Skip to content

Fix file log sink: zerolog events were never written - #1069

Merged
javuto merged 1 commit into
developfrom
fix-zerolog-events-written
Oct 1, 2026
Merged

javuto merged 1 commit into
developfrom
fix-zerolog-events-written

Conversation

@javuto

@javuto javuto commented Oct 1, 2026

Copy link
Copy Markdown
Collaborator

Fix file log sink: zerolog events were never written

Fixes #1068

Problem

With a file log sink, osctrl-tls silently dropped all osquery status, result, and on-demand query logs. The sink's target file was never created, while the log_sinks counters (exports_count, bytes_sent) kept incrementing — making the sink appear healthy from the UI.

Status, Result, and Query in pkg/logging/file.go each built a zerolog event chain but never called a terminal method (.Msg() / .Send()), so zerolog discarded every event before it reached the lumberjack writer (which creates the file lazily on first write). The stdout sink works because it uses Msgf — hence the copy-paste artifacts in this file's comments and debug message that also said "stdout".

Behavioral change

  • Terminal .Send() added to the event chain in Status, Result, and Query, so status, scheduled results, and on-demand query results are now written as JSON lines (metadata + RawJSON payload) to the configured file.
  • The file sink's debug trace and doc comments corrected from "stdout" to "file" to aid diagnosis.
  • No interface, route, schema, or configuration changes; additive and reversible. Other sinks are untouched.

Security / operational impact

  • Data loss: deployments on v0.5.9 with logger.type: file have been silently losing those logs; they cannot be recovered, but upgrading restores writes going forward.
  • Diagnostics: CountedExporter increments bytes_sent/exports_count before the inner export, so the counters count attempts, not deliveries — they cannot be trusted as a health signal for this sink. (Pre-existing; not addressed here.)
  • No authentication/authorization, TLS handler, or MCP surface changes.

Testing

New regression test pkg/logging/file_test.go:

  • Reproduces the issue — fails on main before the fix (file sink wrote nothing: file not created), passes after.
  • Exercises status + result via Log and a query via Export, asserting the file exists with 3 valid JSON lines carrying the expected type, environment, uuid, and inlined data payload.

Validation performed:

  • go test ./pkg/logging/ — all pass
  • go build ./...
  • go vet ./pkg/logging/
  • gofmt clean

@javuto javuto added osctrl-tls osctrl-tls related changes 🗄️ logging Logging related issues 🚧 bugfix Fix for an existing bug labels Oct 1, 2026
@javuto
javuto merged commit d8bd93f into develop Oct 1, 2026
7 checks passed
@javuto
javuto deleted the fix-zerolog-events-written branch October 1, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

🚧 bugfix Fix for an existing bug 🗄️ logging Logging related issues osctrl-tls osctrl-tls related changes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

File log sink never writes: LoggerFile builds zerolog events without sending them

1 participant