Add nftables table (#23941)

Following the discussion in #15651, this adds the `nftables` table by parsing the binary output.

---------

Co-authored-by: Zach Wasserman <zach@fleetdm.com>
This commit is contained in:
Andrea Scarpino
2024-12-04 10:10:09 -07:00
committed by GitHub
co-authored by Zach Wasserman
parent ca54b2264e
commit 0028e2ce3f
2 changed files with 3 additions and 0 deletions
+1
View File
@@ -0,0 +1 @@
- Add `nftables` table to show configuration for Linux `nftables` network filters.
+2
View File
@@ -6,6 +6,7 @@ import (
"github.com/fleetdm/fleet/v4/orbit/pkg/table/crowdstrike/falcon_kernel_check"
"github.com/fleetdm/fleet/v4/orbit/pkg/table/crowdstrike/falconctl"
"github.com/fleetdm/fleet/v4/orbit/pkg/table/cryptsetup"
"github.com/fleetdm/fleet/v4/orbit/pkg/table/dataflattentable"
"github.com/rs/zerolog/log"
"github.com/osquery/osquery-go"
@@ -16,5 +17,6 @@ func PlatformTables(_ PluginOpts) ([]osquery.OsqueryPlugin, error) {
cryptsetup.TablePlugin(log.Logger), // table name is "cryptsetup_status"
falconctl.NewFalconctlOptionTable(log.Logger), // table name is "falconctl_option"
falcon_kernel_check.TablePlugin(log.Logger), // table name is "falcon_kernel_check"
dataflattentable.TablePluginExec(log.Logger, "nftables", dataflattentable.JsonType, []string{"nft", "-jat", "list", "ruleset"}, dataflattentable.WithBinDirs("/usr/bin", "/usr/sbin")), // -j (json) -a (show object handles) -t (terse, omit set contents)
}, nil
}