Documentation
¶
Overview ¶
Package systemd manages systemd journal entries for Hive.
Index ¶
- Constants
- type DigestError
- type JournalEntry
- func (e *JournalEntry) Blake2b256Digest() string
- func (e *JournalEntry) Command() string
- func (e *JournalEntry) ContainerName() string
- func (e *JournalEntry) Hostname() string
- func (e *JournalEntry) ID() string
- func (entry *JournalEntry) MarshalEvent() (*messaging_event.Event, error)
- func (e *JournalEntry) Message() Message
- func (e *JournalEntry) Priority() Priority
- func (e *JournalEntry) Time() time.Time
- func (entry *JournalEntry) UnmarshalEvent(event *messaging_event.Event) error
Constants ¶
const EventType = "net.gbenson.hive.systemd_journal_event"
EventType is the CloudEvent type of systemd journal entries published to EventsQueue.
const EventsQueue = "systemd.journal.events"
EventsQueue is where log collectors publish system journal entries they collect.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type DigestError ¶
type DigestError struct {
Got, Want string
}
A checksum failed.
func (*DigestError) Error ¶
func (e *DigestError) Error() string
type JournalEntry ¶
type JournalEntry struct {
// Digest of Fields plus the two timestamp address fields.
Digest string `json:"digest,omitempty"`
// systemd address fields that sdjournal moves out of line.
// Both are in **microseconds** since the epoch.
RealtimeTimestamp uint64 `json:"realtime_usec" bson:"realtime_us"`
MonotonicTimestamp uint64 `json:"monotonic_usec" bson:"monotonic_us"`
// Hive collection and ingestion timestamps.
// These are in **nanoseconds** since the epoch.
CollectionTimestamp int64 `json:"collected_nsec,omitempty" bson:"hive_collect_time_ns"`
IngestionTimestamp int64 `json:"ingested_nsec,omitempty" bson:"hive_ingest_time_ns"`
// All fields of a journal entry, less outlined address fields, as defined in
// https://www.freedesktop.org/software/systemd/man/latest/systemd.journal-fields.html.
// Note that fields prefixed with an underscore are systemd _trusted fields_
// added by systemd on the originating host. Note that it's _systemd_ doing
// the trusting.
Fields map[string]string `json:"fields"`
}
JournalEntry represents a systemd journal entry plus address fields.
func UnmarshalEvent ¶
func UnmarshalEvent(event *messaging_event.Event) (*JournalEntry, error)
UnmarshalEvent unmarshals a messaging_event.Event into a JournalEntry.
func (*JournalEntry) Blake2b256Digest ¶
func (e *JournalEntry) Blake2b256Digest() string
Blake2b256Digest returns the string-encoded BLAKE2b-256 digest of Fields, including the address field timestamps systemd moved out of line: everything the log collector read from the journal except the cursor which is dropped before forwarding.
func (*JournalEntry) Command ¶
func (e *JournalEntry) Command() string
Command returns the name of the process this journal entry originates from. Generally this will be the name you see in top, so mostly lowercase alphanumeric with the occasional random one in parentheses.
func (*JournalEntry) ContainerName ¶
func (e *JournalEntry) ContainerName() string
ContainerName returns the name of the container the originating process is running in. Docker sets this, maybe others too. Will be empty if the originating process isn't in a container, or if the originating process is in a container managed by an engine we don't yet handle.
func (*JournalEntry) Hostname ¶
func (e *JournalEntry) Hostname() string
Hostname returns the name of the originating host.
func (*JournalEntry) ID ¶
func (e *JournalEntry) ID() string
ID returns an opaque string that can be used to uniquely identify this event.
func (*JournalEntry) MarshalEvent ¶
func (entry *JournalEntry) MarshalEvent() (*messaging_event.Event, error)
MarshalEvent implements the messaging_event.Marshaler interface.
func (*JournalEntry) Message ¶
func (e *JournalEntry) Message() Message
Message returns the human-readable text of this entry, as supplied by the originating process. It's supposed to be the primary text shown to the user. Note that newline characters are permitted. Expect to find ANSI control sequences too.
func (*JournalEntry) Priority ¶
func (e *JournalEntry) Priority() Priority
Priority returns the RFC 5424 syslog severity level of this event, as reported by the originating process. This isn't always present or useful, e.g. entries from processes in Docker containers are reported as PriInfo if collected from stdout or PriErr if reported on stderr, so the reported priority may well not line up with the content of the message.
func (*JournalEntry) Time ¶
func (e *JournalEntry) Time() time.Time
Time returns the wallclock time of the originating host at the point in time the entry was received by the systemd journal. It has microsecond granularity.
func (*JournalEntry) UnmarshalEvent ¶
func (entry *JournalEntry) UnmarshalEvent(event *messaging_event.Event) error
UnmarshalEvent implements the messaging_event.Unarshaler interface.