2024-05-20 01:52:16 +00:00
|
|
|
package logstorage
|
|
|
|
|
|
|
|
import (
|
|
|
|
"fmt"
|
2024-05-22 16:34:08 +00:00
|
|
|
"slices"
|
2024-05-20 01:52:16 +00:00
|
|
|
"strings"
|
|
|
|
)
|
|
|
|
|
|
|
|
// pipeUnpackLogfmt processes '| unpack_logfmt ...' pipe.
|
|
|
|
//
|
|
|
|
// See https://docs.victoriametrics.com/victorialogs/logsql/#unpack_logfmt-pipe
|
|
|
|
type pipeUnpackLogfmt struct {
|
2024-05-21 10:55:11 +00:00
|
|
|
// fromField is the field to unpack logfmt fields from
|
2024-05-20 01:52:16 +00:00
|
|
|
fromField string
|
|
|
|
|
2024-05-22 16:34:08 +00:00
|
|
|
// fields is an optional list of fields to extract from logfmt.
|
|
|
|
//
|
|
|
|
// if it is empty, then all the fields are extracted.
|
|
|
|
fields []string
|
|
|
|
|
2024-05-21 10:55:11 +00:00
|
|
|
// resultPrefix is prefix to add to unpacked field names
|
2024-05-20 01:52:16 +00:00
|
|
|
resultPrefix string
|
2024-05-21 10:55:11 +00:00
|
|
|
|
|
|
|
// iff is an optional filter for skipping unpacking logfmt
|
|
|
|
iff *ifFilter
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func (pu *pipeUnpackLogfmt) String() string {
|
|
|
|
s := "unpack_logfmt"
|
2024-05-22 16:34:08 +00:00
|
|
|
if pu.iff != nil {
|
|
|
|
s += " " + pu.iff.String()
|
|
|
|
}
|
2024-05-20 01:52:16 +00:00
|
|
|
if !isMsgFieldName(pu.fromField) {
|
|
|
|
s += " from " + quoteTokenIfNeeded(pu.fromField)
|
|
|
|
}
|
2024-05-22 16:34:08 +00:00
|
|
|
if len(pu.fields) > 0 {
|
|
|
|
s += " fields (" + fieldsToString(pu.fields) + ")"
|
|
|
|
}
|
2024-05-20 01:52:16 +00:00
|
|
|
if pu.resultPrefix != "" {
|
|
|
|
s += " result_prefix " + quoteTokenIfNeeded(pu.resultPrefix)
|
|
|
|
}
|
|
|
|
return s
|
|
|
|
}
|
|
|
|
|
|
|
|
func (pu *pipeUnpackLogfmt) updateNeededFields(neededFields, unneededFields fieldsSet) {
|
|
|
|
if neededFields.contains("*") {
|
|
|
|
unneededFields.remove(pu.fromField)
|
2024-05-21 10:55:11 +00:00
|
|
|
if pu.iff != nil {
|
|
|
|
unneededFields.removeFields(pu.iff.neededFields)
|
|
|
|
}
|
2024-05-20 01:52:16 +00:00
|
|
|
} else {
|
|
|
|
neededFields.add(pu.fromField)
|
2024-05-21 10:55:11 +00:00
|
|
|
if pu.iff != nil {
|
|
|
|
neededFields.addFields(pu.iff.neededFields)
|
|
|
|
}
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func (pu *pipeUnpackLogfmt) newPipeProcessor(workersCount int, _ <-chan struct{}, _ func(), ppBase pipeProcessor) pipeProcessor {
|
2024-05-22 16:34:08 +00:00
|
|
|
addField := func(uctx *fieldsUnpackerContext, name, value string) {
|
|
|
|
if len(pu.fields) == 0 || slices.Contains(pu.fields, name) {
|
|
|
|
uctx.addField(name, value)
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
2024-05-22 16:34:08 +00:00
|
|
|
}
|
2024-05-20 12:09:39 +00:00
|
|
|
|
2024-05-22 16:34:08 +00:00
|
|
|
unpackLogfmt := func(uctx *fieldsUnpackerContext, s string) {
|
|
|
|
for {
|
|
|
|
// Search for field name
|
|
|
|
n := strings.IndexByte(s, '=')
|
2024-05-20 12:09:39 +00:00
|
|
|
if n < 0 {
|
2024-05-22 16:34:08 +00:00
|
|
|
// field name couldn't be read
|
2024-05-20 12:09:39 +00:00
|
|
|
return
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
2024-05-22 16:34:08 +00:00
|
|
|
|
|
|
|
name := strings.TrimSpace(s[:n])
|
2024-05-20 12:09:39 +00:00
|
|
|
s = s[n+1:]
|
2024-05-22 16:34:08 +00:00
|
|
|
if len(s) == 0 {
|
|
|
|
addField(uctx, name, "")
|
|
|
|
}
|
|
|
|
|
|
|
|
// Search for field value
|
|
|
|
value, nOffset := tryUnquoteString(s)
|
|
|
|
if nOffset >= 0 {
|
|
|
|
addField(uctx, name, value)
|
|
|
|
s = s[nOffset:]
|
|
|
|
if len(s) == 0 {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
if s[0] != ' ' {
|
|
|
|
return
|
|
|
|
}
|
|
|
|
s = s[1:]
|
|
|
|
} else {
|
|
|
|
n := strings.IndexByte(s, ' ')
|
|
|
|
if n < 0 {
|
|
|
|
addField(uctx, name, s)
|
|
|
|
return
|
|
|
|
}
|
|
|
|
addField(uctx, name, s[:n])
|
|
|
|
s = s[n+1:]
|
|
|
|
}
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
|
|
|
}
|
2024-05-22 16:34:08 +00:00
|
|
|
|
|
|
|
return newPipeUnpackProcessor(workersCount, unpackLogfmt, ppBase, pu.fromField, pu.resultPrefix, pu.iff)
|
|
|
|
|
2024-05-20 01:52:16 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func parsePipeUnpackLogfmt(lex *lexer) (*pipeUnpackLogfmt, error) {
|
|
|
|
if !lex.isKeyword("unpack_logfmt") {
|
|
|
|
return nil, fmt.Errorf("unexpected token: %q; want %q", lex.token, "unpack_logfmt")
|
|
|
|
}
|
|
|
|
lex.nextToken()
|
|
|
|
|
2024-05-22 16:34:08 +00:00
|
|
|
var iff *ifFilter
|
|
|
|
if lex.isKeyword("if") {
|
|
|
|
f, err := parseIfFilter(lex)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
iff = f
|
|
|
|
}
|
|
|
|
|
2024-05-20 01:52:16 +00:00
|
|
|
fromField := "_msg"
|
|
|
|
if lex.isKeyword("from") {
|
|
|
|
lex.nextToken()
|
|
|
|
f, err := parseFieldName(lex)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("cannot parse 'from' field name: %w", err)
|
|
|
|
}
|
|
|
|
fromField = f
|
|
|
|
}
|
|
|
|
|
2024-05-22 16:34:08 +00:00
|
|
|
var fields []string
|
|
|
|
if lex.isKeyword("fields") {
|
|
|
|
lex.nextToken()
|
|
|
|
fs, err := parseFieldNamesInParens(lex)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("cannot parse 'fields': %w", err)
|
|
|
|
}
|
|
|
|
fields = fs
|
|
|
|
if slices.Contains(fields, "*") {
|
|
|
|
fields = nil
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2024-05-20 01:52:16 +00:00
|
|
|
resultPrefix := ""
|
|
|
|
if lex.isKeyword("result_prefix") {
|
|
|
|
lex.nextToken()
|
|
|
|
p, err := getCompoundToken(lex)
|
|
|
|
if err != nil {
|
|
|
|
return nil, fmt.Errorf("cannot parse 'result_prefix': %w", err)
|
|
|
|
}
|
|
|
|
resultPrefix = p
|
|
|
|
}
|
|
|
|
|
|
|
|
pu := &pipeUnpackLogfmt{
|
|
|
|
fromField: fromField,
|
2024-05-22 16:34:08 +00:00
|
|
|
fields: fields,
|
2024-05-20 01:52:16 +00:00
|
|
|
resultPrefix: resultPrefix,
|
2024-05-22 16:34:08 +00:00
|
|
|
iff: iff,
|
2024-05-21 10:55:11 +00:00
|
|
|
}
|
|
|
|
|
2024-05-20 01:52:16 +00:00
|
|
|
return pu, nil
|
|
|
|
}
|