Configuration

Configuration reference

Every source, destination and processing stage, with the settings each one accepts.

This page lists every component you can put in agent.yaml, and every setting each one accepts. It is generated from the agent itself, so it always matches the version you are running.

Each component is written as a list entry with a type, a name you choose, and a params block:

sources:
  - type: wel
    name: security-log
    params:
      batch_size: "500"

Values in params are written as strings. Quoting numbers and true/false is optional but harmless, and it avoids surprises with values such as on or no, which YAML would otherwise read as booleans.

Some components also take a structured block — a richer, nested section that sits beside params rather than inside it, because its shape is more than a flat list of values. Filter and mask rules, parser settings, aggregation windows and file-integrity watch lists all work this way. Where a component has one, it is noted below and shown in full on Configuration examples.

Settings marked Advanced have sensible defaults and are collapsed behind Advanced settings in the console. You rarely need to change them.

For where the file lives, how changes are applied and what the top-level sections mean, see How DPLens is configured.

Sources

A source collects events. Every source needs a unique name; add enabled: false to keep one in the file without running it.

syslog

Receive RFC 3164/5424 syslog from network devices (UDP/TCP)

SettingValueDefaultDescription
listenText0.0.0.0:514Listen address ip:port (default 0.0.0.0:514)
protocoludp · tcpudpudp (default) | tcp.
allow_ipsComma-separated listNot setComma-separated source-IP CIDR allowlist, IPv4/IPv6 (empty = allow all)

Advanced settings

SettingValueDefaultDescription
framinglf · octet-countedlfTCP framing: lf (default) | octet-counted.
max_message_bytesWhole number of bytes, 1 to 104857665536Max bytes per record (default 65536)
max_connectionsWhole number, 1 to 65536512Max concurrent TCP connections (default 512)
idle_timeout_secsWhole number of seconds, 1 or more300Close an idle TCP connection after this many seconds (default 300, min 1)
max_connections_per_ipWhole number, 1 to 6553616Max concurrent TCP connections from one source address (default 16)
max_connection_secsWhole number of seconds, 60 to 3153600086400Close a TCP connection after this many seconds however busy it is; the sender reconnects (default 86400)
batch_sizeWhole number, 1 to 65536256Records per emitted batch (default 256)
batch_timeout_msWhole number of milliseconds, 1 to 60000200Flush a partial batch after this many ms (default 200)
queue_max_bytesWhole number of bytes, 1048576 to 107374182416777216Byte ceiling on the receive queue; UDP sheds (counted) and TCP parks the read at it (default 16 MiB, 1 GiB)
source_tagTextNot setOverride the source tag (default: component name)

netflow

Receive NetFlow v5 / IPFIX (v10) flow export (UDP; IPFIX also TCP), decoded in-source.

SettingValueDefaultDescription
listenText0.0.0.0:2055Listen address ip:port (default 0.0.0.0:2055)
protocoludp · tcpudpudp = v5 + IPFIX, version auto-detected (default) | tcp = IPFIX only.
allow_ipsComma-separated listNot setComma-separated source-IP CIDR allowlist, IPv4/IPv6 (empty = allow all)

Advanced settings

SettingValueDefaultDescription
max_message_bytesWhole number of bytes, 16 to 6553565535Max bytes per TCP IPFIX message (default 65535, the wire maximum)
max_connectionsWhole number, 1 to 6553664Max concurrent TCP connections (default 64)
idle_timeout_secsWhole number of seconds, 1 or more300Close an idle TCP connection after this many seconds (default 300)
max_connections_per_ipWhole number, 1 to 6553616Max concurrent TCP connections from one source address (default 16)
max_connection_secsWhole number of seconds, 60 to 3153600086400Close a TCP connection after this many seconds however busy it is; the exporter reconnects and re-sends its templates (default 86400)
queue_max_bytesWhole number of bytes, 1048576 to 107374182416777216Byte ceiling on the receive queue; UDP sheds (counted) and TCP parks the read at it (default 16 MiB, 1 GiB)
max_exportersWhole number, 1 to 6553664Template-cache bound: max exporters (default 64)
max_exporters_per_ipWhole number, 1 to 6553616Template-cache bound: max exporter identities per source IP (default 16)
max_templates_per_exporterWhole number, 1 to 65536256Template-cache bound per exporter (default 256)
max_fields_per_templateWhole number, 1 to 4096128Max fields in one template (default 128)
max_records_per_messageWhole number, 1 to 655364096Max flow records decoded from one message (default 4096)
batch_sizeWhole number, 1 to 65536256Records per emitted batch (default 256)
batch_timeout_msWhole number of milliseconds, 1 to 60000200Flush a partial batch after this many ms (default 200)
source_tagTextNot setOverride the source tag (default: component name)

wel

Windows Event Log channels.

SettingValueDefaultDescription
channelTextNot setLegacy single channel (back-compat); prefer the 'channels' list.
queryTextNot setRaw XPath event filter applied to every channel (default: all events). Prefer the typed filter: block (levels / event_ids / exclude_event_ids / providers, compiled to the same XPath at apply; channel_filters: overrides per channel, YAML-only) — when both are set the raw query wins and a validate warning says so.
renderoff · lazy · snare · uf-classicoffMessage rendering: off (default) | lazy | snare (lazy plus the manifest task display name — fills the Snare CategoryString column) | uf-classic (lazy plus the flattened Windows-event rendering family)
read_existingtrue or falsefalseRead events already in the log at start (default false — new events only; set true to backfill the channel history)
resolve_sidstrue or falsefalseResolve SIDs to account names (default false). Adds <field>_account beside each SID field and SIDType for the record's user; bounded per batch and cached, so a slow domain controller cannot stall collection.

Advanced settings

SettingValueDefaultDescription
batch_sizeWhole number, 1 to 1024256Events per poll (default 256 — EvtNext rejects more)
render_templatesauto · on · offautoMessage-template cache: auto (default — resolve messages from a cached template set, with periodic verification; faster when rendering is on) | on (use the cache without the periodic verification) | off (resolve every event individually). Only affects the rendering modes above.
render_workersWhole number, 0 to 640Threads used to render events, in both render modes (default 0 = auto-size from the host; 1 = no pool)

This component also takes a structured block. See Configuration examples for a worked one.

file-tail

Tail a set of log files by glob.

SettingValueDefaultDescription
path (required)Path or wildcard pattern—Glob of files to tail.
includeComma-separated listNot setComma-separated include globs.
excludeComma-separated listNot setComma-separated exclude globs.
recursivetrue or falsefalseRecurse into subdirectories (default false)
separatorText\nRecord separator (default newline)
encodingauto · utf8 · utf16le · utf16beautoauto (default) | utf8 | utf16le | utf16be.
read_existingtrue or falsetrueRead existing file contents at start (default true)

Advanced settings

SettingValueDefaultDescription
max_record_bytesWhole number of bytes, 1 to 83886081048576Max bytes per record (default 1048576)
poll_interval_msWhole number of milliseconds1000Poll interval in ms (default 1000)
flush_partial_after_msWhole number of milliseconds, 0 to 36000003000Emit an unterminated final line once the file has gone this long without growing (default 3000; 0 disables and holds it until terminated)
max_open_filesWhole number, 1 to 65536512Max concurrently open files (default 512)
source_tagTextNot setOverride the source tag (default: component name)

fim

File-integrity monitoring (scheduled scans)

Advanced settings

SettingValueDefaultDescription
source_tagTextNot setOverride the source tag (default: component name)

This component also takes a structured block. See Configuration examples for a worked one.

Destinations

A destination delivers events to your SIEM or collector. Every destination has its own disk cache, so an outage queues events rather than losing them.

tcp

TCP stream delivery.

SettingValueDefaultDescription
address (required)Text—host:port of the primary receiver.
failover_addressesComma-separated listNot setComma-separated ordered failover host:port list.
formatndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · rawndjsonndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay)
flatten_messagetrue or falsetrueNDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites.
cache_full_policyblock-upstream · drop-oldest · drop-newestblock-upstreamblock-upstream (default) | drop-oldest | drop-newest.
cache_max_bytesWhole number of bytes1073741824Disk cache cap in bytes (default 1 GiB)

Advanced settings

SettingValueDefaultDescription
framinglf · octet-countedlflf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only)
submission_modebatched · single · single-connectionbatchedbatched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers)
cache_dirTextNot setOverride the cache directory (default: state dir)
cache_segment_bytesWhole number of bytes67108864Cache segment size in bytes (default 64 MiB)
disk_reserve_bytesWhole number of bytes0Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits)
failback_stability_msWhole number of milliseconds30000Stable ms before failing back to primary (default 30000)
reconnect_backoff_max_secsWhole number of seconds30Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600)
fsync_interval_msWhole number of milliseconds100Cache fsync interval in ms (default 100)
facilityWhole number, 0 to 231Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23)
severityWhole number, 0 to 7Not setSyslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats)
hostnameTextNot setOverride the syslog/snare hostname (default: this host)
app_nameTextdplensSyslog APP-NAME (default dplens)
enterprise_idText32473Syslog-5424 enterprise ID (default 32473)
criticalityWhole number0Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4)

udp

UDP datagram delivery.

SettingValueDefaultDescription
address (required)Text—host:port of the primary receiver.
failover_addressesComma-separated listNot setComma-separated ordered failover host:port list.
formatndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · rawndjsonndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay)
flatten_messagetrue or falsetrueNDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites.
cache_full_policyblock-upstream · drop-oldest · drop-newestblock-upstreamblock-upstream (default) | drop-oldest | drop-newest.
cache_max_bytesWhole number of bytes1073741824Disk cache cap in bytes (default 1 GiB)

Advanced settings

SettingValueDefaultDescription
framinglflflf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only)
submission_modebatched · singlebatchedbatched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers)
cache_dirTextNot setOverride the cache directory (default: state dir)
cache_segment_bytesWhole number of bytes67108864Cache segment size in bytes (default 64 MiB)
disk_reserve_bytesWhole number of bytes0Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits)
failback_stability_msWhole number of milliseconds30000Stable ms before failing back to primary (default 30000)
reconnect_backoff_max_secsWhole number of seconds30Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600)
fsync_interval_msWhole number of milliseconds100Cache fsync interval in ms (default 100)
facilityWhole number, 0 to 231Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23)
severityWhole number, 0 to 7Not setSyslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats)
hostnameTextNot setOverride the syslog/snare hostname (default: this host)
app_nameTextdplensSyslog APP-NAME (default dplens)
enterprise_idText32473Syslog-5424 enterprise ID (default 32473)
criticalityWhole number0Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4)

tls

TLS (TCP) delivery.

SettingValueDefaultDescription
address (required)Text—host:port of the primary receiver.
failover_addressesComma-separated listNot setComma-separated ordered failover host:port list.
formatndjson · syslog-3164 · syslog-5424 · snare · snare-3164 · rawndjsonndjson (default) | syslog-3164 | syslog-5424 | snare | snare-3164 | raw (verbatim relay)
flatten_messagetrue or falsetrueNDJSON only: collapse whitespace and line breaks in the message to single spaces and trim the ends (default true). Windows renders event messages with CRLF layout for the event viewer; keeping it can split one record in half at a receiver that line-splits the extracted message. The snare and syslog formats always flatten and raw never rewrites.
cache_full_policyblock-upstream · drop-oldest · drop-newestblock-upstreamblock-upstream (default) | drop-oldest | drop-newest.
cache_max_bytesWhole number of bytes1073741824Disk cache cap in bytes (default 1 GiB)
tls_insecure_skip_verifytrue or falsefalseDisable certificate verification — dev only (default false)

Advanced settings

SettingValueDefaultDescription
framinglf · octet-countedlflf (default; raw defaults to octet-counted on TCP/TLS) | octet-counted (TCP/TLS only)
submission_modebatched · single · single-connectionbatchedbatched (default) | single (one event per send) | single-connection (connect, send one event, close — TCP/TLS only; expensive, for one-event-per-submission receivers)
cache_dirTextNot setOverride the cache directory (default: state dir)
cache_segment_bytesWhole number of bytes67108864Cache segment size in bytes (default 64 MiB)
disk_reserve_bytesWhole number of bytes0Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits)
failback_stability_msWhole number of milliseconds30000Stable ms before failing back to primary (default 30000)
reconnect_backoff_max_secsWhole number of seconds30Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600)
fsync_interval_msWhole number of milliseconds100Cache fsync interval in ms (default 100)
facilityWhole number, 0 to 231Syslog/Snare facility 0–23 (default 1 = user; higher values clamp to 23)
severityWhole number, 0 to 7Not setSyslog/Snare severity 0–7 (default 6 for the syslog formats, 5 for the snare formats)
hostnameTextNot setOverride the syslog/snare hostname (default: this host)
app_nameTextdplensSyslog APP-NAME (default dplens)
enterprise_idText32473Syslog-5424 enterprise ID (default 32473)
criticalityWhole number0Snare criticality, the fallback when an event carries no Criticality field (default 0; Snare receivers conventionally use 0–4)
ca_fileTextNot setPEM CA bundle to verify the server (default: system roots)
sniTextNot setOverride the TLS SNI (default: address host)
client_cert_handleTextNot setMutual TLS: secret-store handle of the agent's client certificate chain (PEM), e.g. secret://dest-1/client-cert — set with client_key_handle, or neither (mTLS)
client_key_handleTextNot setMutual TLS: secret-store handle of the agent's client private key (PEM), e.g. secret://dest-1/client-key — sealed with dplens.exe --set-secret; refused unless it belongs to client_cert_handle's certificate.

splunk-s2s

Splunk cooked S2S delivery.

SettingValueDefaultDescription
address (required)Text—host:port of the Splunk indexer or heavy forwarder (cooked S2S receiver, conventionally port 9997) — the single/failover form; a POOL uses addresses instead.
failover_addressesComma-separated listNot setComma-separated ordered failover host:port list (ordered group; not with addresses)
addressesComma-separated listNot setComma-separated EQUAL-PEER pool of indexer host:port members: traffic rotates across every member (autoLB), a member whose send fails is ejected and re-admitted after a stability window, and only ALL members down spools to the cache. Selects the pool instead of address/failover_addresses — never both. 1…64 members, no duplicates. Composes with ack (ack × pool clause: acknowledgement ids are routed per member — an id is only ever polled on the member that issued it)
cache_full_policyblock-upstream · drop-oldest · drop-newestblock-upstreamblock-upstream (default) | drop-oldest | drop-newest.
cache_max_bytesWhole number of bytes1073741824Disk cache cap in bytes (default 1 GiB)
tlstrue or falsefalseEnable TLS to the receiver (default FALSE: a stock indexer receiver on the conventional 9997 port accepts plaintext, so defaulting TLS on would fail against an unprepared receiver; the HEC destination defaults TRUE because that input is HTTPS). Once on, certificate validation is on by default and tls_insecure_skip_verify is the audited opt-out.
tls_insecure_skip_verifytrue or falsefalseDisable certificate verification — dev only (default false)
acktrue or falsefalseIndexer acknowledgement: resolve events only on the indexer's per-connection record ack (useACK), with a bounded in-flight window and re-send on timeout. Default FALSE Composes with failover_addresses and addresses (ack × pool clause: ids routed per member; a member closed on switch has its unconfirmed records re-sent on the current member at once — bounded, counted duplicates)

Advanced settings

SettingValueDefaultDescription
lb_rotate_secsWhole number of seconds30Pool only: seconds on one member before rotating to the next at a batch boundary (default 30; 1…86400, time rotation is always on)
lb_rotate_bytesWhole number of bytes0Pool only: also rotate after this many bytes on the current member (default 0 = off)
lb_readmit_secsWhole number of seconds30Pool only: stability window before an ejected member is probed for re-admission (a background TCP connect off the data plane; the first real send confirms) (default 30; 1…3600)
submission_modebatchedbatchedbatched only: a channel's records must reach a connection in order and without gaps (measured)
cache_dirTextNot setOverride the cache directory (default: state dir)
cache_segment_bytesWhole number of bytes67108864Cache segment size in bytes (default 64 MiB)
disk_reserve_bytesWhole number of bytes0Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits)
failback_stability_msWhole number of milliseconds30000Stable ms before failing back to primary (default 30000)
reconnect_backoff_max_secsWhole number of seconds30Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600)
fsync_interval_msWhole number of milliseconds100Cache fsync interval in ms (default 100)
s2s_server_nameTextNot setThe serverName the S2S handshake advertises (default: this host's name — the UF-shaped identity). Recorded in the audit log.
s2s_mgmt_portText8089The management port the handshake advertises (default 8089; an identity claim, not a connection)
ca_fileTextNot setPEM CA bundle to verify the server (default: system roots)
sniTextNot setOverride the TLS SNI (default: address host)
client_cert_handleTextNot setMutual TLS: secret-store handle of the agent's client certificate chain (PEM) — with client_key_handle, or neither.
client_key_handleTextNot setMutual TLS: secret-store handle of the agent's client private key (PEM); refused unless it belongs to the certificate.
require_hellotrue or falsetrueFail the connection when the receiver does not answer our S2S handshake (default TRUE) The measured indexer refuses a protocol line either by closing at once or by holding the connection open and sending nothing — so silence is treated as refusal and no events are streamed into it. Set false only for a receiver that legitimately sends no hello: silence and unrecognised greetings are then tolerated as before. A receiver that CLOSES the connection always fails, either way.
ack_window_eventsWhole number8192In-flight (sent-but-unacked) event bound; exhaustion applies backpressure upstream rather than dropping (default 8192)
ack_window_bytesWhole number of bytes67108864In-flight byte bound (encoded record bytes) — whichever of the two window bounds trips first (default 64 MiB)
ack_poll_interval_msWhole number of milliseconds1000Cadence of the ack read-drain off the data socket (default 1000; the indexer streams acks spontaneously as records index, so this only bounds read latency)
ack_timeout_msWhole number of milliseconds60000Per-batch ack deadline; expiry re-sends the batch — bounded, counted duplicates (default 60000)
ack_resend_limitWhole number3Consecutive timeouts of one batch before the ack-stalled destination fault raises; delivery keeps retrying regardless (default 3)

This component also takes a structured block. See Configuration examples for a worked one.

Accepted rendering values: classic, xml.

splunk-hec

Splunk HEC delivery (HTTP Event Collector)

SettingValueDefaultDescription
address (required)Text—host:port of the HEC endpoint (conventionally port 8088) — the single/failover form; a POOL uses addresses instead.
failover_addressesComma-separated listNot setComma-separated ordered failover host:port list (ordered group; not with addresses)
addressesComma-separated listNot setComma-separated EQUAL-PEER pool of HEC endpoint host:port members: traffic rotates across every member (autoLB), a member whose send fails is ejected and re-admitted after a stability window, and only ALL members down spools to the cache. Selects the pool instead of address/failover_addresses — never both. 1…64 members, no duplicates. Composes with ack (ack × pool clause: acknowledgement ids are routed per member — an id is only ever polled on the member that issued it)
token_handle (required)Text—Secret-store handle for the HEC token (e.g. secret://splunk/hec-token). Seed with dplens.exe --set-secret <handle>; the VALUE never appears in config, logs or the UI.
endpointevent · raweventevent (default): batched JSON to /services/collector/event | raw: one event per request to /services/collector/raw, metadata in the query string.
cache_full_policyblock-upstream · drop-oldest · drop-newestblock-upstreamblock-upstream (default) | drop-oldest | drop-newest.
cache_max_bytesWhole number of bytes1073741824Disk cache cap in bytes (default 1 GiB)
tlstrue or falsetrueHTTPS to the HEC endpoint (default TRUE —: the HEC input is HTTPS by default; set false only for a plaintext input)
tls_insecure_skip_verifytrue or falsefalseDisable certificate verification — dev only (default false)
acktrue or falsefalseIndexer acknowledgement (…24): resolve events only on the server's ack, with bounded in-flight window, 1 s polling and re-send on timeout. Default FALSE requires useACK on the token, and the channel GUID is generated per instance (per member on a pool / failover group), never configured. Composes with failover_addresses and addresses (ack × pool clause: ackIds routed per member — never polled on another member)

Advanced settings

SettingValueDefaultDescription
lb_rotate_secsWhole number of seconds30Pool only: seconds on one member before rotating to the next at a batch boundary (default 30; 1…86400, time rotation is always on)
lb_rotate_bytesWhole number of bytes0Pool only: also rotate after this many bytes on the current member (default 0 = off)
lb_readmit_secsWhole number of seconds30Pool only: stability window before an ejected member is probed for re-admission (a background TCP connect off the data plane; the first real send confirms) (default 30; 1…3600)
max_request_bytesWhole number of bytes1048576Upper bound on one request body in bytes (default 1 MiB)
max_request_eventsWhole number1024Upper bound on events per request (default 1024)
submission_modebatchedbatchedbatched only: the encoder's request frames already bound per-request size and event count.
cache_dirTextNot setOverride the cache directory (default: state dir)
cache_segment_bytesWhole number of bytes67108864Cache segment size in bytes (default 64 MiB)
disk_reserve_bytesWhole number of bytes0Free disk to keep in reserve on the cache volume, in bytes (default 0 = no floor beyond physically full). Enforced: the cache stops growing when the volume would drop below it and cache_full_policy applies there exactly as at cache_max_bytes; every activation is counted (reserve_floor_hits)
failback_stability_msWhole number of milliseconds30000Stable ms before failing back to primary (default 30000)
reconnect_backoff_max_secsWhole number of seconds30Reconnect backoff ceiling while the destination is unreachable: retries double from the 0.5 s drain cadence with jitter up to this (default 30; 1…3600)
fsync_interval_msWhole number of milliseconds100Cache fsync interval in ms (default 100)
ca_fileTextNot setPEM CA bundle to verify the server (default: system roots)
client_cert_handleTextNot setMutual TLS: secret-store handle of the agent's client certificate chain (PEM) — with client_key_handle, or neither.
client_key_handleTextNot setMutual TLS: secret-store handle of the agent's client private key (PEM); refused unless it belongs to the certificate.
ack_window_eventsWhole number8192In-flight (sent-but-unacked) event bound; exhaustion applies backpressure upstream rather than dropping (default 8192)
ack_window_bytesWhole number of bytes67108864In-flight byte bound (encoded request bytes) — whichever of the two window bounds trips first (default 64 MiB)
ack_poll_interval_msWhole number of milliseconds1000Cadence of the /ack poll (default 1000)
ack_timeout_msWhole number of milliseconds60000Per-request ack deadline from the request's 2xx; expiry re-sends the batch as a fresh request — bounded, counted duplicates (default 60000)
ack_resend_limitWhole number3Consecutive timeouts of one batch before the ack-stalled destination fault raises; delivery keeps retrying regardless (default 3)

