{"record":{"id":"c1cf5bc776babe63","repo":"vectordotdev/vector","slug":"checkpoint","errorCode":null,"errorMessage":"{}","messagePattern":"\\{\\}","errorType":"exception","errorClass":"WindowsEventLogError","httpStatus":null,"severity":"error","filePath":"src/sources/windows_event_log/checkpoint.rs","lineNumber":224,"sourceCode":"            }\n        }\n    }\n\n    /// Save checkpoint state to disk atomically\n    async fn save_to_disk(&self, state: &CheckpointState) -> Result<(), WindowsEventLogError> {\n        // Use atomic write: write to temp file, then rename\n        let temp_path = self.checkpoint_path.with_extension(\"tmp\");\n\n        // Serialize state\n        let contents = match serde_json::to_vec_pretty(state) {\n            Ok(c) => c,\n            Err(e) => {\n                error!(\n                    message = \"Failed to serialize checkpoint state.\",\n                    error = %e\n                );\n                return Err(WindowsEventLogError::IoError {\n                    source: io::Error::new(ErrorKind::InvalidData, e),\n                });\n            }\n        };\n\n        // Write to temp file\n        let mut file = OpenOptions::new()\n            .write(true)\n            .create(true)\n            .truncate(true)\n            .open(&temp_path)\n            .await\n            .map_err(|e| WindowsEventLogError::IoError { source: e })?;\n\n        file.write_all(&contents)\n            .await\n            .map_err(|e| WindowsEventLogError::IoError { source: e })?;\n\n        file.sync_all()","sourceCodeStart":206,"sourceCodeEnd":242,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/src/sources/windows_event_log/checkpoint.rs#L206-L242","documentation":"The Windows Event Log source persists its checkpoint state to disk. If serializing the checkpoint state fails, the code logs 'Failed to serialize checkpoint state.' and returns WindowsEventLogError::IoError wrapping an io::Error with ErrorKind::InvalidData. The checkpoint write is aborted, meaning the source's saved position cannot be updated and replay/at-least-once semantics may apply on restart.","triggerScenarios":"save_checkpoint (checkpoint.rs) calls serialization of the checkpoint state and gets Err(e); the error is wrapped as io::Error::new(ErrorKind::InvalidData, e) inside WindowsEventLogError::IoError and returned to the caller.","commonSituations":"Corrupt or incompatible checkpoint file from a previous Vector version (schema change); serializer (serde_json etc.) failing on unexpected state; disk issues returning partial data on read-then-write flows; permission problems on the checkpoint path causing malformed state.","solutions":["Delete/reset the checkpoint file so the source recreates it from scratch (accepting event replay).","Inspect the wrapped serializer error in logs to identify which field failed to serialize.","Ensure the checkpoint directory is writable and the file is not corrupted (check disk health).","If it appeared after a Vector upgrade, check for checkpoint format changes in release notes and migrate or remove old checkpoints."],"exampleFix":"// before: corrupt checkpoint file\nC:\\ProgramData\\Vector\\checkpoints\\application.json  (invalid JSON)\n// after: remove it so Vector recreates the checkpoint\ndel C:\\ProgramData\\Vector\\checkpoints\\application.json\nnet restart vector","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"match save_checkpoint(state) {\n    Err(WindowsEventLogError::IoError { source }) => {\n        error!(\"checkpoint write failed: {source}; falling back to default cursor\");\n        // reset checkpoint file and continue from the default position\n    }\n    other => other,\n}","preventionTips":["Keep the checkpoint directory writable by the Vector service account.","After Vector upgrades, verify checkpoint compatibility; delete stale checkpoints if formats changed.","Monitor 'Failed to serialize checkpoint state.' log lines."],"tags":["windows","checkpoint","serialization","invalid-data","source"],"backgroundTag":"json-serialization-failed","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}