---
title: "HTTP Status Code Extractor"
description: "enrich TenXObjects with an extracted HTTP status code"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/initialize/httpCode/module.yaml"
icon: "material/web"

---
Enrich TenXObjects with an extracted HTTP [status code](https://en.wikipedia.org/wiki/List_of_HTTP_status_codes){target="\_blank"}, if present in the underlying event's text.

This module applies a heuristic that extracts HTTP status codes from tokenized log events in two phases: template-level identification to locate a valid candidate token, and instance-level extraction to parse the code value. It uses configurable arrays for validation and preclusion, ensuring efficiency (O(1) per check) and minimizing false positives.

This process ensures the [template](https://doc.log10x.com/run/template/ "Import joint JSON schemas files to expand events into well-defined TenXObjects.") identifies the correct [variable token](https://doc.log10x.com/run/transform/structure/#variables) position once, and instances extract the HTTP code efficiently via direct access using the [token](https://doc.log10x.com/api/js/#TenXBaseObject+token "Returns the value of specific tokens within the current tenxObject.") function.

Use the [lookup initializer](https://doc.log10x.com/run/initialize/lookup/ "Enrich TenXObjects with lookup table values") to map codes (e.g., 200) to messages (e.g., `OK`).

## :material-wrench-outline: Config Files

To configure the HTTP Status Code Extractor module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [httpCode/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/initialize/httpCode/config.yaml "httpCode/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/initialize/httpCode/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/initialize/httpCode/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/initialize/httpCode/config.yaml"
                            data-copy-win="C:\log10x\configs/run/initialize/httpCode/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/initialize/httpCode/config.yaml">$TENX_CONFIG/run/initialize/httpCode/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/initialize/httpCode/config.yaml">./pipelines/run/initialize/httpCode/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAidGVueCIgOiB7CiAgICAgICJ0eXBlIiA6ICJzdHJpbmciCiAgICB9LAogICAgImh0dHBDb2RlIiA6IHsKICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICJmaWVsZCIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiSFRUUCBjb2RlIHRhcmdldCBmaWVsZCBuYW1lXG5cblNwZWNpZnkgdGhlIGZpZWxkIG5hbWUgdG8gYXNzaWduIHdpdGggdGhlIGluZmVycmVkIEhUVFAgY29kZSAoRGVmYXVsdDogaHR0cENvZGUpIiwKICAgICAgICAgICJkZWZhdWx0IiA6ICJodHRwQ29kZSIKICAgICAgICB9LAogICAgICAgICJwcmVjbHVkZXJzQmVmb3JlIiA6IHsKICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgImFycmF5IiwKICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICJudWxsIgogICAgICAgICAgXSwKICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJQcmVjZWRpbmcgY2hhcmFjdGVycyBmb3IgZXhjbHVkaW5nIEhUVFAgY29kZSBjYW5kaWRhdGVzXG5cbkFycmF5IG9mIGNoYXJhY3RlcnMgb3IgcGF0dGVybnMgdGhhdCwgd2hlbiBhcHBlYXJpbmcgaW1tZWRpYXRlbHkgYmVmb3JlIGEgY2FuZGlkYXRlIEhUVFAgc3RhdHVzIGNvZGUgaW4gdG9rZW5pemVkIGxvZ3MsIGluZGljYXRlIGl0IGlzIG5vdCBhIHZhbGlkIEhUVFAgY29kZS4gVXNlZCB0byBwcmVjbHVkZSBmYWxzZSBwb3NpdGl2ZXMgbGlrZSBuZWdhdGl2ZSBudW1iZXJzICgnLTIwMCcpLCBmbG9hdHMgKCcuMjAwJyksIG9yIHZhcmlhYmxlcyAoJ18yMDAnKS4gRW50cmllcyBhcmUgc2luZ2xlIGNoYXJhY3RlcnMgb3Igc2hvcnQgc3RyaW5ncyBmb3IgTygxKSBsb29rdXAgZWZmaWNpZW5jeSBpbiB0aGUgaGV1cmlzdGljLiIsCiAgICAgICAgICAiaXRlbXMiIDogewogICAgICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgInByZWNsdWRlcnNBZnRlciIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJhcnJheSIsCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiU3Vic2VxdWVudCBjaGFyYWN0ZXJzIGZvciBleGNsdWRpbmcgSFRUUCBjb2RlIGNhbmRpZGF0ZXNcblxuQXJyYXkgb2YgY2hhcmFjdGVycyBvciBwYXR0ZXJucyB0aGF0LCB3aGVuIGFwcGVhcmluZyBpbW1lZGlhdGVseSBhZnRlciBhIGNhbmRpZGF0ZSBIVFRQIHN0YXR1cyBjb2RlIGluIHRva2VuaXplZCBsb2dzLCBpbmRpY2F0ZSBpdCBpcyBub3QgYSB2YWxpZCBIVFRQIGNvZGUuIFVzZWQgdG8gcHJlY2x1ZGUgZmFsc2UgcG9zaXRpdmVzIGxpa2UgcGVyY2VudGFnZXMgKCcyMDAlJyksIGZsb2F0cyAoJzIwMC4nKSwgb3IgZXhwcmVzc2lvbnMgKCcyMDArJykuIEVudHJpZXMgYXJlIHNpbmdsZSBjaGFyYWN0ZXJzIG9yIHNob3J0IHN0cmluZ3MgZm9yIE8oMSkgbG9va3VwIGVmZmljaWVuY3kgaW4gdGhlIGhldXJpc3RpYy4iLAogICAgICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogInN0cmluZyIKICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJ2YWxpZFZhbHVlcyIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJhcnJheSIsCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiU3RhbmRhcmQgSFRUUCBzdGF0dXMgY29kZXNcblxuQXJyYXkgb2YgYWxsIHN0YW5kYXJkIEhUVFAgc3RhdHVzIGNvZGVzIGFzIGRlZmluZWQgYnkgdGhlIElBTkEgSFRUUCBTdGF0dXMgQ29kZSBSZWdpc3RyeSBhbmQgcmVsZXZhbnQgUkZDcyAoZS5nLiwgUkZDIDkxMTAsIFJGQyA2NTg1LCBSRkMgNzIzMS03MjM1LCBSRkMgNzUzOCwgUkZDIDc3MjUsIFJGQyA4Mjk3LCBSRkMgOTExMSkuIFRoaXMgYXJyYXlzIHZhbGlkYXRlcyBwb3RlbnRpYWwgSFRUUCBzdGF0dXMgY29kZXMgaW4gbG9nIGV2ZW50cywgZW5zdXJpbmcgb25seSByZWNvZ25pemVkIGNvZGVzIGFyZSBleHRyYWN0ZWQuIEVhY2ggZW50cnkgaW5jbHVkZXMgdGhlIG51bWVyaWMgY29kZSBmb2xsb3dlZCBieSBhIGNvbW1lbnQgZGVzY3JpYmluZyBpdHMgbWVhbmluZyBhbmQgcHVycG9zZS4iLAogICAgICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogInN0cmluZyIKICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJrZXl3b3JkcyIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJhcnJheSIsCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQXJyYXkgb2Yga2V5d29yZHMgaW5kaWNhdGluZyBIVFRQLXJlbGF0ZWQgY29udGV4dCBpbiBsb2cgZXZlbnRzXG5cblRoaXMgbGlzdCBmaWx0ZXJzIGxvZ3MgbGlrZWx5IGNvbnRhaW5pbmcgSFRUUCBzdGF0dXMgY29kZXMsIHJlZHVjaW5nIGZhbHNlIHBvc2l0aXZlcy4gS2V5d29yZHMgY292ZXIgSFRUUCBtZXRob2RzLCBjb21tb24gbG9nIGZpZWxkcywgYW5kIGZvcm1hdC1zcGVjaWZpYyB0ZXJtcyBmcm9tIHNvdXJjZXMgbGlrZSBBcGFjaGUsIE5naW54LCBIQVByb3h5LCBTcXVpZCwgSUlTLCBTcHJpbmcgQm9vdC4iLAogICAgICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogInN0cmluZyIKICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJzdHJpY3RLZXl3b3JkcyIgOiB7CiAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICJhcnJheSIsCiAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAibnVsbCIKICAgICAgICAgIF0sCiAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQXJyYXkgb2Ygc3RyaWN0IEhUVFAgbWFya2VycyB0aGF0IG11c3QgYXBwZWFyIG5lYXIgYSBjYW5kaWRhdGUgSFRUUCBjb2RlIHRva2VuXG5cblNob3J0LCBoaWdoLXNpZ25hbCBzdWJzZXQgb2YgSFRUUCBtYXJrZXJzIHVzZWQgYXMgYSBzdHJ1Y3R1cmFsIGd1YXJkIGR1cmluZyB0ZW1wbGF0ZSBpbml0aWFsaXphdGlvbi4gQWZ0ZXIgYSBjYW5kaWRhdGUgSFRUUCBzdGF0dXMgdmFyaWFibGUgdG9rZW4gaXMgZm91bmQgdmlhIFtodHRwQ29kZVZhbGlkVmFsdWVzXSgjaHR0cGNvZGV2YWxpZHZhbHVlcyksIHRoZSB0ZW1wbGF0ZSBpbml0aWFsaXplciByZXF1aXJlcyB0aGF0IGF0IGxlYXN0IG9uZSBvZiB0aGVzZSBzdHJpY3QgbWFya2VycyBhcHBlYXIgd2l0aGluIGEgc21hbGwgdG9rZW4gd2luZG93ICjCsTUgYnkgZGVmYXVsdCkgYXJvdW5kIHRoZSBjYW5kaWRhdGUuIFdpdGhvdXQgdGhpcyBjaGVjaywgYW55IG51bWVyaWMgdmFyaWFibGUgdGhhdCBoYXBwZW5zIHRvIGhvbGQgYSB2YWx1ZSBpbiAxMDAuLjU5OSBvbiBpdHMgZmlyc3Qgb2JzZXJ2ZWQgZXZlbnQgKGUuZy4sIGEga2Fma2EgY29uZmlnIGxpbWl0IGxpa2UgYG1heC5yZXF1ZXN0LnNpemUgPSAyMDBgLCBhIEpWTSBgLURjbGsudGNrPTEwMGApIGdldHMgd3JvbmdseSBib3VuZCBhcyBhbiBIVFRQIGNvZGUgYW5kIHN1YnNlcXVlbnQgZXZlbnRzIGNhcnJ5IHRocm91Z2ggYXJiaXRyYXJ5IG5vbi1IVFRQIHZhbHVlcyBhdCB0aGF0IHBvc2l0aW9uLiAgVGhlIHN0cmljdCBsaXN0IHNob3VsZCBjb250YWluIG9ubHkgdG9rZW5zIHRoYXQgdW5hbWJpZ3VvdXNseSBtYXJrIGFuIEhUVFAgZXhjaGFuZ2U6IEhUVFAgbWV0aG9kIHZlcmJzIChgR0VUYCwgYFBPU1RgLCAuLi4pLCBwcm90b2NvbCB2ZXJzaW9ucyAoYEhUVFAvMS4xYCwgYEhUVFAvMmApLCBzdGF0dXMta2V5ZWQgSlNPTiBmaWVsZHMgKGBzdGF0dXNgLCBgc3RhdHVzQ29kZWAsIGBodHRwX3N0YXR1c2AsIGB1cHN0cmVhbV9zdGF0dXNgKSwgYW5kIGZyYW1ld29yay1zcGVjaWZpYyBwaHJhc2VzIHRoYXQgYWx3YXlzIHByZWNlZGUgYSBzdGF0dXMgY29kZSBpbiByZWFsIHRyYWZmaWMgKGBDb21wbGV0ZWRgLCBgRGlzcGF0Y2hlclNlcnZsZXRgLCBgVENQX01JU1NgKS4gSXQgaXMgaW50ZW50aW9uYWxseSBtdWNoIHNtYWxsZXIgdGhhbiBbaHR0cENvZGVLZXl3b3Jkc10oI2h0dHBjb2Rla2V5d29yZHMpLCB3aGljaCBpcyB1c2VkIGFzIGEgY2hlYXAgcHJlLWZpbHRlciBvdmVyIHRoZSBmdWxsIHRlbXBsYXRlIGJvZHkgYW5kIGNhbiBpbmNsdWRlIGxvb3NlIHRlcm1zLiIsCiAgICAgICAgICAiaXRlbXMiIDogewogICAgICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICAgICAgfQogICAgICAgIH0KICAgICAgfSwKICAgICAgInJlcXVpcmVkIiA6IFsKICAgICAgICAiZmllbGQiCiAgICAgIF0KICAgIH0KICB9LAogICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiB0cnVlCn0=</template>

```yaml
# 🔟❎ 'run' HTTP code classifier configuration

