vectordotdev/vector · error · WindowsEventLogError
{}
Error message
{} What it means
The Windows Event Log source persists its checkpoint state to disk. If serializing the checkpoint state fails, the code logs 'Failed to serialize checkpoint state.' and returns WindowsEventLogError::IoError wrapping an io::Error with ErrorKind::InvalidData. The checkpoint write is aborted, meaning the source's saved position cannot be updated and replay/at-least-once semantics may apply on restart.
Solutions
- Delete/reset the checkpoint file so the source recreates it from scratch (accepting event replay).
- Inspect the wrapped serializer error in logs to identify which field failed to serialize.
- Ensure the checkpoint directory is writable and the file is not corrupted (check disk health).
- If it appeared after a Vector upgrade, check for checkpoint format changes in release notes and migrate or remove old checkpoints.
Example fix
// before: corrupt checkpoint file C:\ProgramData\Vector\checkpoints\application.json (invalid JSON) // after: remove it so Vector recreates the checkpoint del C:\ProgramData\Vector\checkpoints\application.json net restart vector
Defensive patterns
Strategy: try-catch
Try / catch
match save_checkpoint(state) {
Err(WindowsEventLogError::IoError { source }) => {
error!("checkpoint write failed: {source}; falling back to default cursor");
// reset checkpoint file and continue from the default position
}
other => other,
} Prevention
- Keep the checkpoint directory writable by the Vector service account.
- After Vector upgrades, verify checkpoint compatibility; delete stale checkpoints if formats changed.
- Monitor 'Failed to serialize checkpoint state.' log lines.
When it happens
Trigger: save_checkpoint (checkpoint.rs) calls serialization of the checkpoint state and gets Err(e); the error is wrapped as io::Error::new(ErrorKind::InvalidData, e) inside WindowsEventLogError::IoError and returned to the caller.
Common situations: Corrupt or incompatible checkpoint file from a previous Vector version (schema change); serializer (serde_json etc.) failing on unexpected state; disk issues returning partial data on read-then-write flows; permission problems on the checkpoint path causing malformed state.
Understand the failure class
Background: "JSON serialization failed", "not JSON serializable", "Failed to serialize": why JSON marshaling errors happen and how to fix them — this error's family across 46 libraries.
Related errors
- {}
- a record with a next ID must have an event count
- a source must always have an external resource
- {}
- Could not convert duration to JSON
AI-assisted analysis of vectordotdev/vector@bdb87aeaa4 (2026-09-16).
Data as JSON: /api/errors/c1cf5bc776babe63.
Report an issue: GitHub.
Appendix: source
Thrown at src/sources/windows_event_log/checkpoint.rs:224
}
}
}
/// Save checkpoint state to disk atomically
async fn save_to_disk(&self, state: &CheckpointState) -> Result<(), WindowsEventLogError> {
// Use atomic write: write to temp file, then rename
let temp_path = self.checkpoint_path.with_extension("tmp");
// Serialize state
let contents = match serde_json::to_vec_pretty(state) {
Ok(c) => c,
Err(e) => {
error!(
message = "Failed to serialize checkpoint state.",
error = %e
);
return Err(WindowsEventLogError::IoError {
source: io::Error::new(ErrorKind::InvalidData, e),
});
}
};
// Write to temp file
let mut file = OpenOptions::new()
.write(true)
.create(true)
.truncate(true)
.open(&temp_path)
.await
.map_err(|e| WindowsEventLogError::IoError { source: e })?;
file.write_all(&contents)
.await
.map_err(|e| WindowsEventLogError::IoError { source: e })?;
file.sync_all()View on GitHub (pinned to bdb87aeaa4)