normalize

package
v0.2.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 27, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package normalize turns a decoded kernel event (the sensor's raw, pre-identity output) into the canonical telemetry.TelemetryEnvelope the whole data plane consumes (A1, #622). It is PURE and DETERMINISTIC: the same DecodedEvent always yields the same envelope, including its derived entity ids and event id, so ingest is idempotent (A3) and golden fixtures are stable. It owns no I/O and no clock — the collector stamps ObservedAt and resolves the kernel OccurredAt before calling Normalize; ReceivedAt is stamped later at ingest via TelemetryEnvelope.StampReceived.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type DecodedEvent

type DecodedEvent struct {
	Class detection.Class

	AgentID        shared.ID
	AgentSessionID shared.ID
	AssetID        shared.ID
	BootID         shared.ID
	StreamID       shared.ID
	SensorID       string
	SensorVersion  string
	Sequence       uint64

	// OccurredAt is the KERNEL source time of the event; zero when the sensor could not read a kernel
	// timestamp (the normalizer then falls back to ObservedAt and records the quality flag).
	OccurredAt time.Time
	// ObservedAt is when the collector decoded the event (userspace); it is required.
	ObservedAt time.Time

	Resource telemetry.ResourceContext
	Coverage telemetry.CoverageFlags

	Process   *DecodedProcess
	Network   *DecodedNetwork
	File      *DecodedFile
	Privilege *DecodedPrivilege
}

DecodedEvent is the sensor decode output the normalizer consumes: the raw per-class fields plus the identity, sequencing, timestamps, and placement the sensor already knows. Exactly one payload pointer is set — the one matching Class. The eBPF decode side (internal/infrastructure/ebpf) builds this from a kernel record; the normalizer never touches the kernel or the wire.

type DecodedFile

type DecodedFile struct {
	Op                 string // "open" | "write" | "rename"
	Path               string
	Device             uint64
	Inode              uint64
	ContentHash        string
	PathTruncated      bool
	PID                int
	ProcStartTimeNanos uint64
	Comm               string
}

DecodedFile carries the raw file fields plus device+inode for a stable target id.

type DecodedNetwork

type DecodedNetwork struct {
	Kind               string // "connect" | "sendmsg"
	Proto              string
	Direction          string
	LocalAddr          string
	LocalPort          int
	RemoteAddr         string
	RemotePort         int
	PID                int
	ProcStartTimeNanos uint64
	Comm               string
}

DecodedNetwork carries the raw flow fields. ProcStartTimeNanos (resolved by the sensor's process table) lets the normalizer link the flow to a stable ProcessEntityID; 0 leaves the link empty (honest).

type DecodedPrivilege

type DecodedPrivilege struct {
	Kind               string // "setuid" | "setresuid" | "capset"
	PID                int
	ProcStartTimeNanos uint64
	Comm               string
	FromUID            int
	ToUID              int
	Cap                string
}

DecodedPrivilege carries the raw privilege-change fields.

type DecodedProcess

type DecodedProcess struct {
	Kind                 string // "exec" | "fork"
	PID                  int
	PPID                 int
	StartTimeNanos       uint64 // this process's kernel start time; 0 => unknown
	ParentStartTimeNanos uint64 // the parent's kernel start time; 0 => unknown
	Comm                 string
	Path                 string
	Args                 []string
	ArgsTruncated        bool
	PathTruncated        bool
	UID                  int
}

DecodedProcess carries the raw process fields including the parent pid and the kernel start times the normalizer needs to derive stable entity ids (the fields D4 was missing).

type Normalizer

type Normalizer struct{}

Normalizer maps DecodedEvent → telemetry.TelemetryEnvelope. It is stateless; a zero value is ready to use. It is a type (not just a function) so a future caller can inject it behind an interface without a signature change.

func (Normalizer) Normalize

Normalize produces the canonical envelope for one decoded event, deriving stable entity ids, resolving the source timestamp, recording coverage/quality honesty, and validating the result. It returns a wrapped shared.ErrValidation for any malformed input so the caller maps it to a 4xx at the edge.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL