123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146 |
- #ifdef HAVE_CONFIG_H
- #include "config.h"
- #endif
- #include <netdissect-stdinc.h>
- #include "netdissect.h"
- #include "extract.h"
- static const char tstr[] = "[|syslog]";
- #define SYSLOG_SEVERITY_MASK 0x0007
- #define SYSLOG_FACILITY_MASK 0x03f8
- #define SYSLOG_MAX_DIGITS 3
- static const struct tok syslog_severity_values[] = {
- { 0, "emergency" },
- { 1, "alert" },
- { 2, "critical" },
- { 3, "error" },
- { 4, "warning" },
- { 5, "notice" },
- { 6, "info" },
- { 7, "debug" },
- { 0, NULL },
- };
- static const struct tok syslog_facility_values[] = {
- { 0, "kernel" },
- { 1, "user" },
- { 2, "mail" },
- { 3, "daemon" },
- { 4, "auth" },
- { 5, "syslog" },
- { 6, "lpr" },
- { 7, "news" },
- { 8, "uucp" },
- { 9, "cron" },
- { 10, "authpriv" },
- { 11, "ftp" },
- { 12, "ntp" },
- { 13, "security" },
- { 14, "console" },
- { 15, "cron" },
- { 16, "local0" },
- { 17, "local1" },
- { 18, "local2" },
- { 19, "local3" },
- { 20, "local4" },
- { 21, "local5" },
- { 22, "local6" },
- { 23, "local7" },
- { 0, NULL },
- };
- void
- syslog_print(netdissect_options *ndo,
- register const u_char *pptr, register u_int len)
- {
- uint16_t msg_off = 0;
- uint16_t pri = 0;
- uint16_t facility,severity;
-
- ND_TCHECK2(*pptr, 1);
- if (*(pptr+msg_off) == '<') {
- msg_off++;
- ND_TCHECK2(*(pptr + msg_off), 1);
- while ( *(pptr+msg_off) >= '0' &&
- *(pptr+msg_off) <= '9' &&
- msg_off <= SYSLOG_MAX_DIGITS) {
- pri = pri * 10 + (*(pptr+msg_off) - '0');
- msg_off++;
- ND_TCHECK2(*(pptr + msg_off), 1);
- }
- if (*(pptr+msg_off) != '>') {
- ND_PRINT((ndo, "%s", tstr));
- return;
- }
- msg_off++;
- } else {
- ND_PRINT((ndo, "%s", tstr));
- return;
- }
- facility = (pri & SYSLOG_FACILITY_MASK) >> 3;
- severity = pri & SYSLOG_SEVERITY_MASK;
- if (ndo->ndo_vflag < 1 )
- {
- ND_PRINT((ndo, "SYSLOG %s.%s, length: %u",
- tok2str(syslog_facility_values, "unknown (%u)", facility),
- tok2str(syslog_severity_values, "unknown (%u)", severity),
- len));
- return;
- }
- ND_PRINT((ndo, "SYSLOG, length: %u\n\tFacility %s (%u), Severity %s (%u)\n\tMsg: ",
- len,
- tok2str(syslog_facility_values, "unknown (%u)", facility),
- facility,
- tok2str(syslog_severity_values, "unknown (%u)", severity),
- severity));
-
- for (; msg_off < len; msg_off++) {
- ND_TCHECK2(*(pptr + msg_off), 1);
- safeputchar(ndo, *(pptr + msg_off));
- }
- if (ndo->ndo_vflag > 1)
- print_unknown_data(ndo, pptr, "\n\t", len);
- return;
- trunc:
- ND_PRINT((ndo, "%s", tstr));
- }
|