Class CEFParser


  • public class CEFParser
    extends Object
    A Common Event Format (CEF) parser used to convert String or byte array into a Map containing the parsed and validated CEF fields The parser does not make any assertion in regards to thread safety. Proceed with care.
    • Constructor Summary

      Constructors 
      Constructor Description
      CEFParser()
      Creates a CEFParser instance utilizing the default Bean Validator.
      CEFParser​(jakarta.validation.Validator validator)
      Creates a CEFParser instance utilizing thread-safe Beans Validator.
    • Constructor Detail

      • CEFParser

        public CEFParser()
        Creates a CEFParser instance utilizing the default Bean Validator.
      • CEFParser

        public CEFParser​(jakarta.validation.Validator validator)
        Creates a CEFParser instance utilizing thread-safe Beans Validator. The use of this constructor should result in significantly higher throughput when performing multiple instatiations of CEFParser.
        Parameters:
        validator - A JSR-303 complianceValidator such as Hibernate or Apache bVal
    • Method Detail

      • parse

        public CommonEvent parse​(byte[] cefByteArray)
        Parse byte array after converting to UTF-8 string with validation disabled
        Parameters:
        cefByteArray - byte [] containing the CEF message to be parsed - Array will be converted String using UTF-8
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(byte[] cefByteArray,
                                 boolean validate)
        Parse byte array after converting to UTF-8 string with validation enabled or disabled
        Parameters:
        cefByteArray - byte [] containing the CEF message to be parsed - Array will be converted String using UTF-8
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(byte[] cefByteArray,
                                 boolean validate,
                                 Locale locale)
        Parse byte array after converting to UTF-8 string using specified Locale and with validation enabled or disabled
        Parameters:
        cefByteArray - byte [] containing the CEF message to be parsed - Array will be converted String using UTF-8
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        locale - The locale to be used when parsing dates (so that parser can handle both jul (en_US) and juil.(fr_FR)
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(byte[] cefByteArray,
                                 boolean validate,
                                 boolean allowNulls,
                                 Locale locale)
        Parse byte array after converting to UTF-8 string using specified Locale and with validation and allow nulsl enabled or disabled
        Parameters:
        cefByteArray - byte [] containing the CEF message to be parsed - Array will be converted String using UTF-8
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        allowNulls - If true, extensions with an empty value will be seen as null. If false, parsing may fail depending on extension types
        locale - The locale to be used when parsing dates (so that parser can handle both jul (en_US) and juil.(fr_FR)
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(String cefString)

        Converts a CEF formatted String into a CommonEvent object without enforcing strict validation.

        The use of this method is discouraged and future versions may deprecate its use.

        Parameters:
        cefString - String containing the CEF message to be parsed
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(String cefString,
                                 boolean validate)

        Converts a CEF formatted String into a CommonEvent object with exposed control over strict validation.

        All CEF extension fields containing Dates are processed with the Locale.ENGLISH.

        Parameters:
        cefString - String containing the CEF message to be parsed
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(String cefString,
                                 boolean validate,
                                 Locale locale)
        Converts a CEF formatted String into a CommonEvent object with exposed control over validation and the Locale used to parse fields containing Dates
        Parameters:
        cefString - String containing the CEF message to be parsed
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        locale - The locale to be used when parsing dates (so that parser can handle both jul (en_US) and juil.(fr_FR)
        Returns:
        CommonEvent
      • parse

        public CommonEvent parse​(String cefString,
                                 boolean validate,
                                 boolean allowNulls,
                                 Locale locale)
        Converts a CEF formatted String into a CommonEvent object with exposed control over validation and the Locale used to parse fields containing Dates
        Parameters:
        cefString - String containing the CEF message to be parsed
        validate - Boolean if parser should validate values beyond type compatibility (e.g. Values within acceptable lengths, value lists, etc)
        allowNulls - If true, extensions with an empty value will be seen as null. If false, parsing may fail depending on extension types
        locale - The locale to be used when parsing dates (so that parser can handle both jul (en_US) and juil.(fr_FR)
        Returns:
        CommonEvent