This page lists every component you can put in agent.yaml, and every setting each one accepts. It is generated from the agent itself, so it always matches the version you are running.
Each component is written as a list entry with a type, a name you choose, and a params block:
sources:
- type: wel
name: security-log
params:
batch_size: "500"
Values in params are written as strings. Quoting numbers and true/false is optional but harmless, and it avoids surprises with values such as on or no, which YAML would otherwise read as booleans.
Some components also take a structured block — a richer, nested section that sits beside params rather than inside it, because its shape is more than a flat list of values. Filter and mask rules, parser settings, aggregation windows and file-integrity watch lists all work this way. Where a component has one, it is noted below and shown in full on Configuration examples.
Settings marked Advanced have sensible defaults and are collapsed behind Advanced settings in the console. You rarely need to change them.
For where the file lives, how changes are applied and what the top-level sections mean, see How DPLens is configured.
Sources
A source collects events. Every source needs a unique name; add enabled: false to keep one in the file without running it.
syslog
Receive RFC 3164/5424 syslog from network devices (UDP/TCP)
| Setting | Value | Default | Description |
|---|---|---|---|
listen | Text | 0.0.0.0:514 | Listen address ip:port (default 0.0.0.0:514) |
protocol | udp · tcp | udp | udp (default) | tcp. |
allow_ips | Comma-separated list | Not set | Comma-separated source-IP CIDR allowlist, IPv4/IPv6 (empty = allow all) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
framing | lf · octet-counted | lf | TCP framing: lf (default) | octet-counted. |
max_message_bytes | Whole number of bytes, 1 to 1048576 | 65536 | Max bytes per record (default 65536) |
max_connections | Whole number, 1 to 65536 | 512 | Max concurrent TCP connections (default 512) |
idle_timeout_secs | Whole number of seconds, 1 or more | 300 | Close an idle TCP connection after this many seconds (default 300, min 1) |
max_connections_per_ip | Whole number, 1 to 65536 | 16 | Max concurrent TCP connections from one source address (default 16) |
max_connection_secs | Whole number of seconds, 60 to 31536000 | 86400 | Close a TCP connection after this many seconds however busy it is; the sender reconnects (default 86400) |
batch_size | Whole number, 1 to 65536 | 256 | Records per emitted batch (default 256) |
batch_timeout_ms | Whole number of milliseconds, 1 to 60000 | 200 | Flush a partial batch after this many ms (default 200) |
queue_max_bytes | Whole number of bytes, 1048576 to 1073741824 | 16777216 | Byte ceiling on the receive queue; UDP sheds (counted) and TCP parks the read at it (default 16 MiB, 1 GiB) |
source_tag | Text | Not set | Override the source tag (default: component name) |
netflow
Receive NetFlow v5 / IPFIX (v10) flow export (UDP; IPFIX also TCP), decoded in-source.
| Setting | Value | Default | Description |
|---|---|---|---|
listen | Text | 0.0.0.0:2055 | Listen address ip:port (default 0.0.0.0:2055) |
protocol | udp · tcp | udp | udp = v5 + IPFIX, version auto-detected (default) | tcp = IPFIX only. |
allow_ips | Comma-separated list | Not set | Comma-separated source-IP CIDR allowlist, IPv4/IPv6 (empty = allow all) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
max_message_bytes | Whole number of bytes, 16 to 65535 | 65535 | Max bytes per TCP IPFIX message (default 65535, the wire maximum) |
max_connections | Whole number, 1 to 65536 | 64 | Max concurrent TCP connections (default 64) |
idle_timeout_secs | Whole number of seconds, 1 or more | 300 | Close an idle TCP connection after this many seconds (default 300) |
max_connections_per_ip | Whole number, 1 to 65536 | 16 | Max concurrent TCP connections from one source address (default 16) |
max_connection_secs | Whole number of seconds, 60 to 31536000 | 86400 | Close a TCP connection after this many seconds however busy it is; the exporter reconnects and re-sends its templates (default 86400) |
queue_max_bytes | Whole number of bytes, 1048576 to 1073741824 | 16777216 | Byte ceiling on the receive queue; UDP sheds (counted) and TCP parks the read at it (default 16 MiB, 1 GiB) |
max_exporters | Whole number, 1 to 65536 | 64 | Template-cache bound: max exporters (default 64) |
max_exporters_per_ip | Whole number, 1 to 65536 | 16 | Template-cache bound: max exporter identities per source IP (default 16) |
max_templates_per_exporter | Whole number, 1 to 65536 | 256 | Template-cache bound per exporter (default 256) |
max_fields_per_template | Whole number, 1 to 4096 | 128 | Max fields in one template (default 128) |
max_records_per_message | Whole number, 1 to 65536 | 4096 | Max flow records decoded from one message (default 4096) |
batch_size | Whole number, 1 to 65536 | 256 | Records per emitted batch (default 256) |
batch_timeout_ms | Whole number of milliseconds, 1 to 60000 | 200 | Flush a partial batch after this many ms (default 200) |
source_tag | Text | Not set | Override the source tag (default: component name) |
wel
Windows Event Log channels.
