Socket
Socket Sink
Overview
The Socket sink delivers logs, metrics, or traces to a remote socket endpoint using TCP, UDP, or Unix domain sockets. It is commonly used to forward telemetry data to custom collectors, legacy systems, or lightweight ingestion services that accept raw socket input.
This sink is stateless and optimized for streaming data with configurable buffering, encoding, framing, and optional end-to-end acknowledgements.
Key Characteristics
- Delivery: Best effort
- Acknowledgements: Supported (sink-level control)
- Egress: Stream
- State: Stateless
- Supported Inputs: Logs, Metrics, Traces
- Supported Modes: TCP, UDP, Unix stream, Unix datagram
Connection Modes
- tcp – Reliable, ordered delivery using TCP
- udp – Fire-and-forget delivery with minimal overhead
- unix_stream – Stream-based Unix domain socket
- unix_datagram – Datagram-based Unix domain socket (Linux only)
Required Configuration
- inputs List of upstream source or transform IDs.
- mode Socket type to use (tcp, udp, unix_stream, unix_datagram).
- address Target address in host:port format (required for TCP/UDP).
- path Absolute Unix socket path (required for Unix socket modes).
- encoding.codec Defines how events are serialized before transmission.
Encoding
The Socket sink supports multiple encoding formats, including:
- json
- text
- raw_message
- csv
- cef
- gelf
- protobuf
- otlp
- avro
Encoding configuration determines which event types (logs, metrics, traces) are supported and how data is serialized on the wire.
Framing
Framing controls how encoded events are delimited in the stream:
- newline_delimited
- character_delimited
- length_delimited
- varint_length_delimited
- bytes (no framing)
Framing is required for stream-based transports such as TCP and Unix stream sockets.
Buffering
Optional buffering improves reliability and backpressure handling:
- memory – High performance, volatile
- disk – Durable, survives restarts
Behavior when full:
- block (default)
- drop_newest
TLS Support
For TCP mode, TLS can be enabled to secure data in transit:
- Certificate-based authentication
- Optional hostname and certificate verification
- ALPN protocol support