models

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Feb 28, 2026 License: MIT Imports: 1 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type Event

type Event struct {
	ID        string    `json:"id"`
	Type      EventType `json:"type"`
	Severity  Severity  `json:"severity"`
	Hostname  string    `json:"hostname"`
	Timestamp time.Time `json:"timestamp"`
	Message   string    `json:"message"`
	Details   string    `json:"details"`   // Extended info
	Suggested string    `json:"suggested"` // Suggested fix action
	Source    string    `json:"source"`    // Which watcher generated this

	// Optional typed payloads
	Port     *PortInfo      `json:"port,omitempty"`
	Firewall *FirewallState `json:"firewall,omitempty"`
	Health   *SystemHealth  `json:"health,omitempty"`
}

Event is the core event structure that flows through the system

type EventType

type EventType string

EventType categorises what happened

const (
	EventPortOpened        EventType = "port.opened"
	EventPortClosed        EventType = "port.closed"
	EventFirewallChanged   EventType = "firewall.changed"
	EventFirewallOK        EventType = "firewall.ok"
	EventSSHBruteForce     EventType = "ssh.bruteforce"
	EventDiskHigh          EventType = "system.disk_high"
	EventMemoryHigh        EventType = "system.memory_high"
	EventTempHigh          EventType = "system.temp_high"
	EventReboot            EventType = "system.reboot"
	EventContainerDied     EventType = "docker.container_died"
	EventContainerStart    EventType = "docker.container_start"
	EventContainerHealth   EventType = "docker.container_unhealthy"
	EventContainerStopped  EventType = "docker.container_stopped"
	EventFileChanged       EventType = "file.changed"
	EventDailySummary      EventType = "summary.daily"
	EventMalwareFound      EventType = "malware.found"       // ClamAV FOUND line
	EventRootkitWarning    EventType = "rootkit.warning"     // rkhunter Warning: line
	EventNetworkNewDevice  EventType = "network.new_device"  // Unknown device appeared on LAN
	EventNetworkDeviceLeft EventType = "network.device_left" // Known device disappeared from LAN
)

type FirewallState

type FirewallState struct {
	Chain       string `json:"chain"`
	Table       string `json:"table"`
	Policy      string `json:"policy"`
	RuleHash    string `json:"rule_hash"`
	HasDropRule bool   `json:"has_drop_rule"`
}

FirewallState captures iptables chain state

type PortInfo

type PortInfo struct {
	Address       string `json:"address"`  // e.g. "0.0.0.0:8080"
	Protocol      string `json:"protocol"` // "tcp" or "udp"
	PID           int    `json:"pid"`
	ProcessName   string `json:"process_name"`   // e.g. "docker-proxy"
	ContainerName string `json:"container_name"` // e.g. "nginx" (empty if not Docker)
	ContainerID   string `json:"container_id"`
	IsExposed     bool   `json:"is_exposed"` // true if bound to 0.0.0.0 or ::
}

PortInfo describes a listening port with full context

func (PortInfo) RiskLevel

func (p PortInfo) RiskLevel() Severity

type Severity

type Severity int

Severity levels for events

const (
	SeverityInfo Severity = iota
	SeverityWarning
	SeverityCritical
)

func (Severity) Emoji

func (s Severity) Emoji() string

func (Severity) String

func (s Severity) String() string

type SystemHealth

type SystemHealth struct {
	DiskUsagePercent  int     `json:"disk_usage_percent"`
	MemoryUsedPercent int     `json:"memory_used_percent"`
	CPUTempCelsius    float64 `json:"cpu_temp_celsius"`
	UptimeSeconds     int64   `json:"uptime_seconds"`
	ContainersRunning int     `json:"containers_running"`
	ContainersHealthy int     `json:"containers_healthy"`
	ListeningPorts    int     `json:"listening_ports"`
}

SystemHealth holds system metrics

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL