Add Tier-2 per-app Vector transform pipelines (structured logs) #320
Reference in New Issue
Block a user
Delete Branch "benvin/vector-tier2-pipelines"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why: extend the Tier-1 survey with 7 more high-value log sources so they parse into logs.raw columns/.fields for real querying instead of the generic catch-all. Stacks on #318 — merge after it.
How:
.postgrescontainer), gitea (router+access, k8s+VM), puppet (openvoxserver/openvoxdb logback + access), litellm (JSON request logs), postfix (per-line maillog)..postgresout of the Tier-1 authentik route + new puppet/gitea/litellm routes so the single cnpg_pg route claims every CNPG pod without double-insert (keeps app_route mutually exclusive). Catch-all intact.JSON_LOGS=True; bindquerylog yeson both bind-internal BindClusters; gitea router+access logging to stdout. Rancher auditLog was already on.vector testcases (routing + field extraction + authentik-postgres→cnpg exclusivity proof); all 35 green (vector 0.57). Fields go into the existingfields Map(String,String)— no DDL change.Puppet-side follow-ups (out of scope for argocd): enable named query logging (profiles/dns/server.pp); ship the VM vector rollout with
.file/.SYSLOG_IDENTIFIERtags for named/gitea/puppetserver(+multiline logback join)/postfix maillog.https://claude.ai/code/session_015ur3i7D2azsMAWTSVABApv