1
.TH "AUPARSE_FEED" "3" "May 2007" "Red Hat" "Linux Audit API"
3
auparse_feed \- feed data into parser
5
.B #include <auparse.h>
8
int auparse_feed(auparse_state_t *au, const char *data, size_t data_len);
16
a buffer of data to feed into the parser, it is
18
bytes long. The data is copied in the parser, upon return the caller may free or reuse the data buffer.
27
supplies new data for the parser to consume.
29
must have been called with a source type of AUSOURCE_FEED and a NULL pointer.
32
The parser consumes as much data
33
as it can invoking a user supplied callback specified with
34
.I auparse_add_callback
35
with a cb_event_type of
36
.I AUPARSE_CB_EVENT_READY
37
each time the parser recognizes a complete event in the data stream. Data not fully parsed will persist and be
38
prepended to the next feed data. After all data has been feed to the parser
40
should be called to signal the end of input data and flush any pending parse data through the parsing system.
45
auparse_callback(auparse_state_t *au, auparse_cb_event_t cb_event_type,
48
int *event_cnt = (int *)user_data;
50
if (cb_event_type == AUPARSE_CB_EVENT_READY) {
51
if (auparse_first_record(au) <= 0) return;
52
printf("event: %d\\n", *event_cnt);
53
printf("records:%d\\n", auparse_get_num_records(au));
55
printf("fields:%d\\n", auparse_get_num_fields(au));
56
printf("type=%d ", auparse_get_type(au));
57
const au_event_t *e = auparse_get_timestamp(au);
58
if (e == NULL) return;
59
printf("event time: %u.%u:%lu\\n",
60
(unsigned)e->sec, e->milli, e->serial);
61
auparse_first_field(au);
63
printf("%s=%s (%s)\\n", auparse_get_field_name(au),
64
auparse_get_field_str(au),
65
auparse_interpret_field(au));
66
} while (auparse_next_field(au) > 0);
69
} while(auparse_next_record(au) > 0);
74
main(int argc, char **argv)
76
char *filename = argv[1];
80
int *event_cnt = malloc(sizeof(int));
82
au = auparse_init(AUSOURCE_FEED, 0);
85
auparse_add_callback(au, auparse_callback, event_cnt, free);
87
if ((fp = fopen(filename, "r")) == NULL) {
88
fprintf(stderr, "could not open '%s', %s\n", filename, strerror(errno));
92
while ((len = fread(buf, 1, sizeof(buf), fp))) {
93
auparse_feed(au, buf, len);
95
auparse_flush_feed(au);
101
Returns -1 if an error occurs; otherwise, 0 for success.
105
.BR auparse_add_callback (3),
106
.BR auparse_flush_feed (3)