2021年9月26日 星期日

LibreNMS平均CPU使用率監控功能

  最近有一個需求是要去CPU的監控,但使用的方式為 

processors.processor_usage >= processor_perc_warn

這個方式去監控是依據每一顆CPU去做監控的.如果該主機有 8 顆CPU,

其中有 1 顆 超過告警值 即會發出告警,但其它 7 顆可能沒那麼重的 loading .

這種方式的監控似乎不是那麼合理.理想的情境應是依 這 8 顆的平均值去做告警才是.

在 官方 https://docs.librenms.org/Alerting/Rules/ 的 Advanced 處,

有看到一個 SQL 語法.


SELECT *,AVG(processors.processor_usage) as cpu_avg FROM devices,processors WHERE (devices.device_id = ? AND devices.device_id = processors.device_id) AND (devices.status = 1 && (devices.disabled = 0 && devices.ignore = 0)) = 1 HAVING AVG(processors.processor_usage) > 10


後來試一下真的可以用.

壓測方式

[root@librenms CPULoadGenerator]# python3.6 -m cpu_load_generator -l 0.8 -d 600 -c -1

使用工具

https://pypi.org/project/cpu-load-generator/


Project description


CPU Load Generator


This package allows to generate a fixed CPU load for a finite time period. 

The script takes in input the desired CPU load, the duration of the experiment 

and the CPU core or all cores on which the load has to be generated.


Python versions This master branch refers to Python versions 3.x


Dependencies Installment of psutil is required 

(it is already set as dependency in the setup.py)


Install psutil:


pip install psutil

Other dependencies for unit tests and linters:


pip install mock pytest flake8 tox

Usage To generate 20% of load on core 0 for 20 seconds run:


python -m cpu_load_generator -l 0.2 -d 20 -c 0

To generate 50% of load on all logical cores for 20 seconds run:


python -m cpu_load_generator -l 0.5 -d 20 -c -1

There is an option to run CPU load based on profile file. An exemplary profile 

is under load_profiles/default_profile.json. In order to run generator based on

a profile issue the following command:


python -m cpu_load_generator -p <path_to_profile_json>

To use the package features from python code:


Install the package from PyPi by issuing the following command:


python -m pip instal cpu-load-generator

To use its features from your code:


from cpu_load_generator import load_single_core, load_all_cores, from_profile


load_single_core(core_num=0, duration_s=20, target_load=0.4)  # generate load on single core (0)

load_all_cores(duration_s=30, target_load=0.2)  # generates load on all cores

from_profile(path_to_profile_json=r"c:\profiles\profile1.json")


DEMO














2021年9月25日 星期六

LibreNMS 外掛 Service 監控功能

源自 Nagios Plugins - Services 

https://docs.librenms.org/Extensions/Services/

Demo




















Setting

======================================================


Service


{{ $alert->title }}

@if ($alert->faults)

@foreach ($alert->faults as $key => $value) {{ $value['service_desc'] }} - {{ $value['service_type'] }}

{{ $value['service_message'] }}

@endforeach

@endif


Error=========

Service: {{ $value['service_name'] }} {{ $value['service_type'] }}

=============

=========================================================

Other

SELECT * FROM devices,services WHERE (devices.device_id = ? AND devices.device_id = services.device_id) AND services.service_status != 0 AND (devices.status = 1 && (devices.disabled = 0 && devices.ignore = 0)) = 1

 

2021年7月28日 星期三

L2TP over IPsec VPN on VyOS / Vyatta


VPN Topology (Client to Site VPN)


L2TP  Client  <--> Firewall<---> Internet<---->Firewall<--->VyOS-L2TP-Server



VyOS Setting 


 vyos@vyos:~$ show configuration commands

set interfaces ethernet eth0 address '10.1.1.254/24'

set interfaces ethernet eth0 duplex 'auto'

set interfaces ethernet eth0 hw-id '00:0d:30:bb:72:57'

set interfaces ethernet eth0 smp-affinity 'auto'

set interfaces ethernet eth0 speed 'auto'

set interfaces loopback lo

set nat source rule 110 outbound-interface 'eth0'

set nat source rule 110 source address '192.168.1.0/24'

set nat source rule 110 translation address 'masquerade'

set protocols static route 0.0.0.0/0 next-hop 10.1.1.1

set service ssh port '22'

set system config-management commit-revisions '100'

set system console device ttyS0 speed '9600'

set system host-name 'vyos'

set system login user vyos authentication encrypted-password ''

set system login user vyos authentication plaintext-password ''

set system login user vyos level 'admin'

set system name-server '168.95.1.1'

set system ntp server clock.hinet.net

set system syslog global facility all level 'info'

set system syslog global facility protocols level 'debug'

set system time-zone 'Asia/Taipei'

set vpn ipsec esp-group l2tp compression 'disable'

set vpn ipsec esp-group l2tp lifetime '3600'

set vpn ipsec esp-group l2tp mode 'tunnel'

set vpn ipsec esp-group l2tp pfs 'dh-group2'

set vpn ipsec esp-group l2tp proposal 1 encryption 'aes128'

set vpn ipsec esp-group l2tp proposal 1 hash 'sha1'

set vpn ipsec ike-group l2tp close-action 'none'

set vpn ipsec ike-group l2tp ikev2-reauth 'no'

set vpn ipsec ike-group l2tp key-exchange 'ikev2'

set vpn ipsec ike-group l2tp lifetime '3600'

set vpn ipsec ike-group l2tp proposal 1 dh-group '2'

set vpn ipsec ike-group l2tp proposal 1 encryption 'aes128'

set vpn ipsec ike-group l2tp proposal 1 hash 'sha1'

set vpn ipsec ipsec-interfaces interface 'eth0'

set vpn ipsec logging log-level '1'

set vpn ipsec logging log-modes 'any'

set vpn ipsec nat-networks allowed-network 0.0.0.0/0

set vpn ipsec nat-traversal 'enable'

set vpn l2tp remote-access authentication local-users username VPNUser1 password 'User1Password'

set vpn l2tp remote-access authentication local-users username VPNUser2 password 'User2Password'

set vpn l2tp remote-access authentication mode 'local'

set vpn l2tp remote-access client-ip-pool start '192.168.1.50'

set vpn l2tp remote-access client-ip-pool stop '192.168.1.100'

set vpn l2tp remote-access dns-servers server-1 '8.8.8.8'

set vpn l2tp remote-access idle '1800'

set vpn l2tp remote-access ipsec-settings authentication mode 'pre-shared-secret'

set vpn l2tp remote-access ipsec-settings authentication pre-shared-secret 'L2TP-PASSWORD'

set vpn l2tp remote-access ipsec-settings ike-lifetime '3600'

set vpn l2tp remote-access ipsec-settings lifetime '3600'

set vpn l2tp remote-access mtu '1492'

set vpn l2tp remote-access outside-address '0.0.0.0'

vyos@vyos:~$


=================================================


vyos@vyos:~$  show vpn debug

Status of IKE charon daemon (strongSwan 5.7.2, Linux 4.19.195-amd64-vyos, x86_64):

  uptime: 25 minutes, since Jul 29 01:13:44 2021

  malloc: sbrk 2973696, mmap 0, used 813120, free 2160576

  worker threads: 11 of 16 idle, 5/0/0/0 working, job queue: 0/0/0/0, scheduled: 1

  loaded plugins: charon test-vectors ldap pkcs11 tpm aesni aes rc2 sha2 sha1 md5 mgf1

  rdrand random nonce x509 revocation constraints pubkey pkcs1 pkcs7 pkcs8 pkcs12 pgp 

 dnskey sshkey pem openssl gcrypt af-alg fips-prf gmp curve25519 agent chapoly xcbc cmac 

 hmac ctr ccm gcm curl attr kernel-netlink resolve socket-default connmark stroke vici 

 updown eap-identity eap-aka eap-md5 eap-gtc eap-mschapv2 eap-radius eap-tls eap-ttls 

 eap-tnc xauth-generic xauth-eap xauth-pam tnc-tnccs dhcp lookip error-notify certexpire 

 led addrblock counters

Listening IP addresses:

  10.1.1.254

Connections:

remote-access:  0.0.0.0...%any  IKEv1, dpddelay=15s

remote-access:   local:  [10.1.1.254] uses pre-shared key authentication

remote-access:   remote: uses pre-shared key authentication

remote-access:   child:  dynamic[0/l2f] === dynamic TRANSPORT, dpdaction=clear

Security Associations (1 up, 0 connecting):

remote-access[1]: ESTABLISHED 11 minutes ago, 10.1.1.254[10.1.1.254]...114.35.xxx.xxx[192.168.1.51]

remote-access[1]: IKEv1 SPIs: 6e74c683a4e351d3_i 0cc2f51574ea4e80_r*, rekeying disabled

remote-access[1]: IKE proposal: 3DES_CBC/HMAC_SHA1_96/PRF_HMAC_SHA1/MODP_1024

remote-access{1}:  INSTALLED, TRANSPORT, reqid 1, ESP in UDP SPIs: cc8f0e29_i ce27b6dd_o

remote-access{1}:  3DES_CBC/HMAC_SHA1_96, 438878 bytes_i, 420717 bytes_o (1724 pkts, 14s ago), rekeying disabled

remote-access{1}:   10.1.1.254/32[udp/l2f] === 114.35.xxx.xxx/32[udp/l2f]


=================================================

Reference

https://docs.vyos.io/en/latest/configuration/vpn/l2tp.html

https://support.vyos.io/en/kb/articles/l2tp-over-ipsec-vpn-2

https://brezular.com/2019/06/01/l2tp-ipsec-remote-access-vpn-on-vyos/


===========================================


Firewall Policy Rule  (https://support.vyos.io/en/kb/articles/l2tp-over-ipsec-vpn-2)


UDP port 500 (IKE)

IP protocol number 50 (ESP)

UDP port 1701 for IPsec

As well as the below to allow NAT-traversal 


(when NAT is detected by the VPN client, ESP is encapsulated in UDP for NAT-traversal):


UDP port 4500 (NAT-T)



=============================================

Debug CLI

vyos@vyos:~$  show vpn ipsec state

vyos@vyos:~$  show vpn ipsec status

vyos@vyos:~$  show vpn debug

vyos@vyos:~$  show log vpn all

vyos@vyos:~$  show vpn remote-access


======================================

Other

configure-l2tp-ipsec-server-behind-nat-t-device (Windows)

https://docs.microsoft.com/en-US/troubleshoot/windows-server/networking/configure-l2tp-ipsec-server-behind-nat-t-device


Set AssumeUDPEncapsulationContextOnSendRule registry key


To create and configure the AssumeUDPEncapsulationContextOnSendRule registry value, follow these steps:


1.Log on to the Windows Vista client computer as a user who is a member of the Administrators group.


2.Select Start > All Programs > Accessories > Run, type regedit, and then select OK. If the 


User Account Control dialog box is displayed on the screen and prompts you to elevate your 

administrator token, select Continue.


3. Locate and then select the following registry subkey:


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent


=======================================================


 Note


You can also apply the AssumeUDPEncapsulationContextOnSendRule DWORD value to a 

Microsoft Windows XP Service Pack 2 (SP2)-based VPN client computer. To do so, 

locate and then select the 


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\IPSec registry subkey.


======================================================


4. On the Edit menu, point to New, and then select DWORD (32-bit) Value.


5. Type AssumeUDPEncapsulationContextOnSendRule, and then press ENTER.


6. Right-click AssumeUDPEncapsulationContextOnSendRule, and then select Modify.


7. In the Value Data box, type one of the following values:


0.

It's the default value. When it's set to 0, Windows can't establish security 

associations with servers located behind NAT devices.


1.

When it's set to 1, Windows can establish security associations with 

servers that are located behind NAT devices.


2.

When it's set to 2, Windows can establish security associations when 

both the server and VPN client computer 

        (Windows Vista or Windows Server 2008-based) 

are behind NAT devices.


8. Select OK, and then exit Registry Editor.


9. Restart the computer.

========================================


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\PolicyAgent]

"AssumeUDPEncapsulationContextOnSendRule"=dword:00000002

2021年6月20日 星期日

使用 Container 去 Build VyOS ISO 小筆記

 前導文件:

vyos [ vyatta ]

http://xrcd2.blogspot.tw/2014/09/vyos-vyatta.html

VyOS OpenVpn Plugin OTP ( SOP )

http://xrcd2.blogspot.tw/2015/03/vyos-openvpn-plugin-otp-sop.html

VyOS+OpenVPN+MFA

http://xrcd2.blogspot.tw/2016/09/vyosopenvpnmfa.html

使用 Debian 8.9 去 Build VyOS ISO 小筆記

http://xrcd2.blogspot.com/2017/10/debian-89-build-vyos-iso.html


LAB

yum -y install yum-utils device-mapper-persistent-data lvm2 git wget

yum-config-manager --add-repo https://download.docker.com/linux/centos/docker-ce.repo

yum -y install docker-ce docker-ce-cli containerd.io

systemctl start docker

systemctl enable docker


git clone -b crux --single-branch https://github.com/vyos/vyos-build

cd vyos-build

docker run --rm -it --privileged -v $(pwd):/vyos -w /vyos vyos/vyos-build:crux bash


./configure --architecture amd64 --build-by "xrcd2@OOXX.com" --build-type release --version 1.2.7

make iso












參考文件

https://docs.docker.com/engine/install/centos/

https://docs.vyos.io/en/latest/contributing/build-vyos.html

https://www.blog.slow-fire.net/2021/04/09/vyos%E3%82%B3%E3%83%B3%E3%83%91%E3%82%A4%E3%83%AB-1-2-7/

https://qiita.com/s64s_y/items/f2b32f4ba257fbab9358


2020年2月13日 星期四

PCAP Analyzer for Splunk

Splunk APP URL

https://splunkbase.splunk.com/app/2748/

GETTING STARTED

https://schwartzdaniel.com/pcap-analyzer-for-splunk-getting-started/



# dnf install wireshark

# tshark --version

# chown splunk.splunk -R /opt/splunk/etc/apps/SplunkForPCAP




[root@centos8 apps]# pwd
/opt/splunk/etc/apps
[root@centos8 apps]# ll
total 0
drwxr-xr-x  7 splunk splunk  79 Feb 14 10:04 alert_logevent
drwxr-xr-x  7 splunk splunk  79 Feb 14 10:04 alert_webhook
drwxr-xr-x  4 splunk splunk  37 Feb 14 10:04 appsbrowser
drwxr-xr-x  6 splunk splunk  68 Feb 14 10:04 gettingstarted
drwxr-xr-x  4 splunk splunk  32 Feb 14 10:04 introspection_generator_addon
drwxr-xr-x  6 splunk splunk  68 Feb 14 10:04 launcher
drwxr-xr-x  5 splunk splunk  50 Feb 14 10:05 learned
drwxr-xr-x  3 splunk splunk  21 Feb 14 10:04 legacy
drwxr-xr-x  6 splunk splunk  66 Feb 14 10:04 sample_app
drwxr-xr-x  9 splunk splunk 109 Feb 14 10:04 search
drwxr-xr-x  6 splunk splunk  64 Feb 14 10:17 splunk_archiver
drwxr-xr-x 11 splunk splunk 179 Feb 14 10:14 SplunkForPCAP
drwxr-xr-x  4 splunk splunk  37 Feb 14 10:04 SplunkForwarder
drwxr-xr-x  7 splunk splunk 130 Feb 14 10:04 splunk_gdi
drwxr-xr-x  3 splunk splunk  21 Feb 14 10:04 splunk_httpinput
drwxr-xr-x  8 splunk splunk  92 Feb 14 10:05 splunk_instrumentation
drwxr-xr-x  4 splunk splunk  37 Feb 14 10:04 SplunkLightForwarder
drwxr-xr-x  8 splunk splunk  96 Feb 14 10:04 splunk_metrics_workspace
drwxr-xr-x 11 splunk splunk 135 Feb 14 10:05 splunk_monitoring_console
drwxr-xr-x  4 splunk splunk  37 Feb 14 10:04 user-prefs
[root@centos8 apps]#


2019年8月23日 星期五

Switched Port Analyzer (SPAN) 試作 ( NetFlow )

簡要架構說明:

Linux eth0 預備接收從 Switch Mirror 過來的網路封包介面
           eth1 預備將來使用 NetFlow 軟體的 web 登入介面

透過 nprobe / fprobe  這一類的程式,將特定網卡介面的網路封包,
轉導給 NetFlow 軟體做分析與使用!

如下圖所示:

nprobe

https://www.ntop.org/products/netflow/nprobe/





nprobe 可使用 yum 安裝即可,參考的 URL 如下:

http://packages.ntop.org/centos/

如使用 fprobe  可參考如下步驟:

yum install libpcap-devel -y

wget http://sourceforge.net/projects/fprobe/files/fprobe/1.1/fprobe-1.1.tar.bz2
tar jxvf fprobe-1.1.tar.bz2
cd fprobe-1.1/
./configure
make
make install

使用的參考指令如下:

fprobe -i eth0 127.0.0.1:9996


其它參考資訊

(1)

NetFlow Analyzer

https://www.manageengine.com/products/netflow/


nProbe and NetFlow Analyzer

https://blogs.manageengine.com/network/netflowanalyzer/2011/05/19/nprobe-and-netflow-analyzer.html

(2)

NetFlow Traffic Analyzer

https://www.solarwinds.com/netflow-traffic-analyzer


NTA - How to configure nProbe to export flows to Solarwinds NTA

https://support.solarwinds.com/SuccessCenter/s/article/NTA-How-to-configure-nProbe-to-export-flows-to-Solarwinds-NTA





2019年6月16日 星期日

Zabbix 4.2 + TimescaleDB 安裝小筆記


Zabbix 4.2 + TimescaleDB


Zabbix 4.2 的新功能部份已支援 TimescaleDB,故留下這個小筆記,方便日後使用

(1) OS CentOS 7

(2) PostgreSQL 11

https://docs.timescale.com/v1.3/getting-started/installation/rhel-centos/installation-yum

PostgreSQL repository & Install

# yum install https://download.postgresql.org/pub/repos/yum/reporpms/EL-7-x86_64/pgdg-redhat-repo-latest.noarch.rpm

# yum install postgresql11

# yum install postgresql11-server

# /usr/pgsql-11/bin/postgresql-11-setup initdb

# systemctl enable postgresql-11

# systemctl start postgresql-11


Add PATH


PATH=$PATH:/usr/pgsql-11/bin/
export PATH
PGDATA=/var/lib/pgsql/11/data
export PGDATA


# vi /var/lib/pgsql/11/data/pg_hba.conf

local   all all md5
# or  local   all all trust
host    all     all     127.0.0.1/32 md5

# vi /var/lib/pgsql/11/data/postgresql.conf


# - Connection Settings -

listen_addresses = '*'       # what IP address(es) to listen on;
                                        # comma-separated list of addresses;
                                        # defaults to 'localhost'; use '*' for all
                                        # (change requires restart)
port = 5432                     # (change requires restart)
max_connections = 100  # (change requires restart)



(3) TimescaleDB 1.3


TimescaleDB repository & Install

sudo cat > /etc/yum.repos.d/timescale_timescaledb.repo <<EOL
[timescale_timescaledb]
name=timescale_timescaledb
baseurl=https://packagecloud.io/timescale/timescaledb/el/7/\$basearch
repo_gpgcheck=1
gpgcheck=0
enabled=1
gpgkey=https://packagecloud.io/timescale/timescaledb/gpgkey
sslverify=1
sslcacert=/etc/pki/tls/certs/ca-bundle.crt
metadata_expire=300
EOL

# yum update -y

# yum install -y timescaledb-postgresql-11




(4) Configure database

# timescaledb-tune


[root@centos75 ~]# timescaledb-tune
Using postgresql.conf at this path:
/var/lib/pgsql/11/data/postgresql.conf

Is this correct? [(y)es/(n)o]: y
Writing backup to:
/tmp/timescaledb_tune.backup201906151823

shared_preload_libraries needs to be updated
Current:
#shared_preload_libraries = ''
Recommended:
shared_preload_libraries = 'timescaledb'
Is this okay? [(y)es/(n)o]: y
success: shared_preload_libraries will be updated

Tune memory/parallelism/WAL and other settings? [(y)es/(n)o]: y
Recommendations based on 3.69 GB of available memory and 4 CPUs for PostgreSQL 11

Memory settings recommendations
Current:
shared_buffers = 128MB
#effective_cache_size = 4GB
#maintenance_work_mem = 64MB
#work_mem = 4MB
Recommended:
shared_buffers = 966208kB
effective_cache_size = 2830MB
maintenance_work_mem = 483104kB
work_mem = 2415kB
Is this okay? [(y)es/(s)kip/(q)uit]: y
success: memory settings will be updated

Parallelism settings recommendations
Current:
missing: timescaledb.max_background_workers
#max_worker_processes = 8
#max_parallel_workers_per_gather = 2
#max_parallel_workers = 8
Recommended:
timescaledb.max_background_workers = 8
max_worker_processes = 15
max_parallel_workers_per_gather = 2
max_parallel_workers = 4
Is this okay? [(y)es/(s)kip/(q)uit]: y
success: parallelism settings will be updated

WAL settings recommendations
Current:
#wal_buffers = -1
min_wal_size = 80MB
max_wal_size = 1GB
Recommended:
wal_buffers = 16MB
min_wal_size = 4GB
max_wal_size = 8GB
Is this okay? [(y)es/(s)kip/(q)uit]: y
success: WAL settings will be updated

Miscellaneous settings recommendations
Current:
#default_statistics_target = 100
#random_page_cost = 4.0
#checkpoint_completion_target = 0.5
#max_locks_per_transaction = 64
#effective_io_concurrency = 1
Recommended:
default_statistics_target = 500
random_page_cost = 1.1
checkpoint_completion_target = 0.9
max_locks_per_transaction = 64
effective_io_concurrency = 200
Is this okay? [(y)es/(s)kip/(q)uit]: y
success: miscellaneous settings will be updated
Saving changes to: /var/lib/pgsql/11/data/postgresql.conf
[root@centos75 ~]#


# systemctl restart postgresql-11


(4) Zabbix 4.2


https://www.zabbix.com/download?zabbix=4.2&os_distribution=centos&os_version=7&db=postgresql

Install Zabbix repository

# rpm -Uvh https://repo.zabbix.com/zabbix/4.2/rhel/7/x86_64/zabbix-release-4.2-1.el7.noarch.rpm

Install Zabbix server, frontend, agent

# yum -y install zabbix-server-pgsql zabbix-web-pgsql zabbix-agent

Create initial database

# sudo -u postgres createuser --pwprompt zabbix
# sudo -u postgres createdb -O zabbix zabbix

Import initial schema and data. You will be prompted to enter your newly created password.

# zcat /usr/share/doc/zabbix-server-pgsql*/create.sql.gz | sudo -u zabbix psql zabbix

========================================

https://www.zabbix.com/documentation/4.2/manual/appendix/install/timescaledb



[root@centos75 zabbix-server-pgsql-4.2.3]# pwd
/usr/share/doc/zabbix-server-pgsql-4.2.3
[root@centos75 zabbix-server-pgsql-4.2.3]# ll
total 2292
-rw-r--r-- 1 root root      98 Jun  7 18:18 AUTHORS
-rw-r--r-- 1 root root 1000750 Jun  7 18:19 ChangeLog
-rw-r--r-- 1 root root   17990 Jun  7 18:18 COPYING
-rw-r--r-- 1 root root 1305981 Jun  7 18:26 create.sql.gz
-rw-r--r-- 1 root root      52 Jun  7 18:18 NEWS
-rw-r--r-- 1 root root    1317 Jun  7 18:19 README
-rw-r--r-- 1 root root     219 Jun  7 18:19 timescaledb.sql.gz
[root@centos75 zabbix-server-pgsql-4.2.3]#

root@centos75 zabbix-server-pgsql-4.2.3]# echo "CREATE EXTENSION IF NOT EXISTS timescaledb CASCADE;" | sudo -u postgres psql zabbix
WARNING:
WELCOME TO
 _____ _                               _     ____________
|_   _(_)                             | |    |  _  \ ___ \
  | |  _ _ __ ___   ___  ___  ___ __ _| | ___| | | | |_/ /
  | | | |  _ ` _ \ / _ \/ __|/ __/ _` | |/ _ \ | | | ___ \
  | | | | | | | | |  __/\__ \ (_| (_| | |  __/ |/ /| |_/ /
  |_| |_|_| |_| |_|\___||___/\___\__,_|_|\___|___/ \____/
               Running version 1.3.1
For more information on TimescaleDB, please visit the following links:

 1. Getting started: https://docs.timescale.com/getting-started
 2. API reference documentation: https://docs.timescale.com/api
 3. How TimescaleDB is designed: https://docs.timescale.com/introduction/architecture

Note: TimescaleDB collects anonymous reports to better understand and assist our users.
For more information and how to disable, please see our docs https://docs.timescaledb.com/using-timescaledb/telemetry.

CREATE EXTENSION
[root@centos75 zabbix-server-pgsql-4.2.3]# zcat /usr/share/doc/zabbix-server-pgsql-4.2.3/timescaledb.sql.gz | sudo -u zabbix psql zabbix
  create_hypertable 
----------------------
 (1,public,history,t)
(1 row)

     create_hypertable   
---------------------------
 (2,public,history_uint,t)
(1 row)

    create_hypertable   
--------------------------
 (3,public,history_log,t)
(1 row)

     create_hypertable   
---------------------------
 (4,public,history_text,t)
(1 row)

    create_hypertable   
--------------------------
 (5,public,history_str,t)
(1 row)

  create_hypertable
---------------------
 (6,public,trends,t)
(1 row)

    create_hypertable   
--------------------------
 (7,public,trends_uint,t)
(1 row)

UPDATE 1
[root@centos75 zabbix-server-pgsql-4.2.3]#




=======================================

Configure the database for Zabbix server

vi  /etc/zabbix/zabbix_server.conf

--> DBPassword=password


Configure PHP for Zabbix frontend

vi /etc/httpd/config.d/zabbix.conf

--> php_value date.timezone Asia/Taipei


Start Zabbix server and agent processes

Start Zabbix server and agent processes and make it start at system boot:

# systemctl restart zabbix-server zabbix-agent httpd
# systemctl enable zabbix-server zabbix-agent httpd

其它參考的 URL

https://www.opensourcetech.tokyo/entry/20190510/1557484230

2019年1月11日 星期五

CentOS7 Pritunl OpenVPN

https://docs.pritunl.com/docs/getting-started

https://docs.pritunl.com/docs/installation

sudo tee /etc/yum.repos.d/mongodb-org-4.0.repo << EOF
[mongodb-org-4.0]
name=MongoDB Repository
baseurl=https://repo.mongodb.org/yum/redhat/7/mongodb-org/4.0/x86_64/
gpgcheck=1
enabled=1
gpgkey=https://www.mongodb.org/static/pgp/server-4.0.asc
EOF

sudo tee /etc/yum.repos.d/pritunl.repo << EOF
[pritunl]
name=Pritunl Repository
baseurl=https://repo.pritunl.com/stable/yum/centos/7/
gpgcheck=1
enabled=1
EOF

sudo rpm -Uvh https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 7568D9BB55FF9E5287D586017AE645C0CF8E292A
gpg --armor --export 7568D9BB55FF9E5287D586017AE645C0CF8E292A > key.tmp; sudo rpm --import key.tmp; rm -f key.tmp
sudo yum -y install pritunl mongodb-org
sudo systemctl start mongod pritunl
sudo systemctl enable mongod pritunl

OpenVPN + 2FA + OTP


2018年9月22日 星期六

zabbix 繁體中文顯示常見問題

Zabbix 繁中支援修改

[root@centos75 include]# pwd
/var/www/html/zabbix/include

[root@centos75 include]# vi locales.inc.php


function getLocales() {
        return [
                'en_GB' => ['name' => _('English (en_GB)'),     'display' => true],
                'en_US' => ['name' => _('English (en_US)'),     'display' => true],
                'bg_BG' => ['name' => _('Bulgarian (bg_BG)'),   'display' => false],
                'zh_CN' => ['name' => _('Chinese (zh_CN)'),     'display' => true],
                'zh_TW' => ['name' => _('Chinese (zh_TW)'),     'display' => true],


=========================================================



Zabbix MAP 支援中文字顯示修改的方式


[root@centos75 fonts]# pwd
/var/www/html/zabbix/fonts

[root@centos75 fonts]# ls -la DejaVuSans.ttf
-rw-r--r-- 1 root root 756072 Sep 15 16:26 DejaVuSans.ttf

[root@centos75 fonts]# file DejaVuSans.ttf
DejaVuSans.ttf: TrueType font data

可以用任一種繁中 TrueType font 去取代  DejaVuSans.ttf 檔案即可

=============================================================

Zabbix MAP 字型大小修改處

[root@centos75 include]# pwd
/var/www/html/zabbix/include
[root@centos75 include]# vi maps.inc.php


imagetext($im, 8, 0,

$dims = imageTextSize(8, 0, $str);

==============================================================

Zabbix interface Traffic count32 count64

http://www.oidview.com/mibs/0/IF-MIB.html

count32

ifInOctets     1.3.6.1.2.1.2.2.1.10
ifOutOctets     1.3.6.1.2.1.2.2.1.16

count64

ifHCOutOctets     1.3.6.1.2.1.31.1.1.1.10
ifHCInOctets     1.3.6.1.2.1.31.1.1.1.6




F5 Using SNMP to view throughput statistics

https://support.f5.com/csp/article/K50309321




2018年7月19日 星期四

line webhook example


webhook.py

#!/bin/python3.6

from flask import Flask, request, abort

from linebot import (
    LineBotApi, WebhookHandler
)
from linebot.exceptions import (
    InvalidSignatureError
)
from linebot.models import (
    MessageEvent, TextMessage, TextSendMessage, ImageSendMessage
)

app = Flask(__name__)

# Channel Access Token
line_bot_api = LineBotApi('XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX=')
# Channel Secret
handler = WebhookHandler('XXXXXXXXXXXXXXXXXXXXX')

@app.route("/callback", methods=['POST'])
def callback():
    # get X-Line-Signature header value
    signature = request.headers['X-Line-Signature']

    # get request body as text
    body = request.get_data(as_text=True)
    app.logger.info("Request body: " +body)

    # handle webhook body
    try:
        handler.handle(body, signature)
    except InvalidSignatureError:
        abort(400)

    return 'OK'



@handler.add(MessageEvent, message=TextMessage)
def handle_message(event):
    message = TextSendMessage(text=event.message.text+" "+event.source.user_id+" ")
    print(message)
    #line_bot_api.reply_message(event.reply_token, message)

import os
if __name__ == "__main__":
    port = int(os.environ.get('PORT', 8888))
    app.run(host='0.0.0.0', port=port)

more example

https://github.com/line/line-bot-sdk-python

Install Python 3.6.X on CentOS 7


Install Python 3.6.X on CentOS 7

=======================================

yum -y install https://centos7.iuscommunity.org/ius-release.rpm
yum -y install python36
yum -y install python36u-devel
yum -y install python36u-libs
yum -y install python36u-pip

pip3.6  install --upgrade pip
pip3.6  install  line-bot-sdk
pip3.6  install  simplejson
pip3.6  install  responses
pip3.6  install  flask

pip3.6 install pyinstaller

=====================================

Python Flask Test

test.py

#!/bin/python3.6

from flask import Flask

app = Flask(__name__)

@app.route("/")
def index():
    return "Hello from FLASK"

if __name__ == "__main__":
    app.run(host='127.0.0.1')

======================================

Apache Proxy Setting

proxy.conf

<VirtualHost *:80>
    <Proxy *>
        Order deny,allow
          Allow from all
    </Proxy>
    ProxyPreserveHost On
    <Location "/test">
          ProxyPass "http:///127.0.0.1:5000"
          ProxyPassReverse "http://127.0.0.1:5000"
    </Location>
</VirtualHost>

===========================================

https://www.pyinstaller.org/

PyInstaller Quickstart
Install PyInstaller from PyPI:

pip install pyinstaller

Go to your program’s directory and run:

pyinstaller yourprogram.py


This will generate the bundle in a subdirectory called dist.

