ScienceLogic Policy/Rule API
Rules are the individual parts of a device policy. ## Regular Expressions A regular expression specifies a set of strings as a pattern, rather than a list. For example, the pattern `C(o|as?)t` matches the strings Cot, Cat, and Cast, but not Coast. Skylar Compliance uses Perl-flavour Regular Expressions. Most characters can be used in a regular expression; however, some characters, called metacharacters, have special meanings: * `()` denote grouping: `(a|b)b` matches `ab` and `bb` * `|` denotes an alternative (see above) * `^` matches the beginning of a line * `$` matches the end of a line * `.` matches any character * `+` denotes one or more occurrences of the previous character: `a+b` matches `ab`, `aab`, `abb`, but not `b` * `*` denotes zero or more occurrences of the previous character: `a*b` matches `b`, `ab`, `aab`, `aaab` * `?` denotes zero or one occurrences of the previous character: `a?b` matches `b` and `ab`, but not `aab` or `aaab` Character classes are matches for sets of possible characters, rather than just a single character. For instance: * `[bcr]at` matches `bat`, `cat` and `rat` * `-` can be used as a range operator in a character class, so `[a-g]` matches any character from `a` to `g` There are some useful abbreviations for common character classes, in particular: * `\d` matches a digit * `\s` matches whitespace (a space or a tab) * `\w` matches a word character (alphanumeric or a _) For instance, `\d\d:\d\d:\d\d` would match a time in a hh:mm:ss format. For more information and examples of regular expressions, please see [this reference guide](http://www.regularexpressions.info/reference.html). ## Lua Functions Rules can be defined as Lua functions. Available functions for compliance rules are: * `nextline()` returns the next line of text * `getline(n)` returns the given line of text * `numlines()` returns the number of lines * `addmessage(m)` allows you to replace a series of variables in the remediation text. For instance, `addmessage("Hello")` with a remediation text of `$1` "World!" would produce the output `Hello World!`. The next `addmessage` call would replace `$2`, and so on. ### Example This function checks that the number of lines containing "configure" matches the lines containing "port": ```lua num1 = 0 num2 = 0 line, next = nextline() while next do if line:match("configure") then num1 = num1+1 end if line:match("port") then num2 = num2+1 end line, next = nextline end if num1 > num2 then addmessage("more") else if num2 < num1 then addmessage("less") end return num1 == num2 ``` Remediation Text: `Config contains $1 configures than ports.` ## Remediation Remediation is an action to be performed when a compliance rule is not met, generally intended to rectify the violation. The following remediation types can be configured: * `Manual`: in this case, the remediation text will simply be appended to the notification email, signifying that the recipient should take the appropriate action. * `Command`: this will execute one of the stored Actions on the device (see Controlling a device). * `Automatic`: this setting will treat the text specified in the textbox as a command and execute it on the device. If the rule match type is **Regex**, the remediation can make use of the **Capture** feature, whereby parts of the pattern in brackets can be captured and then referred to in the remediation text (as `$1`, `$2`, etc.). For example, a rule may state that a configuration must not contain the regex: ``` set telnet (\d+\.\d+\.\d+\.\d+) ``` where the part in brackets is a match for an IP address. If this rule is violated, the configuration can be remedied using the phrase: ``` unset telnet $1 ``` In this case, the brackets in the rule will capture the IP address, and fill it in when the command is performed, expanding to ``` unset telnet 1.2.3.4 ``` if that was the matched IP address.