---
title: "Compact"
description: "lossless wire-format volume reduction; expanded at query time by analyzer-side plugins or Retriever"
source: "https://github.com/log-10x/modules/tree/main/apps/receiver/app.yaml"
icon: "material/arrow-collapse-horizontal"

---
Cut log analytics and storage costs, where the destination supports it, by losslessly compacting log/trace events at the edge before shipping them to Splunk or self-hosted Elasticsearch/OpenSearch, or to object storage paired with Retriever. Compact is one of the [Receiver](../index.md)'s per-pattern actions, alongside pass, sample, tier_down, offload, and drop. Events ship as a compact wire-form that downstream analyzer plugins or [Retriever](../../retriever/) expand at query time.


<h3 id="storage-costs"><span class="twemoji"><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 640 512"><!--! Font Awesome Free 6.5.2 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2024 Fonticons, Inc.--><path d="M180.41 203.01c-.72 22.65 10.6 32.68 10.88 39.05a8.164 8.164 0 0 1-4.1 6.27l-12.8 8.96a10.66 10.66 0 0 1-5.63 1.92c-.43-.02-8.19 1.83-20.48-25.61a78.608 78.608 0 0 1-62.61 29.45c-16.28.89-60.4-9.24-58.13-56.21-1.59-38.28 34.06-62.06 70.93-60.05 7.1.02 21.6.37 46.99 6.27v-15.62c2.69-26.46-14.7-46.99-44.81-43.91-2.4.01-19.4-.5-45.84 10.11-7.36 3.38-8.3 2.82-10.75 2.82-7.41 0-4.36-21.48-2.94-24.2 5.21-6.4 35.86-18.35 65.94-18.18a76.857 76.857 0 0 1 55.69 17.28 70.285 70.285 0 0 1 17.67 52.36l-.01 69.29zM93.99 235.4c32.43-.47 46.16-19.97 49.29-30.47 2.46-10.05 2.05-16.41 2.05-27.4-9.67-2.32-23.59-4.85-39.56-4.87-15.15-1.14-42.82 5.63-41.74 32.26-1.24 16.79 11.12 31.4 29.96 30.48zm170.92 23.05c-7.86.72-11.52-4.86-12.68-10.37l-49.8-164.65c-.97-2.78-1.61-5.65-1.92-8.58a4.61 4.61 0 0 1 3.86-5.25c.24-.04-2.13 0 22.25 0 8.78-.88 11.64 6.03 12.55 10.37l35.72 140.83 33.16-140.83c.53-3.22 2.94-11.07 12.8-10.24h17.16c2.17-.18 11.11-.5 12.68 10.37l33.42 142.63L420.98 80.1c.48-2.18 2.72-11.37 12.68-10.37h19.72c.85-.13 6.15-.81 5.25 8.58-.43 1.85 3.41-10.66-52.75 169.9-1.15 5.51-4.82 11.09-12.68 10.37h-18.69c-10.94 1.15-12.51-9.66-12.68-10.75L328.67 110.7l-32.78 136.99c-.16 1.09-1.73 11.9-12.68 10.75h-18.3zm273.48 5.63c-5.88 .01-33.92-.3-57.36-12.29a12.802 12.802 0 0 1-7.81-11.91v-10.75c0-8.45 6.2-6.9 8.83-5.89 10.04 4.06 16.48 7.14 28.81 9.6 36.65 7.53 52.77-2.3 56.72-4.48 13.15-7.81 14.19-25.68 5.25-34.95-10.48-8.79-15.48-9.12-53.13-21-4.64-1.29-43.7-13.61-43.79-52.36-.61-28.24 25.05-56.18 69.52-55.95 12.67-.01 46.43 4.13 55.57 15.62 1.35 2.09 2.02 4.55 1.92 7.04v10.11c0 4.44-1.62 6.66-4.87 6.66-7.71-.86-21.39-11.17-49.16-10.75-6.89-.36-39.89.91-38.41 24.97-.43 18.96 26.61 26.07 29.7 26.89 36.46 10.97 48.65 12.79 63.12 29.58 17.14 22.25 7.9 48.3 4.35 55.44-19.08 37.49-68.42 34.44-69.26 34.42zm40.2 104.86c-70.03 51.72-171.69 79.25-258.49 79.25A469.127 469.127 0 0 1 2.83 327.46c-6.53-5.89-.77-13.96 7.17-9.47a637.37 637.37 0 0 0 316.88 84.12 630.22 630.22 0 0 0 241.59-49.55c11.78-5 21.77 7.8 10.12 16.38zm29.19-33.29c-8.96-11.52-59.28-5.38-81.81-2.69-6.79.77-7.94-5.12-1.79-9.47 40.07-28.17 105.88-20.1 113.44-10.63 7.55 9.47-2.05 75.41-39.56 106.91-5.76 4.87-11.27 2.3-8.71-4.1 8.44-21.25 27.39-68.49 18.43-80.02z"></path></svg></span> Cut Storage Costs</h3>

Reduce storage costs by forwarding [compact](https://doc.log10x.com/run/transform/#compact) events to object storage (e.g., AWS S3, Azure Blobs). Expand events on-the-fly using the [Retriever](../../retriever/ "Stream events from low-cost storage to log analyzer and metric outputs on-demand") app to forward raw data to log analytics and metric outputs periodically or on-demand.

<h3 id="analytics-costs"><span class="twemoji" ><svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M11 21H7v-2h4v2m4.5-2H17v2h-4v-2h.2l-1.4-6.1-2.5.6c-.1.5-.3.9-.5 1.3-.9 1.5-2.8 1.9-4.3 1-1.5-.9-1.9-2.8-1-4.3.9-1.5 2.8-1.9 4.3-1 .4.2.7.6.9.9l2.5-.6-.6-2.5c-.4-.1-.8-.3-1.2-.5C8 6.9 7.5 5 8.4 3.5c.9-1.5 2.8-1.9 4.3-1 1.5.9 1.9 2.8 1 4.3-.2.4-.6.7-.9.9L15.5 19M7 11.8c-.7-.5-1.7-.2-2.2.5-.5.7-.2 1.7.5 2.1.7.5 1.7.3 2.2-.5.4-.7.2-1.7-.5-2.1M12.4 6c.5-.7.2-1.7-.5-2.2-.7-.5-1.7-.2-2.2.5-.4.7-.2 1.7.6 2.2.7.4 1.7.2 2.1-.5m.4 5.3c-.2-.1-.4-.1-.5.1-.1.2-.1.4.1.5.2.1.4.1.5-.1.2-.2.1-.4-.1-.5M21 8.5 14.5 10l.5 2.2 7.5-1.8.5-.7-2-1.2M23 19h-4v2h4v-2M5 19H1v2h4v-2Z"></path></svg></span> Cut Log Analytics Costs</h3>

Reduce ingestion and licensing costs, where the destination supports it, by forwarding [compact](https://doc.log10x.com/run/transform/#compact) events to Splunk or self-hosted Elasticsearch/OpenSearch. The open-source [10x for Splunk](splunk.md) app and [L1ES Elasticsearch plugin](elasticsearch.md) expand events in real-time, maintaining full querying, dashboard, and alerting capabilities; compact is lossless, so expanded events match the originals.

## :material-cog-transfer-outline: Workflow

Compact mode processes events from a variety of [log forwarders](https://doc.log10x.com/run/input/forwarder), such as Fluentd, Fluent Bit, Filebeat, and Logstash.
Configure the app to process all or a subset of the events, allowing for targeted analysis and volume reduction.

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>🚙 Forwarder</div><div style='font-size: 10px; text-align: center;'>Sidecar Process</div>"] --> B["<div style='font-size: 14px;'>📡 Receive</div><div style='font-size: 10px; text-align: center;'>Stream Events</div>"]
    B --> C["<div style='font-size: 14px;'>🔄 Transform</div><div style='font-size: 10px; text-align: center;'>into TenXObjects</div>"]
    C --> D["<div style='font-size: 14px;'>🎁 Enrich</div><div style='font-size: 10px; text-align: center;'>Add Context</div>"]
    D --> E["<div style='font-size: 14px;'>🗜️ Compact</div><div style='font-size: 10px; text-align: center;'>Encode Events</div>"]
    E --> F["<div style='font-size: 14px;'>📤 Output</div><div style='font-size: 10px; text-align: center;'>Return to Forwarder</div>"]
    
    classDef deploy fill:#7c3aed88,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef receive fill:#9333ea88,stroke:#7c3aed,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef transform fill:#2563eb88,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef enrich fill:#059669,stroke:#047857,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef compact fill:#f59e0b,stroke:#d97706,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#ea580c88,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    
    class A deploy
    class B receive
    class C transform
    class D enrich
    class E compact
    class F output
```

</div>

🚙 **Forwarder**: Runs 10x as a [sidecar process](https://doc.log10x.com/engine/launcher/sidecar) to log forwarders for real-time event analysis

📡 **Receive**: Read events continuously from [log forwarders](https://doc.log10x.com/run/input/forwarder) via IPC

🔄 **Transform**: Structure raw events into well-defined [TenXObjects](https://doc.log10x.com/run/transform/)

🎁 **Enrich**: Apply [enrichment rules](https://doc.log10x.com/run/initialize/) to augment TenXObjects with intelligent context

🚦 **Filter**: Shed over-budget events via [per-node budget sampling or a declarative field-set mute file](https://doc.log10x.com/run/receive/rate/) to prevent over-billing

🗜️ **Compact**: [Losslessly compact](https://doc.log10x.com/run/transform/#compact) events using templates the runtime engine builds from [AOT compiler](https://doc.log10x.com/compile/) symbols

📤 **Output**: Return compact events to forwarder to ship to destination analyzers or storage


## :material-hexagon-multiple-outline: Architecture

Compact mode executes inside the [Receiver](../index.md) sidecar, compacting events ***before*** they ship to a log analyzer or object storage.

=== ":octicons-x-12: No 10x"

    Forwarders ship verbose events containing repetitive elements such as JSON/KV field names, messages, severity levels and app-specific low-cardinality values, inflating cost by a large margin, the share that compact recovers where the destination supports it.

    <figure markdown="span">
      ![Architecture diagram: Log forwarders ship verbose events with repetitive JSON field names and low-cardinality values to log analyzers, inflating log-analyzer cost by the share that compact recovers](../../../assets/tenx-edge-optimizer-none.png){ align=left }
      <figcaption>:x: Forwarders ship costly duplicative events to log analyzers</figcaption>
    </figure>

=== ":material-aws: Storage"

    Forward compact events to low-cost storage (e.g., AWS S3, Azure Blobs). The [Retriever](../../retriever/) app expands and streams selected events to log analyzers and metric outputs.

    <figure markdown="span">
      ![Architecture diagram: Compact mode losslessly compacts events before uploading to S3 or S3-compatible storage, where Retriever expands and streams them on demand](../../../assets/tenx-edge-optimizer-storage.png){ align=left }
      <figcaption>:white_check_mark: **Compact mode** losslessly compacts events before they upload to storage</figcaption>
    </figure>

=== ":material-greater-than: Splunk"

    Forward compact events to Splunk. The open-source [10x for Splunk](splunk.md) app expands events on-the-fly at search time, displaying them in full JSON/text form in dashboards and queries.

    <figure markdown="span">
      ![Architecture diagram: Compact mode losslessly compacts events before shipping to Splunk, where the 10x for Splunk app expands them at search time](../../../assets/tenx-edge-optimizer-splunk.png){ align=left }
      <figcaption>:white_check_mark: **Compact mode** losslessly compacts events before they ship to Splunk</figcaption>
    </figure>

=== ":simple-elasticsearch: Elasticsearch"

    Forward compact events to Elasticsearch or OpenSearch. The open-source [L1ES plugin](elasticsearch.md) transparently rewrites standard queries and decodes `_source` at search time, Kibana dashboards, saved searches, and alerts work unchanged.

    <figure markdown="span">
      ![Architecture diagram: Compact mode losslessly compacts events before shipping to Elasticsearch or OpenSearch, where the L1ES plugin expands them at search time](../../../assets/tenx-edge-optimizer-elasticsearch.png){ align=left }
      <figcaption>:white_check_mark: **Compact mode** losslessly compacts events before they ship to ElasticSearch</figcaption>
    </figure>

## :material-shield-check-outline: Safety & Reliability

Compact mode runs inside the Receiver sidecar with fail-open design, if the receiver crashes or stops, your logs continue flowing normally at full volume to your analyzer.

|Topic|Detail|
|---|---|
|[Fail-open design](../faq.md#what-happens-if-the-sidecar-fails)|Logs continue flowing if 10x goes down|
|[Backpressure handling](../faq.md#how-does-the-receiver-handle-failures)|Disk buffering prevents data loss during spikes|
|[Resource requirements](../faq.md#which-log-forwarders-does-the-receiver-support)|512MB heap + 2 threads handles 100+ GB/day|
|[Rollback](../faq.md#what-happens-if-the-sidecar-fails)|`helm uninstall` takes ~1 minute, no data loss|

See the [Receiver FAQ](../faq.md) for complete operational details, capacity planning, and deployment guidance.