For a more detailed walkthrough, see the manual.

2017年10月20日 星期五

使用 Debian 8.9 去 Build VyOS ISO 小筆記

前導文件:

vyos [ vyatta ]
http://xrcd2.blogspot.tw/2014/09/vyos-vyatta.html

VyOS OpenVpn Plugin OTP ( SOP )
http://xrcd2.blogspot.tw/2015/03/vyos-openvpn-plugin-otp-sop.html

VyOS+OpenVPN+MFA
http://xrcd2.blogspot.tw/2016/09/vyosopenvpnmfa.html


Debian 9(stretch) — 當前的穩定版

https://www.debian.org/releases/

發行版目錄

下一代 Debian 正式發行版的代號為 buster — 發布時間尚未確定
Debian 9(stretch) — 當前的穩定版
Debian 8(jessie) — 被淘汰的穩定版
Debian 7(wheezy) — 被淘汰的穩定版
Debian 6.0(squeeze) — 被淘汰的穩定版


VyOS build 的方式可參考:

https://wiki.vyos.net/wiki/Howto_build_an_ISO_image

1.2.0-beta and newer
The image build scripts for 1.2.0 had been rewritten from scratch to clean up the legacy code and
make it easier to add new features.

The build procedures also got much simpler.

Build host preparation
For building VyOS 1.2.0, the build host should run Debian Jessie. Building on Wheezy or Stretch
is theoretically possible but wasn't tested, you can try it at your own risk.

或

https://github.com/vyos/vyos-build/

===============================

VyOS 官網 https://vyos.io/


這裡選擇使用 Debian 8(jessie)做出 ISO  ( live-image-amd64.hybrid.iso ) ,
使用它去開機即可看到如下畫面:





開機完成後即可以看 vyos login 的登入畫面,如下所示: ( default id/pwd vyos/vyos )






安裝及設定方式可參考如下URL

https://wiki.vyos.net/wiki/Installation
https://wiki.vyos.net/wiki/User_Guide
https://wiki.vyos.net/wiki/OpenVPN

為方便安裝 debian 套件所以必需修改 /etc/apt/sources.list
可參考 https://linuxconfig.org/debian-apt-get-jessie-sources-list


Security Updates

# /etc/apt/sources.list :
deb http://security.debian.org/ jessie/updates main contrib non-free
deb-src http://security.debian.org/ jessie/updates main contrib non-free


Taiwan Mirror

# /etc/apt/sources.list :
deb http://ftp.tw.debian.org/debian/ jessie main contrib non-free
deb-src http://ftp.tw.debian.org/debian/ jessie main contrib non-free


之後下 apt-get update 即可透過  apt-get install 去安裝 google-authenticator

google-authenticator  git url  https://github.com/google/google-authenticator 

#apt-get install libpam-google-authenticator


OpenVPN MFA 的介接設定


root@Test-OTP-VPN-Server:~# cat /etc/pam.d/openvpn

## A B part

auth required    /lib/security/pam_google_authenticator.so   forward_pass
auth required    /lib/x86_64-linux-gnu/security/pam_unix.so  use_first_pass


vyos@Test-OTP-VPN-Server:~$ cat /etc/debian_version
8.9

root@Test-OTP-VPN-Server:~# uname  -ar
Linux Test-OTP-VPN-Server 4.4.47-amd64-vyos #1 SMP Sun Jul 23 11:41:18
EDT 2017 x86_64 GNU/Linux
root@Test-OTP-VPN-Server:~#


vyos@Test-OTP-VPN-Server:~$ show version
Version:          VyOS 999.201709061524
Built by:         root@debian
Built on:         Wed 06 Sep 2017 15:24 UTC
Build ID:         b1b93737-e3ee-459c-9e72-082479727dac

Architecture:     x86_64
Boot via:         installed image
System type:      VMware guest

Hardware vendor:  VMware, Inc.
Hardware model:   VMware Virtual Platform
Hardware S/N:     VMware-42 3a e8 ed 94 81 e8 34-4f c3 a7 33 b3 2a 8a ef
Hardware UUID:    423AE8ED-9481-E834-4FC3-A733B32A8AEF

Copyright:        VyOS maintainers and contributors
vyos@Test-OTP-VPN-Server:~$


vyos@Test-OTP-VPN-Server:~$ show system image
The system currently has the following image(s) installed:

   1: 999.201709061524 (default boot)

vyos@Test-OTP-VPN-Server:~$

OpenVpn MFA 參考設定:

vyos@Test-OTP-VPN-Server:~$ show configuration commands
set interfaces ethernet eth0 address '192.168.1.168/24'
set interfaces ethernet eth0 duplex 'auto'
set interfaces ethernet eth0 hw-id '00:50:56:ba:38:3b'
set interfaces ethernet eth0 smp-affinity 'auto'
set interfaces ethernet eth0 speed 'auto'
set interfaces loopback 'lo'
set interfaces openvpn vtun0 encryption 'aes128'
set interfaces openvpn vtun0 hash 'sha1'
set interfaces openvpn vtun0 local-port '1194'
set interfaces openvpn vtun0 mode 'server'
set interfaces openvpn vtun0 openvpn-option '--reneg-sec 0
                                                --duplicate-cn --comp-lzo
                                               --script-security 2
                                               --plugin  /usr/lib/openvpn/openvpn-plugin-auth-pam.so
                                                openvpn
                                          --username-as-common-name'
set interfaces openvpn vtun0 protocol 'tcp-passive'
set interfaces openvpn vtun0 server push-route '192.168.1.0/24'
set interfaces openvpn vtun0 server push-route '192.168.2.0/24'
set interfaces openvpn vtun0 server subnet '192.168.168.0/28'
set interfaces openvpn vtun0 tls ca-cert-file '/config/auth/keys/ca.crt'
set interfaces openvpn vtun0 tls cert-file '/config/auth/keys/vpn-server.crt'
set interfaces openvpn vtun0 tls dh-file '/config/auth/keys/dh1024.pem'
set interfaces openvpn vtun0 tls key-file '/config/auth/keys/vpn-server.key'
set nat source rule 10 destination address '0.0.0.0/0'
set nat source rule 10 outbound-interface 'eth0'
set nat source rule 10 protocol 'all'
set nat source rule 10 source address '192.168.170.0/28'
set nat source rule 10 translation address 'masquerade'
set protocols static route 0.0.0.0/0 next-hop '192.168.1.202'
set service ssh port '22'
set system config-management commit-revisions '20'
set system console device ttyS0 speed '9600'
set system host-name 'Test-OTP-VPN-Server'
set system login user vyos authentication encrypted-password 'XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX'
set system login user vyos authentication plaintext-password ''
set system login user vyos level 'admin'
set system name-server '168.95.1.1'
set system name-server '168.95.192.1'
set system ntp server '168.95.195.12'
set system syslog global facility all level 'notice'
set system syslog global facility protocols level 'debug'
set system time-zone 'Asia/Taipei'


PC 的 client.ovpn  參考設定


client
dev tun
proto tcp
remote xxx.xxx.xxx.xxx 1194
ca ca.crt
cert client.crt
key client.key
resolv-retry infinite
nobind
persist-key
persist-tun
ns-cert-type server
cipher AES-128-CBC
comp-lzo
verb 3
route-method exe
route-delay 2
auth-user-pass
reneg-sec 0
keepalive 10 120
auth-nocache
inactive 600

2017年9月21日 星期四

cacti plugin thold + Line API Alert




 cacti 0.8.x  + setting plugin (0.71)

# vi /var/www/html/cacti/plugins/settings/include/functions.php

function send_mail($to, $from, $subject, $message, $filename = '', $headers = '') {
....
.....

       // Line API plugin here

        return '';

}

## thold (0.5)

# vi /var/www/html/cacti/plugins/thold/thold_functions.php


function thold_mail($to, $from, $subject, $message, $filename, $headers = '') {
....
.....

       // Line API plugin here

        return '';
}


======================================================

cacti 1.1.x

# vi /var/www/html/cacti/lib/functions.php


function send_mail($to, $from, $subject, $body, $attachments = '', $headers = '', $html = false) {
....
...

// Line API plugin here

        return mailer($from, $to, '', '', '', $subject, $body, '', $attachments, $headers, $html);
}


## thold (1.0.x)


# vi /var/www/html/cacti/plugins/thold/thold_functions.php



function thold_mail($to_email, $from_email, $subject, $message, $filename, $headers = '') {
.......
....

// Line API plugin here

        return '';
}


參考資訊

如何做出 cacti plugin manager + Line API Alert
http://xrcd2.blogspot.tw/2017/01/cacti-plugin-manager-line-api-alert.html

使用 Perl 建立 Line API 運用環境
http://xrcd2.blogspot.tw/2016/12/perl-line-api.html

Line API 使用小筆記
http://www.vlab.com.tw/index.php/forum/21/15572-line-api

本 LAB 參考資訊

CACTI Alert 增加 LineNotify
http://penguinbbs.blogspot.tw/2017/08/cacti-alert-linenotify.html



Demo






















Demo2




2017年8月9日 星期三

2017年8月7日 星期一

Perl for Windows

Perl for windows

依據 https://www.perl.org/ 這裡的介紹,我們可以知道 Perl 可以在不同的平台上使用,
如 AIX/Solaris/Linux/FreeBSD/Windows/MAC OS.....

但在 Windows 平台上並沒有內建 Perl 的,所以得另外安裝,目前較多人使用有:

Strawberry Perl ( http://strawberryperl.com/ )

ActivePerl ( https://www.activestate.com/activeperl )

以 ActivePerl 為例可透過 ppm 去安裝 perl module ,
ppm 是一個 Windows UI 介面的安裝
如下圖中的 ActivePerl  為 5.20.2 (目前官網上已有更新至其它較新版本)

Microsoft Windows [版本 6.1.7601]
Copyright (c) 2009 Microsoft Corporation.  All rights reserved.

C:\Users\user>perl -v

This is perl 5, version 20, subversion 2 (v5.20.2) built for MSWin32-x86-multi-thread-64int
(with 1 registered patch, see perl -V for more detail)

Copyright 1987-2015, Larry Wall

Binary build 2001 [298913] provided by ActiveState http://www.ActiveState.com
Built Mar 19 2015 15:26:52

Perl may be copied only under the terms of either the Artistic License or the
GNU General Public License, which may be found in the Perl 5 source kit.

Complete documentation for Perl, including FAQ lists, should be found on
this system using "man perl" or "perldoc perl".  If you have access to the
Internet, point your browser at http://www.perl.org/, the Perl Home Page.


C:\Users\user>


另外 如使用  Strawberry Perl  則可使用 cpan or cpanm 去安裝,
下面 Demo 為  Strawberry Perl ( 5.26.0 )

Microsoft Windows [版本 6.3.9600]
(c) 2013 Microsoft Corporation. All rights reserved.

C:\Windows\system32>perl -v

This is perl 5, version 26, subversion 0 (v5.26.0) built for MSWin32-x86-multi-thread-64int

Copyright 1987-2017, Larry Wall

Perl may be copied only under the terms of either the Artistic License or the
GNU General Public License, which may be found in the Perl 5 source kit.

Complete documentation for Perl, including FAQ lists, should be found on
this system using "man perl" or "perldoc perl".  If you have access to the
Internet, point your browser at http://www.perl.org/, the Perl Home Page.


C:\Windows\system32>cpanm
Usage: cpanm [options] Module [...]

Try `cpanm --help` or `man cpanm` for more options.

C:\Windows\system32>cpanm LINE::Bot::API
--> Working on LINE::Bot::API
Fetching http://www.cpan.org/authors/id/Y/YA/YAPPO/LINE-Bot-API-1.04.tar.gz ...
OK
Configuring LINE-Bot-API-1.04 ... OK
==> Found dependencies: Furl
--> Working on Furl
Fetching http://www.cpan.org/authors/id/T/TO/TOKUHIROM/Furl-3.11.tar.gz ... OK
Configuring Furl-3.11 ... OK
==> Found dependencies: HTTP::Parser::XS, Test::TCP
--> Working on HTTP::Parser::XS
Fetching http://www.cpan.org/authors/id/K/KA/KAZUHO/HTTP-Parser-XS-0.17.tar.gz .
.. OK
Configuring HTTP-Parser-XS-0.17 ... OK
Building and testing HTTP-Parser-XS-0.17 ... OK
Successfully installed HTTP-Parser-XS-0.17
--> Working on Test::TCP
Fetching http://www.cpan.org/authors/id/T/TO/TOKUHIROM/Test-TCP-2.19.tar.gz ...
OK
Configuring Test-TCP-2.19 ... OK
==> Found dependencies: Test::SharedFork
--> Working on Test::SharedFork
Fetching http://www.cpan.org/authors/id/E/EX/EXODIST/Test-SharedFork-0.35.tar.gz
 ... OK
Configuring Test-SharedFork-0.35 ... OK
Building and testing Test-SharedFork-0.35 ... OK
Successfully installed Test-SharedFork-0.35
Building and testing Test-TCP-2.19 ... O
......
.........

這要看個人喜愛,這2個都不錯...


當然  ActivePerl  也是可以在 CLI 下 ppm install 去裝 Perl module 如下 Demo...

C:\Perl\bin>ppm install LINE-Bot-API
Downloading LINE-Bot-API-1.04...done
Downloading Furl-3.08...done
Downloading JSON-XS-3.03...done
Downloading HTTP-Parser-XS-0.17...done
Downloading Class-Accessor-Lite-0.08...done
Downloading common-sense-3.74...done
Downloading Types-Serialiser-1.0...done
Unpacking LINE-Bot-API-1.04...done
Unpacking Furl-3.08...done
Unpacking JSON-XS-3.03...done
Unpacking HTTP-Parser-XS-0.17...done
Unpacking Class-Accessor-Lite-0.08...done
Unpacking common-sense-3.74...done
Unpacking Types-Serialiser-1.0...done
Generating HTML for LINE-Bot-API-1.04...done
Generating HTML for Furl-3.08...done
Generating HTML for JSON-XS-3.03...done
Generating HTML for HTTP-Parser-XS-0.17...done
Generating HTML for Class-Accessor-Lite-0.08...done
Generating HTML for common-sense-3.74...done
Generating HTML for Types-Serialiser-1.0...done
Updating files in site area...done
  54 files installed

C:\Perl\bin>


2017年7月19日 星期三

Zabbix 3.0.x 整合 Line Alert 圖解



Zabbix 3.0.x 整合 Line Alert 圖解,下方有 Perl 的範例程式,可供參考,
使用其的慣用程式也行,至於 Line API 的使用方式可參考下面的其它參考資訊,
或見 https://github.com/line





































































Demo



























其它參考資訊

http://xrcd2.blogspot.tw/2016/12/perl-line-api.html
http://xrcd2.blogspot.tw/2017/07/line-api-emoticons.html

Demo Perl Shell:

[root@CentOS73 shell]# pwd
/usr/local/zabbix/shell
[root@CentOS73 shell]# cat line.pl
#!/usr/local/perl-5.26/bin/perl
# Line
#recipient = sys.argv[1]  $ARGV[0]
#subject = sys.argv[2]    $ARGV[1]
#body = sys.argv[3]       $ARGV[2]

$myid="$ARGV[0]";
$subj="$ARGV[1]";
$body="$ARGV[2]";

use LINE::Bot::API;
use LINE::Bot::API::Builder::SendMessage;
$bot = LINE::Bot::API->new(
 channel_secret => 'xxxxxxxxxxxxxxxxxxxxxxxxxxx',
 channel_access_token => 'xxxxxxxxxxxxxxxxxxxxxx',
);

$messages = LINE::Bot::API::Builder::SendMessage->new;
$messages->add_text( text => "$subj \r\n \r\n $body " );
$bot->push_message($myid, $messages->build);
[root@CentOS73 shell]#


2017年7月14日 星期五

line API emoticons 試用

為解一個 line API 傳送文字的限制,在官網上看到的資訊,
順便玩玩這個  emoticons 功能.
官網上的 URL 為 https://devdocs.line.me/en/#send-message-object

Send message object

JSON object which contains the contents of the message you send.

Text
Image
Video
Audio
Location
Sticker
Imagemap
Template
Text

Text example
{
    "type": "text",
    "text": "Hello, world"
}
Field Type Required Description
type String Yes text
text String Yes Message text
Max: 2000 characters
Text example with emoticon

{
    "type": "text",
    "text": "Hello, world 􀂲"
}
You can include emoticons in your message text. Because emoticons are
a part of Unicode, they must be converted from their character codes.
Note that the character code, 0x1000B2, is used in the example on the
right. Although the emoticon does not show up correctly in the browser,
it will show up in LINE.
For a list of emoticons that can be sent with the Messaging API,
see emoticon list.

https://devdocs.line.me/files/emoticon.pdf

perl 的用法可參考
http://www.drdobbs.com/web-development/unicode-in-perl/184416148 
及
https://github.com/patch-orphan/text-emoticon-unicode-pm5


加上 https://github.com/line/line-bot-sdk-perl

所以可以加以變化成 如下的程式.....

[root@CentOS73 bin]# cat Send-Line-Message.pl
#!/usr/local/perl-5.26/bin/perl
use LINE::Bot::API;
use LINE::Bot::API::Builder::SendMessage;

$bot = LINE::Bot::API->new(
    channel_secret       => 'xxxxxxxxxxxxxxxxxxxxxxxxx',
    channel_access_token => 'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx=',
);


use Text::Emoticon;
$emoticon = Text::Emoticon->new('Unicode');
$msg = $emoticon->filter('Howdy :) :( ');


$ToLineUid = 'Uxxxxxxxxxxxxxxxxxxxxxxxxxxxx';


$messages = LINE::Bot::API::Builder::SendMessage->new;
$messages->add_text( text => "Example push text \r\n $msg \x{1F480}" );
$bot->push_message($ToLineUid, $messages->build);
[root@CentOS73 bin]#

Demo



其它參考資訊

http://unicode.org/emoji/charts/full-emoji-list.html

http://xrcd2.blogspot.tw/2016/12/perl-line-api.html