# The HTTP code classifier enriches TenXObjects with an extracted HTTP numeric response code (e.g., 404) field.

# Set the 10x pipeline to 'run'
tenx: run

# =============================== Dependencies ================================

include: run/modules/initialize/httpCode

# =============================== GeoIP Options ===============================

httpCode:

  # 'field' specifies the name of the field in which to assign an extracted HTTP status code, if found
  field: http_code

  # 'precludersBefore' specifies an array of characters or patterns that, when appearing immediately before a candidate HTTP status code in tokenized logs, indicate it is not a valid HTTP code.
  #  Used to preclude false positives like negative numbers ('-200'), floats ('.200'), or variables ('_200').
  #  Entries are single characters or short strings for O(1) lookup efficiency in the heuristic.
  precludersBefore: ['+', '$', '#', '@', '(', '[', '~', '-', '.', ':']

  # 'precludersAfter' specifies an array of characters or patterns that, when appearing immediately after a candidate HTTP status code in tokenized logs, indicate it is not a valid HTTP code.
  #  Used to preclude false positives like percentages ('200%'), floats ('200.'), or expressions ('200+').
  #  Entries are single characters or short strings for O(1) lookup efficiency in the heuristic.
  precludersAfter: ['%', ')', ']', '=', '!', '?', '+', '-', '.']

  # 'keywords' specifies an array of keywords indicating HTTP-related context in log events.
  #  Used to filter logs likely containing HTTP status codes, reducing false positives.
  #  Keywords cover HTTP methods, common log fields, and format-specific terms from sources like Apache, Nginx, HAProxy, Squid, IIS, Spring Boot.
  keywords:
    - HTTP/             # Indicates HTTP protocol version in request lines (e.g., "GET / HTTP/1.1").
    - GET               # HTTP method for retrieving resources.
    - POST              # HTTP method for submitting data.
    - PUT               # HTTP method for updating resources.
    - DELETE            # HTTP method for deleting resources.
    - HEAD              # HTTP method for retrieving headers only.
    - OPTIONS           # HTTP method for describing communication options.
    - TRACE             # HTTP method for diagnostic purposes.
    - PATCH             # HTTP method for partial updates.
    - request           # Common in log fields referring to HTTP requests (e.g., "requestMethod").
    - Request           # Title case variant for HTTP requests
    - response          # Common in log fields referring to HTTP responses (e.g., "responseSize").
    - Response          # Title case variant for HTTP responses
    - status            # Common key for HTTP status codes (e.g., "status":200).
    - Status            # Title case variant for HTTP status
    - code              # Shorthand for status code (e.g., "code":404).
    - Code              # Title case variant for status code
    - upstream_status   # Nginx-specific for backend status codes.
    - Upstream_status   # Title case variant for Nginx backend status
    - Upstream_Status   # Title case variant for Nginx backend status
    - http_status       # JSON key for HTTP status (e.g., "http_status":500).
    - Http_status       # Title case variant for JSON key for HTTP status
    - Http_Status       # Title case variant for JSON key for HTTP status
    - status_code       # Alternative key for status codes (e.g., "status_code":429).
    - statusCode        # Camel case variant for status codes (e.g., "statusCode":200)
    - Completed         # Spring Boot DispatcherServlet log indicator (e.g., "Completed 200 OK").
    - access            # Indicates access logs (e.g., Apache access log).
    - Access            # Title case variant for access logs
    - error             # Indicates error logs containing HTTP errors.
    - Error             # Title case variant for error logs
    - method            # Refers to HTTP request method (e.g., "method":"GET").
    - Method            # Title case variant for HTTP method
    - path              # Refers to request path or URI (e.g., "path":"/api").
    - Path              # Title case variant for request path
    - url               # Refers to request URL (e.g., "url":"http://example.com").
    - Url               # Title case variant for request URL
    - URL               # Title case variant for request URL
    - referrer          # HTTP referrer header field.
    - referrer          # Title case variant for referrer header field.
