Skip to content

Commit ee8ca25

Browse files
committed
wip
1 parent f1160d2 commit ee8ca25

File tree

6 files changed

+277
-0
lines changed

6 files changed

+277
-0
lines changed
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
# Container image that runs your code
2+
# FROM python:3-slim AS builder
3+
4+
# # Copies your code file from your action repository to the filesystem path `/` of the container
5+
# ADD . /app
6+
# WORKDIR /app
7+
8+
# RUN pip install --target=/app requests
9+
10+
# Code file to execute when the docker container starts up (`entrypoint.sh`)
11+
# FROM gcr.io/distroless/python3-debian10
12+
FROM registry.access.redhat.com/ubi9/python-312:latest
13+
14+
ADD . /app
15+
WORKDIR /app
16+
17+
RUN pip install requests
18+
19+
# COPY --from=builder /app /app
20+
ENV PYTHONPATH=/app
21+
CMD [ "python", "/app/main.py" ]
Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
MIT License
2+
3+
Copyright (c) 2022 Splunk GitHub
4+
5+
Permission is hereby granted, free of charge, to any person obtaining a copy
6+
of this software and associated documentation files (the "Software"), to deal
7+
in the Software without restriction, including without limitation the rights
8+
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
9+
copies of the Software, and to permit persons to whom the Software is
10+
furnished to do so, subject to the following conditions:
11+
12+
The above copyright notice and this permission notice shall be included in all
13+
copies or substantial portions of the Software.
14+
15+
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
16+
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
17+
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
18+
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
19+
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
20+
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21+
SOFTWARE.
Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
# POST GitHub Workflow Logs to Splunk HTTP Event Collector
2+
test
Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,28 @@
1+
# action.yml
2+
name: 'Send Workflow Logs to Splunk'
3+
description: 'Upload GitHub Workflow logs to Splunk HEC'
4+
inputs:
5+
splunk_url:
6+
description: 'Full URL for Splunk HEC endpoint'
7+
required: true
8+
hec_token:
9+
description: 'Splunk HEC Token'
10+
required: true
11+
github_token:
12+
description: 'Github PAT'
13+
required: true
14+
sourcetype:
15+
description: 'Splunk Sourcetype'
16+
default: 'github_workflow_log_action'
17+
source:
18+
description: 'GitHub Workflow name'
19+
default: ${{ github.workflow }}
20+
workflow_id:
21+
description: 'The Workflow Run number'
22+
default: ${{ github.run_number}}
23+
outputs:
24+
status:
25+
description: 'value is success/fail based on POST result'
26+
runs:
27+
using: 'docker'
28+
image: 'Dockerfile'
Lines changed: 162 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,162 @@
1+
import os
2+
import requests
3+
import json
4+
import zipfile
5+
import io
6+
import glob
7+
import re
8+
from datetime import datetime
9+
10+
def main():
11+
print("######################")
12+
13+
GITHUB_REF=os.environ["GITHUB_REF"]
14+
GITHUB_REPOSITORY=os.environ["GITHUB_REPOSITORY"]
15+
GITHUB_RUN_ID=os.environ["GITHUB_RUN_ID"]
16+
GITHUB_API_URL=os.environ["GITHUB_API_URL"]
17+
GITHUB_WORKFLOWID=os.environ["INPUT_WORKFLOW_ID"]
18+
GITHUB_TOKEN = os.environ.get("INPUT_GITHUB_TOKEN")
