Skip to main content

Module journal

Module journal 

Source
Expand description

The systemd journal as journalctl -o json writes it: NDJSON whose records carry __CURSOR and __REALTIME_TIMESTAMP.

journalctl has already parsed the journal, so this is the NDJSON reader with a few expressions on top: time from __REALTIME_TIMESTAMP, level from PRIORITY in order of severity, MESSAGE as text where it came as bytes, and the columns put in the order a reader of logs looks for them. Every field stays. A file’s records are read whole into memory, up to limits.journal_bytes, with the schema inferred from all of them, so a field first seen late is a column too. A pipe or a followed file is scanned as it grows (crate::loading::follow::lines); a pipe’s fields first seen after the open join once it ends.

Constants§

LEVEL
LEVELS
The levels PRIORITY 0 to 7 names, most severe first: the order a sort and level <= "err" go by.
TIME

Functions§

looks_like
Whether head begins journal JSON: its first line is an object with __CURSOR and __REALTIME_TIMESTAMP. A first line longer than the head is judged on the keys it names so far.