suricata
suricata-plugin.h
Go to the documentation of this file.
1 /* Copyright (C) 2020-2021 Open Information Security Foundation
2  *
3  * You can copy, redistribute or modify this Program under the terms of
4  * the GNU General Public License version 2 as published by the Free
5  * Software Foundation.
6  *
7  * This program is distributed in the hope that it will be useful,
8  * but WITHOUT ANY WARRANTY; without even the implied warranty of
9  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
10  * GNU General Public License for more details.
11  *
12  * You should have received a copy of the GNU General Public License
13  * version 2 along with this program; if not, write to the Free Software
14  * Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
15  * 02110-1301, USA.
16  */
17 
18 #ifndef __SURICATA_PLUGIN_H__
19 #define __SURICATA_PLUGIN_H__
20 
21 #include <stdint.h>
22 #include <stdbool.h>
23 
24 #include "conf.h"
25 
26 /**
27  * The size of the data chunk inside each packet structure a plugin
28  * has for private data (Packet->plugin_v).
29  */
30 #define PLUGIN_VAR_SIZE 64
31 
32 /**
33  * Structure to define a Suricata plugin.
34  */
35 typedef struct SCPlugin_ {
36  const char *name;
37  const char *license;
38  const char *author;
39  void (*Init)(void);
41 
42 typedef SCPlugin *(*SCPluginRegisterFunc)(void);
43 
44 /**
45  * Structure used to define an Eve output file type plugin.
46  */
47 typedef struct SCEveFileType_ {
48  /* The name of the output, used to specify the output in the filetype section
49  * of the eve-log configuration. */
50  const char *name;
51  /* Init Called on first access */
52  int (*Init)(ConfNode *conf, bool threaded, void **init_data);
53  /* Write - Called on each write to the object */
54  int (*Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data);
55  /* Close - Called on final close */
56  void (*Deinit)(void *init_data);
57  /* ThreadInit - Called for each thread using file object*/
58  int (*ThreadInit)(void *init_data, int thread_id, void **thread_data);
59  /* ThreadDeinit - Called for each thread using file object */
60  int (*ThreadDeinit)(void *init_data, void *thread_data);
63 
66 
67 typedef struct SCCapturePlugin_ {
68  char *name;
69  void (*Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot);
70  int (*ThreadInit)(void *ctx, int thread_id, void **thread_ctx);
71  int (*ThreadDeinit)(void *ctx, void *thread_ctx);
72  const char *(*GetDefaultMode)(void);
75 
77 
78 #endif /* __SURICATA_PLUGIN_H */
SCEveFileType_::Write
int(* Write)(const char *buffer, int buffer_len, void *init_data, void *thread_data)
Definition: suricata-plugin.h:54
SCPluginRegisterCapture
int SCPluginRegisterCapture(SCCapturePlugin *)
SCEveFileType_::name
const char * name
Definition: suricata-plugin.h:50
SCEveFileType
struct SCEveFileType_ SCEveFileType
SCCapturePlugin_::Init
void(* Init)(const char *args, int plugin_slot, int receive_slot, int decode_slot)
Definition: suricata-plugin.h:69
SCEveFileType_::Init
int(* Init)(ConfNode *conf, bool threaded, void **init_data)
Definition: suricata-plugin.h:52
SCCapturePlugin_::ThreadInit
int(* ThreadInit)(void *ctx, int thread_id, void **thread_ctx)
Definition: suricata-plugin.h:70
SCCapturePlugin_::name
char * name
Definition: suricata-plugin.h:68
SCRegisterEveFileType
bool SCRegisterEveFileType(SCEveFileType *)
SCCapturePlugin_
Definition: suricata-plugin.h:67
SCPlugin_::license
const char * license
Definition: suricata-plugin.h:37
SCCapturePlugin_::TAILQ_ENTRY
TAILQ_ENTRY(SCCapturePlugin_) entries
SCPlugin_::author
const char * author
Definition: suricata-plugin.h:38
SCPlugin_
Definition: suricata-plugin.h:35
conf.h
SCCapturePlugin
struct SCCapturePlugin_ SCCapturePlugin
SCPluginRegisterEveFileType
bool SCPluginRegisterEveFileType(SCEveFileType *)
SCPlugin_::Init
void(* Init)(void)
Definition: suricata-plugin.h:39
SCEveFileType_::Deinit
void(* Deinit)(void *init_data)
Definition: suricata-plugin.h:56
SCEveFileType_::TAILQ_ENTRY
TAILQ_ENTRY(SCEveFileType_) entries
SCEveFileType_::ThreadDeinit
int(* ThreadDeinit)(void *init_data, void *thread_data)
Definition: suricata-plugin.h:60
ConfNode_
Definition: conf.h:32
SCPlugin
struct SCPlugin_ SCPlugin
SCPlugin_::name
const char * name
Definition: suricata-plugin.h:36
SCEveFileType_::ThreadInit
int(* ThreadInit)(void *init_data, int thread_id, void **thread_data)
Definition: suricata-plugin.h:58
SCCapturePlugin_::ThreadDeinit
int(* ThreadDeinit)(void *ctx, void *thread_ctx)
Definition: suricata-plugin.h:71
SCEveFileType_
Definition: suricata-plugin.h:47