Lnav – An advanced log file viewer for the small-scale
lnav.org
lnav.org
I've always had trouble before figuring out what a good compromise between log format and flexibility looks like. Especially wrt newlines in the log message itself (eg if I want to log a stack trace)
Any thoughts for a format that would generally work ootb in lnav or other log viewers?
Of those json is better if you want to be able to do more advanced stuff (nest dictionaries, use lists, ...) and logfmt is better if you want to have human-readable logs without external tools as well, an example line can look like
msg="Request finished" tag=request_finish status=200 user=brandur@mutelight.org user_id=1234 app=mutelight app_id=1234
Some more info here https://www.brandur.org/logfmtFor logfmt, I seem to remember the spec not being very clear on quoting semantics (maybe I'm wrong). Anyhow, I would suggest using JSON since it has pretty broad support at this point.
You would know what is supported what with you being the author, just saying that the docs aren't super clear from a quick glance :).
And yes, I second the suggestion to focus on JSON. The main benefit of logfmt is that it's simpler for a human to parse directly but in general you probably shouldn't aim for that so..
Yes, I should mention it on the features page. It's currently only mentioned in the main docs:
But some other places describe this a bit more liberally. And [2] notes that I should include a time stamp in each log entry which makes sense.
[1]: https://stackoverflow.com/questions/10699953/format-for-writ... [2]: https://www.papertrail.com/solution/tips/8-essential-tips-fo...
It makes parsing and keeping track of the "state" of the file a lot easier. Say that your application crashes/gets killed halfway through writing a log message / json dict and then gets restarted and appends to the log file. How should the log reader handle that case if it suddenly becomes a valid nested object? And even if it doesn't, should it throw away the first new log message as well because that was embedded in the invalid json object? Much easier to just say "one line is one json object, if there are literal newlines that's the delimeter to start a new parse".
And yes in any case it's good to have a timestamp on your log message no matter the format, unless you're logging somewhere you know that it gets added immediately (like the systemd journal). Your log parser/forwarder can add a timestamp for when it reads your log message but that is not necessarily the same as when your application emits it.
This means that you shouldn't just write (to reuse the previous example):
msg="Request for brandur@mutelight.org finished with status 200"
you should do it like msg="Request finished" status=200 user=brandur@mutelight.org
and not put any variables into the msg key (and not really do advanced formatting for any of the keys for that matter). This way once you get it put into a log system that understands your format you can do searches like "all log messages where user=foo" or "all statuses that are >=500 and <600" or search on specific messages, all without having to craft elaborate regular expressions and with better performance since the log search system can do indexing and various optimizations so that it doesn't have to be a full-text search every time.Probably the most common one (or at least was most common, maybe not anymore) would be "NCSA Common log format" (or just CLF) which looks something like this:
127.0.0.1 user-identifier frank [10/Oct/2000:13:55:36 -0700] "GET /apache_pb.gif HTTP/1.0" 200 2326
https://en.wikipedia.org/wiki/Common_Log_FormatMany tools for getting analytics out of server-side logs can work with CLF and the various variations. But probably today there are more "modern" formats as well.
[1]: https://serilog.net/
[2]: https://datalust.co/
Shred also isn't perfect as it has no concept of the file systems journal and does not clean that data but I think it is still good practice for sensitive data, in addition to filesystem or file level encryption on systems with highly sensitive data.
With sensitive data one must look at the value of the data vs the value of the SSD. If I go out of my way to extend the life of my SSD, do I risk losing $5billion? That is how I factor in whether or not extra wear-and-tear on a SSD makes sense.
Either way one should also use filesystem and file level encryption for sensitive files and encrypt sensitive attributes inside databases. Swap must also be encrypted as it may contain sensitive data. Datacenter bad-drive mishaps do happen as in not shredding the physical drive as a few government and military agencies have recently been embarrassed by.
I do agree with pinkorchid that ultimately drives should be destroyed physically.
This behavior is fundamental; it's what wear leveling is and why it exists. Wear leveling exists to prevent you from writing to the same block repeatedly, which is exactly what you're trying to do with shred.
I'm not sure what other source you're looking for, but I hope you find it. Perhaps, at least, the number of people "on StackExchange, ServerFault and Reddit" and now also HackerNews telling you the same thing is sufficient evidence to stop spreading the idea that shred might work on SSDs. Do what you want on your own systems, of course, but this is dangerously misleading guidance to be offering on an open forum.
So even if wear leveling prevents overwriting a file then such tools should in theory be a risk of data corruption. If this is the case then the tool should be updated to detect if the target is an SSD and abort with a scary message. Perhaps another route is to reach out to the coreutils team.
It won't wipe unrelated files as far as the file system sees it, but it might overwrite some previously discarded internal blocks. "inodes" is a too high-level concept in this context.
You can read more about it on wikipedia which might be an authorative enough source for you? https://en.wikipedia.org/wiki/Wear_leveling
Also note that most ssds actually have more internal blocks available than what they present to the host device so that they can have a "cache" to be able to move things around internally, and also so they can mark certain positions as "bad" when writes to one internal block start failing and still operate properly.
Instead, you may want to encrypt your disk so that as soon as the key is gone it all becomes unreadable. For a bigger threat, maybe you need to follow the NIST destroy guidelines [1] to "Disintegrate, Pulverize, Melt, and Incinerate" the media.
1: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.s...
> something to probably add to my clean up script.
These capture files are deleted if they are older than a day the next time lnav is run.
(I realize they should've been stored in ~/.local/state instead of ~/.config ...)
It has a similar feature set (tail, syntax highlighting, SQL reporting) with a focus on accessing files remotely.
I would be happy to chat to a like mind if you are interested. You can contact me here: https://www.logviewplus.com/contact.aspx
Steal away! :-)
I love that so many Windows tools get a nice-looking GUI, versus a heavy CUI lean to *nix tools.
I would love to do a Linux port as soon as there is a viable cross-platform GUI technology with strong 3rd party vendor support. The controls in LogViewPlus are very rich.
Let me know if you have any questions or feedback. You can reach me on the contact page of the site.
For example the http 403/404 is red but it does not stand out. Also why a 404 would be red in the first place.
Identifiers, like process-names/pids/IPs, are semantically highlighted by default to make it easier to visually match up values that are the same. And, it's this way because I like it this way, so that's the default.
> For example the http 403/404 is red but it does not stand out.
To me, the red stands out. But, I would also have a much wider window, so the red would stand out even more with the rest of the text.
> Also why a 404 would be red in the first place.
Because 4XX are error codes.
Of course, lnav is pretty customizable at this point, so you can adjust it to your liking. The theme can be changed to something less colorful and the log format definitions can be patched to change their behavior.
For logs managed by syslog daemons, most implementations allows you to set the owner and group of the log files. You could decide on a specific log group and add the desired dedicated user to this group.
In the end it is usually better to ship the logs to a dedicated machine/space/database.
Yes, you can use → https://goaccess.io/
You can see it in action here: https://www.logviewplus.com/docs/create_a_custom_report.html
If you want to write more complicated queries, lnav exposes log data through SQLite vtables[1]. So, you can do a SQL query and get a simple bar chart visualization.
[1] - https://docs.lnav.org/en/latest/sqlext.html#sqlite-interface
With caddy server
Not everyone checks out daily HN to see all the reposts. Pulling numbers out of the air, I'd say that 5-10% of daily content on HN is a repost, should get used to it. Just hide it an carry on is what I would suggest.
There were submissions with links to lnav.org main site:
- 21 days ago
- 22 days ago
- 46 days ago
- 68 days ago
It's a spam campaign from my pov.
It seems very reasonable that most visitors simply never saw any of those submissions.