<#991 Add severity filter for status logs> Pull re...
# osctrl
g
#991 Add severity filter for status logs Pull request opened by javuto Add severity filter for status logs Problem The status logs tab only had a free-text search bar. Operators investigating osquery issues had no way to quickly filter by severity (info, warning, error), forcing them to visually scan through all log entries or craft search terms that might match unrelated text. Change Added a severity filter dropdown next to the existing search bar in the status logs tab, covering the full stack from backend to UI: Backend (
pkg/logging
,
cmd/api/handlers
): • Added a
severity
parameter to the
LogReader.NodeLogs
interface,
GetNodeLogs
,
dbLogReader
, and
s3LogReader
• DB reader applies
WHERE severity = ?
for status logs when the param is non-empty; S3 reader filters decoded rows client-side by matching the
severity
field •
NodeLogsHandler
reads
?severity=
from the query string and passes it through • Updated Swagger annotation with the new
severity
param • Ignored for result logs (no severity concept) Frontend API (
frontend/src/api/nodes.ts
): • Added optional
severity
parameter to
listNodeLogs()
, serialized as
?severity=
query param Frontend UI (
frontend/src/features/nodes/NodeDetailPage.tsx
): • Added a severity
<select>
dropdown next to the search bar in
LogsTab
, visible only for status logs • Options: All severities (default), Info (0), Warning (1), Error (2) — matching the existing
severityBadge
mapping • Search input set to
flex-1
so it and the dropdown together span the full width of the log entries below • Changing the filter resets the accumulator and re-fetches, same as the search text behavior • Included in the TanStack Query key so cache is per-severity Validation •
go test ./pkg/logging/...
—
TestGetNodeLogsSeverityFilter
verifies DB-level filtering by severity 0/1/2 •
go test ./cmd/api/handlers/...
—
TestNodeLogsHandlerPassesSeverityFilter
verifies the handler passes
?severity=2
through to the LogReader •
go test ./pkg/... ./cmd/...
— full Go test suite passes (no regressions) •
npm run check
— TypeScript typecheck passes •
npm run test
— 267 frontend tests pass (no regressions) jmpsec/osctrl