/src/suricata8/src/log-flush.c
Line | Count | Source |
1 | | /* Copyright (C) 2026 Open Information Security Foundation |
2 | | * |
3 | | * You can copy, redistribute or modify this Program under the terms of |
4 | | * the GNU General Public License version 2 as published by the Free |
5 | | * Software Foundation. |
6 | | * |
7 | | * This program is distributed in the hope that it will be useful, |
8 | | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
9 | | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
10 | | * GNU General Public License for more details. |
11 | | * |
12 | | * You should have received a copy of the GNU General Public License |
13 | | * version 2 along with this program; if not, write to the Free Software |
14 | | * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA |
15 | | * 02110-1301, USA. |
16 | | */ |
17 | | |
18 | | /** |
19 | | * \file |
20 | | * |
21 | | * \author Jeff Lucovsky <jlucovsky@oisf.net> |
22 | | */ |
23 | | |
24 | | #include "suricata-common.h" |
25 | | #include "suricata.h" |
26 | | #include "log-flush.h" |
27 | | #include "util-logopenfile.h" |
28 | | #include "tm-threads.h" |
29 | | #include "conf.h" |
30 | | #include "conf-yaml-loader.h" |
31 | | #include "util-privs.h" |
32 | | #include "util-logopenfile.h" |
33 | | |
34 | | int OutputFlushInterval(void) |
35 | 8 | { |
36 | 8 | intmax_t output_flush_interval = 0; |
37 | 8 | if (SCConfGetInt("heartbeat.output-flush-interval", &output_flush_interval) == 0) { |
38 | 8 | output_flush_interval = 0; |
39 | 8 | } |
40 | 8 | if (output_flush_interval < 0 || output_flush_interval > 60) { |
41 | 0 | SCLogConfig("flush_interval must be 0 or less than 60; using 0"); |
42 | 0 | output_flush_interval = 0; |
43 | 0 | } |
44 | | |
45 | 8 | return (int)output_flush_interval; |
46 | 8 | } |
47 | | |
48 | | static void *LogFlusherWakeupThread(void *arg) |
49 | 0 | { |
50 | 0 | int output_flush_interval = OutputFlushInterval(); |
51 | | /* This was checked by the logic creating this thread */ |
52 | 0 | BUG_ON(output_flush_interval == 0); |
53 | | |
54 | 0 | SCLogConfig("Using output-flush-interval of %d seconds", output_flush_interval); |
55 | | /* |
56 | | * Calculate the number of sleep intervals based on the output flush interval. This is necessary |
57 | | * because this thread pauses a fixed amount of time to react to shutdown situations more |
58 | | * quickly. |
59 | | */ |
60 | 0 | const int log_flush_sleep_time = 500; /* milliseconds */ |
61 | 0 | const int flush_wait_count = (1000 * output_flush_interval) / log_flush_sleep_time; |
62 | |
|
63 | 0 | ThreadVars *tv_local = (ThreadVars *)arg; |
64 | 0 | SCSetThreadName(tv_local->name); |
65 | |
|
66 | 0 | if (tv_local->thread_setup_flags != 0) |
67 | 0 | TmThreadSetupOptions(tv_local); |
68 | | |
69 | | /* Set the threads capability */ |
70 | 0 | tv_local->cap_flags = 0; |
71 | 0 | SCDropCaps(tv_local); |
72 | |
|
73 | 0 | TmThreadsSetFlag(tv_local, THV_INIT_DONE | THV_RUNNING); |
74 | |
|
75 | 0 | int wait_count = 0; |
76 | 0 | uint64_t worker_flush_count = 0; |
77 | 0 | bool run = TmThreadsWaitForUnpause(tv_local); |
78 | 0 | while (run) { |
79 | 0 | SleepMsec(log_flush_sleep_time); |
80 | |
|
81 | 0 | if (++wait_count == flush_wait_count) { |
82 | 0 | worker_flush_count++; |
83 | 0 | LogFileFlushAll(); |
84 | 0 | wait_count = 0; |
85 | 0 | } |
86 | |
|
87 | 0 | if (TmThreadsCheckFlag(tv_local, THV_KILL)) { |
88 | 0 | break; |
89 | 0 | } |
90 | 0 | } |
91 | |
|
92 | 0 | TmThreadsSetFlag(tv_local, THV_RUNNING_DONE); |
93 | 0 | TmThreadWaitForFlag(tv_local, THV_DEINIT); |
94 | 0 | TmThreadsSetFlag(tv_local, THV_CLOSED); |
95 | 0 | SCLogInfo("%s: initiated %" PRIu64 " flushes", tv_local->name, worker_flush_count); |
96 | 0 | return NULL; |
97 | 0 | } |
98 | | |
99 | | void LogFlushThreads(void) |
100 | 0 | { |
101 | 0 | if (0 == OutputFlushInterval()) { |
102 | 0 | SCLogConfig("log flusher thread not used with heartbeat.output-flush-interval of 0"); |
103 | 0 | return; |
104 | 0 | } |
105 | | |
106 | 0 | ThreadVars *tv_log_flush = |
107 | 0 | TmThreadCreateMgmtThread(thread_name_heartbeat, LogFlusherWakeupThread, 1); |
108 | 0 | if (!tv_log_flush || (TmThreadSpawn(tv_log_flush) != 0)) { |
109 | | FatalError("Unable to create and start log flush thread"); |
110 | 0 | } |
111 | 0 | } |