From 38a51df38047d3dfa6874f8f3a8f3dfda4e10b06 Mon Sep 17 00:00:00 2001 From: Arne Teuke Date: Sun, 8 Jun 2025 15:33:03 +0200 Subject: [PATCH] add shell script for cronjob --- manifests/main/config.pp | 8 ++++---- manifests/main/files.pp | 13 +++++++++++++ manifests/params.pp | 17 ++++++++++++++++- templates/scan.sh.erb | 23 +++++++++++++++++++++++ 4 files changed, 56 insertions(+), 5 deletions(-) create mode 100644 templates/scan.sh.erb diff --git a/manifests/main/config.pp b/manifests/main/config.pp index 5127292..716e252 100644 --- a/manifests/main/config.pp +++ b/manifests/main/config.pp @@ -18,9 +18,9 @@ class clamav_cd::main::config ( # create a cron job to run a daily scan cron { 'clamscan': - command => '/bin/clamscan -r / >> /var/log/clamav/daily-scan.log', - user => 'root', - hour => 2, - minute => 0, + command => $cv_shell_script, + user => $cv_cron_user, + hour => $cv_cron_hour, + minute => $cv_cron_minute, } } diff --git a/manifests/main/files.pp b/manifests/main/files.pp index 0f288b3..bc1b405 100644 --- a/manifests/main/files.pp +++ b/manifests/main/files.pp @@ -47,4 +47,17 @@ class clamav_cd::main::files ( seluser => system_u, content => template($cv_freshclam_svc_erb), } + + # shell script for scanning and alerting + file { $cv_shell_script : + ensure => file, + owner => 'root', + group => 'root', + mode => '0750', + selrange => s0, + selrole => object_r, + seltype => etc_t, + seluser => system_u, + content => template($cv_shell_script_erb), + } } diff --git a/manifests/params.pp b/manifests/params.pp index 8acd7b1..96c8342 100644 --- a/manifests/params.pp +++ b/manifests/params.pp @@ -27,11 +27,17 @@ # prelude-admin. # @param [String] cv_tcpsocket socket port # @param [String] cv_tcpaddress ip address to listen on +# @param [String] cv_alert_email email address to send alerts +# @param [String] cv_cron_hour which hour the scan should start +# @param [String] cv_cron_minute which minute the scan should start +# @param [String] cv_cron_user which user should run the cron job +# @param [String] cv_scan_dir which directory should be scanned +# @param [String] cv_alert_file location and name of the alert file ############################################################################## class clamav_cd::params ( # installation - Array $reqpackages = ['clamav','clamd'], + Array $reqpackages = ['clamav','clamd','s-nail'], String $pkg_ensure = 'present', # clamd @@ -48,6 +54,13 @@ class clamav_cd::params ( String $cv_preludeanalyzername = 'ClamAV', String $cv_tcpsocket = '3310', String $cv_tcpaddress = 'localhost', + String $cv_alert_email = 'you@example.com', + String $cv_cron_hour = '2', + String $cv_cron_minute = '0', + String $cv_cron_user = 'root', + String $cv_scan_dir = '/', + String $cv_alert_file = 'tmp/clamav-alert.txt', + ) { # service @@ -64,6 +77,8 @@ class clamav_cd::params ( $cv_freshclam_erb = 'clamav_cd/freshclam_conf.erb' $cv_freshclam_svc = '/usr/lib/systemd/system/freshclam.service' $cv_freshclam_svc_erb = 'clamav_cd/freshclam_svc.erb' + $cv_shell_script = "${cv_config_d_dir}/scan.sh" + $cv_shell_script_erb = 'clamav_cd/scan.sh.erb' # includes must be last diff --git a/templates/scan.sh.erb b/templates/scan.sh.erb new file mode 100644 index 0000000..a6b951b --- /dev/null +++ b/templates/scan.sh.erb @@ -0,0 +1,23 @@ +#!/bin/bash + +# Set paths +SCAN_DIR="<%= @cv_scan_dir %>" +LOG_FILE="<%= @cv_logfile %>" +TMP_ALERT="<%= @cv_alert_file %>" +EMAIL="<%= @cv_alert_email %>" + +# Run clamscan +clamscan -r --infected --log="$LOG_FILE" "$SCAN_DIR" > /dev/null + +# Check if infections were found +if grep -q "Infected files: [^0]" "$LOG_FILE"; then + echo "ClamAV has found infected files on $(hostname)!" > "$TMP_ALERT" + echo "" >> "$TMP_ALERT" + grep "FOUND" "$LOG_FILE" >> "$TMP_ALERT" + + # Send the alert email + mail -s "⚠️ ClamAV Alert on $(hostname)" "$EMAIL" < "$TMP_ALERT" +fi + +# Clean up +rm -f "$TMP_ALERT"