Skip to content

Only warn about small files when they are not empty #1065

Description

@binarylogic

This is a follow up to #863 (comment).

To recap, when the file source is configured to use the checksum fingerprinting strategy a warning log message is emitted letting the user know the file is too small to generate a fingerprint:

warn!(message = "Ignoring file smaller than fingerprint_bytes", file = ?path);

This is a very welcome feature for files that are actually too small. It helps to prevent confusion around why small files aren't being tailed. Unfortunately, it can produce a lot of noise in production environments where many empty files are present.

I'm unsure if we should ignore empty files, given that it could lead to the same confusion that we experienced previously with small files. Then again, I can see the reasoning behind ignoring empty files. I'm opening this up for discussion so we can come to a conclusion about what to do in this scenario.

Update:

New log line for too small files is:

Currently ignoring file too small to fingerprint

Metadata

Metadata

Assignees

No one assigned

    Labels

    domain: observabilityAnything related to monitoring/observing Vectorgood first issueAnything that is good for new contributors.meta: feedbackAnything related to customer/user feedback.source: fileAnything `file` source related

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions