Skip to content

LOG-10325: match structured log levels case-insensitively - #3525

Open
kchawlani19 wants to merge 1 commit into
openshift:masterfrom
kchawlani19:fix/log-10325-case-insensitive-level
Open

kchawlani19 wants to merge 1 commit into
openshift:masterfrom
kchawlani19:fix/log-10325-case-insensitive-level

Conversation

@kchawlani19

@kchawlani19 kchawlani19 commented Oct 1, 2026 •

Copy link
Copy Markdown

Summary

  • Structured level tokens such as "level":"info" were matched case-sensitively, so "level":"INFO" missed attempt 4 in SetLogLevel.
  • Detection then fell through to the keyword scan and kept the earliest severity word. {"message":"There were no error","level":"INFO"} was stored as error.
  • The structured alternatives are now case-insensitive ((?i:...)). Klog prefixes such as ^E[0-9]+ stay case-sensitive, and a matching level field still wins over words in the message.
  • Fixes https://redhat.atlassian.net/browse/LOG-10325

Test plan

  • TestStructuredLevelIsCaseInsensitive covers uppercase JSON, logfmt, and Value: tokens, and checks that a lowercase klog-like prefix is not treated as an error
  • make test-unit for the vector generator fixtures (internal/generator/vector/input and internal/generator/vector/conf)
  • Forward {"message":"There were no error","level":"INFO"} and confirm .level is info

Summary by CodeRabbit

  • Bug Fixes
    • Log severity is now detected regardless of letter case in structured log fields, including level=, Value:, and JSON level values. Existing severity precedence and syslog-style prefix matching are unchanged.

Uppercase tokens such as "level":"INFO" missed the structured matcher,
so the keyword scan tagged the line from an earlier severity word in
the message. Keep klog prefixes case-sensitive.

Signed-off-by: kchawlani19 <kchawlan@redhat.com>
@openshift-ci-robot openshift-ci-robot added the jira/valid-reference Indicates that this PR references a valid Jira ticket of any type. label Oct 1, 2026
@openshift-ci-robot

Copy link
Copy Markdown

@kchawlani19: This pull request references LOG-10325 which is a valid jira issue.

Warning: The referenced jira issue has an invalid target version for the target branch this PR targets: expected the bug to target the "4.8.0" version, but no target version was set.

Details

In response to this:

Summary

  • Structured level tokens such as "level":"info" were matched case-sensitively, so "level":"INFO" missed attempt 4 in SetLogLevel.
  • Detection then fell through to the keyword scan and kept the earliest severity word. {"message":"There were no error","level":"INFO"} was stored as error.
  • The structured alternatives are now case-insensitive ((?i:...)). Klog prefixes such as ^E[0-9]+ stay case-sensitive, and a matching level field still wins over words in the message.
  • Fixes https://redhat.atlassian.net/browse/LOG-10325

Test plan

  • TestStructuredLevelIsCaseInsensitive covers uppercase JSON, logfmt, and Value: tokens, and checks that a lowercase klog-like prefix is not treated as an error
  • make test-unit for the vector generator fixtures (internal/generator/vector/input and internal/generator/vector/conf)
  • Forward {"message":"There were no error","level":"INFO"} and confirm .level is info

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the openshift-eng/jira-lifecycle-plugin repository.

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: openshift/cluster-logging-operator/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 76019510-283c-488d-b29c-e45645a448fa

📥 Commits

Reviewing files that changed from the base of the PR and between 88f7786 and 6f31cdb.

📒 Files selected for processing (25)
  • internal/generator/vector/conf/complex.toml
  • internal/generator/vector/conf/complex_http_receiver.toml
  • internal/generator/vector/conf/container.toml
  • internal/generator/vector/filter/openshift/viaq/v1/normalize.go
  • internal/generator/vector/filter/openshift/viaq/v1/normalize_test.go
  • internal/generator/vector/input/application.toml
  • internal/generator/vector/input/application_exclude_container_from_infra.toml
  • internal/generator/vector/input/application_excludes_container.toml
  • internal/generator/vector/input/application_includes_container.toml
  • internal/generator/vector/input/application_with_includes_excludes.toml
  • internal/generator/vector/input/application_with_infra_includes_excludes.toml
  • internal/generator/vector/input/application_with_infra_includes_infra_excludes.toml
  • internal/generator/vector/input/application_with_matchLabels.toml
  • internal/generator/vector/input/application_with_max_merge_line_size.toml
  • internal/generator/vector/input/application_with_specific_infra_includes_infra_excludes.toml
  • internal/generator/vector/input/application_with_throttle.toml
  • internal/generator/vector/input/audit.toml
  • internal/generator/vector/input/audit_host.toml
  • internal/generator/vector/input/audit_host_with_ignore_older.toml
  • internal/generator/vector/input/audit_ovn.toml
  • internal/generator/vector/input/audit_with_ignore_older.toml
  • internal/generator/vector/input/infrastructure.toml
  • internal/generator/vector/input/infrastructure_container.toml
  • internal/generator/vector/input/infrastructure_container_with_max_merge_line_size.toml
  • internal/generator/vector/input/infrastructure_container_with_throttle.toml

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Walkthrough

Walkthrough

Structured severity matching is now case-insensitive in the log normalizer and Vector transform configurations. Severity precedence, assignments, and existing syslog-style prefix matching remain unchanged.

Changes

Structured severity matching

Layer / File(s) Summary
Normalize structured severity levels
internal/generator/vector/filter/openshift/viaq/v1/normalize.go, internal/generator/vector/filter/openshift/viaq/v1/normalize_test.go
SetLogLevel matches structured severity forms without regard to case. Tests cover casing, severity precedence, and case-sensitive klog-like prefixes.
Update Vector severity patterns
internal/generator/vector/conf/*, internal/generator/vector/input/*
Vector transform configurations match structured severity forms case-insensitively. Severity order, assignments, and syslog-style prefix behavior remain unchanged.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~12 minutes

Change: Bug fix

Suggested reviewers: jcantrill

Merge Risk: ⚪ Minimal · up to 6f31c

The change makes structured log levels case-insensitive while preserving severity precedence and prefix matching. No actionable merge-blocking risk is identified; merge after normal checks pass.

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (2 warnings)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description explains the issue, the implementation, the precedence behavior, the Jira issue, and the test plan. However, it omits the mandatory /cc and /assign entries and does not include the req… Add at least one reviewer with /cc and one approver with /assign from the top-level OWNERS file. Add the required Links section, including the related Jira issue and any dependent PRs or enhancement proposals, or state that none apply.
Docstring Coverage ⚠️ Warning Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. (23 skipped: 2… Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (3 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and concisely states the main change: structured log levels now match case-insensitively.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Full details: Description check

Explanation

The description explains the issue, the implementation, the precedence behavior, the Jira issue, and the test plan. However, it omits the mandatory /cc and /assign entries and does not include the required Links section.

Full details: Docstring Coverage

Explanation

Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 2 functions across 2 files. (23 skipped: 23 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@openshift-ci
openshift-ci Bot requested review from cahartma and jcantrill October 1, 2026 20:32
@openshift-ci

openshift-ci Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: kchawlani19
Once this PR has been reviewed and has the lgtm label, please assign xperimental for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@openshift-ci

openshift-ci Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@kchawlani19: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

jira/valid-reference Indicates that this PR references a valid Jira ticket of any type.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants