mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 05:23:16 +00:00
64 lines
1.8 KiB
Terraform
64 lines
1.8 KiB
Terraform
|
|
resource "aws_athena_workgroup" "this" {
|
||
|
|
name = local.athena_workgroup
|
||
|
|
|
||
|
|
configuration {
|
||
|
|
enforce_workgroup_configuration = true
|
||
|
|
publish_cloudwatch_metrics_enabled = false
|
||
|
|
|
||
|
|
result_configuration {
|
||
|
|
output_location = "s3://${aws_s3_bucket.unifi.bucket}/${local.athena_results_prefix}"
|
||
|
|
|
||
|
|
encryption_configuration {
|
||
|
|
encryption_option = "SSE_S3"
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_athena_named_query" "recent_denies" {
|
||
|
|
name = "unifi-recent-denies"
|
||
|
|
workgroup = aws_athena_workgroup.this.id
|
||
|
|
database = aws_glue_catalog_database.unifi.name
|
||
|
|
query = <<-SQL
|
||
|
|
SELECT timestamp, site, hostname, src, dst, proto, action, raw
|
||
|
|
FROM iptables
|
||
|
|
WHERE dt >= date_format(current_date - interval '7' day, '%Y-%m-%d')
|
||
|
|
AND action = 'deny'
|
||
|
|
ORDER BY timestamp DESC
|
||
|
|
LIMIT 200
|
||
|
|
SQL
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_athena_named_query" "src_dst_lookup" {
|
||
|
|
name = "unifi-src-dst-lookup"
|
||
|
|
workgroup = aws_athena_workgroup.this.id
|
||
|
|
database = aws_glue_catalog_database.unifi.name
|
||
|
|
query = <<-SQL
|
||
|
|
SELECT timestamp, format, site, hostname, src, dst, proto, action, raw
|
||
|
|
FROM iptables
|
||
|
|
WHERE dt >= date_format(current_date - interval '1' day, '%Y-%m-%d')
|
||
|
|
AND (src = 'x.x.x.x' OR dst = 'x.x.x.x')
|
||
|
|
ORDER BY timestamp DESC
|
||
|
|
LIMIT 200
|
||
|
|
SQL
|
||
|
|
}
|
||
|
|
|
||
|
|
resource "aws_athena_named_query" "cef_security" {
|
||
|
|
name = "unifi-cef-security"
|
||
|
|
workgroup = aws_athena_workgroup.this.id
|
||
|
|
database = aws_glue_catalog_database.unifi.name
|
||
|
|
query = <<-SQL
|
||
|
|
SELECT timestamp, site, hostname, src, dst, proto, action, raw
|
||
|
|
FROM cef
|
||
|
|
WHERE dt >= date_format(current_date - interval '7' day, '%Y-%m-%d')
|
||
|
|
AND (
|
||
|
|
lower(raw) LIKE '%security%'
|
||
|
|
OR lower(raw) LIKE '%intrusion%'
|
||
|
|
OR lower(raw) LIKE '%blocked%'
|
||
|
|
OR lower(raw) LIKE '%threat%'
|
||
|
|
)
|
||
|
|
ORDER BY timestamp DESC
|
||
|
|
LIMIT 200
|
||
|
|
SQL
|
||
|
|
}
|