Add agent heartbeat monitoring and fix a query-language lexer bug
Agents now send an independent "still alive" record on a configurable schedule (seconds/minutes/hours, [heartbeat] in agent.toml), separate from real log traffic and tagged with a sentry.heartbeat attribute. No new wire protocol -- it's an ordinary record through the same PushBatch RPC/mTLS identity every log line already uses. Unavailability alerting reuses the existing absence-condition alert rule type unchanged; no new alerting code was needed. See /docs/agent-heartbeat-monitoring.md for the design and how to build the alert rule. While verifying the alert rule live, found that the query language's lexer never treated '-' as part of an identifier, so any unquoted hyphenated filter value -- including the reference doc's own canonical example, `host!=host-03` -- failed to parse at all. Fixed in api/internal/querylang/lexer/lexer.go with regression tests; a leading '-' still lexes as its own token so earliest=-1h/sort -count are unaffected.
This commit is contained in:
@@ -38,6 +38,19 @@ kind = "journald"
|
||||
max_size = 500
|
||||
flush_interval_ms = 2000
|
||||
|
||||
[heartbeat]
|
||||
# How often this agent proves it's still alive to the platform, sent as
|
||||
# its own record independent of whatever real log traffic is flowing --
|
||||
# pair with an "absence" alert rule on the sentry.heartbeat attribute to
|
||||
# get paged when a host goes quiet. Accepts a plain number + unit: s
|
||||
# (seconds), m (minutes), or h (hours) -- same vocabulary as
|
||||
# earliest=/latest= in the query language. See
|
||||
# /docs/agent-heartbeat-monitoring.md.
|
||||
enabled = true
|
||||
interval = "60s"
|
||||
# interval = "5m"
|
||||
# interval = "1h"
|
||||
|
||||
[ingest]
|
||||
endpoint = "https://ingest.internal:4317"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user