Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Document device.listen_addr and Handling Twisted Web Logs #349

Merged
merged 1 commit into from
Mar 24, 2024

Conversation

nbuuckssi
Copy link
Contributor

Proposed changes

This PR documents what I learned about Twisted HTTP logs that continued to appear in my host's syslog despite removing the default Syslog and Console handler's from my OpenCanary installation's configuration. This duplication of HTTP logs was undesirable because another security tool was capturing both the syslog and the JSON logged by my OpenCanary configuration to a rotating file in /var/log.

This PR also documents the seemingly-undocumented device.listen_addr configuration option added in #337.

Types of changes

What types of changes does your code introduce to this repository?
Put an x in the boxes that apply

  • Bugfix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation Update

Checklist

Put an x in the boxes that apply. You can also fill these out after creating the PR. If you're unsure about any of them, don't hesitate to ask. We're here to help! This is simply a reminder of what we are going to look for before merging your code.

  • Lint and unit tests pass locally with my changes (if applicable)
  • I have run pre-commit (pre-commit in the repo)
  • I have added tests that prove my fix is effective or that my feature works
  • I have added necessary documentation (if appropriate)
  • Linked to the relevant github issue or github discussion

Adds docs about handling Twisted syslog output and the undocumented `device.listen_addr` configuration option.
@nbuuckssi
Copy link
Contributor Author

I suppose it's worth considering whether device.listen_addr should just be added to the default configuration file in lieu of adding the table presently in this PR. The table has the advantage of being able to explain the caveat that it only applies to certain modules.

Copy link
Contributor

@thinkst-francois thinkst-francois left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the update.

@thinkst-francois thinkst-francois merged commit dfa8c55 into thinkst:master Mar 24, 2024
nbuuckssi added a commit to nbuuckssi/opencanary that referenced this pull request Mar 24, 2024
thinkst-francois pushed a commit that referenced this pull request Mar 26, 2024
* Update configuration.rst

Adds docs about handling Twisted syslog output and the undocumented `device.listen_addr` configuration option.

* Fix whitespace from #349
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants