Documentation
¶
Overview ¶
Package logql implements the LogQL subset published in docs/logql-subset.md without Loki code.
Index ¶
- Constants
- func InjectScope(query string, m []*labels.Matcher) (string, error)
- func ToLogsQL(query string) (string, error)
- type AggOp
- type BinaryExpr
- type BinaryOp
- type BudgetError
- type CompareOp
- type Direction
- type Expr
- type Grouping
- type JSONParam
- type JSONStage
- type LabelFilter
- type LabelFilterBinary
- type LabelFilterNumeric
- type LabelFilterStage
- type LabelFilterString
- type Limits
- type Line
- type LineFilter
- type LineFilterOp
- type LineSource
- type LineSourceFunc
- type Lines
- type LogExpr
- type LogfmtStage
- type NumberLiteral
- type NumericKind
- type ParseError
- type PatternStage
- type PipelineError
- type Program
- func (p *Program) Eval(ts time.Time) (promql.Vector, error)
- func (p *Program) Expr() Expr
- func (p *Program) Matches(streamLabels map[string]string) bool
- func (p *Program) MemoryBytes() int
- func (p *Program) Observe(streamLabels map[string]string, ts time.Time, line string) (matched bool)
- func (p *Program) Status() Status
- func (p *Program) Window() time.Duration
- type RangeAggregation
- type RangeOp
- type RegexpStage
- type Result
- type ResultLine
- type ResultType
- type SourceRequest
- type Stage
- type Status
- type TranslationError
- type UnsupportedError
- type VectorAggregation
Constants ¶
const ( DefaultMaxLines = 1000 DefaultMaxBytes = 1 << 20 DefaultQuerySeries = 500 DefaultMaxSamples = 50000 )
Default investigation limits, applied when a Limits field is zero.
const ( LimitLines = "max_lines" LimitBytes = "max_bytes" LimitSeries = "max_series" LimitSamples = "max_samples" LimitTimeout = "timeout" )
Truncation reasons reported in Result.Limited.
const ( // DefaultMaxSeries bounds rule counter cardinality when the budget sets none. DefaultMaxSeries = 1000 // DefaultCounterBytes is the rule counter memory budget when the budget sets none. DefaultCounterBytes = 4 << 20 )
const LogsQLValueField = "value"
LogsQLValueField is the field holding the sample value in translated metric queries.
const SubsetDoc = "docs/logql-subset.md"
SubsetDoc is the published reference for the supported grammar.
Variables ¶
This section is empty.
Functions ¶
func InjectScope ¶
InjectScope ANDs m into every stream selector of the parsed query and re-serializes it; nothing is replaced.
Types ¶
type BinaryExpr ¶
BinaryExpr applies Op between a vector and a scalar or two scalars.
func (*BinaryExpr) String ¶
func (e *BinaryExpr) String() string
type BudgetError ¶
BudgetError reports a rule whose counters cannot fit its memory budget.
func (*BudgetError) Error ¶
func (e *BudgetError) Error() string
type Expr ¶
type Expr interface {
String() string
// contains filtered or unexported methods
}
Expr is a parsed LogQL expression. String returns the canonical form, which re-parses to an identical AST.
type JSONStage ¶
type JSONStage struct {
Params []JSONParam
}
JSONStage is the json parser, extracting all fields or only Params.
type LabelFilter ¶
type LabelFilter interface {
String() string
// contains filtered or unexported methods
}
LabelFilter is a label filter expression.
type LabelFilterBinary ¶
type LabelFilterBinary struct {
Or bool
Left, Right LabelFilter
}
LabelFilterBinary combines two label filters with and (Or false) or or (Or true).
func (*LabelFilterBinary) String ¶
func (f *LabelFilterBinary) String() string
type LabelFilterNumeric ¶
type LabelFilterNumeric struct {
Name string
Op CompareOp
Kind NumericKind
Value float64
}
LabelFilterNumeric compares a label parsed as Kind with Value (nanoseconds for durations, bytes for sizes).
func (*LabelFilterNumeric) String ¶
func (f *LabelFilterNumeric) String() string
type LabelFilterStage ¶
type LabelFilterStage struct {
Filter LabelFilter
}
LabelFilterStage filters lines by labels.
func (*LabelFilterStage) String ¶
func (s *LabelFilterStage) String() string
type LabelFilterString ¶
LabelFilterString compares a label with a string matcher.
func (*LabelFilterString) String ¶
func (f *LabelFilterString) String() string
type Limits ¶
type Limits struct {
Start, End time.Time
// Step selects a range metric query; zero evaluates a metric query at End only.
Step time.Duration
Direction Direction
MaxLines int
MaxBytes int
MaxSeries int
MaxSamples int
Timeout time.Duration
}
Limits bounds an investigation query (PRD I3). Start and End are required.
type LineFilter ¶
type LineFilter struct {
Op LineFilterOp
Match string
}
LineFilter keeps lines containing (or matching) Match.
func (*LineFilter) String ¶
func (f *LineFilter) String() string
type LineFilterOp ¶
type LineFilterOp string
LineFilterOp is a line filter operator.
const ( LineContains LineFilterOp = "|=" LineNotContains LineFilterOp = "!=" LineMatchRegexp LineFilterOp = "|~" LineNotRegexp LineFilterOp = "!~" )
type LineSource ¶
type LineSource interface {
Scan(ctx context.Context, req SourceRequest, yield func(Line) bool) error
}
LineSource streams candidate lines in any order; yield returning false stops the scan.
type LineSourceFunc ¶
LineSourceFunc adapts a function to LineSource.
func (LineSourceFunc) Scan ¶
func (f LineSourceFunc) Scan(ctx context.Context, req SourceRequest, yield func(Line) bool) error
Scan calls f.
type LogfmtStage ¶
type LogfmtStage struct{}
LogfmtStage is the logfmt parser.
func (*LogfmtStage) String ¶
func (*LogfmtStage) String() string
type NumberLiteral ¶
type NumberLiteral struct {
Value float64
}
NumberLiteral is a scalar literal.
func (*NumberLiteral) String ¶
func (e *NumberLiteral) String() string
type NumericKind ¶
type NumericKind string
NumericKind selects how a numeric label filter parses label values.
const ( NumericNumber NumericKind = "number" NumericDuration NumericKind = "duration" NumericBytes NumericKind = "bytes" )
type ParseError ¶
ParseError reports malformed input at a byte offset.
func (*ParseError) Error ¶
func (e *ParseError) Error() string
type PatternStage ¶
type PatternStage struct {
Pattern string
}
PatternStage is the pattern parser.
func (*PatternStage) String ¶
func (s *PatternStage) String() string
type PipelineError ¶
type PipelineError struct {
Err string
}
PipelineError reports samples carrying __error__ in a metric evaluation, as Loki does.
func (*PipelineError) Error ¶
func (e *PipelineError) Error() string
type Program ¶
type Program struct {
// contains filtered or unexported fields
}
Program is a compiled LogQL rule evaluated over per-series time-bucketed counters; lines are never retained.
func CompileRule ¶
CompileRule validates a metric query against the subset and its counter budget.
func (*Program) Eval ¶
Eval computes the rule expression over the counters in the window ending at ts.
func (*Program) Matches ¶
Matches reports whether a stream is selected by the rule, for the tailer's stream filter.
func (*Program) MemoryBytes ¶
MemoryBytes is the counter memory reserved for the rule at its cardinality bound.
func (*Program) Observe ¶
Observe applies the pipeline to one line and counts it; the line is never retained.
type RangeAggregation ¶
RangeAggregation aggregates a log query over a range window.
func (*RangeAggregation) String ¶
func (e *RangeAggregation) String() string
type RegexpStage ¶
type RegexpStage struct {
Pattern string
}
RegexpStage is the regexp parser.
func (*RegexpStage) String ¶
func (s *RegexpStage) String() string
type Result ¶
type Result struct {
Type ResultType
Lines []ResultLine
Vector promql.Vector
Matrix promql.Matrix
Start, End time.Time
Step time.Duration
Truncated bool
Limited []string
ScannedLines int64
ScannedBytes int64
ResultBytes int
}
Result is a bounded investigation result; Truncated is set with the limits that cut it.
type ResultLine ¶
ResultLine is one matching line with its stream and extracted labels.
type ResultType ¶
type ResultType string
ResultType is the shape of a query result.
const ( ResultStreams ResultType = "streams" ResultVector ResultType = "vector" ResultMatrix ResultType = "matrix" )
type SourceRequest ¶
SourceRequest names the streams and the inclusive time range a query can use.
type Stage ¶
type Stage interface {
String() string
// contains filtered or unexported methods
}
Stage is one pipeline stage.
type Status ¶
type Status struct {
Series int
MaxSeries int
// LiveBytes is the counter bucket memory in use; LabelBytes is the size of the series keys.
LiveBytes int
LabelBytes int
// DroppedLines counts matched lines not counted because their series exceeded MaxSeries.
DroppedLines uint64
// LateLines counts matched lines older than the counter window.
LateLines uint64
LastDrop time.Time
// BudgetLimited is true while a cardinality drop lies within the current window.
BudgetLimited bool
}
Status reports counter usage and budget-limited drops (PRD R9).
type TranslationError ¶
TranslationError reports a LogQL construct without an exact LogsQL mapping.
func (*TranslationError) Error ¶
func (e *TranslationError) Error() string
type UnsupportedError ¶
UnsupportedError reports a valid LogQL construct outside the published subset.
func (*UnsupportedError) Error ¶
func (e *UnsupportedError) Error() string
type VectorAggregation ¶
VectorAggregation aggregates a vector; Param is k for topk.
func (*VectorAggregation) String ¶
func (e *VectorAggregation) String() string