19+
20+
SPLUNK_HEC_URL=os.environ["INPUT_SPLUNK_URL"]+"services/collector/event"
21+
SPLUNK_HEC_TOKEN=os.environ["INPUT_HEC_TOKEN"]
22+
SPLUNK_SOURCE=os.environ["INPUT_SOURCE"]
23+
SPLUNK_SOURCETYPE=os.environ["INPUT_SOURCETYPE"]
24+
25+
batch = count = 0
26+
eventBatch = ""
27+
headers = {"Authorization": "Splunk "+SPLUNK_HEC_TOKEN}
28+
host=os.uname()[1]
29+
30+
summary_url = "{url}/repos/{repo}/actions/runs/{run_id}".format(url=GITHUB_API_URL,repo=GITHUB_REPOSITORY,run_id=GITHUB_WORKFLOWID)
31+
32+
print(f"GITHUB_REF: {GITHUB_REF}")
33+
print(f"GITHUB_REPOSITORY: {GITHUB_REPOSITORY}")
34+
print(f"GITHUB_RUN_ID: {GITHUB_RUN_ID}")
35+
print(f"GITHUB_API_URL: {GITHUB_API_URL}")
36+
print(f"GITHUB_WORKFLOWID: {GITHUB_WORKFLOWID}")
37+
print(f"GITHUB_TOKEN: {GITHUB_TOKEN}")
38+
print(f"SPLUNK_HEC_URL: {SPLUNK_HEC_URL}")
39+
print(f"SPLUNK_HEC_TOKEN: {SPLUNK_HEC_TOKEN}")
40+
print(f"SPLUNK_SOURCE: {SPLUNK_SOURCE}")
41+
print(f"SPLUNK_SOURCETYPE: {SPLUNK_SOURCETYPE}")
42+
print(f"host: {host}")
43+
print(f"headers: {headers}")
44+
print(f"summary_url: {summary_url}")
45+
print("######################")
46+
47+
try:
48+
x = requests.get(summary_url, stream=True, auth=('token',GITHUB_TOKEN))
49+
x.raise_for_status()
50+
except requests.exceptions.HTTPError as errh:
51+
output = "GITHUB API Http Error:" + str(errh)
52+
print(f"Error: {output}")
53+
print(f"::set-output name=result::{output}")
54+
return x.status_code
55+
except requests.exceptions.ConnectionError as errc:
56+
output = "GITHUB API Error Connecting:" + str(errc)
57+
print(f"Error: {output}")
58+
print(f"::set-output name=result::{output}")
59+
return x.status_code
60+
except requests.exceptions.Timeout as errt:
61+
output = "Timeout Error:" + str(errt)
62+
print(f"Error: {output}")
63+
print(f"::set-output name=result::{output}")
64+
return x.status_code
65+
except requests.exceptions.RequestException as err:
66+
output = "GITHUB API Non catched error conecting:" + str(err)
67+
print(f"Error: {output}")
68+
print(f"::set-output name=result::{output}")
69+
return x.status_code
70+
except Exception as e:
71+
print("Internal error", e)
72+
return x.status_code
73+
74+
summary = x.json()
75+
76+
summary.pop('repository')
77+
78+
summary["repository"]=summary["head_repository"]["name"]
79+
summary["repository_full"]=summary["head_repository"]["full_name"]
80+
81+
summary.pop('head_repository')
82+
83+
utc_time = datetime.strptime(summary["updated_at"], "%Y-%m-%dT%H:%M:%SZ")
84+
epoch_time = (utc_time - datetime(1970, 1, 1)).total_seconds()
85+
86+
event={'event':json.dumps(summary),'sourcetype':SPLUNK_SOURCETYPE,'source':'workflow_summary','host':host,'time':epoch_time}
87+
event=json.dumps(event)
88+
89+
x=requests.post(SPLUNK_HEC_URL, data=event, headers=headers)
90+
91+
92+
url = "{url}/repos/{repo}/actions/runs/{run_id}/logs".format(url=GITHUB_API_URL,repo=GITHUB_REPOSITORY,run_id=GITHUB_WORKFLOWID)
93+
print(url)
94+
95+
# try:
96+
# x = requests.get(url, stream=True, auth=('token',GITHUB_TOKEN))
97+
98+
# except requests.exceptions.HTTPError as errh:
99+
# output = "GITHUB API Http Error:" + str(errh)
100+
# print(f"Error: {output}")
101+
# print(f"::set-output name=result::{output}")
102+
# return
103+
# except requests.exceptions.ConnectionError as errc:
104+
# output = "GITHUB API Error Connecting:" + str(errc)
105+
# print(f"Error: {output}")
106+
# print(f"::set-output name=result::{output}")
107+
# return
108+
# except requests.exceptions.Timeout as errt:
109+
# output = "Timeout Error:" + str(errt)
110+
# print(f"Error: {output}")
111+
# print(f"::set-output name=result::{output}")
112+
# return
113+
# except requests.exceptions.RequestException as err:
114+
# output = "GITHUB API Non catched error conecting:" + str(err)
115+
# print(f"Error: {output}")
116+
# print(f"::set-output name=result::{output}")
117+
# return
118+
119+
# z = zipfile.ZipFile(io.BytesIO(x.content))
120+
# z.extractall('/app')
121+
122+
# timestamp = batch = count = 0
123+
124+
# for name in glob.glob('/app/*.txt'):
125+
# logfile = open(os.path.join(os.path.dirname(os.path.abspath(__file__)), name.replace('./','')),'r')
126+
# Lines = logfile.readlines()
127+
# for line in Lines:
128+
129+
# if line:
130+
# count+=1
131+
# if timestamp:
132+
# t2=timestamp
133+
# timestamp = re.search("\d{4}-\d{2}-\d{2}T\d+:\d+:\d+.\d+Z",line.strip())
134+
135+
# if timestamp:
136+
# timestamp = re.sub("\dZ","",timestamp.group())
137+
# timestamp = datetime.strptime(timestamp,"%Y-%m-%dT%H:%M:%S.%f")
138+
# timestamp = (timestamp - datetime(1970,1,1)).total_seconds()
139+
# else:
140+
# timestamp=t2
141+
142+
# x = re.sub("\d{4}-\d{2}-\d{2}T\d+:\d+:\d+.\d+Z","",line.strip())
143+
# x=x.strip()
144+
# job_name=re.search("\/\d+\_(?P<job>.*)\.txt",name)
145+
# job_name=job_name.group('job')
146+
# fields = {'lineNumber':count,'workflowID':GITHUB_WORKFLOWID,'job':job_name}
147+
# if x:
148+
# batch+=1
149+
# event={'event':x,'sourcetype':SPLUNK_SOURCETYPE,'source':SPLUNK_SOURCE,'host':host,'time':timestamp,'fields':fields}
150+
# eventBatch=eventBatch+json.dumps(event)
151+
# else:
152+
# print("skipped line "+str(count))
153+
154+
# if batch>=1000:
155+
# batch=0
156+
# x=requests.post(SPLUNK_HEC_URL, data=eventBatch, headers=headers)
157+
# eventBatch=""
158+
159+
# x=requests.post(SPLUNK_HEC_URL, data=eventBatch, headers=headers)
160+
161+
if __name__ == '__main__':
162+
main()
Lines changed: 43 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,43 @@
1+
name: Send Workflow Logs to Splunk
2+
3+
# Controls when the action will run.
4+
on:
5+
workflow_dispatch:
6+
workflow_run:
7+
workflows: ["*"]
8+
types:
9+
- completed
10+
11+
env:
12+
triggerID: ${{ github.event.workflow_run.id }}
13+
triggerJob: ${{ github.event.workflow_run.name }}
14+
15+
jobs:
16+
WriteLogs:
17+
runs-on: ubuntu-latest
18+
# if: ${{ github.event.workflow_run.name!='WriteLogs'}}
19+
20+
steps:
21+
- name: Debug Workflow Information
22+
run: |
23+
echo "Trigger ID: ${{ env.triggerID }}"
24+
echo "Trigger Job: ${{ env.triggerJob }}"
25+
echo "Event type: ${{ github.event_name }}"
26+
echo "Workflow ID that triggered this: ${{ github.event.workflow_run.id }}"
27+
echo "Workflow Name that triggered this: ${{ github.event.workflow_run.name }}"
28+
echo "Workflow file: ${{ github.event.workflow_run.path }}"
29+
30+
- uses: actions/checkout@v2
31+
32+
- name: Output Job ID
33+
run: echo ${{ github.event.workflow_run.id }}
34+
35+
- name: Send Workflow logs to Splunk
36+
if: ${{ always() }}
37+
uses: ./.github/actions/log_to_splunk
38+
with:
39+
splunk_url: ${{ secrets.HEC_URL }}
40+
hec_token: ${{ secrets.HEC_TOKEN }}
41+
github_token: ${{ secrets.GITHUB_TOKEN }}
42+
workflow_id: ${{ env.triggerID }}
43+
source: ${{ env.triggerJob }}

0 commit comments

Comments
 (0)