diff --git a/global/global.go b/global/global.go index 4b50940..61f494f 100644 --- a/global/global.go +++ b/global/global.go @@ -66,6 +66,7 @@ var ( GWAF_RELEASE_VERSION_NAME string = "20241028" // 发行版的版本号名称 GWAF_RELEASE_VERSION string = "v1.0.0" // 发行版的版本号 GWAF_LAST_UPDATE_TIME time.Time // 上次时间 + GWAF_LAST_TIME_UNIX int64 = 0 // 上次时间戳 GWAF_NOTICE_ENABLE bool = false // 是否开启通知 GWAF_CAN_EXPORT_DOWNLOAD_LOG bool = false //是否可以导出下载日志 GWAF_DLP dlpheader.EngineAPI // 脱敏引擎 diff --git a/model/response/waf_stat.go b/model/response/waf_stat.go index 7800a1b..05c5259 100644 --- a/model/response/waf_stat.go +++ b/model/response/waf_stat.go @@ -28,8 +28,8 @@ type WafCityStats struct { NormalCityOfRange map[string]int64 //区间正常城市数量 } type WafIPStats struct { - AttackIPOfRange []model.StatsIPCount //区间攻击IP数量 - NormalIPOfRange []model.StatsIPCount //区间正常IP数量 + AttackIPOfRange []model.StatsIPCountMore //区间攻击IP数量 + NormalIPOfRange []model.StatsIPCountMore //区间正常IP数量 } /* diff --git a/model/stats.go b/model/stats.go index b99331c..626485b 100644 --- a/model/stats.go +++ b/model/stats.go @@ -73,6 +73,16 @@ type StatsDayCount struct { 域名对应的数量[临时] */ type StatsIPCount struct { + IP string `json:"ip"` //ip + IPBelong string `json:"ip_belong"` //归属地 + Count int64 `json:"count"` //数量 +} + +/* +* +域名对应的数量丰富的标签内容 +*/ +type StatsIPCountMore struct { IP string `json:"ip"` //ip IPBelong string `json:"ip_belong"` //归属地 IPTag []IPTag `json:"ip_tags"` //IP标签 diff --git a/service/waf_service/waf_log.go b/service/waf_service/waf_log.go index e18eb1b..736de25 100644 --- a/service/waf_service/waf_log.go +++ b/service/waf_service/waf_log.go @@ -174,6 +174,14 @@ func (receiver *WafLogService) DeleteHistory(day string) { global.GWAF_LOCAL_LOG_DB.Where("create_time < ?", day).Delete(&innerbean.WebLog{}) } +// GetUnixTimeByCounter 依据开始时间和到期时间获取一个最新的时间戳 +func (receiver *WafLogService) GetUnixTimeByCounter(lastStartCreateUnix int64, lastEndCreateUnix int64) innerbean.WebLog { + var weblog innerbean.WebLog + global.GWAF_LOCAL_LOG_DB.Where("unix_add_time>=? and unix_add_time ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host", - 1, currenyDayMillisecondsBak, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultHosts) + global.GWAF_LOCAL_LOG_DB.Raw("SELECT host_code, user_code,tenant_id ,action,count(req_uuid) as count,day,host FROM \"web_logs\" where task_flag = ? and unix_add_time >= ? and unix_add_time < ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host", + 1, statTimeUnix, endTimeUnix, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultHosts) /**** 1.如果不存在则创建 2.如果存在则累加这个周期的统计数 @@ -123,7 +139,7 @@ func TaskCounter() { } else { statDayMap := map[string]interface{}{ "Count": value.Count + statDay.Count, - "UPDATE_TIME": customtype.JsonTime(currenyDayBak), + "UPDATE_TIME": customtype.JsonTime(time.Now()), } updateBean := innerbean.UpdateModel{ Model: model.StatsDay{}, @@ -139,8 +155,8 @@ func TaskCounter() { //二、 IP聚合统计 { var resultIP []CountIPResult - global.GWAF_LOCAL_LOG_DB.Raw("SELECT host_code, user_code,tenant_id ,action,count(req_uuid) as count,day,host,src_ip as ip FROM \"web_logs\" where task_flag = ? and unix_add_time > ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host,ip", - 1, currenyDayMillisecondsBak, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultIP) + global.GWAF_LOCAL_LOG_DB.Raw("SELECT host_code, user_code,tenant_id ,action,count(req_uuid) as count,day,host,src_ip as ip FROM \"web_logs\" where task_flag = ? and unix_add_time >= ? and unix_add_time < ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host,ip", + 1, statTimeUnix, endTimeUnix, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultIP) /**** 1.如果不存在则创建 2.如果存在则累加这个周期的统计数 @@ -170,7 +186,7 @@ func TaskCounter() { } else { statDayMap := map[string]interface{}{ "Count": value.Count + statDay.Count, - "UPDATE_TIME": customtype.JsonTime(currenyDayBak), + "UPDATE_TIME": customtype.JsonTime(time.Now()), } updateBean := innerbean.UpdateModel{ @@ -188,8 +204,8 @@ func TaskCounter() { //三、 城市信息聚合统计 { var resultCitys []CountCityResult - global.GWAF_LOCAL_LOG_DB.Raw("SELECT host_code, user_code,tenant_id ,action,count(req_uuid) as count,day,host,country,province,city FROM \"web_logs\" where task_flag = ? and unix_add_time > ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host,country,province,city", - 1, currenyDayMillisecondsBak, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultCitys) + global.GWAF_LOCAL_LOG_DB.Raw("SELECT host_code, user_code,tenant_id ,action,count(req_uuid) as count,day,host,country,province,city FROM \"web_logs\" where task_flag = ? and unix_add_time >= ? and unix_add_time < ? and tenant_id = ? and user_code =? GROUP BY host_code, user_code,action,tenant_id,day,host,country,province,city", + 1, statTimeUnix, endTimeUnix, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultCitys) /**** 1.如果不存在则创建 2.如果存在则累加这个周期的统计数 @@ -221,7 +237,7 @@ func TaskCounter() { } else { statDayMap := map[string]interface{}{ "Count": value.Count + statDay.Count, - "UPDATE_TIME": customtype.JsonTime(currenyDayBak), + "UPDATE_TIME": customtype.JsonTime(time.Now()), } updateBean := innerbean.UpdateModel{ @@ -239,8 +255,8 @@ func TaskCounter() { //第四 给IP打标签 开始 { var resultIPRule []CountIPRuleResult - global.GWAF_LOCAL_LOG_DB.Raw("SELECT src_ip as ip ,rule,count(src_ip) as cnt FROM \"web_logs\" where task_flag = ? and unix_add_time > ? and tenant_id = ? and user_code =? GROUP BY user_code,tenant_id, rule,src_ip", - 1, currenyDayMillisecondsBak, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultIPRule) + global.GWAF_LOCAL_LOG_DB.Raw("SELECT src_ip as ip ,rule,count(src_ip) as cnt FROM \"web_logs\" where task_flag = ? and unix_add_time >= ? and unix_add_time < ? and tenant_id = ? and user_code =? GROUP BY user_code,tenant_id, rule,src_ip", + 1, statTimeUnix, endTimeUnix, global.GWAF_TENANT_ID, global.GWAF_USER_CODE).Scan(&resultIPRule) /**** 1.如果不存在则创建 2.如果存在则累加这个IP这个rule的统计数 @@ -270,7 +286,7 @@ func TaskCounter() { } else { ipTagUpdateMap := map[string]interface{}{ "Cnt": value.Cnt + ipTag.Cnt, - "UPDATE_TIME": customtype.JsonTime(currenyDayBak), + "UPDATE_TIME": customtype.JsonTime(time.Now()), } updateBean := innerbean.UpdateModel{ Model: model.IPTag{}, @@ -283,6 +299,5 @@ func TaskCounter() { } } //给IP打标签结束 - global.GWAF_LAST_UPDATE_TIME = currenyDayBak global.GWAF_SWITCH_TASK_COUNTER = false }