Repository navigation
Add CEF and LEEF parsers (SIEM event formats) - #33
Conversation
Two parsers in ax-normalize for the ArcSight/QRadar SIEM wire formats, each one row per event. The category fields (signatureId/name for CEF, eventId for LEEF) and severity are what dist.chi2 reads as a signature/category mix shift, and a value never seen in the baseline surfaces as a new category automatically. CefParser: 7 pipe-delimited header fields with \| / \\ escaping, then a space-separated extension whose values may themselves contain spaces — a new key begins only at a space-preceded ident=, with \= / \\ / \n value escaping. Severity is type-inferred (numeric or named level); extension values inferred. LeefParser: 5 header fields; LEEF 2.0 adds an explicit delimiter field (a char or xHH hex), LEEF 1.0 uses a tab. Extension is plain key=value pairs. Both detected by their CEF: / LEEF: prefix (STRONG); claim .cef / .leef. A line missing the prefix or with too few header fields is a clean Parse error. Mutation gate: 0 surviving mutants on the new file. The CEF extension scan's i = j + 1 advance has one documented-equivalent variant (+ -> *, i = j skips the '=' next iteration → identical keys); the + -> - variant re-detects forever and is caught as a timeout. Closes #9 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 35 minutes and 9 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Implements the CEF / LEEF SIEM plugins — issue #9.
Two parsers for the ArcSight/QRadar wire formats (one row per event). The
category fields —
signatureId/name(CEF),eventId(LEEF) — andseverityare exactly what
dist.chi2reads as a signature/category mix shift, and avalue never seen in the baseline surfaces as a new category automatically.
CefParserCEF:Version|Vendor|Product|Version|SignatureID|Name|Severity|ext. 7pipe-delimited header fields with
\|/\\escaping, then a space-separatedextension whose values may contain spaces — a new key begins only at a
space-preceded
ident=, with\=/\\/\nvalue escaping.severityistype-inferred (numeric, or a named level); extension values inferred. Extension
absent (7-field) and escaped pipes handled. Extension
.cef.LeefParserLEEF:Version|Vendor|Product|Version|EventID|[Delimiter|]ext. 5 header fields;LEEF 2.0 adds an explicit delimiter field (a char or
xHHhex), LEEF 1.0 uses atab. Extension is plain
key=value. Extension.leef.Routing & errors
Detected by the
CEF:/LEEF:prefix (STRONG). A line missing the prefix orwith too few header fields is a clean
AxError::Parse.Gates
fmt/clippy -D warnings/ full workspace tests green (both feature sets).cef.rs(73 caught, 4 unviable, 4loop-bound timeouts). The CEF extension-scan
i = j + 1advance has onedocumented-equivalent variant (
+→*setsi = j, which skips the=next iteration → identical keys); the
+→-variant re-detects a 1-char keyforever and is caught as a timeout (
a=1 b=2test).signatureIdmix shift isflagged by
dist.chi2 --baseline(exit 1).Closes #9
🤖 Generated with Claude Code