---
title: "Reporter"
description: "pre-ingestion cost insight from a DaemonSet alongside your forwarder"
source: "https://github.com/log-10x/modules/tree/main/apps/reporter/app.yaml"
icon: "material/pipe-leak"

---
The Reporter pinpoints app/infra events driving the most storage and licensing cost, _before_ the forwarder ships them to the log analyzer.

## :material-cog-transfer-outline: Workflow

The Reporter app processes events from a variety of [log forwarders](https://doc.log10x.com/run/input/forwarder), such as Fluentd, Fluent Bit, Filebeat, and Logstash. 
Configure the app to process all or a subset of collected events, allowing for targeted cost analysis.

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>🚙 DaemonSet</div><div style='font-size: 10px; text-align: center;'>Alongside Forwarder</div>"] --> B["<div style='font-size: 14px;'>📡 Tail</div><div style='font-size: 10px; text-align: center;'>Pre-SIEM Stream</div>"]
    B --> C["<div style='font-size: 14px;'>🔄 Transform</div><div style='font-size: 10px; text-align: center;'>into TenXObjects</div>"]
    C --> D["<div style='font-size: 14px;'>🎁 Enrich</div><div style='font-size: 10px; text-align: center;'>Add Context</div>"]
    D --> E["<div style='font-size: 14px;'>📊 Aggregate</div><div style='font-size: 10px; text-align: center;'>Group by Cost</div>"]
    E --> F["<div style='font-size: 14px;'>📈 Report</div><div style='font-size: 10px; text-align: center;'>Publish Metrics</div>"]
    
    classDef deploy fill:#7c3aed88,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef receive fill:#9333ea88,stroke:#7c3aed,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef transform fill:#2563eb88,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef enrich fill:#059669,stroke:#047857,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef aggregate fill:#ea580c88,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef report fill:#16a34a88,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8
    
    class A deploy
    class B receive
    class C transform
    class D enrich
    class E aggregate
    class F report
```

</div>

🚙 **DaemonSet**: Runs 10x as a separate DaemonSet pod alongside your forwarder, not a sidecar inside it; logs never pass through it

📡 **Tail**: Reads the same pre-ingestion event stream the forwarder sees, from container logs, files, or a duplicated IPC channel

🔄 **Transform**: Structures log events into well-defined [TenXObjects](https://doc.log10x.com/run/transform/)

🎁 **Enrich**: Applies [enrichment rules](https://doc.log10x.com/run/initialize/) to augment TenXObjects with intelligent context 

📊 **Aggregate**: Groups TenXObjects to show data volume per event type, severity, and more

📈 **Report**: Publishes [cost insight metrics](https://doc.log10x.com/run/output/metric "Time-series outputs provide an extensible method for publishing TenXSummary instances") for visualization and alerting


## :material-hexagon-multiple-outline: Architecture

The Reporter executes as a [DaemonSet](https://kubernetes.io/docs/concepts/workloads/controllers/daemonset/) alongside your log forwarder to report on log/trace events _before_ they ship to output destinations (e.g., Splunk, Datadog). Logs never pass through it.

=== ":material-check: Reporter :material-arrow-right-thin: 10x Console "

    The 10x Engine runs as a DaemonSet alongside your forwarder to identify the app/infra events incurring the highest costs and report as metrics to the [**10x Console**](https://doc.log10x.com/manage/).
    
    <figure markdown="span">
      ![Architecture diagram: Reporter DaemonSet analyzes events pre-ingestion and publishes cost metrics to the 10x Console](../../assets/tenx-edge-reporter-tenx.svg){ align=left;width: 80%;height: 80%; }
      <figcaption>:white_check_mark: **Reporters** publish event cost metrics to the 10x console.</figcaption>
    </figure>

=== ":material-check: Reporter :material-arrow-right-thin: Metric Output"

    The 10x Engine runs as a DaemonSet alongside your forwarder to identify the app/infra events incurring the highest costs and report as metrics to a [**Metric output**](https://doc.log10x.com/run/output/metric/) for visualization, alerting and anomaly detection.
    
    <figure markdown="span">
      ![Architecture diagram: Reporter DaemonSet analyzes events pre-ingestion and publishes cost metrics to time-series databases like Prometheus or Datadog](../../assets/tenx-edge-reporter-tsdb.svg){ align=left;width: 80%;height: 80%; }
      <figcaption>:white_check_mark: **Reporters** publish event cost metrics to time-series DBs.</figcaption>
    </figure>

## :material-shield-check-outline: Safety & Reliability

The Reporter runs as a DaemonSet alongside your log forwarder; logs never pass through it. If the Reporter crashes or stops, your logs continue flowing normally to your analyzer (insights go stale; the DaemonSet controller respawns the pod).

|Topic|Detail|
|---|---|
|[Fail-independent design](faq.md#what-happens-if-the-reporter-fails)|Logs continue flowing if the Reporter goes down|
|[Logs never pass through it](faq.md#is-the-reporter-in-the-critical-log-path)|Adds zero latency to the forwarder pipeline; doesn't mutate forwarder configs|
|[Resource requirements](faq.md#which-log-forwarders-does-the-reporter-support)|512MB heap + 2 threads handles 100+ GB/day|
|[Rollback](faq.md#what-happens-if-the-reporter-fails)|`helm uninstall` takes ~1 minute, forwarders untouched|

See the [Reporter FAQ](faq.md) for complete operational details, capacity planning, and deployment guidance.