    - Referer           # Alternative spelling for HTTP referrer
    - Referer           # Title case variant for alternative spelling
    - user-agent        # HTTP user-agent header field.
    - User-agent        # Title case variant for user-agent
    - User-Agent        # Title case variant for user-agent
    - latency           # Common in logs for request/response time (e.g., HAProxy, ELB).
    - Latency           # Title case variant for latency
    - frontend          # HAProxy term for incoming connections.
    - Frontend          # Title case variant for HAProxy frontend
    - backend           # HAProxy term for upstream servers.
    - Backend           # Title case variant for HAProxy backend
    - TCP_MISS          # Squid hierarchy code prefix (e.g., "TCP_MISS/200").
    - W3SVC             # IIS log prefix (e.g., "W3SVC1").
    - DispatcherServlet # Spring Boot servlet class for HTTP handling.

  # 'strictKeywords' is a short, high-signal subset of keywords used as a
  #  structural guard during template initialization. After a candidate HTTP
  #  status variable token is found in the template via 'validValues', the
  #  initializer requires at least one of these strict markers to appear
  #  within a small token window (±5) around the candidate before the
  #  httpToken position is bound.
  #
  #  Without this check, any numeric variable that happens to hold a value
  #  in 100..599 on the first observed event gets wrongly bound as the HTTP
  #  code position, e.g. a kafka config limit `max.request.size = 200`, a
  #  JVM `-Dclk.tck=100`, or any framework metric that emits counts in the
  #  low hundreds. Subsequent events at the same variable position then
  #  carry arbitrary non-HTTP values (1, 2, 2000, ...) that get emitted as
  #  http_code garbage.
  #
  #  Entries here should be ONLY tokens that unambiguously mark an HTTP
  #  exchange. The loose list in 'keywords' above (which includes terms
  #  like `error`, `path`, `url`) is too broad for adjacency gating.
  strictKeywords:
    - HTTP/             # HTTP protocol version marker in request lines (e.g., "HTTP/1.1 200 OK").
    - status            # JSON/KV key for HTTP status (e.g., "status":200, status=500).
    - Status            # Title case variant.
    - statusCode        # CamelCase variant of status code key.
    - status_code       # Snake case variant.
    - http_status       # HTTP-prefixed status key.
    - Http_Status       # Title case variant.
    - Http_status       # Mixed case variant.
    - upstream_status   # Nginx backend status key.
    - Upstream_Status   # Title case variant.
    - code              # JSON/KV key for response code (e.g., "code":404).
    - Code              # Title case variant (also catches `statusCode`-style splits).
    - Completed         # Spring Boot DispatcherServlet log phrase (e.g., "Completed 200 OK").
    - DispatcherServlet # Spring Boot servlet class that always emits a status next.
    - TCP_MISS          # Squid hierarchy code prefix (always followed by "/<code>").
    - response          # HTTP response marker.
    - Response          # Title case variant.
    - GET               # HTTP method verbs, always appear in request-log entries with codes.
    - POST
    - PUT
    - DELETE
    - PATCH
    - HEAD
    - OPTIONS
    - TRACE

  # 'validValues' specifies an array of all standard HTTP status codes as defined by the IANA HTTP Status Code Registry and relevant RFCs (e.g., RFC 9110, RFC 6585, RFC 7231-7235, RFC 7538, RFC 7725, RFC 8297, RFC 9111).
  #  Used to validate potential HTTP status codes in log events, ensuring only recognized codes are extracted.
  #  Each entry includes the numeric code followed by a comment describing its meaning and purpose.
  validValues:
    - '200' # OK: Standard response for successful HTTP requests.
    - '304' # Not Modified: Resource has not been modified since last requested.
    - '404' # Not Found: Server cannot find the requested resource.
    - '301' # Moved Permanently: Resource has been moved permanently to a new URI.
    - '302' # Found: Resource temporarily located at a different URI.
    - '403' # Forbidden: Client does not have access rights to the content.
    - '400' # Bad Request: Server cannot process due to client error.
    - '500' # Internal Server Error: Generic server error.
    - '206' # Partial Content: Server is delivering only part of the resource due to a range header.
    - '503' # Service Unavailable: Server temporarily unable to handle request.
    - '401' # Unauthorized: Authentication required and has failed or not provided.
    - '204' # No Content: Server processed request but no content is returned.
    - '502' # Bad Gateway: Server received an invalid response from upstream.
    - '201' # Created: Request has been fulfilled, resulting in new resource creation.
    - '429' # Too Many Requests: Client has sent too many requests in a given time.
    - '308' # Permanent Redirect: Resource permanently at another URI, method unchanged.
    - '307' # Temporary Redirect: Resource temporarily at another URI, method unchanged.
    - '303' # See Other: Response can be found under a different URI using GET.
    - '405' # Method Not Allowed: Request method is not supported for the resource.
    - '406' # Not Acceptable: Server cannot produce a response matching client’s Accept headers.
    - '408' # Request Timeout: Server timed out waiting for the request.
    - '409' # Conflict: Request conflicts with current state of the resource.
    - '410' # Gone: Resource is permanently unavailable.
    - '413' # Content Too Large: Request entity is larger than server limits.
    - '414' # URI Too Long: Request-URI is longer than the server can handle.
    - '415' # Unsupported Media Type: Media format of the requested data is not supported.
    - '416' # Range Not Satisfiable: Requested range cannot be fulfilled.
    - '422' # Unprocessable Content: Request is well-formed but semantically incorrect.
    - '504' # Gateway Timeout: Server, as gateway, did not get timely upstream response.
    - '505' # HTTP Version Not Supported: Server does not support the HTTP version.
    - '100' # Continue: Client should continue with request.
    - '101' # Switching Protocols: Server is switching protocols as requested.
    - '202' # Accepted: Request accepted for processing, but processing is not complete.
    - '203' # Non-Authoritative Information: Server is a transforming proxy with non-authoritative metadata.
    - '205' # Reset Content: Client should reset the document view.
    - '300' # Multiple Choices: Indicates multiple options for the resource.
    - '411' # Length Required: Content-Length header is required but not provided.
    - '412' # Precondition Failed: Server does not meet one of the preconditions.
    - '417' # Expectation Failed: Server cannot meet Expect header requirements.
    - '421' # Misdirected Request: Request sent to server unable to produce a response.
    - '423' # Locked: Resource is locked (WebDAV).
    - '424' # Failed Dependency: Request failed due to failure of a previous request.
    - '425' # Too Early: Server unwilling to risk processing a request that might be replayed.
    - '426' # Upgrade Required: Client should switch to a different protocol.
    - '428' # Precondition Required: Server requires conditional request headers.
    - '431' # Request Header Fields Too Large: Headers exceed server limits.
    - '451' # Unavailable For Legal Reasons: Resource access blocked for legal reasons.
    - '501' # Not Implemented: Server does not support the requested functionality.
    - '506' # Variant Also Negotiates: Server configuration error in content negotiation.
    - '507' # Insufficient Storage: Server cannot store the representation (WebDAV).
    - '508' # Loop Detected: Server detected an infinite loop in request processing.
    - '510' # Not Extended: Further extensions required for request fulfillment.
    - '511' # Network Authentication Required: Client needs to authenticate for network access.
    - '102' # Processing: Server has received and is processing the request.
    - '103' # Early Hints: Used to return some response headers before final HTTP message.
    - '207' # Multi-Status: Conveys information about multiple resources in WebDAV.
    - '208' # Already Reported: Used inside a DAV binding to avoid enumerating bindings repeatedly.
    - '226' # IM Used: Server has fulfilled a request for the resource using instance-manipulations.
    - '305' # Use Proxy: Resource is available only through a proxy.
    - '306' # (Unused): Previously used for Switch Proxy, now reserved.
    - '402' # Payment Required: Reserved for future use, e.g., digital payments.
    - '407' # Proxy Authentication Required: Client must authenticate with proxy.
    - '418' # (Unused): Previously “I’m a teapot” (RFC 2324, joke).
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the HTTP Status Code Extractor:

|Name|Description|
|---|---|
|[httpCodeField](#httpcodefield "HTTP code target field name")|HTTP code target field name|
|[httpCodePrecludersBefore](#httpcodeprecludersbefore "preceding characters for excluding HTTP code candidates")|Preceding characters for excluding HTTP code candidates|
|[httpCodePrecludersAfter](#httpcodeprecludersafter "subsequent characters for excluding HTTP code candidates")|Subsequent characters for excluding HTTP code candidates|
|[httpCodeValidValues](#httpcodevalidvalues "standard HTTP status codes")|Standard HTTP status codes|
|[httpCodeKeywords](#httpcodekeywords "Array of keywords indicating HTTP-related context in log events")|Array of keywords indicating HTTP-related context in log events|
|[httpCodeStrictKeywords](#httpcodestrictkeywords "Array of strict HTTP markers that must appear near a candidate HTTP code token")|Array of strict HTTP markers that must appear near a candidate HTTP code token|

### :material-menu-right-outline:**`httpCodeField`**

HTTP code target field name.

|Type|Required|
|---|---|
|String|✔|

Specify the field name to assign with the inferred HTTP code.


### :material-menu-right-outline:**`httpCodePrecludersBefore`**

Preceding characters for excluding HTTP code candidates.

|Type|Default|
|---|---|
|List|\[\]|

Array of characters or patterns that, when appearing immediately before a candidate HTTP status code in tokenized logs, indicate it is not a valid HTTP code.
Used to preclude false positives like negative numbers ('-200'), floats ('.200'), or variables ('\_200').
Entries are single characters or short strings for O(1) lookup efficiency in the heuristic.


### :material-menu-right-outline:**`httpCodePrecludersAfter`**

Subsequent characters for excluding HTTP code candidates.

|Type|Default|
|---|---|
|List|\[\]|

Array of characters or patterns that, when appearing immediately after a candidate HTTP status code in tokenized logs, indicate it is not a valid HTTP code.
Used to preclude false positives like percentages ('200%'), floats ('200.'), or expressions ('200+').
Entries are single characters or short strings for O(1) lookup efficiency in the heuristic.


### :material-menu-right-outline:**`httpCodeValidValues`**

Standard HTTP status codes.

|Type|Default|
|---|---|
|List|\[\]|

Array of all standard HTTP status codes as defined by the IANA HTTP Status Code Registry and relevant RFCs (e.g., RFC 9110, RFC 6585, RFC 7231-7235, RFC 7538, RFC 7725, RFC 8297, RFC 9111).
This arrays validates potential HTTP status codes in log events, ensuring only recognized codes are extracted.
Each entry includes the numeric code followed by a comment describing its meaning and purpose.


### :material-menu-right-outline:**`httpCodeKeywords`**

Array of keywords indicating HTTP-related context in log events.

|Type|Default|
|---|---|
|List|\[\]|

This list filters logs likely containing HTTP status codes, reducing false positives.
Keywords cover HTTP methods, common log fields, and format-specific terms from sources like Apache, Nginx, HAProxy, Squid, IIS, Spring Boot.


### :material-menu-right-outline:**`httpCodeStrictKeywords`**

Array of strict HTTP markers that must appear near a candidate HTTP code token.

|Type|Default|
|---|---|
|List|\[\]|

Short, high-signal subset of HTTP markers used as a structural guard during template
initialization. After a candidate HTTP status variable token is found via
[httpCodeValidValues](#httpcodevalidvalues "standard HTTP status codes"), the template initializer requires that at
least one of these strict markers appear within a small token window (±5 by default)
around the candidate. Without this check, any numeric variable that happens to hold
a value in 100..599 on its first observed event (e.g., a kafka config limit like
`max.request.size = 200`, a JVM `-Dclk.tck=100`) gets wrongly bound as an HTTP code
and subsequent events carry through arbitrary non-HTTP values at that position.

The strict list should contain only tokens that unambiguously mark an HTTP exchange:
HTTP method verbs (`GET`, `POST`, ...), protocol versions (`HTTP/1.1`, `HTTP/2`),
status-keyed JSON fields (`status`, `statusCode`, `http_status`, `upstream_status`),
and framework-specific phrases that always precede a status code in real traffic
(`Completed`, `DispatcherServlet`, `TCP_MISS`). It is intentionally much smaller
than [httpCodeKeywords](#httpcodekeywords "Array of keywords indicating HTTP-related context in log events"), which is used as a cheap pre-filter
over the full template body and can include loose terms.


<br/>:material-github: This module is defined in [httpCode/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/initialize/httpCode/module.yaml "httpCode/module.yaml"){target="\_blank"}.