| Setting | Value | Default | Description |
|---|---|---|---|
channel | Text | Not set | Legacy single channel (back-compat); prefer the 'channels' list. |
query | Text | Not set | Raw XPath event filter applied to every channel (default: all events). Prefer the typed filter: block (levels / event_ids / exclude_event_ids / providers, compiled to the same XPath at apply; channel_filters: overrides per channel, YAML-only) — when both are set the raw query wins and a validate warning says so. |
render | off · lazy · snare · uf-classic | off | Message rendering: off (default) | lazy | snare (lazy plus the manifest task display name — fills the Snare CategoryString column) | uf-classic (lazy plus the flattened Windows-event rendering family) |
read_existing | true or false | false | Read events already in the log at start (default false — new events only; set true to backfill the channel history) |
resolve_sids | true or false | false | Resolve SIDs to account names (default false). Adds <field>_account beside each SID field and SIDType for the record's user; bounded per batch and cached, so a slow domain controller cannot stall collection. |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
batch_size | Whole number, 1 to 1024 | 256 | Events per poll (default 256 — EvtNext rejects more) |
render_templates | auto · on · off | auto | Message-template cache: auto (default — resolve messages from a cached template set, with periodic verification; faster when rendering is on) | on (use the cache without the periodic verification) | off (resolve every event individually). Only affects the rendering modes above. |
render_workers | Whole number, 0 to 64 | 0 | Threads used to render events, in both render modes (default 0 = auto-size from the host; 1 = no pool) |
This component also takes a structured block. See Configuration examples for a worked one.
file-tail
Tail a set of log files by glob.
| Setting | Value | Default | Description |
|---|---|---|---|
path (required) | Path or wildcard pattern | — | Glob of files to tail. |
include | Comma-separated list | Not set | Comma-separated include globs. |
exclude | Comma-separated list | Not set | Comma-separated exclude globs. |
recursive | true or false | false | Recurse into subdirectories (default false) |
separator | Text | \n | Record separator (default newline) |
encoding | auto · utf8 · utf16le · utf16be | auto | auto (default) | utf8 | utf16le | utf16be. |
read_existing | true or false | true | Read existing file contents at start (default true) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
max_record_bytes | Whole number of bytes, 1 to 8388608 | 1048576 | Max bytes per record (default 1048576) |
poll_interval_ms | Whole number of milliseconds | 1000 | Poll interval in ms (default 1000) |
flush_partial_after_ms | Whole number of milliseconds, 0 to 3600000 | 3000 | Emit an unterminated final line once the file has gone this long without growing (default 3000; 0 disables and holds it until terminated) |
max_open_files | Whole number, 1 to 65536 | 512 | Max concurrently open files (default 512) |
source_tag | Text | Not set | Override the source tag (default: component name) |
fim
File-integrity monitoring (scheduled scans)
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
source_tag | Text | Not set | Override the source tag (default: component name) |
This component also takes a structured block. See Configuration examples for a worked one.
Destinations
A destination delivers events to your SIEM or collector. Every destination has its own disk cache, so an outage queues events rather than losing them.
tcp
TCP stream delivery.
| Setting | Value | Default | Description |
|---|---|---|---|
address (required) | Text | — | host:port of the primary receiver. |
failover_addresses | Comma-separated list | Not set | Comma-separated ordered failover host:port list. |
format | ndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · raw | ndjson | ndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay) |
flatten_message | true or false | true | NDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites. |
cache_full_policy | block-upstream · drop-oldest · drop-newest | block-upstream | block-upstream (default) | drop-oldest | drop-newest. |
cache_max_bytes | Whole number of bytes | 1073741824 | Disk cache cap in bytes (default 1 GiB) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
framing | lf · octet-counted | lf | lf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only) |
submission_mode | batched · single · single-connection | batched | batched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers) |
cache_dir | Text | Not set | Override the cache directory (default: state dir) |
cache_segment_bytes | Whole number of bytes | 67108864 | Cache segment size in bytes (default 64 MiB) |
disk_reserve_bytes | Whole number of bytes | 0 | Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits) |
failback_stability_ms | Whole number of milliseconds | 30000 | Stable ms before failing back to primary (default 30000) |
reconnect_backoff_max_secs | Whole number of seconds | 30 | Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600) |
fsync_interval_ms | Whole number of milliseconds | 100 | Cache fsync interval in ms (default 100) |
facility | Whole number, 0 to 23 | 1 | Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23) |
severity | Whole number, 0 to 7 | Not set | Syslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats) |
hostname | Text | Not set | Override the syslog/snare hostname (default: this host) |
app_name | Text | dplens | Syslog APP-NAME (default dplens) |
enterprise_id | Text | 32473 | Syslog-5424 enterprise ID (default 32473) |
criticality | Whole number | 0 | Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4) |
udp
UDP datagram delivery.
| Setting | Value | Default | Description |
|---|---|---|---|
address (required) | Text | — | host:port of the primary receiver. |
failover_addresses | Comma-separated list | Not set | Comma-separated ordered failover host:port list. |
format | ndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · raw | ndjson | ndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay) |
flatten_message | true or false | true | NDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites. |
cache_full_policy | block-upstream · drop-oldest · drop-newest | block-upstream | block-upstream (default) | drop-oldest | drop-newest. |
cache_max_bytes | Whole number of bytes | 1073741824 | Disk cache cap in bytes (default 1 GiB) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
framing | lf | lf | lf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only) |
submission_mode | batched · single | batched | batched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers) |
cache_dir | Text | Not set | Override the cache directory (default: state dir) |
cache_segment_bytes | Whole number of bytes | 67108864 | Cache segment size in bytes (default 64 MiB) |
disk_reserve_bytes | Whole number of bytes | 0 | Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits) |
failback_stability_ms | Whole number of milliseconds | 30000 | Stable ms before failing back to primary (default 30000) |
reconnect_backoff_max_secs | Whole number of seconds | 30 | Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600) |
fsync_interval_ms | Whole number of milliseconds | 100 | Cache fsync interval in ms (default 100) |
facility | Whole number, 0 to 23 | 1 | Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23) |
severity | Whole number, 0 to 7 | Not set | Syslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats) |
hostname | Text | Not set | Override the syslog/snare hostname (default: this host) |
app_name | Text | dplens | Syslog APP-NAME (default dplens) |
enterprise_id | Text | 32473 | Syslog-5424 enterprise ID (default 32473) |
criticality | Whole number | 0 | Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4) |
tls
TLS (TCP) delivery.
| Setting | Value | Default | Description |
|---|---|---|---|
address (required) | Text | — | host:port of the primary receiver. |
failover_addresses | Comma-separated list | Not set | Comma-separated ordered failover host:port list. |
format | ndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · raw | ndjson | ndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay) |
flatten_message | true or false | true | NDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites. |
cache_full_policy | block-upstream · drop-oldest · drop-newest | block-upstream | block-upstream (default) | drop-oldest | drop-newest. |
cache_max_bytes | Whole number of bytes | 1073741824 | Disk cache cap in bytes (default 1 GiB) |
tls_insecure_skip_verify | true or false | false | Disable certificate verification — dev only (default false) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
framing | lf · octet-counted | lf | lf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only) |
submission_mode | batched · single · single-connection | batched | batched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers) |
cache_dir | Text | Not set | Override the cache directory (default: state dir) |
cache_segment_bytes | Whole number of bytes | 67108864 | Cache segment size in bytes (default 64 MiB) |
disk_reserve_bytes | Whole number of bytes | 0 | Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits) |
failback_stability_ms | Whole number of milliseconds | 30000 | Stable ms before failing back to primary (default 30000) |
reconnect_backoff_max_secs | Whole number of seconds | 30 | Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600) |
fsync_interval_ms | Whole number of milliseconds | 100 | Cache fsync interval in ms (default 100) |
facility | Whole number, 0 to 23 | 1 | Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23) |
severity | Whole number, 0 to 7 | Not set | Syslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats) |
hostname | Text | Not set | Override the syslog/snare hostname (default: this host) |
app_name | Text | dplens | Syslog APP-NAME (default dplens) |
enterprise_id | Text | 32473 | Syslog-5424 enterprise ID (default 32473) |
criticality | Whole number | 0 | Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4) |
ca_file | Text | Not set | PEM CA bundle to verify the server (default: system roots) |
sni | Text | Not set | Override the TLS SNI (default: address host) |
client_cert_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client certificate chain (PEM), e.g. secret://dest-1/client-cert — set with client_key_handle, or neither (mTLS) |
client_key_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client private key (PEM), e.g. secret://dest-1/client-key — sealed with dplens.exe --set-secret; refused unless it belongs to client_cert_handle's certificate. |
splunk-s2s
Splunk cooked S2S delivery.
| Setting | Value | Default | Description |
|---|---|---|---|
address (required) | Text | — | host:port of the Splunk indexer or heavy forwarder (cooked S2S receiver, conventionally port 9997) — the single/failover form; a POOL uses addresses instead. |
failover_addresses | Comma-separated list | Not set | Comma-separated ordered failover host:port list (ordered group; not with addresses) |
addresses | Comma-separated list | Not set | Comma-separated EQUAL-PEER pool of indexer host:port members: traffic rotates across every member (autoLB), a member whose send fails is ejected and re-admitted after a stability window, and only ALL members down spools to the cache. Selects the pool instead of address/failover_addresses — never both. 1…64 members, no duplicates. Composes with ack (ack × pool clause: acknowledgement ids are routed per member — an id is only ever polled on the member that issued it) |
cache_full_policy | block-upstream · drop-oldest · drop-newest | block-upstream | block-upstream (default) | drop-oldest | drop-newest. |
cache_max_bytes | Whole number of bytes | 1073741824 | Disk cache cap in bytes (default 1 GiB) |
tls | true or false | false | Enable TLS to the receiver (default FALSE: a stock indexer receiver on the conventional 9997 port accepts plaintext, so defaulting TLS on would fail against an unprepared receiver; the HEC destination defaults TRUE because that input is HTTPS). Once on, certificate validation is on by default and tls_insecure_skip_verify is the audited opt-out. |
tls_insecure_skip_verify | true or false | false | Disable certificate verification — dev only (default false) |
ack | true or false | false | Indexer acknowledgement: resolve events only on the indexer's per-connection record ack (useACK), with a bounded in-flight window and re-send on timeout. Default FALSE Composes with failover_addresses and addresses (ack × pool clause: ids routed per member; a member closed on switch has its unconfirmed records re-sent on the current member at once — bounded, counted duplicates) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
lb_rotate_secs | Whole number of seconds | 30 | Pool only: seconds on one member before rotating to the next at a batch boundary (default 30; 1…86400, time rotation is always on) |
lb_rotate_bytes | Whole number of bytes | 0 | Pool only: also rotate after this many bytes on the current member (default 0 = off) |
lb_readmit_secs | Whole number of seconds | 30 | Pool only: stability window before an ejected member is probed for re-admission (a background TCP connect off the data plane; the first real send confirms) (default 30; 1…3600) |
submission_mode | batched | batched | batched only: a channel's records must reach a connection in order and without gaps (measured) |
cache_dir | Text | Not set | Override the cache directory (default: state dir) |
cache_segment_bytes | Whole number of bytes | 67108864 | Cache segment size in bytes (default 64 MiB) |
disk_reserve_bytes | Whole number of bytes | 0 | Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits) |
failback_stability_ms | Whole number of milliseconds | 30000 | Stable ms before failing back to primary (default 30000) |
reconnect_backoff_max_secs | Whole number of seconds | 30 | Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600) |
fsync_interval_ms | Whole number of milliseconds | 100 | Cache fsync interval in ms (default 100) |
s2s_server_name | Text | Not set | The serverName the S2S handshake advertises (default: this host's name — the UF-shaped identity). Recorded in the audit log. |
s2s_mgmt_port | Text | 8089 | The management port the handshake advertises (default 8089; an identity claim, not a connection) |
ca_file | Text | Not set | PEM CA bundle to verify the server (default: system roots) |
sni | Text | Not set | Override the TLS SNI (default: address host) |
client_cert_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client certificate chain (PEM) — with client_key_handle, or neither. |
client_key_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client private key (PEM); refused unless it belongs to the certificate. |
require_hello | true or false | true | Fail the connection when the receiver does not answer our S2S handshake (default TRUE) The measured indexer refuses a protocol line either by closing at once or by holding the connection open and sending nothing — so silence is treated as refusal and no events are streamed into it. Set false only for a receiver that legitimately sends no hello: silence and unrecognised greetings are then tolerated as before. A receiver that CLOSES the connection always fails, either way. |
ack_window_events | Whole number | 8192 | In-flight (sent-but-unacked) event bound; exhaustion applies backpressure upstream rather than dropping (default 8192) |
ack_window_bytes | Whole number of bytes | 67108864 | In-flight byte bound (encoded record bytes) — whichever of the two window bounds trips first (default 64 MiB) |
ack_poll_interval_ms | Whole number of milliseconds | 1000 | Cadence of the ack read-drain off the data socket (default 1000; the indexer streams acks spontaneously as records index, so this only bounds read latency) |
ack_timeout_ms | Whole number of milliseconds | 60000 | Per-batch ack deadline; expiry re-sends the batch — bounded, counted duplicates (default 60000) |
ack_resend_limit | Whole number | 3 | Consecutive timeouts of one batch before the ack-stalled destination fault raises; delivery keeps retrying regardless (default 3) |
This component also takes a structured block. See Configuration examples for a worked one.
Accepted rendering values: classic, xml.
splunk-hec
Splunk HEC delivery (HTTP Event Collector)
| Setting | Value | Default | Description |
|---|---|---|---|
address (required) | Text | — | host:port of the HEC endpoint (conventionally port 8088) — the single/failover form; a POOL uses addresses instead. |
failover_addresses | Comma-separated list | Not set | Comma-separated ordered failover host:port list (ordered group; not with addresses) |
addresses | Comma-separated list | Not set | Comma-separated EQUAL-PEER pool of HEC endpoint host:port members: traffic rotates across every member (autoLB), a member whose send fails is ejected and re-admitted after a stability window, and only ALL members down spools to the cache. Selects the pool instead of address/failover_addresses — never both. 1…64 members, no duplicates. Composes with ack (ack × pool clause: acknowledgement ids are routed per member — an id is only ever polled on the member that issued it) |
token_handle (required) | Text | — | Secret-store handle for the HEC token (e.g. secret://splunk/hec-token). Seed with dplens.exe --set-secret <handle>; the VALUE never appears in config, logs or the UI. |
endpoint | event · raw | event | event (default): batched JSON to /services/collector/event | raw: one event per request to /services/collector/raw, metadata in the query string. |
cache_full_policy | block-upstream · drop-oldest · drop-newest | block-upstream | block-upstream (default) | drop-oldest | drop-newest. |
cache_max_bytes | Whole number of bytes | 1073741824 | Disk cache cap in bytes (default 1 GiB) |
tls | true or false | true | HTTPS to the HEC endpoint (default TRUE —: the HEC input is HTTPS by default; set false only for a plaintext input) |
tls_insecure_skip_verify | true or false | false | Disable certificate verification — dev only (default false) |
ack | true or false | false | Indexer acknowledgement (…24): resolve events only on the server's ack, with bounded in-flight window, 1 s polling and re-send on timeout. Default FALSE requires useACK on the token, and the channel GUID is generated per instance (per member on a pool / failover group), never configured. Composes with failover_addresses and addresses (ack × pool clause: ackIds routed per member — never polled on another member) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
lb_rotate_secs | Whole number of seconds | 30 | Pool only: seconds on one member before rotating to the next at a batch boundary (default 30; 1…86400, time rotation is always on) |
lb_rotate_bytes | Whole number of bytes | 0 | Pool only: also rotate after this many bytes on the current member (default 0 = off) |
lb_readmit_secs | Whole number of seconds | 30 | Pool only: stability window before an ejected member is probed for re-admission (a background TCP connect off the data plane; the first real send confirms) (default 30; 1…3600) |
max_request_bytes | Whole number of bytes | 1048576 | Upper bound on one request body in bytes (default 1 MiB) |
max_request_events | Whole number | 1024 | Upper bound on events per request (default 1024) |
submission_mode | batched | batched | batched only: the encoder's request frames already bound per-request size and event count. |
cache_dir | Text | Not set | Override the cache directory (default: state dir) |
cache_segment_bytes | Whole number of bytes | 67108864 | Cache segment size in bytes (default 64 MiB) |
disk_reserve_bytes | Whole number of bytes | 0 | Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits) |
failback_stability_ms | Whole number of milliseconds | 30000 | Stable ms before failing back to primary (default 30000) |
reconnect_backoff_max_secs | Whole number of seconds | 30 | Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600) |
fsync_interval_ms | Whole number of milliseconds | 100 | Cache fsync interval in ms (default 100) |
ca_file | Text | Not set | PEM CA bundle to verify the server (default: system roots) |
client_cert_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client certificate chain (PEM) — with client_key_handle, or neither. |
client_key_handle | Text | Not set | Mutual TLS: secret-store handle of the agent's client private key (PEM); refused unless it belongs to the certificate. |
ack_window_events | Whole number | 8192 | In-flight (sent-but-unacked) event bound; exhaustion applies backpressure upstream rather than dropping (default 8192) |
ack_window_bytes | Whole number of bytes | 67108864 | In-flight byte bound (encoded request bytes) — whichever of the two window bounds trips first (default 64 MiB) |
ack_poll_interval_ms | Whole number of milliseconds | 1000 | Cadence of the /ack poll (default 1000) |
ack_timeout_ms | Whole number of milliseconds | 60000 | Per-request ack deadline from the request's 2xx; expiry re-sends the batch as a fresh request — bounded, counted duplicates (default 60000) |
ack_resend_limit | Whole number | 3 | Consecutive timeouts of one batch before the ack-stalled destination fault raises; delivery keeps retrying regardless (default 3) |
This component also takes a structured block. See Configuration examples for a worked one.