This component also takes a structured block. See Configuration examples for a worked one.

Accepted rendering values: classic, xml.

Processing stages

Stages run in the order you list them inside a pipeline's stages. Masking always runs before anything is written to disk or sent.

tag

Add a single static key/value tag.

SettingValueDefaultDescription
keyTexttagField name to set (default "tag")
valueTexttrueValue to set (default "true")

filter

Keep/drop events by an AND/OR/NOT rule tree.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted action values: keep, drop.

Accepted op values: eq, ne, contains, regex, gt, ge, lt, le, in, cidr.

static-tags

Add a map of static tags.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

system-fields

Enrich with host/OS/agent/network facts.

Advanced settings

SettingValueDefaultDescription
refresh_secsWhole number of seconds300Fact refresh interval in seconds (default 300)

This component also takes a structured block. See Configuration examples for a worked one.

Accepted fields values: host_name, host_fqdn, domain, os_name, os_version, os_build, agent_id, agent_version, local_ipv4, local_ipv6, mac, logged_on_user, timezone.

public-ip

Enrich with the agent's public IP (HTTPS lookup)

SettingValueDefaultDescription
fieldTextpublic_ipField to set (default public_ip)
enabledtrue or falsetrueEnable the lookup (default true)

Advanced settings

SettingValueDefaultDescription
endpointTexthttps://checkip.amazonaws.comHTTPS endpoint (default https://checkip.amazonaws.com)
ttl_secsWhole number of seconds900Cache TTL in seconds (default 900)
timeout_msWhole number of milliseconds5000Lookup timeout in ms (default 5000)

parse-json

Parse a JSON record into fields.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

parse-syslog

Parse a syslog record into fields.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

parse-delimited

Parse a delimited record (CSV/TSV/…)

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

parse-kv

Parse key=value pairs into fields.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

parse-regex

Parse with a named-capture regex.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

normalise

Map fields onto an OCSF/CIM schema, or apply custom field remaps (rename/copy/drop) with an optional pack; emit: remapped keeps only the fields the stage writes.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted action values: set, copy, rename, cast, default, drop.

Accepted cast.to values: str, int, uint, bool, ip, ts.

Accepted emit values: all, remapped.

Accepted map.cim values: windows-security, file-fallback.

Accepted map.ocsf values: windows-security.

Accepted schema values: ocsf, cim.

mask

Detect and mask sensitive data.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted action values: redact, partial, token, hmac.

Accepted detector values: luhn, email, ipv4, ipv6, us-ssn, uk-ni, phone, regex.

aggregate

Windowed aggregation of similar events.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted op values: eq, ne, contains, regex, gt, ge, lt, le, in, cidr.

Accepted representative values: first, last, none.

prune

Drop fields whose value carries no forensic meaning — a placeholder such as -, N/A, null or 0x0.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted values values: , -, N/A, null, none, (null), NULL SID, S-1-0-0, 0x0, ?, --.

rate-control

Token-bucket rate limiting / smoothing.

This component takes no params settings.

This component also takes a structured block. See Configuration examples for a worked one.

Accepted policy values: drop_newest, drop_priority, sample.