Heroku Logplex
Heroku Logplex Source
The Heroku Logplex source receives log data from Heroku log drains via Heroku’s Logplex system. Logplex is the routing layer responsible for collecting and forwarding logs generated by Heroku applications, dynos, routers, and add-ons.
This source runs in an aggregator role and is designed for reliable log ingestion with at-least-once delivery guarantees and acknowledgement support.
Network Binding
Required Field
- address (string) The socket address the source listens on for incoming HTTP connections. This must include both IP address and port.
This address must be reachable from Heroku’s Logplex infrastructure or from any intermediary forwarding layer.
Acknowledgements
Deprecated Configuration
- acknowledgements.enabled
Acknowledgement configuration at the source level is deprecated. Acknowledgement behavior is now controlled globally or at the sink level.
Changing this setting has no effect on delivery guarantees.
Authentication (auth)
Defines how incoming HTTP requests are authenticated.
Authentication credentials are passed via HTTP headers and must be used only over HTTPS.
Supported Strategies
- basic Uses HTTP Basic Authentication with a username and password.
- custom Uses a VRL boolean expression to validate incoming requests.
Strategy-Specific Fields
- auth.username Username for basic authentication.
- auth.password Password for basic authentication.
- auth.source VRL expression used to validate the incoming request when using custom authentication.
Decoding Configuration (decoding)
Controls how incoming raw bytes are converted into log events. Some decoders may also infer event structure automatically.
Codec Selection
- decoding.codec (string, default: bytes)
Supported codecs include:
- bytes
- json
- avro
- gelf
- influxdb
- syslog
- protobuf
- otlp
- native
- native_json
- vrl
Codec-Specific Behavior
- Lossy decoding options determine whether invalid UTF-8 sequences are replaced or rejected.
- Avro and Protobuf codecs require schema or descriptor configuration.
- VRL decoding executes a VRL program to produce the final event.
Framing Configuration (framing)
Defines how individual log events are extracted from the incoming byte stream before decoding.
Supported Framing Methods
- bytes
- character_delimited
- newline_delimited
- length_delimited
- varint_length_delimited
- octet_counting
- chunked_gelf
Each framing method supports safety limits (such as maximum frame length or timeout) to prevent unbounded memory usage when processing malformed input.
HTTP Keepalive (keepalive)
Controls HTTP connection reuse behavior for incoming log drain connections.
Available Options
- max_connection_age_secs Maximum lifetime of an HTTP connection before it is closed.
- max_connection_age_jitter_factor Adds randomized jitter to connection lifetime to avoid connection storms.
These settings apply to HTTP/0.9, HTTP/1.0, and HTTP/1.1 connections.
Query Parameters
- query_parameters (list of strings) Specifies which URL query parameters are included in emitted log events.
Wildcards are supported. Query parameters override body fields when name conflicts occur.
TLS Configuration (tls)
Configures TLS for incoming HTTPS connections.
Supported Options
- enabled
- crt_file
- key_file
- key_pass
- ca_file
- alpn_protocols
- server_name
- verify_certificate
- verify_hostname
Disabling certificate or hostname verification is strongly discouraged unless the security implications are fully understood.