Add rsyslog plugin support for frr log (#16192)
### Why I did it Currently there is only rsyslog plugin support for /var/log/syslog, meaning we do not detect events that occur in frr logs such as BGP Hold Timer Expiry that appears in frr/bgpd.log. ##### Work item tracking - Microsoft ADO **(number only)**: 13366345 #### How I did it Add omprog action to frr/bgpd.log and frr/zebra.log. Add appropriate regex for both events. #### How to verify it sonic-mgmt test case
This commit is contained in:
parent
51fb6d7d9f
commit
337a9dbcf4
1
dockers/docker-fpm-frr/00-frr.conf
Normal file
1
dockers/docker-fpm-frr/00-frr.conf
Normal file
@ -0,0 +1 @@
|
||||
$ModLoad omprog
|
@ -54,6 +54,7 @@ COPY ["TSC", "/usr/bin/TSC"]
|
||||
COPY ["TS", "/usr/bin/TS"]
|
||||
COPY ["files/supervisor-proc-exit-listener", "/usr/bin"]
|
||||
COPY ["zsocket.sh", "/usr/bin/"]
|
||||
COPY ["00-frr.conf", "/etc/rsyslog.d/"]
|
||||
COPY ["*.json", "/etc/rsyslog.d/"]
|
||||
COPY ["files/rsyslog_plugin.conf.j2", "/etc/rsyslog.d/"]
|
||||
RUN chmod a+x /usr/bin/TSA && \
|
||||
|
@ -3,16 +3,6 @@
|
||||
"tag": "bgp-state",
|
||||
"regex": "Peer .default\\|([0-9a-f:.]*[0-9a-f]*). admin state is set to .(up|down).",
|
||||
"params": [ "ip", "status" ]
|
||||
},
|
||||
{
|
||||
"tag": "zebra-no-buff",
|
||||
"regex": "No buffer space available",
|
||||
"params": []
|
||||
},
|
||||
{
|
||||
"tag": "notification",
|
||||
"regex": "NOTIFICATION: (received|sent) (?:to|from) neighbor ([0-9a-f:.]*[0-9a-f+]*)\\s*.* (\\d*)\/(\\d*)",
|
||||
"params": [ "is_sent", "ip", "major_code", "minor_code" ]
|
||||
}
|
||||
]
|
||||
|
||||
|
7
files/build_templates/bgpd_regex.json
Normal file
7
files/build_templates/bgpd_regex.json
Normal file
@ -0,0 +1,7 @@
|
||||
[
|
||||
{
|
||||
"tag": "notification",
|
||||
"regex": ".*NOTIFICATION: (received|sent) (?:to|from) neighbor ([0-9a-f:.]*[0-9a-f+]*)\\s*.* (\\d*)\/(\\d*)",
|
||||
"params": [ "is_sent:ret=(arg==\"sent\")and\"true\"or\"false\"", "ip", "major_code", "minor_code" ]
|
||||
}
|
||||
]
|
@ -7,8 +7,6 @@ template(name="prog_msg" type="list") {
|
||||
constant(value="\n")
|
||||
}
|
||||
|
||||
$ModLoad omprog
|
||||
|
||||
{% for proc in proclist %}
|
||||
if re_match($programname, "{{ proc.name }}") then {
|
||||
action(type="omprog"
|
||||
|
@ -335,6 +335,8 @@ sudo cp $BUILD_TEMPLATES/syncd_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
sudo cp $BUILD_TEMPLATES/kernel_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
sudo cp $BUILD_TEMPLATES/dockerd_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
sudo cp $BUILD_TEMPLATES/seu_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
sudo cp $BUILD_TEMPLATES/zebra_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
sudo cp $BUILD_TEMPLATES/bgpd_regex.json $FILESYSTEM_ROOT_ETC/rsyslog.d/
|
||||
|
||||
# Install custom-built monit package and SONiC configuration files
|
||||
sudo dpkg --root=$FILESYSTEM_ROOT -i $debs_path/monit_*.deb || \
|
||||
|
7
files/build_templates/zebra_regex.json
Normal file
7
files/build_templates/zebra_regex.json
Normal file
@ -0,0 +1,7 @@
|
||||
[
|
||||
{
|
||||
"tag": "zebra-no-buff",
|
||||
"regex": "No buffer space available",
|
||||
"params": []
|
||||
}
|
||||
]
|
@ -1,12 +1,27 @@
|
||||
## Quagga rules
|
||||
|
||||
template(name="prog_msg" type="list") {
|
||||
property(name="msg")
|
||||
constant(value="\n")
|
||||
}
|
||||
|
||||
$ModLoad omprog
|
||||
|
||||
if re_match($programname, "bgp[0-9]*#(frr|zebra|staticd|watchfrr)") then {
|
||||
/var/log/frr/zebra.log
|
||||
action(type="omprog"
|
||||
binary="/usr/bin/rsyslog_plugin -r /etc/rsyslog.d/zebra_regex.json -m sonic-events-bgp"
|
||||
output="/var/log/rsyslog_plugin.log"
|
||||
template="prog_msg")
|
||||
stop
|
||||
}
|
||||
|
||||
if re_match($programname, "bgp[0-9]*#bgpd") then {
|
||||
/var/log/frr/bgpd.log
|
||||
action(type="omprog"
|
||||
binary="/usr/bin/rsyslog_plugin -r /etc/rsyslog.d/bgpd_regex.json -m sonic-events-bgp"
|
||||
output="/var/log/rsyslog_plugin.log"
|
||||
template="prog_msg")
|
||||
stop
|
||||
}
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user