Skip to content

T-1178 [vector] Match only real MySQL log layouts when detecting the MySQL platform - #30

Merged
PetrHeinz merged 2 commits into
mainfrom
claude/t-1178-mysql-false-positives
Oct 9, 2026
Merged

PetrHeinz merged 2 commits into
mainfrom
claude/t-1178-mysql-false-positives

Conversation

@PetrHeinz

@PetrHeinz PetrHeinz commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

The MySQL detector in the Vector remap matched any pod log line shaped <ISO timestamp> <number> <text> and tagged it platform: MySQL with a bogus mysql.command and an overwritten dt. The regexes now follow the layouts MySQL actually writes, the same change as Vector::ParserFactory::MYSQL in BetterStackHQ/logtail#18031:

  • Error log: the priority has to be one of MySQL's (System, Note, Warning, ERROR) and the error code one of 8.0's MY-xxxxxx codes. The code and subsystem pair is optional, so MySQL 5.7 error log lines now parse with their priority and message.
  • General query log: sql/log.cc File_query_log::write_general writes <timestamp>\t<connection id padded to 5> <command>\t<argument>, both tabs always. The regex requires exactly that: a tab after the timestamp, the padded id, one space, the command, and a tab before the optional argument.
  • Timestamps: both logs come from make_iso8601_timestamp, so six fractional digits always, followed by Z or by ±hh:mm with log_timestamps=SYSTEM. Requiring that shape rejects the common <millisecond timestamp> <pid> [ERROR] ... app line and makes SYSTEM-timezone logs parse, which they never did.

Also ports the null handling for non-participating regex groups from logtail, so a general log line without an argument keeps its raw message rather than getting a null one that made the following string!(.message) fail.

Bumps the chart version to 2.0.1.

🤖 Generated with Claude Code

PetrHeinz and others added 2 commits October 7, 2026 18:54
The general-log fallback accepted any "<ISO timestamp> <number> <text>" line, so pods of unrelated apps got platform MySQL. The error log regex now requires one of MySQL's priorities (System, Note, Warning, ERROR) and, when present, a MY-xxxxxx error code, which also lets MySQL 5.7 error lines parse with their priority and message. The general query log regex requires the layout MySQL writes (sql/log.cc File_query_log::write_general): a tab after the timestamp, the padded connection id, one space, the command, and a tab before the optional argument.

Also ports the null handling for non-participating regex groups from BetterStackHQ/logtail, so a line without an argument keeps its raw message instead of a null one.

Same change as Vector::ParserFactory::MYSQL in BetterStackHQ/logtail.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Both MySQL logs format timestamps with make_iso8601_timestamp: YYYY-MM-DDTHH:MM:SS.ffffff followed by Z, or by +hh:mm/-hh:mm when log_timestamps=SYSTEM. Requiring that shape rejects the common "<millisecond timestamp> <pid> [ERROR] ..." app line, which the optional error-code group had let through, and makes logs written with log_timestamps=SYSTEM parse, which they never did. Mirrors the same commit in BetterStackHQ/logtail.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@PetrHeinz
PetrHeinz marked this pull request as ready for review October 9, 2026 10:25
@PetrHeinz
PetrHeinz merged commit bccb7c7 into main Oct 9, 2026
4 checks passed
@PetrHeinz
PetrHeinz deleted the claude/t-1178-mysql-false-positives branch October 9, 2026 10:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant