch .wazuh-version index');
}
} catch (err) {
2018-03-22 12:35:58 +00:00
return reply({
statusCode: 500,
error : 99,
message : err.message || 'Could not fetch .wazuh-version index'
}).code(500);
}
}
async getTemplate(req, reply) {
2018-03-22 12:35:58 +00:00
try {
const data = await this.wzWrapper.getTemplates();
2018-03-22 12:35:58 +00:00
if (req.params.pattern == "wazuh-alerts-3.x-*" && data.includes("wazuh-alerts-3.*")) {
2018-03-22 12:35:58 +00:00
return reply({
statusCode: 200,
status : true,
data : `Template found for ${req.params.pattern}`
});
} else {
2018-03-22 12:35:58 +00:00
const lastChar = req.params.pattern[req.params.pattern.length -1];
const array = data.match(/[^\s]+/g);
2018-01-18 11:44:58 +00:00
let pattern = req.params.pattern;
if (lastChar === '*') { // Remove last character if it is a '*'
pattern = pattern.slice(0, -1);
}
2018-01-14 13:05:54 +00:00
for (let i = 1; i < array.length; i++) {
2018-01-18 11:44:58 +00:00
if (array[i].includes(pattern) && array[i-1] == `wazuh`) {
2018-03-22 12:35:58 +00:00
return reply({
statusCode: 200,
status : true,
data : `Template found for ${req.params.pattern}`
});
2018-01-14 13:05:54 +00:00
}
}
2018-03-22 12:35:58 +00:00
return reply({
statusCode: 200,
status : false,
data : `No template found for ${req.params.pattern}`
});
2018-01-10 17:00:06 +00:00
}
2018-03-22 12:35:58 +00:00
} catch (error){
return reply({
statusCode: 500,
error : 10000,
message : `Could not retrieve templates from Elasticsearch due to ${error.message || error}`
}).code(500);
2018-03-22 12:35:58 +00:00
}
}
2018-01-10 17:00:06 +00:00
async checkPattern (req, reply) {
2018-03-22 12:35:58 +00:00
try {
const response = await this.wzWrapper.getAllIndexPatterns();
2018-03-22 12:35:58 +00:00
const filtered = response.hits.hits.filter(item => item._source['index-pattern'].title === req.params.pattern);
return filtered.length >= 1 ?
reply({ statusCode: 200, status: true, data: 'Index pattern found' }) :
reply({ statusCode: 500, status: false, error:10020, message: 'Index pattern not found' });
2018-03-22 12:35:58 +00:00
} catch (error) {
return reply({
2018-03-22 12:35:58 +00:00
statusCode: 500,
error : 10000,
message : `Something went wrong retrieving index-patterns from Elasticsearch due to ${error.message || error}`
}).code(500);
2018-03-22 12:35:58 +00:00
}
}
async getFieldTop (req, reply) {
2018-03-22 12:35:58 +00:00
try{
// Top field payload
let payload = {
size: 1,
query: {
bool: {
must : [],
filter: { range: { '@timestamp': {} } }
2017-10-27 08:10:17 +00:00
}
2018-03-22 12:35:58 +00:00
},
aggs: {
'2': {
terms: {
field: '',
size : 1,
order: { _count: 'desc' }
2017-10-27 08:10:17 +00:00
}
}
}
2018-03-22 12:35:58 +00:00
};
2018-03-22 12:35:58 +00:00
// Set up time interval, default to Last 24h
const timeGTE = 'now-1d';
const timeLT = 'now';
payload.query.bool.filter.range['@timestamp']['gte'] = timeGTE;
payload.query.bool.filter.range['@timestamp']['lt'] = timeLT;
2017-10-27 08:10:17 +00:00
// Set up match for default cluster name
2018-03-22 12:35:58 +00:00
payload.query.bool.must.push(
req.params.mode === 'cluster' ?
{ match: { 'cluster.name': req.params.cluster } } :
{ match: { 'manager.name': req.params.cluster } }
);
2018-03-22 12:35:58 +00:00
payload.aggs['2'].terms.field = req.params.field;
const data = await this.wzWrapper.searchWazuhAlertsWithPayload(payload);
2016-11-09 19:11:15 +00:00
2018-03-22 12:35:58 +00:00
return (data.hits.total === 0 || typeof data.aggregations['2'].buckets[0] === 'undefined') ?
reply({ statusCode: 200, data: '' }) :
reply({ statusCode: 200, data: data.aggregations['2'].buckets[0].key });
2016-11-09 19:11:15 +00:00
2018-03-22 12:35:58 +00:00
} catch (error) {
return reply({
statusCode: 500,
error : 9,
message : error.message || error
2017-10-27 08:10:17 +00:00
}).code(500);
2018-03-22 12:35:58 +00:00
}
}
2016-11-09 19:11:15 +00:00
async getSetupInfo (req, reply) {
try {
const data = await this.wzWrapper.getWazuhVersionIndexAsSearch();
return data.hits.total === 0 ?
reply({ statusCode: 200, data: '' }) :
reply({ statusCode: 200, data: data.hits.hits[0]._source });
} catch (error) {
return reply({
statusCode: 500,
error : 9,
message : `Could not get data from elasticsearch due to ${error.message || error}`
2017-10-27 08:19:16 +00:00
}).code(500);
}
}
async filterAllowedIndexPatternList (list,req) {
let finalList = [];
for(let item of list){
try {
const allow = await this.wzWrapper.searchWazuhElementsByIndexWithRequest(req, item.title);
2018-03-26 08:56:50 +00:00
if(allow && allow.hits && allow.hits.total >= 1) finalList.push(item);
} catch (error){
console.log(`Some user trys to fetch the index pattern ${item.title} without permissions`)
}
}
return finalList;
}
validateIndexPattern(indexPatternList){
const minimum = ["@timestamp", "full_log", "manager.name", "agent.id"];
let list = [];
for(const index of indexPatternList){
let valid, parsed;
try{
parsed = JSON.parse(index._source['index-pattern'].fields)
} catch (error){
continue;
}
valid = parsed.filter(item => minimum.includes(item.name));
if(valid.length === 4){
list.push({
id : index._id.split('index-pattern:')[1],
title: index._source['index-pattern'].title
})
}
}
return list;
}
async getlist (req,res) {
try {
const xpack = await this.wzWrapper.getPlugins();
const isXpackEnabled = typeof xpack === 'string' && xpack.includes('x-pack');
const isSuperUser = isXpackEnabled && req.auth.credentials.roles.includes('superuser');
const data = await this.wzWrapper.getAllIndexPatterns();
2018-04-10 13:11:06 +00:00
if(data && data.hits && data.hits.hits.length === 0) throw new Error('There is no index pattern');
2018-03-19 08:50:26 +00:00
if(data && data.hits && data.hits.hits){
const list = this.validateIndexPattern(data.hits.hits);
return res({data: isXpackEnabled && !isSuperUser ? await this.filterAllowedIndexPatternList(list,req) : list});
}
2018-03-19 08:50:26 +00:00
throw new Error('The Elasticsearch request didn\'t fetch the expected data');
} catch(error){
2018-03-22 10:24:40 +00:00
return res({error: error.message || error}).code(500)
}
}
async deleteVis (req, res) {
try {
await this.wzWrapper.refreshIndexByName(this.wzWrapper.WZ_KIBANA_INDEX);
const tmp = await this.wzWrapper.deleteVisualizationByDescription(req.params.timestamp);
return res({acknowledge: true , output: tmp});
} catch(error){
return res({error:error.message || error}).code(500);
}
}
/**
* Replaces visualizations main fields to fit a certain pattern.
* @param {*} app_objects Object containing raw visualizations.
* @param {*} id Index-pattern id to use in the visualizations. Eg: 'wazuh-alerts'
*/
buildVisualizationsRaw (app_objects, id) {
try{
const visArray = [];
let aux_source, bulk_content;
for (let element of app_objects) {
// Stringify and replace index-pattern for visualizations
aux_source = JSON.stringify(element._source);
aux_source = aux_source.replace("wazuh-alerts", id);
aux_source = JSON.parse(aux_source);
// Bulk source
bulk_content = {};
bulk_content[element._type] = aux_source;
visArray.push({
attributes: bulk_content.visualization,
type : element._type,
id : element._id,
_version : bulk_content.visualization.version
});
}
return visArray;
} catch (error) {
return Promise.reject(error)
}
}
async createVis (req, res) {
try {
if(!req.params.pattern ||
!req.params.tab ||
(req.params.tab && !req.params.tab.includes('manager-') && !req.params.tab.includes('overview-') && !req.params.tab.includes('agents-'))
) {
throw new Error('Missing parameters');
}
const apiConfig = (req.headers && req.headers.id) ? await this.wzWrapper.getWazuhConfigurationById(req.headers.id) : false;
const clusterName = apiConfig && apiConfig.cluster_info ? apiConfig.cluster_info.cluster : false;
const tabPrefix = req.params.tab.includes('overview') ?
'overview' : req.params.tab.includes('manager') ?
'manager' :
'agents';
const tabSplit = req.params.tab.split('-');
const tabSufix = tabPrefix === 'manager' ? tabSplit[2] : tabSplit[1];
const file = tabPrefix === 'manager' ?
RulesetVisualizations[tabSufix] :
tabPrefix === 'overview' ?
OverviewVisualizations[tabSufix] :
AgentsVisualizations[tabSufix];
const raw = await this.buildVisualizationsRaw(file, req.params.pattern);
return res({acknowledge: true, raw: raw });
} catch(error){
return res({error:error.message || error}).code(500);
}
}
async refreshIndex (req,res) {
try {
if(!req.params.pattern) throw new Error('Missing parameters');
const output = await this.wzWrapper.updateIndexPatternKnownFields(req.params.pattern);
return res({acknowledge: true, output: output });
} catch(error){
return res({error:error.message || error}).code(500);
}
}
}