vectordotdev/vector · error · WindowsEventLogError

{}

Error message

{}

What it means

The Windows Event Log source persists its checkpoint state to disk. If serializing the checkpoint state fails, the code logs 'Failed to serialize checkpoint state.' and returns WindowsEventLogError::IoError wrapping an io::Error with ErrorKind::InvalidData. The checkpoint write is aborted, meaning the source's saved position cannot be updated and replay/at-least-once semantics may apply on restart.

Solutions

  1. Delete/reset the checkpoint file so the source recreates it from scratch (accepting event replay).
  2. Inspect the wrapped serializer error in logs to identify which field failed to serialize.
  3. Ensure the checkpoint directory is writable and the file is not corrupted (check disk health).
  4. If it appeared after a Vector upgrade, check for checkpoint format changes in release notes and migrate or remove old checkpoints.

Example fix

// before: corrupt checkpoint file
C:\ProgramData\Vector\checkpoints\application.json  (invalid JSON)
// after: remove it so Vector recreates the checkpoint
del C:\ProgramData\Vector\checkpoints\application.json
net restart vector
Defensive patterns

Strategy: try-catch

Try / catch

match save_checkpoint(state) {
    Err(WindowsEventLogError::IoError { source }) => {
        error!("checkpoint write failed: {source}; falling back to default cursor");
        // reset checkpoint file and continue from the default position
    }
    other => other,
}

Prevention

When it happens

Trigger: save_checkpoint (checkpoint.rs) calls serialization of the checkpoint state and gets Err(e); the error is wrapped as io::Error::new(ErrorKind::InvalidData, e) inside WindowsEventLogError::IoError and returned to the caller.

Common situations: Corrupt or incompatible checkpoint file from a previous Vector version (schema change); serializer (serde_json etc.) failing on unexpected state; disk issues returning partial data on read-then-write flows; permission problems on the checkpoint path causing malformed state.

Understand the failure class

Background: "JSON serialization failed", "not JSON serializable", "Failed to serialize": why JSON marshaling errors happen and how to fix them — this error's family across 46 libraries.

Related errors


AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16). Data as JSON: /api/errors/c1cf5bc776babe63. Report an issue: GitHub.

Appendix: source

Thrown at src/sources/windows_event_log/checkpoint.rs:224

            }
        }
    }

    /// Save checkpoint state to disk atomically
    async fn save_to_disk(&self, state: &CheckpointState) -> Result<(), WindowsEventLogError> {
        // Use atomic write: write to temp file, then rename
        let temp_path = self.checkpoint_path.with_extension("tmp");

        // Serialize state
        let contents = match serde_json::to_vec_pretty(state) {
            Ok(c) => c,
            Err(e) => {
                error!(
                    message = "Failed to serialize checkpoint state.",
                    error = %e
                );
                return Err(WindowsEventLogError::IoError {
                    source: io::Error::new(ErrorKind::InvalidData, e),
                });
            }
        };

        // Write to temp file
        let mut file = OpenOptions::new()
            .write(true)
            .create(true)
            .truncate(true)
            .open(&temp_path)
            .await
            .map_err(|e| WindowsEventLogError::IoError { source: e })?;

        file.write_all(&contents)
            .await
            .map_err(|e| WindowsEventLogError::IoError { source: e })?;

        file.sync_all()

View on GitHub (pinned to bdb87aeaa4)