Documentation
¶
Overview ¶
Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares.
Index ¶
- Constants
- type Ring
- func (r *Ring) Add(ruleID string, s Sample) bool
- func (r *Ring) Limited(ruleID string) bool
- func (r *Ring) LimitedRules() []string
- func (r *Ring) Peek(ruleID string, n int) []Sample
- func (r *Ring) SetRules(weights map[string]float64)
- func (r *Ring) Stats() Stats
- func (r *Ring) Take(ruleID string, n int) ([]Sample, bool)
- type RuleStats
- type Sample
- type Stats
Constants ¶
View Source
const DefaultCeiling = 16 << 20
DefaultCeiling is the per-node ring size.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Ring ¶
type Ring struct {
// contains filtered or unexported fields
}
Ring is safe for concurrent use.
func (*Ring) LimitedRules ¶
LimitedRules lists evidence-limited rules in order.
func (*Ring) Peek ¶
Peek returns a rule's newest n samples without removing them (investigation reads, PRD I1).
type RuleStats ¶
type RuleStats struct {
Weight float64
Bytes int64
Samples int
Evicted uint64
Rejected uint64
// Limited is sticky while the rule is active: some of its evidence was evicted or rejected.
Limited bool
}
RuleStats describes one rule's share.
Click to show internal directories.
Click to hide internal directories.