GitHub
10/01/2026, 7:28 PMfile log sink, osctrl-tls silently dropped all osquery status, result, and on-demand query logs. The sink's target file was never created, while the log_sinks counters (exports_count, bytes_sent) kept incrementing — making the sink appear healthy from the UI.
Status, Result, and Query in pkg/logging/file.go each built a zerolog event chain but never called a terminal method (.Msg() / .Send()), so zerolog discarded every event before it reached the lumberjack writer (which creates the file lazily on first write). The stdout sink works because it uses Msgf — hence the copy-paste artifacts in this file's comments and debug message that also said "stdout".
Behavioral change
• Terminal .Send() added to the event chain in Status, Result, and Query, so status, scheduled results, and on-demand query results are now written as JSON lines (metadata + RawJSON payload) to the configured file.
• The file sink's debug trace and doc comments corrected from "stdout" to "file" to aid diagnosis.
• No interface, route, schema, or configuration changes; additive and reversible. Other sinks are untouched.
Security / operational impact
• Data loss: deployments on v0.5.9 with logger.type: file have been silently losing those logs; they cannot be recovered, but upgrading restores writes going forward.
• Diagnostics: CountedExporter increments `bytes_sent`/`exports_count` before the inner export, so the counters count attempts, not deliveries — they cannot be trusted as a health signal for this sink. (Pre-existing; not addressed here.)
• No authentication/authorization, TLS handler, or MCP surface changes.
Testing
New regression test `pkg/logging/file_test.go`:
• Reproduces the issue — fails on main before the fix (file sink wrote nothing: file not created), passes after.
• Exercises status + result via Log and a query via Export, asserting the file exists with 3 valid JSON lines carrying the expected type, environment, uuid, and inlined data payload.
Validation performed:
• go test ./pkg/logging/ — all pass
• go build ./...
• go vet ./pkg/logging/
• gofmt clean
jmpsec/osctrlGitHub
10/01/2026, 7:44 PM