Skip to content

internal/command: evaluate log lines as templates with --template - #213

Merged
kcreddy merged 1 commit into
elastic:mainfrom
kcreddy:log-templating
Aug 20, 2026
Merged

kcreddy merged 1 commit into
elastic:mainfrom
kcreddy:log-templating

Conversation

@kcreddy

@kcreddy kcreddy commented Aug 19, 2026

Copy link
Copy Markdown
Contributor
internal/command: evaluate log lines as templates with --template

The log command streamed each line verbatim, so fixtures with absolute
timestamps eventually age out of time-windowed consumers (for example a
transform that filters on now-90d). Re-dating the fixtures by hand only
resets a ticking clock.

Add a --template flag that evaluates each line as a Go text/template
before sending, using the same function set as the http-server config
(env, hostname, sum, file, glob, minify_json, now). A streamed line can
then keep its timestamps current, for example:

    "eventTime":"{{ (now "-720h").Format "2006-01-02T15:04:05Z07:00" }}"

Each line is rendered independently, and a template error aborts the run
reporting the offending line number. To keep one implementation, the
template function map and helpers move from internal/httpserver into a
new internal/templates package that both the http-server and the log
command use.

Updates elastic/integrations#20792

Co-authored-by: Opus 4.8 High

The log command streamed each line verbatim, so fixtures with absolute
timestamps eventually age out of time-windowed consumers (for example a
transform that filters on now-90d). Re-dating the fixtures by hand only
resets a ticking clock.

Add a --template flag that evaluates each line as a Go text/template
before sending, using the same function set as the http-server config
(env, hostname, sum, file, glob, minify_json, now). A streamed line can
then keep its timestamps current, for example:

    "eventTime":"{{ (now "-720h").Format "2006-01-02T15:04:05Z07:00" }}"

Each line is rendered independently, and a template error aborts the run
reporting the offending line number. To keep one implementation, the
template function map and helpers move from internal/httpserver into a
new internal/templates package that both the http-server and the log
command use.

Updates elastic/integrations#20792

Co-authored-by: Opus 4.8 High
@infra-vault-gh-plugin-prod

Copy link
Copy Markdown

💚 Build Succeeded

cc @kcreddy

@kcreddy
kcreddy merged commit 15bf16f into elastic:main Aug 20, 2026
19 checks passed
@kcreddy
kcreddy deleted the log-templating branch August 20, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Team:Security-Service Integrations Team:Security-Service Integrations

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants