Fix file log sink: zerolog events were never written - #1069
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fix file log sink: zerolog events were never written
Fixes #1068
Problem
With a
filelog sink,osctrl-tlssilently dropped all osquery status, result, and on-demand query logs. The sink's target file was never created, while thelog_sinkscounters (exports_count,bytes_sent) kept incrementing — making the sink appear healthy from the UI.Status,Result, andQueryinpkg/logging/file.goeach built azerologevent chain but never called a terminal method (.Msg()/.Send()), so zerolog discarded every event before it reached the lumberjack writer (which creates the file lazily on first write). The stdout sink works because it usesMsgf— hence the copy-paste artifacts in this file's comments and debug message that also said "stdout".Behavioral change
.Send()added to the event chain inStatus,Result, andQuery, so status, scheduled results, and on-demand query results are now written as JSON lines (metadata +RawJSONpayload) to the configured file.Security / operational impact
logger.type: filehave been silently losing those logs; they cannot be recovered, but upgrading restores writes going forward.CountedExporterincrementsbytes_sent/exports_countbefore the inner export, so the counters count attempts, not deliveries — they cannot be trusted as a health signal for this sink. (Pre-existing; not addressed here.)Testing
New regression test
pkg/logging/file_test.go:mainbefore the fix (file sink wrote nothing: file not created), passes after.Logand a query viaExport, asserting the file exists with 3 valid JSON lines carrying the expectedtype,environment,uuid, and inlineddatapayload.Validation performed:
go test ./pkg/logging/— all passgo build ./...go vet ./pkg/logging/gofmtclean