This has the intended effect of stopping misuses and misconfigurations of this codec when data either has no \n or a different separator, thus making logstash OOM with thousands of events concatenated into 1.
The FileWatch::BufferedTokenizer constructor already exposes a size_limit, we just need to expose it and, in runtime, to catch the exception, dump it, and potentially abort the pipeline or drop the data.
This has the intended effect of stopping misuses and misconfigurations of this codec when data either has no \n or a different separator, thus making logstash OOM with thousands of events concatenated into 1.
The FileWatch::BufferedTokenizer constructor already exposes a size_limit, we just need to expose it and, in runtime, to catch the exception, dump it, and potentially abort the pipeline or drop the data.