Socket
Connection Settings
Address (required, string):
- The socket or systemd socket to bind to. If using a socket, include a port number.
Connection_limit (optional, uint):
Maximum allowed TCP connections at once.
Applies when mode = "tcp".
Mode (required, string enum):
Defines the socket type:
tcp, udp, unix_datagram, or unix_stream.
Path (required when using Unix sockets):
Absolute path to the Unix domain socket file.
Permit_origin (optional, [string]):
List of allowed IP CIDR ranges.
TCP mode only.
Host_key / port_key (optional, string):
Overrides for the log field names capturing host and port.
receive_buffer_bytes (optional, uint):
Receive buffer size per connection.
Max_connection_duration_secs (optional, uint):
Closes connections after this duration to support load balancing.
TCP mode only.
Max_length (optional, uint):
Limits the size of UDP messages.
UDP mode only. Default: 102400 bytes.
Shutdown_timeout_secs (optional, uint):
Time to wait before forcibly closing connections during shutdown.
Default: 30 seconds.
socket_file_mode (optional, uint):
File permission bits for Unix socket files.
keepalive.time_secs (optional, uint):
Delay before sending TCP keepalive probes.
TCP mode only.
🔍 Decoding Settings
- decoding.codec (optional, enum):
Format used to decode raw bytes.
- Supported values: avro, bytes, gelf, influxdb, json, native, native_json, protobuf, syslog, vrl.
Default: bytes.
Each codec may have its own nested configuration:
📦 Avro
- schema (required, string): Avro schema definition.
- strip_schema_id_prefix (required, bool): Strip Confluent-style schema ID prefixes.
⚙️ GELF / InfluxDB / JSON / Native JSON / Syslog
- lossy (optional, bool): Replace invalid UTF-8 with U+FFFD.
Default: true.
🧬 Protobuf
- desc_file (optional, string): Path to descriptor file.
- message_type (optional, string): Message type to decode.
🧾 VRL
- source (required, string): VRL program.
- timezone (optional, string): Time zone for timestamp parsing. Default: local.
🧱 Framing Settings
- framing.method (required, enum):
Determines how byte streams are split into events:
bytes, character_delimited, chunked_gelf, length_delimited, newline_delimited, octet_counting.
Each method may have its own config:
🔤 Character Delimited
- delimiter (required, ascii_char): Delimiter character.
- max_length (optional, uint): Max buffer size (excluding delimiter).
🧩 Chunked GELF
- decompression (optional, enum): Auto, Gzip, Zlib, None.
- max_length (optional, uint): Max full message size.
- pending_messages_limit (optional, uint): Limit on incomplete GELF messages.
- timeout_secs (optional, float): Time to receive full message. Default: 5.
📏 Length Delimited
- length_field_is_big_endian (optional, bool): Byte order. Default: true.
- length_field_length (optional, uint): Byte size of the length field.
- length_field_offset (optional, uint): Bytes before the length field.
- max_frame_length (optional, uint): Max frame size. Default: 8,388,608 bytes.
🆕 Newline Delimited
- max_length (optional, uint): Max buffer size.
🔢 Octet Counting
- max_length (optional, uint): Max buffer size.
🔐 TLS Settings
- tls.enabled (optional, bool): Enable TLS for connections.
- tls.ca_file / crt_file / key_file (optional, string):
- Paths to CA, certificate, and private key files (PEM, DER, or PKCS#12 formats).
- key_pass (optional, string): Passphrase for encrypted keys.
- alpn_protocols (optional, [string]): ALPN protocols in priority order.
- client_metadata_key (optional, string): Field for client cert metadata.
- server_name (optional, string): SNI server name for outgoing TLS.
- verify_certificate / verify_hostname (optional, bool):
Enforce validation of peer certificates and hostnames.
Do not disable unless necessary.
