Files
securityonion/salt/telegraf/scripts/zeekcaptureloss.sh
2020-10-06 18:10:41 -04:00

8 lines
383 B
Bash

#!/bin/bash
{% set WORKERS = salt['pillar.get']('sensor:zeek_lbprocs', salt['pillar.get']('sensor:zeek_pins') | length) %}
ZEEKLOG=/host/nsm/zeek/logs/current/capture_loss.log
if [ -f "$ZEEKLOG" ]; then
LOSS=$(tail -{{WORKERS}} $ZEEKLOG | awk -F, '{print $NF}' | sed 's/}//' | awk -F: '{LOSS += $2 / {{WORKERS}}} END { print "loss: " LOSS}')
echo "zeekcaptureloss loss=$LOSS"
fi