|
1 | 1 | import base64 |
2 | 2 | import collections.abc |
3 | | -from datetime import datetime |
| 3 | +from datetime import datetime, timedelta |
4 | 4 | import hashlib |
5 | 5 | import hmac |
6 | 6 | import json |
7 | 7 | import logging |
| 8 | +import pytz |
8 | 9 | import requests |
9 | 10 | from zentral.core.events import event_from_event_d |
10 | 11 | from zentral.core.stores.backends.base import BaseEventStore |
|
13 | 14 | logger = logging.getLogger('zentral.core.stroes.backends.azure_log_analytics') |
14 | 15 |
|
15 | 16 |
|
| 17 | +def datetime_to_iso8601z_truncated_to_milliseconds(dt): |
| 18 | + # round created at to milliseconds |
| 19 | + dt_microsecond = dt.microsecond |
| 20 | + if dt_microsecond: |
| 21 | + dt_millisecond = round(dt_microsecond / 1000) |
| 22 | + if dt_millisecond == 1000: |
| 23 | + dt = dt.replace(microsecond=0) |
| 24 | + dt += timedelta(seconds=1) |
| 25 | + else: |
| 26 | + dt = dt.replace(microsecond=1000 * dt_millisecond) |
| 27 | + |
| 28 | + # convert created at to UTC, remove the TZ info (naive datetime), convert to isoformat |
| 29 | + dt_iso = dt.astimezone(pytz.utc).replace(tzinfo=None).isoformat() |
| 30 | + |
| 31 | + # truncate the microseconds in isoformat if necessary |
| 32 | + if "." in dt_iso: |
| 33 | + dt_iso = dt_iso[:-3] |
| 34 | + |
| 35 | + # add the pseudo time zone |
| 36 | + return "{}Z".format(dt_iso) |
| 37 | + |
| 38 | + |
16 | 39 | class EventStore(BaseEventStore): |
17 | 40 | log_type = "ZentralEvent" |
18 | 41 | content_type = "application/json" |
@@ -53,23 +76,8 @@ def _prepare_event(self, event): |
53 | 76 |
|
54 | 77 | metadata = event_d.pop("_zentral") |
55 | 78 |
|
56 | | - # created at |
57 | | - created_at = metadata.pop("created_at") |
58 | | - if "." in created_at: |
59 | | - created_at, created_at_ms = created_at.split(".") |
60 | | - if len(created_at_ms) == 6: |
61 | | - created_at_ms = round(int(created_at_ms) / 1000) |
62 | | - elif len(created_at_ms) == 3: |
63 | | - created_at_ms = int(created_at_ms) |
64 | | - else: |
65 | | - # TODO |
66 | | - created_at_ms = 0 |
67 | | - if created_at_ms: |
68 | | - if created_at_ms == 1000: |
69 | | - # TODO |
70 | | - created_at_ms = 999 |
71 | | - created_at = "{}.{:03d}".format(created_at, created_at_ms) |
72 | | - metadata["created_at"] = "{}Z".format(created_at) |
| 79 | + # fix created_at format for use as TimeGenerated field via the time-generated-field header |
| 80 | + metadata["created_at"] = datetime_to_iso8601z_truncated_to_milliseconds(event.metadata.created_at) |
73 | 81 |
|
74 | 82 | # flatten the metadata |
75 | 83 | azure_event = self._flatten_metadata(metadata) |
|
0 commit comments