Skip to content

Abbreviate verbose clickhouse logs.#10443

Merged
jmcarp merged 1 commit into
mainfrom
jmcarp/clickhouse-query-masking
May 15, 2026
Merged

Abbreviate verbose clickhouse logs.#10443
jmcarp merged 1 commit into
mainfrom
jmcarp/clickhouse-query-masking

Conversation

@jmcarp
Copy link
Copy Markdown
Contributor

@jmcarp jmcarp commented May 14, 2026

As of this writing, system.query_log is one of the largest clickhouse tables. From dogfood:

┌─database─┬─table──────────────────────────┬─compressed─┬─uncompressed─┬───────rows─┐
│ system   │ query_log                      │ 17.11 GiB  │ 39.49 GiB    │   24942352 │
│ oximeter │ measurements_cumulativeu64     │ 15.52 GiB  │ 91.91 GiB    │ 1576299396 │
│ oximeter │ measurements_f32               │ 14.52 GiB  │ 85.23 GiB    │ 1849126423 │
│ oximeter │ measurements_histogramu64      │ 2.76 GiB   │ 117.37 GiB   │   78425393 │
│ system   │ metric_log                     │ 742.29 MiB │ 12.84 GiB    │    2543307 │
└──────────┴────────────────────────────────┴────────────┴──────────────┴────────────┘

Most of this table's disk use is attributable to the query column, and most of that usage comes from the very long measurement queries run by oximeter, which take the form of:

SELECT * FROM oximeter.measurements_* WHERE timeseries_key IN (...)

The IN clause can include thousands of keys, and a single oximeter query can run multiple clickhouse queries of this form. This takes up a lot of space in the query log.

This patch truncates long IN (...) clauses. These aren't operationally useful, and shortening them shrinks system.query_log by about 80% in testing.

As of this writing, `system.query_log` is one of the largest clickhouse tables.
From dogfood:

```
┌─database─┬─table──────────────────────────┬─compressed─┬─uncompressed─┬───────rows─┐
│ system   │ query_log                      │ 17.11 GiB  │ 39.49 GiB    │   24942352 │
│ oximeter │ measurements_cumulativeu64     │ 15.52 GiB  │ 91.91 GiB    │ 1576299396 │
│ oximeter │ measurements_f32               │ 14.52 GiB  │ 85.23 GiB    │ 1849126423 │
│ oximeter │ measurements_histogramu64      │ 2.76 GiB   │ 117.37 GiB   │   78425393 │
│ system   │ metric_log                     │ 742.29 MiB │ 12.84 GiB    │    2543307 │
└──────────┴────────────────────────────────┴────────────┴──────────────┴────────────┘
```

Most of this table's disk use is attributable to the `query` column, and most
of that usage comes from the very long measurement queries run by oximeter,
which take the form of:

```
SELECT * FROM oximeter.measurements_* WHERE timeseries_key IN (...)
```

The `IN` clause can include thousands of keys, and a single oximeter query can
run multiple clickhouse queries of this form. This takes up a lot of space in
the query log.

This patch truncates long `IN (...)` clauses. These aren't operationally
useful, and shortening them shrinks `system.query_log` by about 80% in testing.
Copy link
Copy Markdown
Collaborator

@bnaecker bnaecker left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice fix, thanks

@jmcarp jmcarp merged commit 900630e into main May 15, 2026
16 checks passed
@jmcarp jmcarp deleted the jmcarp/clickhouse-query-masking branch May 15, 2026 19:09
jmcarp added a commit that referenced this pull request May 16, 2026
As described in #10444, there's a bug in setting retention policies on
`system.query_log`: because we configure the ttl in config.xml and then
optionally overwrite it in sql via retention policies, user-configured ttls on
the query log table don't survive clickhouse restarts. Instead, clickhouse
moves `system.query_log` to `system.query_log_$ORDINAL`, and creates a new
`system.query_log` table using the ttl from config.xml.

We could solve this by persisting the user-configured ttl in cockroachdb and
propagating that value to config.xml somehow. However, it's simpler to instead
make `system.query_log` small enough that we don't have to care about its ttl,
and remove it from the retention policy concept. We dropped the size of this
table significantly in #10443, and will drop it further by omitting query logs
for fast queries in a follow-up patch. In this patch, we drop logic to manage
the query log ttl.

Fixes #10444.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants