<#1069 Fix file log sink: zerolog events were neve...
# osctrl
g
#1069 Fix file log sink: zerolog events were never written Pull request opened by javuto Fix file log sink: zerolog events were never written Fixes #1068 Problem With a
file
log sink,
osctrl-tls
silently dropped all osquery status, result, and on-demand query logs. The sink's target file was never created, while the
log_sinks
counters (
exports_count
,
bytes_sent
) kept incrementing — making the sink appear healthy from the UI.
Status
,
Result
, and
Query
in
pkg/logging/file.go
each built a
zerolog
event chain but never called a terminal method (
.Msg()
/
.Send()
), so zerolog discarded every event before it reached the lumberjack writer (which creates the file lazily on first write). The stdout sink works because it uses
Msgf
— hence the copy-paste artifacts in this file's comments and debug message that also said "stdout". Behavioral change • Terminal
.Send()
added to the event chain in
Status
,
Result
, and
Query
, so status, scheduled results, and on-demand query results are now written as JSON lines (metadata +
RawJSON
payload) to the configured file. • The file sink's debug trace and doc comments corrected from "stdout" to "file" to aid diagnosis. • No interface, route, schema, or configuration changes; additive and reversible. Other sinks are untouched. Security / operational impact • Data loss: deployments on v0.5.9 with
logger.type: file
have been silently losing those logs; they cannot be recovered, but upgrading restores writes going forward. • Diagnostics:
CountedExporter
increments `bytes_sent`/`exports_count` before the inner export, so the counters count attempts, not deliveries — they cannot be trusted as a health signal for this sink. (Pre-existing; not addressed here.) • No authentication/authorization, TLS handler, or MCP surface changes. Testing New regression test `pkg/logging/file_test.go`: • Reproduces the issue — fails on
main
before the fix (
file sink wrote nothing: file not created
), passes after. • Exercises status + result via
Log
and a query via
Export
, asserting the file exists with 3 valid JSON lines carrying the expected
type
,
environment
,
uuid
, and inlined
data
payload. Validation performed: •
go test ./pkg/logging/
— all pass •
go build ./...
•
go vet ./pkg/logging/
•
gofmt
clean jmpsec/osctrl