Class SplunkAuditEventHandler

    • Constructor Detail

      • SplunkAuditEventHandler

        public SplunkAuditEventHandler​(SplunkAuditEventHandlerConfiguration configuration,
                                       EventTopicsMetaData eventTopicsMetaData,
                                       BatchPublisherFactory publisherFactory,
                                       Client client)
        Constructs a new Splunk audit event handler.
        Parameters:
        configuration - the Splunk audit event handler configuration
        eventTopicsMetaData - topic meta data
        publisherFactory - the batch publisher factory or null
        client - HTTP client or null
    • Method Detail

      • startup

        public void startup()
                     throws ResourceException
        Description copied from interface: AuditEventHandler
        Instruct this object that it is safe to initialize file handles and network connections.

        Reconfiguration of the AuditService and its handlers is achieved by replacing rather than modifying the existing objects. Therefore, it's essential that the replacements do not perform any I/O that would interfere with the operation of the objects they are replacing until the old objects are shutdown. For example, when shutting down an old instance of a file-based AuditEventHandler, the old instance may need to flush buffers, apply file rotation or retention policies, or even add line or block signatures as part of tamper evident logging. Any of these operations could be broken if two handler instances are operating on the same set of files simultaneously.

        Specified by:
        startup in interface AuditEventHandler
        Throws:
        ResourceException - if starting the AuditEventHandler fails
      • publishEvent

        public Promise<ResourceResponse,​ResourceException> publishEvent​(Context context,
                                                                              String topic,
                                                                              JsonValue event)
        Description copied from interface: AuditEventHandler
        Publishes an event to the provided topic.

        Note for implementors, it is imperative that the supplied event is not modified in any way as this may cause undesirable behaviour where multiple handlers are configured. If the event must be modified, then make a copy of it and work with that.

        Specified by:
        publishEvent in interface AuditEventHandler
        Parameters:
        context - The context chain that initiated the event.
        topic - The topic where to publish the event.
        event - The event to publish - which should be considered immutable.
        Returns:
        a promise with either a response or an exception
      • readEvent

        public Promise<ResourceResponse,​ResourceException> readEvent​(Context context,
                                                                           String topic,
                                                                           String resourceId)
        Description copied from interface: AuditEventHandler
        Reads an event with the provided resource id from the provided topic.
        Specified by:
        readEvent in interface AuditEventHandler
        Parameters:
        context - The context chain that initiated the event.
        topic - The topic where event is read.
        resourceId - The identifier of the event.
        Returns:
        a promise with either a response or an exception