-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Description
A note for the community
- Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment
Problem
First - I would like to report that I have been able to capture logs generated by podman containers using the docker_logs source.
I am surprised it has worked this well, considering this is not documented, doubt it has been tested, etc..
This worked by creating a symbolic link as follows:
sudo ln -s /run/podman/podman.sock /var/run/docker.sock
My only real issue ... timestamp seems to be getting the truncated version of the timestamp from the file.
For example:
2025-09-24T15:32:38.563547247+00:00 stderr F Example Message 1
2025-09-24T15:32:39.446549171+00:00 stderr F Example Message 2
Appears to be producing:
"timestamp": "2025-09-24T15:32:38Z"
"timestamp": "2025-09-24T15:32:39Z"
The docker_logs documentation does not include anything about selecting nor tweaking the parsers reading the log file.
I have to assume this is automatically using some type of 'CRI-O'/k8 log format parser?
Can the parser be updated to not truncate the timestamp?
Configuration
sources:
docker_logs:
type: docker_logs
sinks:
stdout:
type: console
inputs:
- docker_logs
encoding:
codec: json
Version
vector 0.50.0 (x86_64-unknown-linux-gnu 9053198 2025-09-23 14:18:50.944442940)
Debug Output
Example Data
No response
Additional Context
No response
References
No response