journal

package
v0.3.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: Apache-2.0 Imports: 20 Imported by: 0

Documentation

Overview

Package journal is a pure-Go, read-only reader of the systemd journal file format.

Index

Constants

View Source
const DefaultCursorKey = "journal/cursor"

DefaultCursorKey is the kv key of the persisted cursor.

Variables

View Source
var ErrCorrupt = errors.New("journal: corrupt file")

ErrCorrupt reports a structurally invalid journal file.

View Source
var ErrUnsupported = errors.New("journal: unsupported file")

ErrUnsupported reports a file using incompatible features this reader does not implement.

Functions

This section is empty.

Types

type Cursor

type Cursor struct {
	SeqnumID ID128
	Seqnum   uint64
	Realtime uint64
}

Cursor identifies a position: the sequence number domain, the sequence number, and realtime in microseconds.

func ParseCursor

func ParseCursor(s string) (Cursor, error)

ParseCursor parses the form written by Cursor.String; unknown keys are ignored.

func (Cursor) String

func (c Cursor) String() string

type Entry

type Entry struct {
	Realtime time.Time
	Fields   map[string]string
	Cursor   Cursor
}

Entry is one journal entry.

func (Entry) Labels

func (e Entry) Labels() map[string]string

Labels returns the LogQL stream labels of the entry; absent fields yield no label.

func (Entry) Message

func (e Entry) Message() string

Message returns the log line.

type ID128

type ID128 [16]byte

ID128 is a systemd 128-bit identifier.

func (ID128) String

func (id ID128) String() string

type Options

type Options struct {
	// Dirs are scanned with their immediate subdirectories (the machine ID directories).
	Dirs []string
	// Store persists the cursor under CursorKey; nil keeps it in memory only.
	Store     kv.Store
	CursorKey string
	// Since skips older entries when no cursor is stored; zero reads from the head.
	Since          time.Time
	PollInterval   time.Duration
	MaxObjectBytes int64
}

Options configures a Reader.

type Reader

type Reader struct {
	// contains filtered or unexported fields
}

Reader merges the entries of every journal file in realtime order. It is not safe for concurrent use.

func Open

func Open(o Options) (*Reader, error)

Open loads the persisted cursor and opens every journal file.

func (*Reader) Close

func (r *Reader) Close() error

Close closes every open file.

func (*Reader) Cursor

func (r *Reader) Cursor() (Cursor, bool)

Cursor returns the position of the last delivered entry, or the loaded cursor.

func (*Reader) FileErrors

func (r *Reader) FileErrors() map[string]error

FileErrors returns files skipped because they are corrupt or unsupported, by path.

func (*Reader) Follow

func (r *Reader) Follow(ctx context.Context, fn func(Entry) error) error

Follow delivers entries until ctx ends or fn fails, saving the cursor per batch and, on failure, before the failed entry.

func (*Reader) Next

func (r *Reader) Next() (Entry, bool)

Next returns the next entry available now across all files.

func (*Reader) Refresh

func (r *Reader) Refresh() error

Refresh re-reads the headers of growing files and picks up new and rotated files.

func (*Reader) SaveCursor

func (r *Reader) SaveCursor() error

SaveCursor persists the cursor.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL