mmaitag: AI-based classification

Module Name:

mmaitag

Author:

Adiscon

Available:

9.0+

Purpose

The mmaitag module enriches log messages with classification tags obtained from an external AI service. Each message is sent to the provider individually and the resulting tag is stored in a custom variable.

Gemini response limits

The Gemini provider bounds each synchronous request so that a stalled or malformed provider response cannot consume resources indefinitely. By default, it accepts at most 1 MiB (1,048,576 bytes) of response data, allows 60 seconds for the complete transfer and 10 seconds to establish the connection, and aborts a transfer that remains below one byte per second for 15 seconds.

These budgets can be tuned per action. Their built-in ceilings preserve a finite defense-in-depth bound: responses cannot exceed 64 MiB, request and connection timeouts cannot exceed one hour, the low-speed threshold cannot exceed 1 MiB per second, and its observation period cannot exceed one hour.

When a request exceeds a limit or otherwise fails, mmaitag uses the REGULAR fallback tag and records an error without copying the provider response body into rsyslog diagnostics.

Default labels

Label

Description

NOISE

Can be ignored, redundant, or irrelevant for most purposes

REGULAR

Normal messages of operational interest

IMPORTANT

Should be logged and may indicate early signs of issues

CRITICAL

Indicates immediate or serious problems

Configuration Parameters

Note

Parameter names are case-insensitive; camelCase is recommended for readability.

Action Parameters

Parameter

Summary

provider

Selects which backend provider processes the classification (gemini or gemini_mock).

tag

Names the message variable used to store the classification tag.

model

Specifies the AI model identifier used by the provider.

expert.initialPrompt

Provides a custom prompt text used by the AI provider before classifying messages.

inputProperty

Selects which message property is classified instead of the raw message.

apiKey

Sets the API key used to authenticate with the provider.

apiKeyFile

Specifies a file containing the API key for the provider.

response.maxBytes

Sets the maximum Gemini response body size retained for one request.

request.timeoutMs

Sets the maximum total duration of one Gemini request in milliseconds.

request.connectTimeoutMs

Sets the Gemini connection-establishment timeout in milliseconds.

request.lowSpeedLimit

Sets the minimum acceptable Gemini transfer rate in bytes per second.

request.lowSpeedTime

Sets how long a slow Gemini transfer may remain below the rate threshold.

Example

module(load="mmaitag")
action(type="mmaitag" provider="gemini" apikey="ABC" tag="$.aitag")

Support: rsyslog Assistant | GitHub Discussions | GitHub Issues: rsyslog source project

Contributing: Source & docs: rsyslog source project

© 2008–2026 Rainer Gerhards and others. Licensed under the Apache License 2.0.