mirror of
https://github.com/domainaware/parsedmarc.git
synced 2026-09-05 21:47:58 +00:00
* Make the output and mailbox integrations optional extras (#883) Breaking change for the next major release: pip install parsedmarc now installs the parsing core plus a working core CLI (file, IMAP, Maildir, and mbox input; CSV/JSON, Splunk HEC, webhook, and syslog output). Everything else moves behind an extra: elastic, opensearch, kafka, s3, gelf, loganalytics, msgraph, and gmail, joining the existing postgresql extra, with an umbrella [all] that deliberately excludes postgresql (psycopg's binary wheels do not exist on every platform, so parsedmarc[all] must never fail to install there). cli.py imports the six SDK-dependent output modules behind the #884 TYPE_CHECKING/try-except guard; a configured section whose extra is missing fails fast with a ConfigurationError naming the section and the exact pip install command — including the msgraph and gmail_api mailbox sections (detected via parsedmarc.mail's placeholder classes) and postgresql (checked before the constructor so the startup retry loop does not retry a missing dependency for a minute). The Azure/kiota Graph error types fall back to never-raised sentinel classes. The Docker image installs [all,postgresql], so container users see no change. CI lint installs [build,all,postgresql]; the unit-test job installs [build,all], deliberately without postgresql so test_postgres.py's absent-psycopg arm stays exercised. The never-imported dateparser dependency is dropped in favor of declaring python-dateutil, which utils.py actually imports; pytz moves to the build extra for the one test that uses it. Verified live: a no-extras wheel install imports, parses samples, and reports the install hint for each gated section; a [all] install restores every integration; the Docker image builds with every SDK importable. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Patch psycopg presence in the PostgreSQL CLI wiring tests CI's unit-test job deliberately installs [build,all] without the postgresql extra, so parsedmarc.cli.postgres.psycopg is None there and the new missing-extra presence check correctly made _main exit 1 before the wiring under test ran. The tests simulate the SDK being available (PostgreSQLClient is mocked at the SDK boundary), so the module-level psycopg handle is now patched present in setUp. Verified against a simulated psycopg-absent environment as well as the local full install. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Address Copilot review: narrow guards to ModuleNotFoundError, fix docs - The optional-integration and Graph error-type import guards now catch ModuleNotFoundError instead of ImportError, so only a genuinely absent package reads as a missing extra; a broken-but-present SDK fails loudly with its real error instead of masquerading as one. The test blocker raises ModuleNotFoundError accordingly — the exact exception a missing package produces. - _missing_extra_hint docstring no longer calls every gated integration an output module (it also serves the msgraph/gmail_api mailbox sections). - Fix the pre-existing passsword typo in usage.md's kafka section; the INI key the code reads is password (cli.py _parse_config). Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Quote extras specs in copy-paste install commands From Copilot's second review round: zsh treats an unquoted .[build,all] as a glob and fails with 'no matches found', so the commands shown in AGENTS.md, CONTRIBUTING.md, dashboards/README.md, and the bootstrap script's comment are now quoted. The CI workflows keep the unquoted form: they run under bash, which passes unmatched globs through literally. The suggestion to change the 'Choosing what to install' heading level was rejected — it is a subsection of 'Installing parsedmarc', matching the file's existing hierarchy. Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Fix upgrade command in the changelog * Documentation review: accuracy, spelling, grammar, and clarity pass A full prose review of docs/source, README, CONTRIBUTING, and the dashboards README, with every accuracy claim verified against the code before changing it. Highlights: - usage.md: documented six missing [general] options (the CSV/JSON filename options, prettify_json, normalize_timespan_threshold_hours), the required kafka smtp_tls_topic, [imap] timeout/max_retries, and the postgresql env-var prefix; corrected the maildir_path default (None, not INBOX — cli.py Namespace defaults), the mailbox check_timeout option name, the systemd restart interval (RestartSec is 5m), and merged the duplicate silent entry; quoted every copy-paste extras spec for zsh safety. - elasticsearch.md: fixed an invalid openssl command (rsa:4096 -nodes), the dashboards filename (opensearch_dashboards.ndjson, matching the file the link serves), and assorted grammar. - davmail.md: the service-enable command now enables davmail.service (was parsedmarc.service — a copy-paste error that left DavMail unenabled), plus a view typo and DavMail capitalization. - output.md: the example schema reference is RFC 7489 Appendix C (7480 is RDAP). kibana.md: SPF relies on the SMTP envelope, not session headers (RFC 7208). dmarc.md: DKM -> DKIM. - README: the intro now also names the OpenSearch/Grafana stack, matching the feature list. CONTRIBUTING: pre-PR checks now include ruff format --check and pyright, matching CI's lint job. - dashboards/README: the service table and seed description now include the PostgreSQL backend the compose stack runs. Sample data blocks, the CLI-help mirror block, and released CHANGELOG entries were deliberately left untouched. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> * Docstring review: accuracy, spelling, grammar, and clarity pass Every docstring in parsedmarc/, parsedmarc/mail/, the maps maintainer scripts, and the test suite reviewed with each claim verified against the code it documents. Text-only — no behavior changes. Highlights: - Copy-paste errors corrected: parsed_smtp_tls_reports_to_csv and splunk/loganalytics save functions described aggregate or failure reports they do not handle; LogAnalyticsException claimed to be an Elasticsearch error. - Docstring/behavior mismatches: parse_report_email's report_type enumeration omitted smtp_tls; parse_failure_report typed msg_date as str (it is datetime); strip_attachment_payloads claimed payloads are replaced with None (the key is deleted); kafkaclient's failure and SMTP TLS savers claimed per-record slicing while sending the whole list in one message (docstrings now describe reality — whether slicing was intended is flagged for follow-up); the postgres savers claimed to take parse_report_file's return value but receive the inner report dict; elastic/opensearch save functions' Raises listed only AlreadySaved. - None-as-semantic-state documented where missing (get_base_domain, get_ip_address_country), enumeration completeness fixed (get_ip_address_info's 9 result keys, maps script outputs, TSV columns), and the stale 44-industry-types count corrected to the 46 the authoritative README list defines. - Test docstrings aligned with what the tests actually assert, including two that overstated coverage of the elastic/opensearch address-list tests. - Two argparse help strings fixed: file_path now names SMTP TLS report files alongside aggregate and failure, mirrored into usage.md's CLI-help block; --offline's doubled spaces removed (rendered help unchanged). - elasticsearch.md's security claim corrected against Elastic's docs: security is enabled and auto-configured on first startup since 8.0 (not "8.7 secure mode"), so the settings are verified, not hand-written. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> --------- Co-authored-by: Claude Fable 5 <noreply@anthropic.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
419 lines
16 KiB
Markdown
419 lines
16 KiB
Markdown
# Elasticsearch and Kibana
|
|
|
|
To set up visual dashboards of DMARC data, install Elasticsearch and Kibana.
|
|
|
|
:::{note}
|
|
Elasticsearch and Kibana 8 or later are required (parsedmarc's 8.x Python
|
|
client also supports Elasticsearch 9). OpenSearch users must use the
|
|
`[opensearch]` configuration section instead — the Elasticsearch 8.x client
|
|
refuses to connect to non-Elasticsearch clusters.
|
|
:::
|
|
|
|
## Installation
|
|
|
|
On Debian/Ubuntu based systems, run:
|
|
|
|
```bash
|
|
sudo apt-get install -y apt-transport-https
|
|
wget -qO - https://artifacts.elastic.co/GPG-KEY-elasticsearch | sudo gpg --dearmor -o /usr/share/keyrings/elasticsearch-keyring.gpg
|
|
echo "deb [signed-by=/usr/share/keyrings/elasticsearch-keyring.gpg] https://artifacts.elastic.co/packages/8.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-8.x.list
|
|
sudo apt-get update
|
|
sudo apt-get install -y elasticsearch kibana
|
|
```
|
|
|
|
For CentOS, RHEL, and other RPM systems, follow the Elastic RPM guides for
|
|
[Elasticsearch] and [Kibana].
|
|
|
|
:::{note}
|
|
Previously, the default JVM heap size for Elasticsearch was very small (1g),
|
|
which will cause it to crash under a heavy load. To fix this, increase the
|
|
minimum and maximum JVM heap sizes in `/etc/elasticsearch/jvm.options` to
|
|
more reasonable levels, depending on your server's resources.
|
|
|
|
Make sure the system has at least 2 GB more RAM than the assigned JVM
|
|
heap size.
|
|
|
|
Always set the minimum and maximum JVM heap sizes to the same
|
|
value.
|
|
|
|
For example, to set a 4 GB heap size, set
|
|
|
|
```bash
|
|
-Xms4g
|
|
-Xmx4g
|
|
```
|
|
|
|
See <https://www.elastic.co/guide/en/elasticsearch/reference/current/important-settings.html#heap-size-settings>
|
|
for more information.
|
|
:::
|
|
|
|
```bash
|
|
sudo systemctl daemon-reload
|
|
sudo systemctl enable elasticsearch.service
|
|
sudo systemctl enable kibana.service
|
|
sudo systemctl start elasticsearch.service
|
|
sudo systemctl start kibana.service
|
|
```
|
|
|
|
Since Elasticsearch 8.0, security is enabled and auto-configured on
|
|
first startup: TLS certificates are generated, the `xpack.security.*`
|
|
settings below are written to `elasticsearch.yml`, and a password is
|
|
generated for the `elastic` user. Verify the settings are present —
|
|
and add them only if your install skipped auto-configuration:
|
|
|
|
```bash
|
|
sudo vim /etc/elasticsearch/elasticsearch.yml
|
|
```
|
|
|
|
The security configuration looks like this:
|
|
|
|
```text
|
|
# Enable security features
|
|
xpack.security.enabled: true
|
|
xpack.security.enrollment.enabled: true
|
|
# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents
|
|
xpack.security.http.ssl:
|
|
enabled: true
|
|
keystore.path: certs/http.p12
|
|
# Enable encryption and mutual authentication between cluster nodes
|
|
xpack.security.transport.ssl:
|
|
enabled: true
|
|
verification_mode: certificate
|
|
keystore.path: certs/transport.p12
|
|
truststore.path: certs/transport.p12
|
|
```
|
|
|
|
```bash
|
|
sudo systemctl restart elasticsearch
|
|
```
|
|
|
|
To create a self-signed certificate, run:
|
|
|
|
```bash
|
|
openssl req -x509 -nodes -days 365 -newkey rsa:4096 -keyout kibana.key -out kibana.crt
|
|
```
|
|
|
|
Or, to create a Certificate Signing Request (CSR) for a CA, run:
|
|
|
|
```bash
|
|
openssl req -newkey rsa:4096 -nodes -keyout kibana.key -out kibana.csr
|
|
```
|
|
|
|
Fill in the prompts. Watch out for Common Name (e.g. server FQDN or YOUR
|
|
domain name), which is the IP address or domain name that you will use to
|
|
access Kibana. It is the most important field.
|
|
|
|
If you generated a CSR, remove the CSR after you have your certs
|
|
|
|
```bash
|
|
rm -f kibana.csr
|
|
```
|
|
|
|
Move the keys into place and secure them:
|
|
|
|
```bash
|
|
sudo mv kibana.* /etc/kibana
|
|
sudo chmod 660 /etc/kibana/kibana.key
|
|
```
|
|
|
|
Activate the HTTPS server in Kibana
|
|
|
|
```bash
|
|
sudo vim /etc/kibana/kibana.yml
|
|
```
|
|
|
|
Add the following configuration
|
|
|
|
```text
|
|
server.host: "SERVER_IP"
|
|
server.publicBaseUrl: "https://SERVER_IP"
|
|
server.ssl.enabled: true
|
|
server.ssl.certificate: /etc/kibana/kibana.crt
|
|
server.ssl.key: /etc/kibana/kibana.key
|
|
```
|
|
|
|
:::{note}
|
|
For more security, you can configure Kibana to use a local network connection
|
|
to Elasticsearch:
|
|
```text
|
|
elasticsearch.hosts: ['https://SERVER_IP:9200']
|
|
```
|
|
=>
|
|
```text
|
|
elasticsearch.hosts: ['https://127.0.0.1:9200']
|
|
```
|
|
:::
|
|
|
|
```bash
|
|
sudo systemctl restart kibana
|
|
```
|
|
|
|
Enroll Kibana in Elasticsearch
|
|
|
|
```bash
|
|
sudo /usr/share/elasticsearch/bin/elasticsearch-create-enrollment-token -s kibana
|
|
```
|
|
|
|
Then access your web server at `https://SERVER_IP:5601`, accept the self-signed
|
|
certificate, and paste the token in the "Enrollment token" field.
|
|
|
|
```bash
|
|
sudo /usr/share/kibana/bin/kibana-verification-code
|
|
```
|
|
|
|
Then enter the verification code in your web browser.
|
|
|
|
End Kibana configuration
|
|
|
|
```bash
|
|
sudo /usr/share/elasticsearch/bin/elasticsearch-setup-passwords interactive
|
|
sudo /usr/share/kibana/bin/kibana-encryption-keys generate
|
|
sudo vim /etc/kibana/kibana.yml
|
|
```
|
|
|
|
Add previously generated encryption keys
|
|
|
|
```text
|
|
xpack.encryptedSavedObjects.encryptionKey: xxxx...xxxx
|
|
xpack.reporting.encryptionKey: xxxx...xxxx
|
|
xpack.security.encryptionKey: xxxx...xxxx
|
|
```
|
|
|
|
```bash
|
|
sudo systemctl restart kibana
|
|
sudo systemctl restart elasticsearch
|
|
```
|
|
|
|
Now that Elasticsearch is up and running, use `parsedmarc` to send data to
|
|
it.
|
|
|
|
Download (right-click the link and click save as) [opensearch_dashboards.ndjson].
|
|
|
|
Connect to Kibana using the "elastic" user and the password you previously
|
|
provided on the console ("End Kibana configuration" part).
|
|
|
|
Import `opensearch_dashboards.ndjson` in the Saved Objects tab of the Stack Management
|
|
page of Kibana. (Hamburger menu -> "Management" -> "Stack Management" ->
|
|
"Kibana" -> "Saved Objects")
|
|
|
|
It will give you the option to overwrite existing saved dashboards or
|
|
visualizations, which could be used to restore them if you or someone else
|
|
breaks them, as there are no permissions/access controls in Kibana without
|
|
the commercial [X-Pack].
|
|
|
|
```{image} _static/screenshots/saved-objects.png
|
|
:align: center
|
|
:alt: A screenshot of the Saved Objects Stack Management UI in Kibana
|
|
:target: _static/screenshots/saved-objects.png
|
|
```
|
|
|
|
```{image} _static/screenshots/confirm-overwrite.png
|
|
:align: center
|
|
:alt: A screenshot of the overwrite confirmation prompt
|
|
:target: _static/screenshots/confirm-overwrite.png
|
|
```
|
|
|
|
## Upgrading Kibana index patterns
|
|
|
|
`parsedmarc` 5.0.0 makes some changes to the way data is indexed in
|
|
Elasticsearch. If you are upgrading from a previous release of
|
|
`parsedmarc`, you need to complete the following steps to replace the
|
|
Kibana index patterns with versions that match the upgraded indexes:
|
|
|
|
1. Login in to Kibana, and click on Management
|
|
2. Under Kibana, click on Saved Objects
|
|
3. Check the checkboxes for the `dmarc_aggregate` and `dmarc_failure`
|
|
index patterns
|
|
4. Click Delete
|
|
5. Click Delete on the confirmation message
|
|
6. Download (right-click the link and click save as)
|
|
the latest version of [opensearch_dashboards.ndjson]
|
|
7. Import `opensearch_dashboards.ndjson` by clicking Import from the Kibana
|
|
Saved Objects page
|
|
|
|
## Backfilling the combined DKIM/SPF result fields
|
|
|
|
As of the version fixing [#169](https://github.com/domainaware/parsedmarc/issues/169),
|
|
aggregate documents include `dkim_results_combined` and `spf_results_combined` —
|
|
scalar string arrays that keep each auth result's selector/scope, domain, and
|
|
result paired, which the dashboards' alignment-detail tables aggregate on.
|
|
Reports saved by older versions lack these fields and will not appear in
|
|
those tables.
|
|
|
|
parsedmarc now backfills this automatically. On startup, it runs a cheap
|
|
count query against each configured aggregate index pattern to check for
|
|
documents that have DKIM or SPF results but are missing the corresponding
|
|
combined field. If any are found, it submits the backfill as a background
|
|
`_update_by_query` task (`wait_for_completion=false`), so startup is never
|
|
blocked on it; progress is logged, including the task ID. The check itself
|
|
is idempotent — once an index is fully backfilled, later startups see a
|
|
count of 0 and log nothing further — and it works the same way on
|
|
OpenSearch. Any error talking to the cluster (for example, no indexes yet
|
|
on a fresh install) is logged as a warning and retried on the next startup,
|
|
rather than aborting parsedmarc.
