@@ -73,6 +73,8 @@ class Router
|
||||
preg_match('#^/alerts/counts$#', $path) && $method === 'GET'
|
||||
=> $this->repo->getAlertCounts(),
|
||||
|
||||
$path === '/logs/search' && $method === 'GET' => $this->searchLogs(),
|
||||
|
||||
$path === '/config/allowed_tokens' && $method === 'GET'
|
||||
=> ['tokens' => $this->repo->getAllowedUserTokens()],
|
||||
$path === '/config/allowed_tokens' && $method === 'PUT'
|
||||
@@ -204,6 +206,17 @@ class Router
|
||||
return $this->repo->searchAlerts($query, $limit);
|
||||
}
|
||||
|
||||
private function searchLogs(): array
|
||||
{
|
||||
$query = $_GET['q'] ?? '';
|
||||
if (empty($query)) {
|
||||
return ['data' => []];
|
||||
}
|
||||
$limit = (int) ($_GET['limit'] ?? 200);
|
||||
$offset = (int) ($_GET['offset'] ?? 0);
|
||||
return ['data' => $this->repo->searchLogEntries($query, $limit, $offset)];
|
||||
}
|
||||
|
||||
private function updateAllowedTokens(): array
|
||||
{
|
||||
$body = json_decode(file_get_contents('php://input'), true);
|
||||
|
||||
@@ -116,25 +116,45 @@ class Database
|
||||
END;
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
$this->pdo->exec("
|
||||
INSERT OR IGNORE INTO alerts_fts(rowid, message, raw_line, rule_name, source_name)
|
||||
SELECT id, message, raw_line, rule_name, source_name FROM alerts
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
CREATE TABLE IF NOT EXISTS rate_limiter (
|
||||
rule_id INTEGER NOT NULL,
|
||||
window_start INTEGER NOT NULL,
|
||||
count INTEGER DEFAULT 0,
|
||||
PRIMARY KEY (rule_id, window_start)
|
||||
CREATE TABLE IF NOT EXISTS log_entries (
|
||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||
line TEXT NOT NULL,
|
||||
source_id INTEGER,
|
||||
source_name TEXT,
|
||||
level TEXT,
|
||||
created_at TEXT DEFAULT (datetime('now'))
|
||||
)
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
CREATE TABLE IF NOT EXISTS config (
|
||||
key TEXT PRIMARY KEY,
|
||||
value TEXT NOT NULL
|
||||
CREATE INDEX IF NOT EXISTS idx_log_entries_created ON log_entries(created_at DESC)
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
CREATE VIRTUAL TABLE IF NOT EXISTS log_entries_fts USING fts5(
|
||||
line, source_name,
|
||||
content='log_entries',
|
||||
content_rowid='id',
|
||||
tokenize='porter unicode61'
|
||||
)
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
CREATE TRIGGER IF NOT EXISTS log_entries_ai AFTER INSERT ON log_entries BEGIN
|
||||
INSERT INTO log_entries_fts(rowid, line, source_name)
|
||||
VALUES (new.id, new.line, new.source_name);
|
||||
END;
|
||||
");
|
||||
|
||||
$this->pdo->exec("
|
||||
INSERT OR IGNORE INTO log_entries_fts(rowid, line, source_name)
|
||||
SELECT id, line, source_name FROM log_entries
|
||||
");
|
||||
}
|
||||
}
|
||||
@@ -159,6 +159,29 @@ class Repository
|
||||
return array_map(fn(array $r) => Alert::fromRow($r), $rows);
|
||||
}
|
||||
|
||||
// --- Log Entries ---
|
||||
|
||||
public function storeLogEntry(string $line, ?int $sourceId = null, ?string $sourceName = null, ?string $level = null): void
|
||||
{
|
||||
$stmt = $this->db->pdo()->prepare(
|
||||
"INSERT INTO log_entries (line, source_id, source_name, level) VALUES (?, ?, ?, ?)"
|
||||
);
|
||||
$stmt->execute([$line, $sourceId, $sourceName, $level]);
|
||||
}
|
||||
|
||||
public function searchLogEntries(string $query, int $limit = 200, int $offset = 0): array
|
||||
{
|
||||
$stmt = $this->db->pdo()->prepare(
|
||||
"SELECT e.* FROM log_entries e
|
||||
JOIN log_entries_fts fts ON e.id = fts.rowid
|
||||
WHERE log_entries_fts MATCH ?
|
||||
ORDER BY rank
|
||||
LIMIT ? OFFSET ?"
|
||||
);
|
||||
$stmt->execute([$query, $limit, $offset]);
|
||||
return $stmt->fetchAll();
|
||||
}
|
||||
|
||||
// --- Config ---
|
||||
|
||||
public function getAllowedUserTokens(): array
|
||||
|
||||
@@ -59,6 +59,9 @@ class Orchestrator
|
||||
private function handleLine(string $line, int $sourceId): void
|
||||
{
|
||||
$source = $this->sourceMap[$sourceId] ?? null;
|
||||
|
||||
$this->repo->storeLogEntry($line, $sourceId, $source?->name);
|
||||
|
||||
$alert = $this->engine->evaluate($line, $source);
|
||||
|
||||
if ($alert !== null) {
|
||||
|
||||
Reference in New Issue
Block a user