Expand description
The systemd journal as journalctl -o json writes it: NDJSON whose records carry
__CURSOR and __REALTIME_TIMESTAMP.
journalctl has already parsed the journal, so this is the NDJSON reader with a few
expressions on top: time from __REALTIME_TIMESTAMP, level from PRIORITY in
order of severity, MESSAGE as text where it came as bytes, and the columns put in
the order a reader of logs looks for them. Every field stays. A file’s records are
read whole into memory, up to limits.journal_bytes, with the schema inferred from
all of them, so a field first seen late is a column too. A pipe or a followed file is scanned as it grows
(crate::loading::follow::lines); a pipe’s fields first seen after the open join once it
ends.
Constants§
- LEVEL
- LEVELS
- The levels
PRIORITY0 to 7 names, most severe first: the order a sort andlevel <= "err"go by. - TIME
Functions§
- looks_
like - Whether
headbegins journal JSON: its first line is an object with__CURSORand__REALTIME_TIMESTAMP. A first line longer than the head is judged on the keys it names so far.