| 485 | bool SystemMonitorController::parseEvent(const Byte* pBuffer, const Size nBufferSize, std::pair<Size, Size>& nTimes) |
| 486 | #else |
| 487 | bool SystemMonitorController::parseEvent(const Byte* pBuffer, const Size nBufferSize) |
| 488 | #endif |
| 489 | { |
| 490 | CMD_TRY |
| 491 | { |
| 492 | #ifdef ENABLE_EVENT_TIMINGS |
| 493 | using namespace std::chrono; |
| 494 | auto t0 = steady_clock::now(); |
| 495 | #endif |
| 496 | Variant vEvent = variant::deserializeFromLbvs(pBuffer, nBufferSize, m_vEventSchema); |
| 497 | edrdrv::SysmonEvent nRawEventId = vEvent["rawEventId"]; |
| 498 | LOGLVL(Trace, "Parse raw event <" << size_t(nRawEventId) << |
| 499 | "> from process <" << getByPath(vEvent, "process.pid", -1) << ">"); |
| 500 | #ifdef ENABLE_EVENT_TIMINGS |
| 501 | auto t1 = steady_clock::now(); |
| 502 | #endif |
| 503 | |
| 504 | // Add LLE type |
| 505 | auto eEvent = mEventMap[nRawEventId]; |
| 506 | vEvent.put("baseType", eEvent); |
| 507 | vEvent.put("rawEventId", createRaw(c_nClassId, (uint32_t)nRawEventId)); |
| 508 | |
| 509 | if (m_eInjection == InjectionMode::Controller && eEvent == Event::LLE_PROCESS_CREATE) |
| 510 | { |
| 511 | uint32_t nPid = getByPath(vEvent, "process.pid", 0); |
| 512 | if (nPid != 0) |
| 513 | { |
| 514 | run([](uint32_t pid) { |
| 515 | (void) execCommand(Dictionary({ |
| 516 | {"processor", "objects.processMonitorController" }, |
| 517 | {"command", "inject"}, |
| 518 | {"params", Dictionary({ {"pid", pid} })}, |
| 519 | })); |
| 520 | }, nPid); |
| 521 | } |
| 522 | } |
| 523 | |
| 524 | // Send message to receiver |
| 525 | if (!m_pReceiver) |
| 526 | error::InvalidArgument(SL, "Receiver interface is undefined").throwException(); |
| 527 | m_pReceiver->put(vEvent); |
| 528 | #ifdef ENABLE_EVENT_TIMINGS |
| 529 | auto t2 = steady_clock::now(); |
| 530 | milliseconds lbvsTime(duration_cast<milliseconds>(t1 - t0)); |
| 531 | milliseconds queueTime(duration_cast<milliseconds>(t2 - t1)); |
| 532 | nTimes.first = Size(lbvsTime.count()); |
| 533 | nTimes.second = Size(queueTime.count()); |
| 534 | #endif |
| 535 | } |
| 536 | CMD_PREPARE_CATCH |
| 537 | catch (error::Exception& e) |
| 538 | { |
no test coverage detected