Accepted rendering values: classic, xml.
Processing stages
Stages run in the order you list them inside a pipeline's stages. Masking always runs before anything is written to disk or sent.
tag
Add a single static key/value tag.
| Setting | Value | Default | Description |
|---|---|---|---|
key | Text | tag | Field name to set (default "tag") |
value | Text | true | Value to set (default "true") |
filter
Keep/drop events by an AND/OR/NOT rule tree.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted action values: keep, drop.
Accepted op values: eq, ne, contains, regex, gt, ge, lt, le, in, cidr.
static-tags
Add a map of static tags.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
system-fields
Enrich with host/OS/agent/network facts.
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
refresh_secs | Whole number of seconds | 300 | Fact refresh interval in seconds (default 300) |
This component also takes a structured block. See Configuration examples for a worked one.
Accepted fields values: host_name, host_fqdn, domain, os_name, os_version, os_build, agent_id, agent_version, local_ipv4, local_ipv6, mac, logged_on_user, timezone.
public-ip
Enrich with the agent's public IP (HTTPS lookup)
| Setting | Value | Default | Description |
|---|---|---|---|
field | Text | public_ip | Field to set (default public_ip) |
enabled | true or false | true | Enable the lookup (default true) |
Advanced settings
| Setting | Value | Default | Description |
|---|---|---|---|
endpoint | Text | https://checkip.amazonaws.com | HTTPS endpoint (default https://checkip.amazonaws.com) |
ttl_secs | Whole number of seconds | 900 | Cache TTL in seconds (default 900) |
timeout_ms | Whole number of milliseconds | 5000 | Lookup timeout in ms (default 5000) |
parse-json
Parse a JSON record into fields.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
parse-syslog
Parse a syslog record into fields.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
parse-delimited
Parse a delimited record (CSV/TSV/…)
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
parse-kv
Parse key=value pairs into fields.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
parse-regex
Parse with a named-capture regex.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
normalise
Map fields onto an OCSF/CIM schema, or apply custom field remaps (rename/copy/drop) with an optional pack; emit: remapped keeps only the fields the stage writes.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted action values: set, copy, rename, cast, default, drop.
Accepted cast.to values: str, int, uint, bool, ip, ts.
Accepted emit values: all, remapped.
Accepted map.cim values: windows-security, file-fallback.
Accepted map.ocsf values: windows-security.
Accepted schema values: ocsf, cim.
mask
Detect and mask sensitive data.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted action values: redact, partial, token, hmac.
Accepted detector values: luhn, email, ipv4, ipv6, us-ssn, uk-ni, phone, regex.
aggregate
Windowed aggregation of similar events.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted op values: eq, ne, contains, regex, gt, ge, lt, le, in, cidr.
Accepted representative values: first, last, none.
prune
Drop fields whose value carries no forensic meaning — a placeholder such as -, N/A, null or 0x0.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted values values: , -, N/A, null, none, (null), NULL SID, S-1-0-0, 0x0, ?, --.
rate-control
Token-bucket rate limiting / smoothing.
This component takes no params settings.
This component also takes a structured block. See Configuration examples for a worked one.
Accepted policy values: drop_newest, drop_priority, sample.