CrowdSec重放模式

CrowdSec重放模式

CrowdSec不仅可以监控实时日志,也可以重放旧日志文件,即重放/取证模式。它适合测试场景、检测误报和漏报,或生成某段历史时期的报告。

在这种模式下,CrowdSec读取日志并提取时间戳,让场景和桶按照日志中的时间评估。桶溢出产生的告警会像其他告警一样推送到API,但采用日志时间戳,因此可以按原始时间线查看。

重放日志文件时,运行:

sudo crowdsec -c /etc/crowdsec/user.yaml -dsn file:///path/to/your/log/file.log -type log_file_type

-dsn指定待处理日志文件,-type类似于采集配置中的label类型字段。例如:

sudo crowdsec -c /etc/crowdsec/user.yaml -dsn file:///var/log/nginx/2019.log -type nginx
sudo crowdsec -c /etc/crowdsec/user.yaml -dsn file:///var/log/sshd-2019.log -type syslog
sudo crowdsec -c /etc/crowdsec/user.yaml -dsn "journalctl://filters=_SYSTEMD_UNIT=ssh.service" -type syslog

以取证模式运行时,告警既输出到标准输出,也写入数据库:

$ sudo crowdsec -c /etc/crowdsec/user.yaml -dsn file:///var/log/nginx/nginx-2019.log.1 -type nginx
...
INFO[13-11-2020 13:05:23] Ip 123.206.50.249 performed 'crowdsecurity/http-probing' (11 events over 6s) at 2019-01-01 01:37:32 +0100 CET
INFO[13-11-2020 13:05:23] Ip 123.206.50.249 performed 'crowdsecurity/http-backdoors-attempts' (2 events over 1s) at 2019-01-01 01:37:33 +0100 CET
INFO[13-11-2020 13:05:24] (14baeedafc1e44c08b806fc0c1cd92c4/crowdsec) crowdsecurity/http-probing by ip 123.206.50.249 (CN) : 1h ban on Ip 123.206.50.249
INFO[13-11-2020 13:05:24] (14baeedafc1e44c08b806fc0c1cd92c4/crowdsec) crowdsecurity/http-backdoors-attempts by ip 123.206.50.249 (CN) : 1h ban on Ip 123.206.50.249
...

告警进入数据库后,就能通过Metabase或cscli查看。

使用Metabase时,在主仪表板的时间选择器中选择相应时期即可:

Metabase时间选择器

警告:

取证模式下,crowdsec-agent依赖crowdsecurity/dateparse-enrich解析日期格式。支持的格式见CrowdSec Hub中的对应条目。

还可以通过--transform指定表达式,在将每一行送入解析器之前执行。例如,从S3桶读取CloudTrail日志时,需要让每条CloudTrail记录生成一个事件:

sudo crowdsec -c /etc/crowdsec/user.yaml --dsn s3://my_cloudtrail_bucket/AWSLogs/ACCOUNT_ID/CloudTrail/REGION/YEAR/MONTH/DAY/CLOUDTRAIL_FILE.json.gz\?max_buffer_size=1048576 --type aws-cloudtrail --transform 'map(JsonExtractSlice(evt.Line.Raw, "Records"), ToJsonString(#))'

该表达式解析JSON数组Records,为每个数组元素生成一个事件,并将各事件转换成字符串返回。

max_buffer_size控制可读取的单行最大长度。

向现有数据库注入告警

如果CrowdSec/Local API已经运行,且希望把事件注入现有数据库,可以直接运行:

sudo crowdsec -dsn file://logs/nginx/access.log -type nginx -no-api

CrowdSec会处理logs/nginx/access.log,并把告警推送到默认配置文件/etc/crowdsec/config.yaml中配置的Local API,参见其中的api.client.credentials_path。

向新数据库注入告警:本地没有运行中的实例

如果当前没有服务运行,可以直接运行CrowdSec:

sudo crowdsec -dsn file://logs/nginx/access.log -type nginx

CrowdSec会启动Local API,并处理logs/nginx/access.log。

向新数据库注入告警:本地已有运行中的实例

如果本地实例正在运行,又不想污染现有数据库,可以配置独立的Local API与数据库。

先复制现有配置,再编辑副本:

$ sudo cp /etc/crowdsec/config.yaml ./forensic.yaml
$ emacs ./forensic.yaml

修改Local API和数据库配置,确保不会污染现有数据:

