evidence

package
v0.16.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 4, 2026 License: Apache-2.0 Imports: 5 Imported by: 0

Documentation

Overview

Package evidence holds redacted matched lines under a per-node byte ceiling split into rule shares.

Index

Constants

View Source
const DefaultCeiling = 16 << 20

DefaultCeiling is the per-node ring size.

Variables

This section is empty.

Functions

This section is empty.

Types

type Ring

type Ring struct {
	// contains filtered or unexported fields
}

Ring is safe for concurrent use.

func New

func New(ceiling int64) *Ring

New returns a ring with the given ceiling (DefaultCeiling when zero or negative).

func (*Ring) Add

func (r *Ring) Add(ruleID string, s Sample) bool

Add redacts and stores a matched sample, activating unknown rules with weight 1.

func (*Ring) Limited

func (r *Ring) Limited(ruleID string) bool

Limited reports whether a rule is evidence-limited.

func (*Ring) LimitedRules

func (r *Ring) LimitedRules() []string

LimitedRules lists evidence-limited rules in order.

func (*Ring) Peek

func (r *Ring) Peek(ruleID string, n int) []Sample

Peek returns a rule's newest n samples without removing them (investigation reads, PRD I1).

func (*Ring) SetRules

func (r *Ring) SetRules(weights map[string]float64)

SetRules sets active rules and weights (non-positive means 1) and drops samples of unlisted rules.

func (*Ring) Stats

func (r *Ring) Stats() Stats

Stats returns a snapshot.

func (*Ring) Take

func (r *Ring) Take(ruleID string, n int) ([]Sample, bool)

Take clears the rule and returns its newest n samples and whether any were lost since the last Take.

type RuleStats

type RuleStats struct {
	Weight   float64
	Share    int64
	Bytes    int64
	Samples  int
	Evicted  uint64
	Rejected uint64
	// Limited is sticky while the rule is active: some of its evidence was evicted or rejected.
	Limited bool
}

RuleStats describes one rule's share.

type Sample

type Sample struct {
	Time   time.Time
	Labels map[string]string
	Text   string
}

Sample is one matched line kept as evidence.

type Stats

type Stats struct {
	Ceiling int64
	Bytes   int64
	Rules   map[string]RuleStats
}

Stats describes the ring.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL