blob: 6204abcca2324c9f68ecfce29382ed7e80e7d299 (
plain)
| 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
 | .. _event-handler:
Event Handler
-------------
Event handler allows you to execute scripts when a string that matches a regex appears in a text stream (e.g. log file).
It uses "feeds" (output of commands, or a named pipes) and "policies" that define what to execute if a regex is matched.
.. code-block:: sh
  system
  event-handler
      feed <name>
      description <feed description>
      policy <policy name>
      source
          preset
          syslog # Use the syslog logs for feed
          custom
          command <command to execute> # E.g. "tail -f /var/log/somelogfile"
          named-pipe <path to a names pipe>
      policy <policy name>
      description <policy description>
      event <event name>
          description <event description>
          pattern <regex>
          run <command to run>
In this small example a script runs every time a login failed and an interface goes down
.. code-block:: sh
  vyos@vyos# show system event-handler 
  feed Syslog {
      policy MyPolicy
      source {
          preset syslog
      }
  }
  policy MyPolicy {
      description "Test policy"
      event BadThingsHappened {
          pattern "authentication failure"
          pattern "interface \.* index \d+ .* DOWN.*"
          run /config/scripts/email-to-admin 
      }
  }
 |