Problem
When log_level trace is enabled, the send_bulk method in out_opensearch.rb logs the full bulk API response:
log.on_trace { log.trace "bulk response: #{response}" }
A bulk request with hundreds of records produces a response object with an equally large items array. Even if only 1 record fails, the entire response is serialized — generating log messages of 10–20 KB per bulk request. In high-throughput environments this floods the log collector and makes triage significantly harder.
This is related to #37, which requests better control over verbosity when bulk requests encounter errors.
Proposed Solution
Add a log_failure_only boolean config parameter (default false, fully backwards-compatible).
When enabled, the bulk response is logged with only the failed items — entries in the items array where the operation returned an error field. Successful items are dropped from the log representation before serialization.
This keeps trace logs actionable for debugging while reducing log volume by orders of magnitude in low-failure-rate scenarios.
Example
With 500 records in a bulk request and 1 failure, instead of logging all 500 items (~15 KB), only the 1 failed item is logged (~200 bytes).
Configuration:
<match logs.**>
@type opensearch
log_failure_only true
</match>
Implementation
The change touches only lib/fluent/plugin/out_opensearch.rb:
- New
config_param after log_os_400_reason:
config_param :log_failure_only, :bool, :default => false,
:desc => 'When true, bulk response trace log includes only failed items instead of the full response.'
- Modified trace log in
send_bulk:
log.on_trace do
loggable = if @log_failure_only && response.is_a?(Hash) && response['items'].is_a?(Array)
failed = response['items'].select { |i| i.values.first.key?('error') }
response.merge('items' => failed)
else
response
end
log.trace "bulk response: #{loggable}"
end
A PR with this implementation is ready for review.
Problem
When
log_level traceis enabled, thesend_bulkmethod inout_opensearch.rblogs the full bulk API response:A bulk request with hundreds of records produces a response object with an equally large
itemsarray. Even if only 1 record fails, the entire response is serialized — generating log messages of 10–20 KB per bulk request. In high-throughput environments this floods the log collector and makes triage significantly harder.This is related to #37, which requests better control over verbosity when bulk requests encounter errors.
Proposed Solution
Add a
log_failure_onlyboolean config parameter (defaultfalse, fully backwards-compatible).When enabled, the bulk response is logged with only the failed items — entries in the
itemsarray where the operation returned anerrorfield. Successful items are dropped from the log representation before serialization.This keeps trace logs actionable for debugging while reducing log volume by orders of magnitude in low-failure-rate scenarios.
Example
With 500 records in a bulk request and 1 failure, instead of logging all 500 items (~15 KB), only the 1 failed item is logged (~200 bytes).
Configuration:
Implementation
The change touches only
lib/fluent/plugin/out_opensearch.rb:config_paramafterlog_os_400_reason:send_bulk:A PR with this implementation is ready for review.