$ emacs ./forensic.yaml
...
db_config:
  type: sqlite
  # we edit the db_path to point to a different SQLite database
  db_path: /var/lib/crowdsec/data/crowdsec_alt.db
  # let's comment out the auto-flush (database garbage collection)
  #flush:
  #   max_items: 5000
  #   max_age: 7d
...
api:
  client:
    # we edit credentials_path to point to a local file
    credentials_path: /tmp/local_api_credentials.yaml
  server:
    # we edit the listen_uri so that it doesn't try to listen on the same port as the existing Local API
    listen_uri: 127.0.0.1:8081

这些改动可以确保:

  • 使用不同的SQLite数据库路径,避免与已有本地实例冲突。

  • 改用独立的本地API凭据文件,将机器注册到临时Local API。

  • 使用不同的Local API监听地址,避免端口冲突。

  • 注释flush配置,避免数据库垃圾回收删除正在导入的旧事件。

创建新数据库并注册机器:

$ touch /tmp/local_api_credentials.yaml
$ cscli -c forensic.yaml machines add --auto
INFO[0000] Machine '...' created successfully
INFO[0000] API credentials dumped to '/tmp/local_api_credentials.yaml'
$ cat /tmp/local_api_credentials.yaml
url: http://127.0.0.1:8081
login: ...
password: ...

现在可以启动新的Local API和CrowdSec:

$ crowdsec -c ./forensic.yaml -dsn file://github/crowdsec/OLDS/LOGS/nginx/10k_ACCESS_LOGS.log -type nginx
...
INFO[15-11-2020 10:09:20] Ip x.x.x.x performed 'crowdsecurity/http-bad-user-agent' (2 events over 0s) at 2017-10-21 13:58:38 +0200 CEST
INFO[15-11-2020 10:09:20] Ip y.y.y.y performed 'crowdsecurity/http-probing' (11 events over 0s) at 2017-10-23 12:00:34 +0200 CEST
...

还可以启动专用仪表板查看这些数据:

$ cscli -c forensic.yaml dashboard setup
INFO[0000] /var/lib/crowdsec/data/metabase.db exists, skip.
INFO[0000] Pulling docker image metabase/metabase:v0.37.0.2
...
INFO[0001] creating container '/crowdsec-metabase'
INFO[0002] waiting for metabase to be up (can take up to a minute)
.........
INFO[0040] Metabase is ready
    URL       : 'http://127.0.0.1:3000'
    username  : 'crowdsec@crowdsec.net'
    password  : ...

向新数据库注入告警:开发环境

从新下载的发布包开始:

$ tar xvzf crowdsec-release.tgz
$ cd crowdsec-v1.0.0-rc
$ ./test_env.sh
$ cd tests

安装所需的集合:

$ ./cscli -c dev.yaml collections install crowdsecurity/nginx

随后处理日志:

$ ./crowdsec -c dev.yaml -dsn file://github/crowdsec/OLDS/LOGS/nginx/10k_ACCESS_LOGS.log -type nginx
INFO[0000] single file mode : log_media=stdout daemonize=true
INFO[15-11-2020 11:18:27] Crowdsec v1.0.0-rc-0ecb142dfffc89b019b6d9044cb7cc5569d12c70
INFO[15-11-2020 11:18:38] Ip x.x.x.x performed 'crowdsecurity/http-sensitive-files' (5 events over 4s) at 2017-10-23 12:35:54 +0200 CEST
INFO[15-11-2020 11:18:39] (test/crowdsec) crowdsecurity/http-probing by ip x.x.x.x (DE) : 1h ban on Ip x.x.x.x

保持CrowdSec运行,就能查询本地API:

$ ./cscli -c dev.yaml alerts list
+----+--------------------+---------------------------------------+---------+--------------+-----------+--------------------------------+
| ID |       VALUE        |                REASON                 | COUNTRY |      AS      | DECISIONS |           CREATED AT           |
+----+--------------------+---------------------------------------+---------+--------------+-----------+--------------------------------+
| 28 | Ip:x.x.x.x  | crowdsecurity/http-crawl-non_statics  | DE      |  Linode, LLC | ban:1     | 2017-10-23 12:36:48 +0200      |
|    |                    |                                       |         |              |           | +0200                          |
| 27 | Ip:x.x.x.x  | crowdsecurity/http-sensitive-files    | DE      |  Linode, LLC | ban:1     | 2017-10-23 12:35:50 +0200      |
|    |                    |                                       |         |              |           | +0200                          |

或者启动仪表板查看数据:

$ sudo ./cscli dashboard setup
...
INFO[0002] waiting for metabase to be up (can take up to a minute)
........

来源与版权

原文:CrowdSec重放模式。中文译文。版权归© 2026 CrowdSec, Inc.,保留所有权利。代码、命令及日志中的版本信息保留原文。

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享
评论 抢沙发

请登录后发表评论

    暂无评论内容