Humio Metrics
Humio Metrics Sink
Overview
The Humio Metrics sink lets worker deliver metric event data into Humio using a Humio ingestion token. Worker turns metric samples into Humio-ingestible events, sends them in batches, and (optionally) enriches them with metadata such as source, host, and selected indexed fields.
This sink is useful when Humio is your backend for both logs and metrics, or when you want to correlate metrics with log-like events inside Humio.
Supported Input Types
- Metrics
Core Configuration Parameters
Token (required)
The Humio ingestion token used to authenticate ingestion requests.
Endpoint (optional)
The base URL of your Humio instance (must include scheme http or https). No path should be included, as worker uses the Humio/Splunk-style ingestion paths.
Default is Humio Cloud.
Index (optional)
The target Humio repository to ingest into.
- In public-facing APIs, if index is provided it typically must match the repository tied to the ingest token.
- In private clusters, Humio may allow ingesting into a different repository than the token’s default.
Because it’s templateable, you can route metrics dynamically to different repositories (if your setup supports it).
Event Type (optional)
Sets the Humio parser name (Humio calls it “event type”) used at ingestion time.
If unset, Humio defaults this to none. Use event_type when you want metrics events parsed/normalized by a particular Humio parser.
Template support allows per-metric/per-service parser selection.
Host Attribution (Metrics-Specific)
Host Key (optional)
Defines the event field name used to carry the hostname in the generated event.
Default: host
Use this if you want to align with an existing Humio field convention or your internal schema.
Host Tag (optional)
The metric tag name to use as the source host.
If the metric includes this tag, worker copies its value into the event’s host field (using the configured/global host key).
This is a key knob for clean attribution when your metrics already carry host identity in tags (e.g., host, node, instance, kubernetes.node.name, etc.).
Tag Encoding Behavior
Metric Tag Values (optional)
Controls how tag values are represented in the emitted event:
- single (default): only the last non-null value is used (compact, backwards-compatible)
- full: all tag values are exposed as arrays (more faithful, can increase event size)
Use full only if you truly need multi-valued tag preservation, because it increases payload volume and can amplify downstream field cardinality.
Field Indexing and Searchability
Indexed Fields (optional)
A list of event fields that are promoted into Humio’s “extra fields” so they become more discoverable/searchable.
Also supports Humio-style tagging by using field names that start with #.
This is where you choose which metric-derived dimensions you want to be easily queryable in Humio without indexing everything.
Source Attribution
Source (optional)
A templateable source identifier mapped to Humio’s @source.
For metrics, this is typically used to encode a logical origin like:
- the scrape/job name,
- collector/agent identity,
- pipeline name,
- environment or tenant identifier.
Payload Handling
Compression (optional)
Controls compression for outbound requests (gzip, snappy, zlib, zstd, none).
Compression can materially reduce egress bandwidth for high-volume metrics, but can trade CPU for bandwidth.
Batch (optional)
Controls batching thresholds (bytes, events, flush timeout). Batch tuning is one of the biggest throughput levers when shipping metrics at scale.
Buffer (optional)
Controls buffering behavior (memory vs disk buffering, limits, behavior when full). Use disk buffering when you want more durability across restarts and transient network issues.
Network and Security
Proxy (optional)
Supports HTTP/HTTPS proxying, including:
- separate HTTP/HTTPS proxy endpoints
- no_proxy exceptions
TLS (optional)
TLS configuration for secure transport:
- custom CA bundles
- client certs (mTLS), if your Humio endpoint requires it
- certificate and hostname verification controls
Time Handling
Timezone (optional)
Sets the timezone applied to timestamp conversions when the metric timestamps don’t include an explicit timezone.
This overrides the global worker timezone.
Useful when upstream metrics are emitted in local time (or ambiguous formats) and you need consistent conversions into Humio.
Common Usage Patterns
- Kubernetes / Prometheus-style metrics: map host_tag to an existing label/tag like instance or node, so host attribution becomes consistent.
- Repository routing: use templated index to separate metrics by tenant/environment (when Humio policy allows it).
- Parser-driven normalization: use event_type to apply a Humio parser that standardizes metric event structure.
- Controlled search dimensions: use indexed_fields to expose only a curated set of tags for query performance and cardinality control.