|
|
|
|
Which index patterns it targets follows the ones parsedmarc writes to, and
|
|
is logged at debug level on startup:
|
|
|
|
- With `index_prefix_domain_map` configured in `[general]` and no
|
|
`index_prefix` set, every tenant prefix in the map gets its own index
|
|
pattern, alongside the unprefixed one — aggregate and failure reports for
|
|
a domain that is not in the map are still saved without a prefix. A
|
|
configuration reload (`SIGHUP`) re-reads the map, so a newly onboarded
|
|
tenant is covered without a restart.
|
|
- With an `index_prefix` set in `[elasticsearch]`/`[opensearch]`, only that
|
|
prefix is targeted, and the map is not consulted. That is deliberate: such
|
|
a deployment writes only under its own prefix, and an `_update_by_query`
|
|
against a pattern it does not write to could reach another deployment's
|
|
data on a shared cluster.
|
|
- With an `index_suffix` set, both the suffixed and the unsuffixed pattern
|
|
are targeted, so documents indexed before the suffix was configured are
|
|
backfilled too. Note that the unsuffixed pattern also matches any *other*
|
|
suffix on the same cluster.
|
|
|
|
If you upgrade the dashboards without pointing the new parsedmarc version
|
|
at the cluster, or you'd rather control when the write load happens, you
|
|
can still run the backfill manually. It is idempotent (documents that
|
|
already have the fields are skipped), so it is safe to re-run. It works
|
|
identically on OpenSearch; just adjust the URL and credentials. The query
|
|
matches only documents that have at least one DKIM or SPF auth result and
|
|
lack the corresponding combined field; documents with no auth results are
|
|
skipped, because an `exists` query cannot see an empty array, and for
|
|
search purposes an empty `dkim_results_combined` is identical to an
|
|
absent one. Each result is matched on either its `domain` or its `result`
|
|
subfield as defense in depth: an empty string indexes no text tokens and
|
|
is invisible to `exists`, and the storage shape of every historical
|
|
parsedmarc version can't be audited, so matching either subfield ensures
|
|
no backfillable document is skipped.
|
|
|
|
```bash
|
|
curl -X POST "http://localhost:9200/dmarc_aggregate*/_update_by_query?conflicts=proceed&wait_for_completion=false" \
|
|
-H "Content-Type: application/json" -d '
|
|
{
|
|
"query": {
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{
|
|
"bool": {
|
|
"must": [
|
|
{
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{"exists": {"field": "dkim_results.domain"}},
|
|
{"exists": {"field": "dkim_results.result"}}
|
|
]
|
|
}
|
|
}
|
|
],
|
|
"must_not": [{"exists": {"field": "dkim_results_combined"}}]
|
|
}
|
|
},
|
|
{
|
|
"bool": {
|
|
"must": [
|
|
{
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{"exists": {"field": "spf_results.domain"}},
|
|
{"exists": {"field": "spf_results.result"}}
|
|
]
|
|
}
|
|
}
|
|
],
|
|
"must_not": [{"exists": {"field": "spf_results_combined"}}]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"script": {
|
|
"lang": "painless",
|
|
"source": "List dk = new ArrayList(); def dr = ctx._source.dkim_results; if (dr != null) { if (!(dr instanceof List)) { dr = [dr]; } for (e in dr) { if (e == null) { continue; } def sel = e.selector != null ? e.selector : \"none\"; def dom = e.domain != null ? e.domain : \"none\"; def res = e.result != null ? e.result : \"none\"; dk.add(sel + \" / \" + dom + \" / \" + res); } } ctx._source.dkim_results_combined = dk; List sp = new ArrayList(); def sr = ctx._source.spf_results; if (sr != null) { if (!(sr instanceof List)) { sr = [sr]; } for (e in sr) { if (e == null) { continue; } def sc = e.scope != null ? e.scope : \"mfrom\"; def dom = e.domain != null ? e.domain : \"none\"; def res = e.result != null ? e.result : (e.results != null ? e.results : \"none\"); sp.add(sc + \" / \" + dom + \" / \" + res); } } ctx._source.spf_results_combined = sp;"
|
|
}
|
|
}'
|
|
```
|
|
|
|
`wait_for_completion=false` returns a task ID — check progress with
|
|
`GET _tasks/<task id>`. Adjust the index pattern if you use a custom
|
|
`index_prefix`/`index_suffix`; with `index_prefix_domain_map`, run the
|
|
command once per tenant prefix (`acme_corp_dmarc_aggregate*`) plus once for
|
|
the unprefixed pattern, or widen it to `*dmarc_aggregate*` to cover every
|
|
tenant in one pass. After backfilling, re-import the updated
|
|
dashboards ndjson (the index pattern saved object changed too) per the
|
|
import instructions above.
|
|
|
|
SMTP TLS documents have the same class of defect one level deeper:
|
|
`policies` is an object array, and each policy's `failure_details` is an
|
|
object array inside it. SMTP TLS documents now also carry
|
|
`policies_combined` and `failure_details_combined`, backfilled
|
|
automatically at startup the same way, and the equivalent manual command
|
|
is:
|
|
|
|
```bash
|
|
curl -X POST "http://localhost:9200/smtp_tls*/_update_by_query?conflicts=proceed&wait_for_completion=false" \
|
|
-H "Content-Type: application/json" -d '
|
|
{
|
|
"query": {
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{
|
|
"bool": {
|
|
"must": [
|
|
{
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{"exists": {"field": "policies.policy_domain"}},
|
|
{"exists": {"field": "policies.policy_type"}}
|
|
]
|
|
}
|
|
}
|
|
],
|
|
"must_not": [{"exists": {"field": "policies_combined"}}]
|
|
}
|
|
},
|
|
{
|
|
"bool": {
|
|
"must": [
|
|
{
|
|
"bool": {
|
|
"minimum_should_match": 1,
|
|
"should": [
|
|
{"exists": {"field": "policies.failure_details.result_type"}},
|
|
{"exists": {"field": "policies.failure_details.sending_mta_ip"}}
|
|
]
|
|
}
|
|
}
|
|
],
|
|
"must_not": [{"exists": {"field": "failure_details_combined"}}]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"script": {
|
|
"lang": "painless",
|
|
"source": "List pols = new ArrayList(); List dets = new ArrayList(); def ps = ctx._source.policies; if (ps != null) { if (!(ps instanceof List)) { ps = [ps]; } for (p in ps) { if (p == null) { continue; } def dom = p.policy_domain != null ? p.policy_domain : \"none\"; def typ = p.policy_type != null ? p.policy_type : \"none\"; pols.add(dom + \" / \" + typ); def fds = p.failure_details; if (fds != null) { if (!(fds instanceof List)) { fds = [fds]; } for (f in fds) { if (f == null) { continue; } def rt = f.result_type != null ? f.result_type : \"none\"; def smi = f.sending_mta_ip != null ? f.sending_mta_ip : \"none\"; def ri = f.receiving_ip != null ? f.receiving_ip : \"none\"; def rmh = f.receiving_mx_hostname != null ? f.receiving_mx_hostname : \"none\"; dets.add(dom + \" / \" + typ + \" / \" + rt + \" / \" + smi + \" / \" + ri + \" / \" + rmh); } } } } ctx._source.policies_combined = pols; ctx._source.failure_details_combined = dets;"
|
|
}
|
|
}'
|
|
```
|
|
|
|
It works identically on OpenSearch; just adjust the URL and credentials, same
|
|
as the aggregate command above.
|
|
|
|
## Records retention
|
|
|
|
Starting in version 5.0.0, `parsedmarc` stores data in a separate
|
|
index for each day to make it easy to comply with records
|
|
retention regulations such as GDPR. For more information,
|
|
check out the Elastic guide to [managing time-based indexes efficiently](https://www.elastic.co/blog/managing-time-based-indices-efficiently).
|
|
|
|
[elasticsearch]: https://www.elastic.co/guide/en/elasticsearch/reference/current/rpm.html
|
|
[opensearch_dashboards.ndjson]: https://raw.githubusercontent.com/domainaware/parsedmarc/master/dashboards/opensearch/opensearch_dashboards.ndjson
|
|
[kibana]: https://www.elastic.co/guide/en/kibana/current/rpm.html
|
|
[x-pack]: https://www.elastic.co/products/x-pack
|