Skip to content

Add log_failure_only option to reduce bulk response log verbosity #173

Description

@rodrigocarvalho-bemobi

Problem

When log_level trace is enabled, the send_bulk method in out_opensearch.rb logs the full bulk API response:

log.on_trace { log.trace "bulk response: #{response}" }

A bulk request with hundreds of records produces a response object with an equally large items array. Even if only 1 record fails, the entire response is serialized — generating log messages of 10–20 KB per bulk request. In high-throughput environments this floods the log collector and makes triage significantly harder.

This is related to #37, which requests better control over verbosity when bulk requests encounter errors.

Proposed Solution

Add a log_failure_only boolean config parameter (default false, fully backwards-compatible).

When enabled, the bulk response is logged with only the failed items — entries in the items array where the operation returned an error field. Successful items are dropped from the log representation before serialization.

This keeps trace logs actionable for debugging while reducing log volume by orders of magnitude in low-failure-rate scenarios.

Example

With 500 records in a bulk request and 1 failure, instead of logging all 500 items (~15 KB), only the 1 failed item is logged (~200 bytes).

Configuration:

<match logs.**>
  @type opensearch
  log_failure_only true
</match>

Implementation

The change touches only lib/fluent/plugin/out_opensearch.rb:

  1. New config_param after log_os_400_reason:
config_param :log_failure_only, :bool, :default => false,
             :desc => 'When true, bulk response trace log includes only failed items instead of the full response.'
  1. Modified trace log in send_bulk:
log.on_trace do
  loggable = if @log_failure_only && response.is_a?(Hash) && response['items'].is_a?(Array)
               failed = response['items'].select { |i| i.values.first.key?('error') }
               response.merge('items' => failed)
             else
               response
             end
  log.trace "bulk response: #{loggable}"
end

A PR with this implementation is ready for review.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions