systemd

package
v0.13.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Nov 12, 2025 License: MIT Imports: 11 Imported by: 0

Documentation

Overview

Package systemd manages systemd journal entries for Hive.

Index

Constants

View Source
const EventType = "net.gbenson.hive.systemd_journal_event"

EventType is the CloudEvent type of systemd journal entries published to EventsQueue.

View Source
const EventsQueue = "systemd.journal.events"

EventsQueue is where log collectors publish system journal entries they collect.

Variables

This section is empty.

Functions

This section is empty.

Types

type DigestError

type DigestError struct {
	Got, Want string
}

A checksum failed.

func (*DigestError) Error

func (e *DigestError) Error() string

type JournalEntry

type JournalEntry struct {
	// Digest of Fields plus the two timestamp address fields.
	Digest string `json:"digest,omitempty"`

	// systemd address fields that sdjournal moves out of line.
	// Both are in **microseconds** since the epoch.
	RealtimeTimestamp  uint64 `json:"realtime_usec" bson:"realtime_us"`
	MonotonicTimestamp uint64 `json:"monotonic_usec" bson:"monotonic_us"`

	// Hive collection and ingestion timestamps.
	// These are in **nanoseconds** since the epoch.
	CollectionTimestamp int64 `json:"collected_nsec,omitempty" bson:"hive_collect_time_ns"`
	IngestionTimestamp  int64 `json:"ingested_nsec,omitempty" bson:"hive_ingest_time_ns"`

	// All fields of a journal entry, less outlined address fields, as defined in
	// https://www.freedesktop.org/software/systemd/man/latest/systemd.journal-fields.html.
	// Note that fields prefixed with an underscore are systemd _trusted fields_
	// added by systemd on the originating host.  Note that it's _systemd_ doing
	// the trusting.
	Fields map[string]string `json:"fields"`
}

JournalEntry represents a systemd journal entry plus address fields.

func UnmarshalEvent

func UnmarshalEvent(event *messaging_event.Event) (*JournalEntry, error)

UnmarshalEvent unmarshals a messaging_event.Event into a JournalEntry.

func (*JournalEntry) Blake2b256Digest

func (e *JournalEntry) Blake2b256Digest() string

Blake2b256Digest returns the string-encoded BLAKE2b-256 digest of Fields, including the address field timestamps systemd moved out of line: everything the log collector read from the journal except the cursor which is dropped before forwarding.

func (*JournalEntry) Command

func (e *JournalEntry) Command() string

Command returns the name of the process this journal entry originates from. Generally this will be the name you see in top, so mostly lowercase alphanumeric with the occasional random one in parentheses.

func (*JournalEntry) ContainerName

func (e *JournalEntry) ContainerName() string

ContainerName returns the name of the container the originating process is running in. Docker sets this, maybe others too. Will be empty if the originating process isn't in a container, or if the originating process is in a container managed by an engine we don't yet handle.

func (*JournalEntry) Hostname

func (e *JournalEntry) Hostname() string

Hostname returns the name of the originating host.

func (*JournalEntry) ID

func (e *JournalEntry) ID() string

ID returns an opaque string that can be used to uniquely identify this event.

func (*JournalEntry) MarshalEvent

func (entry *JournalEntry) MarshalEvent() (*messaging_event.Event, error)

MarshalEvent implements the messaging_event.Marshaler interface.

func (*JournalEntry) Message

func (e *JournalEntry) Message() Message

Message returns the human-readable text of this entry, as supplied by the originating process. It's supposed to be the primary text shown to the user. Note that newline characters are permitted. Expect to find ANSI control sequences too.

func (*JournalEntry) Priority

func (e *JournalEntry) Priority() Priority

Priority returns the RFC 5424 syslog severity level of this event, as reported by the originating process. This isn't always present or useful, e.g. entries from processes in Docker containers are reported as PriInfo if collected from stdout or PriErr if reported on stderr, so the reported priority may well not line up with the content of the message.

func (*JournalEntry) Time

func (e *JournalEntry) Time() time.Time

Time returns the wallclock time of the originating host at the point in time the entry was received by the systemd journal. It has microsecond granularity.

func (*JournalEntry) UnmarshalEvent

func (entry *JournalEntry) UnmarshalEvent(event *messaging_event.Event) error

UnmarshalEvent implements the messaging_event.Unarshaler interface.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL