Skip to content

Syslog's yearless stamp (Oct 1 00:00:02) is a built-in - #186

Merged
torstei merged 2 commits into
mainfrom
feature/yearless-syslog-stamps
Oct 1, 2026
Merged

torstei merged 2 commits into
mainfrom
feature/yearless-syslog-stamps

Conversation

@torstei

@torstei torstei commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Classic syslog stamps carry no year, so every line of such a file went unstamped and a file-intake set could not name them (DECLARE cannot hold a regex with spaces).

  • Built-in syslog stamp, anchored at line start; no declaration needed, so one set serves classic-syslog and ISO hosts alike.
  • The year is the latest one not after a reference: the source's mtime on the write path (re-read as a tail reads), the chunk's write-window end on the read path. Stateless, and a file spanning New Year resolves by itself.
  • A declared timestamp_format that names no year gets the same rule.
  • Known limit: a copied/touched file with a wrong mtime resolves to the wrong year.

Plan: docs/plans/yearless-stamps.md. Tests: unit tests for year resolution; checked end to end with an import and query across New Year.

🤖 Generated with Claude Code

torstei and others added 2 commits October 1, 2026 20:39
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
…data

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@torstei
torstei merged commit 14d6e26 into main Oct 1, 2026
7 checks passed
@torstei
torstei deleted the feature/yearless-syslog-stamps branch October 1, 2026 19:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant