---
title: "Input Extractor"
description: "filter, redact, and capture events from an input stream to transform\
  \ into TenXObjects"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/units/input/extract/unit.yaml"
icon: "material/select-all"

---
Extractors filter, redact and select text to transform into [TenXObjects](https://doc.log10x.com/api/js/#TenXObject "Provide structured, reflective access to log/trace events read from input(s).") from a stream of input events.

Configured extractors scan an input event for specified JSON fields or regex
[capture groups](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Regular_expressions/Named_capturing_group){target="\_blank"} values on which to perform specified actions.

An extractor can be applied to an input via its [targetInput](#extractortargetinput "regex pattern identifying all inputs to which this extractor should be applied") member or by adding the extractor to a target input's [extractors](https://doc.log10x.com/run/input/stream/#inputextractors "names of extractors defining JSON fields/regex capture groups to select") list.

For example, the [k8s enrichment](https://doc.log10x.com/run/initialize/k8s/ "Enrich TenXObjects with k8s pod and container information") module uses JSON extractors to add pod and container context to TenXObjects for filtering and aggregation.

## Actions

Extractors can perform the following actions on input events:

### :material-select-all: Capture

Capture actions control which segments of a log/trace event's text to transform into TenXObjects.

JSON extractors select field values to transform into TenXObjects.
Regex extractors select values using defined by the [extractorPattern](#extractorPattern "for regex extractors, the pattern for capturing named match groups. For JSON, the segment of text within events to scan for objects").

For example, to capture the `message` value of the following simple event:

```json
{
   "event": {
     "origin": "localhost",
     "message": "some event"
   }
}
```

A JSON extractor can specify the `message` field, while a Regex extractor can specify a capture group (see [example](https://regex101.com/r/WmGjnZ/1){target="\_blank"}).

Each capture action specifies which instances of the JSON field/Regex groups within an event to transform:

#### **`All`**

Transform all matching JSON field/capture group values in an event into TenXObjects.

#### **`First`**

Transform the first matching JSON field/capture group value in an event into an TenXObject.

#### **`Last`**

Transform the last matching JSON field/capture group value in an event into an TenXObject.

#### **`Default`**

Serves as a sink for selecting events that fail to match the [extractorFilter](#extractorfilter "regex pattern to match for the extractor to be applied") pattern
or do not contain JSON field names/regex capture groups specified by [extractorActions](#extractoractions "actions in the form of actionType:name. Possible values:[captureAll, captureFirst, captureLast, captureArrays, captureFirstArray, captureLastArray, captureDefault, captureField, setOuterText, drop, redact, noTransform]&#10;").

This action captures the entire text of an event to transform into an TenXObject and
set its [extractorKey](https://doc.log10x.com/api/js/#TenXObject+extractorKey "If the object was extracted from a pattern match or JSON field using an input extractor,") value to the current action's name.

Only one default capture action is allowed.

#### **`Field`**

Capture a JSON field value and attach it to every TenXObject produced by the extractor, under the alias name. Unlike the other capture actions, `captureField` does not emit its own TenXObject.

For example, the [k8s enrichment](https://doc.log10x.com/run/initialize/k8s/ "Enrich TenXObjects with k8s pod and container information") module declares `captureField:kubernetes.namespace_name:namespace_name` to attach pod namespace as a context [field](https://doc.log10x.com/run/initialize/#enrichmentFields "list of field to enrich TenXObjects with") on every extracted TenXObject.

Only the first matching value per field is captured.

### :material-filter-outline: Filter

Filter actions allow for filtering an entire event or redacting some of its values. These actions serve a dual purpose of providing a fast mechanism for filtering out unnecessary events to save on the CPU resources as well as redacting sensitive information (i.e., HIPAA, PII).

#### **`Drop`**

Deletes a matched JSON field and its value(s) from the event entirely. Available only for JSON extractors.

#### **`Redact`**

For JSON extractors resets matching field values:

|JSON Field Type|Redacted Value|
|---|---|
|object|{}|
|array|\[\]|
|number|0|
|string|""|
|boolean|true|

For regex extractors deletes all instances of matching capture groups from an event.

### :material-brain: Advanced

Advanced actions allow more granular control over how events are captured:

#### **`No Transform`**

Select events without transforming them into typed [TenXObjects](https://doc.log10x.com/api/js/#TenXObject "Provide structured, reflective access to log/trace events read from input(s)."). This action enables writing raw events that do not require any structure to output. Only one `noTransform` action is allowed.

#### **`Outer Text`**

Sets a JSON field/capture group as the `outer text` value for TenXObjects extracted by `captureAll`, `captureFirst`, or `captureLast` actions.

For example, if a JSON extractor action specifies `captureFirst:message`,
a `setOuterText:event` action can set the [fullText](https://doc.log10x.com/api/js/#TenXBaseObject+fullText "A text value extracted from the input stream from") value of an TenXObject to the JSON `message` field's enclosing `event` object.

In the [example event](#capture), `some event` is set as the TenXObject's [text](https://doc.log10x.com/api/js/#TenXBaseObject+text "The content of the event from which this instance was structured.") value and its [fullText](https://doc.log10x.com/api/js/#TenXBaseObject+fullText "A text value extracted from the input stream from") value is the entire enclosing JSON object.

The [encode](https://doc.log10x.com/api/js/#TenXObject+encode "Encodes the current object's log event into a compact, template‐based string.") function returns a compact representation of an TenXObject's text value enclosed within the outer text region.

If no `setOuterText` selector is specified, an TenXObject's [fullText](https://doc.log10x.com/api/js/#TenXBaseObject+fullText "A text value extracted from the input stream from") and [text](https://doc.log10x.com/api/js/#TenXBaseObject+text "The content of the event from which this instance was structured.") fields return the same value.

If `outerText` actions are defined but not matched, the extractor applies the `default` capture action (if defined), otherwise, it drops the event.

## :material-wrench-outline: Config Files

To configure the Input extractor unit, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

=== "Pattern"

    Below is the default configuration from: [extract/pattern.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/extract/pattern.yaml "extract/pattern.yaml"){target="\_blank"}.  
  
    <div class="edit-options">
        <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/extract/pattern.yaml" target="_blank" rel="noopener noreferrer">
            <span class="twemoji" style="margin-right: 0.3rem;">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
                </svg>
            </span> Edit Online
        </a>
        <button class="md-button tenx-pattern.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="pattern-yaml0-dialog">
            <span style="margin-right: 0.3rem;">
                <span class="twemoji">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                    </svg>
                </span>
            </span>Edit Locally
        </button>
    </div>
    
    <dialog id="pattern-yaml0-dialog" class="md-dialog md-dialog--editor">
        <div class="editor-dialog-wrapper">
            <div class="editor-dialog-header">
                <span class="editor-dialog-title">Edit pattern.yaml Locally</span>
                <div class="editor-header-actions">
                    <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                    </button>
                    <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                    </button>
                    <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                        <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                        <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                    </button>
                    <span class="header-divider"></span>
                    <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                        <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                        <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                    </button>
                    <span class="header-divider"></span>
                    <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('pattern-yaml0-dialog')" data-tooltip="Close">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                    </button>
                </div>
            </div>
            <div class="editor-dialog-content">
                <div class="yaml-editor-container"></div>
            </div>
            <div class="yaml-editor-statusbar">
                <span class="yaml-editor-status"></span>
            </div>
        </div>
        <!-- Locations Popup -->
        <div class="locations-popup" style="display: none;">
            <div class="locations-popup-content">
                <div class="locations-popup-header">
                    <span class="locations-header-label">Download and save to:</span>
                    <button class="locations-popup-close" aria-label="Close">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                            <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                        </svg>
                    </button>
                </div>
                <ul class="locations-list">
                    <li>
                        <span class="location-label">Linux / Docker / macOS
                            <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="default-path location-path" data-tooltip=""
                                data-copy-osx="/etc/log10x/config/run/input/extract/pattern.yaml"
                                data-copy-nix="/etc/log10x/config/run/input/extract/pattern.yaml"
                                data-copy-win="C:\log10x\configs/run/input/extract/pattern.yaml"></code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                    <li>
                        <span class="location-label">Custom directory
                            <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/extract/pattern.yaml">$TENX_CONFIG/run/input/extract/pattern.yaml</code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                    <li>
                        <span class="location-label">Within cloned repo
                            <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="location-path" data-tooltip="./pipelines/run/input/extract/pattern.yaml">./pipelines/run/input/extract/pattern.yaml</code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                </ul>
                <div class="locations-popup-footer">
                    <button class="locations-download-btn" title="Download config file">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                            <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                        </svg>
                        <span>Download</span>
                    </button>
                </div>
            </div>
        </div>
    </dialog>
    
    <template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJ0ZW54IiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAiZXh0cmFjdG9yIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgIm5hbWUiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMb2dpY2FsIG5hbWUgaWRlbnRpZnlpbmcgdGhpcyBleHRyYWN0b3JcblxuUHJvdmlkZXMgYSBsb2dpY2FsIG5hbWUgKGUuZy4sICdtZXNzYWdlJykgZm9yIHRoaXMgSlNPTi9yZWdleCBleHRyYWN0b3IgdGhhdCB0YXJnZXQgaW5wdXQocykgY2FuIHJlZmVyZW5jZSB0byBhcHBseSB0aGlzIGV4dHJhY3RvciB0byBldmVudHMgd2hpY2ggdGhlIHByb2R1Y2UiCiAgICAgICAgICB9LAogICAgICAgICAgImVuYWJsZWQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQSBKYXZhU2NyaXB0IGV4cHJlc3Npb24gdGhhdCBtdXN0IGJlIGV2YWx1YXRlZCBhcyAndHJ1dGh5JyB0byBlbmFibGUgdGhlIGV4dHJhY3RvclxuXG5FbmFibGVzL2Rpc2FibGVzIHRoaXMgZXh0cmFjdG9yLiBJZiBzZXQsIHRoZSBKYXZhU2NyaXB0IGV4cHJlc3Npb24gcmV0dXJucyBhIHRydXRoeSB2YWx1ZSB0byBlbmFibGUgdGhlIGV4dHJhY3Rvci4gRm9yIGV4YW1wbGUsIHRvIGNvbmZpZ3VyZSB0aGlzIHZhbHVlIHRvIHVzZSBhIHN0YXJ0dXAgYXJndW1lbnQvc2hlbGwgdmFyaWFibGUsIHVzZTogIGBgYCB5YW1sIGV4dHJhY3RvcjogICAgbmFtZTogbXlFeHRyYWN0b3IgICAgZW5hYmxlZDogVGVuWEVudi5nZXQoXCJwZXJmb3JtRXh0cmFjdGlvblwiKSAgICAuLi4gIGBgYCAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogdHJ1ZSkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiB0cnVlCiAgICAgICAgICB9LAogICAgICAgICAgInRhcmdldElucHV0IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiUmVnZXggcGF0dGVybiBpZGVudGlmeWluZyBhbGwgaW5wdXRzIHRvIHdoaWNoIHRoaXMgZXh0cmFjdG9yIHNob3VsZCBiZSBhcHBsaWVkXG5cbkRlZmluZXMgYSByZWdleCBwYXR0ZXJuIGlkZW50aWZ5aW5nIGFsbCBpbnB1dHMgdG8gd2hpY2ggdGhpcyBleHRyYWN0b3Igc2hvdWxkIGJlIGFwcGxpZWQuIEZvciBleGFtcGxlLCB0byBhcHBseSBhbiBleHRyYWN0b3IgdG8gYSBbZGF0YWRvZyBpbnB1dF0oaHR0cHM6Ly9kb2MubG9nMTB4LmNvbS9ydW4vaW5wdXQvYW5hbHl6ZXIvZGF0YWRvZ0xvZ3MpLCBzcGVjaWZ5OiAgYGBgIHlhbWwgZXh0cmFjdG9yOiAgIG5hbWU6IG1lc3NhZ2UgICB0eXBlOiBqc29uICAgdGFyZ2V0SW5wdXQ6IGRhdGFkb2cgICBhY3Rpb25zOiAgIC0gY2FwdHVyZUFsbDptZXNzYWdlICBgYGAgIFRoaXMgYXJndW1lbnQgZW5hYmxlcyBhcHBseWluZyB0aGlzIGV4dHJhY3RvciB0byBpbnB1dChzKSB3aXRob3V0IGNoYW5naW5nIHRoZWlyIGRlZmluaXRpb24uIHZzLiBkaXJlY3RseSB0aGUgaW5wdXQgcmVmZXJlbmNpbmcgdGhlIGV4dHJhY3RvciBkaXJlY3RseSB2aWEgW2V4dHJhY3Rvck5hbWVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3Rvcm5hbWUpLiIKICAgICAgICAgIH0sCiAgICAgICAgICAidHlwZSIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRoZSBtZXRob2QgdXNlZCB0byBleHRyYWN0IHZhbHVlcyBmcm9tIHRoZSBldmVudC4gUG9zc2libGUgdmFsdWVzOltqc29uLCBwYXR0ZXJuXVxuXG5TZXRzIHRoZSB0eXBlIG9mIGV4dHJhY3Rpb24gbWV0aG9kIHRvIHNlbGVjdCwgZHJvcCBhbmQgcmVkYWN0IHZhbHVlcyBmcm9tIGEgdGFyZ2V0IGlucHV0IHN0cmVhbS4gUG9zc2libGUgdmFsdWVzOiAtIGpzb246IHNjYW4gZXZlbnRzIGZvciBKU09OIG9iamVjdHMgY29udGFpbmluZyBmaWVsZHMgc3BlY2lmaWVkIGluIFtleHRyYWN0b3JBY3Rpb25zXShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNleHRyYWN0b3JhY3Rpb25zKS4gLSBwYXR0ZXJuOiBzY2FuIGV2ZW50cyBmb3IgcmVnZXggbmFtZWQgY2FwdHVyZSBncm91cHMgb2YgdGhlIHBhdHRlcm4gc2V0IGJ5IFtleHRyYWN0b3JQYXR0ZXJuXShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNleHRyYWN0b3JwYXR0ZXJuKS4gKERlZmF1bHQ6IGpzb24pIiwKICAgICAgICAgICAgImRlZmF1bHQiIDogImpzb24iCiAgICAgICAgICB9LAogICAgICAgICAgImZpbHRlciIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlJlZ2V4IHBhdHRlcm4gdG8gbWF0Y2ggZm9yIHRoZSBleHRyYWN0b3IgdG8gYmUgYXBwbGllZFxuXG5TcGVjaWZpZXMgYSByZWdleCBwYXR0ZXJuIGFuIGV2ZW50IG11c3QgbWF0Y2ggdG8gc2NhbiBmb3IgSlNPTiBmaWVsZHMvcmVnZXggcGF0dGVybiBjYXB0dXJlIGdyb3Vwcy4gVGhpcyBhcmd1bWVudCBwcm92aWRlcyBhIHdheSB0byBydWxlIG91dCBldmVudHMgZnJvbSBiZWluZyB0cmFuc2Zvcm1lZCBpbnRvIFRlblhPYmplY3QuICBUbyBzZWxlY3QgZXZlbnRzIGZhaWxpbmcgdG8gbWVldCB0aGlzIGZpbHRlciwgZGVmaW5lIGEgW2NhcHR1cmVEZWZhdWx0XShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNkZWZhdWx0KSBhY3Rpb24uIgogICAgICAgICAgfSwKICAgICAgICAgICJwYXR0ZXJuIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiRm9yIHJlZ2V4IGV4dHJhY3RvcnMsIHRoZSBwYXR0ZXJuIGZvciBjYXB0dXJpbmcgbmFtZWQgbWF0Y2ggZ3JvdXBzLiBGb3IgSlNPTiwgdGhlIHNlZ21lbnQgb2YgdGV4dCB3aXRoaW4gZXZlbnRzIHRvIHNjYW4gZm9yIG9iamVjdHNcblxuRGVmaW5lcyBhIHJlZ2V4IHBhdHRlcm4gdGhhdCBhcHBsaWVzIHRvIGV2ZW50cyByZWFkIGZyb20gYW4gaW5wdXQgc3RyZWFtLiBGb3IgW2V4dHJhY3RvclR5cGVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3RvcnR5cGUpID0gcGF0dGVybiwgW21hdGNoaW5nIGdyb3Vwc10oaHR0cHM6Ly9kZXZlbG9wZXIubW96aWxsYS5vcmcvZW4tVVMvZG9jcy9XZWIvSmF2YVNjcmlwdC9SZWZlcmVuY2UvUmVndWxhcl9leHByZXNzaW9ucy9OYW1lZF9jYXB0dXJpbmdfZ3JvdXApIGFyZSB1c2VkIGFzIHRoZSAnbmFtZScgcG9ydGlvbnMgb2YgYWN0aW9ucyBzcGVjaWZpZWQgYnkgJ2V4dHJhY3RvckFjdGlvbnMnLiAgSWYgZXh0cmFjdG9yVHlwZSA9IGpzb24sIG9ubHkgc2NhbiBldmVudHMgZm9yIEpTT05zIHdpdGhpbiB0aGUgYm91bmRhcmllcyBvZiB0aGUgcGF0dGVybidzIG1hdGNoZXMuIgogICAgICAgICAgfSwKICAgICAgICAgICJncm91cCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk5hbWUgb2YgZ3JvdXAgb2YgZXh0cmFjdG9ycyB3aGljaCB3aWxsIHJ1biB0b2dldGhlclxuXG5EZWZpbmVzIHRoZSBuYW1lIG9mIGV4dHJhY3RvciBncm91cCB0aGlzIGV4dHJhY3RvciB3aWxsIGJlbG9uZyB0by4gZXh0cmFjdG9ycyBvZiB0aGUgc2FtZSBncm91cCB3aWxsIGF0dGVtcHQgdG8gcnVuIHRvZ2V0aGVyIG9uIGV2ZW50cyBpbiBhIHNpbmdsZSBwcm9jZXNzaW5nIHBhc3MgdG8gaW1wcm92ZSBwZXJmb3JtYW5jZSIKICAgICAgICAgIH0sCiAgICAgICAgICAiYWN0aW9ucyIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYXJyYXkiLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQWN0aW9ucyBpbiB0aGUgZm9ybSBvZiBhY3Rpb25UeXBlOm5hbWUuIFBvc3NpYmxlIHZhbHVlczpbY2FwdHVyZUFsbCwgY2FwdHVyZUZpcnN0LCBjYXB0dXJlTGFzdCwgY2FwdHVyZUFycmF5cywgY2FwdHVyZUZpcnN0QXJyYXksIGNhcHR1cmVMYXN0QXJyYXksIGNhcHR1cmVEZWZhdWx0LCBjYXB0dXJlRmllbGQsIHNldE91dGVyVGV4dCwgZHJvcCwgcmVkYWN0LCBub1RyYW5zZm9ybV1cblxuXG5EZWZpbmVzIGEgbGlzdCBvZiBhY3Rpb25zIGRlZmluZWQgYXM6ICdhY3Rpb25UeXBlOm5hbWU6YWxpYXMnIChlLmcuLCAnY2FwdHVyZUFsbDptZXNzYWdlOmFsaWFzJykgdG8gY2FwdHVyZSBhbmQgcmVkYWN0IHZhbHVlcyB0byB0cmFuc2Zvcm0gaW50byBUZW5YT2JqZWN0cy4gRm9yIEpTT04gZXh0cmFjdG9ycywgJ25hbWUnIHJlZmVycyB0byBhIGZpZWxkIHRvIGxvb2sgZm9yIGluIGV2ZW50cyBhbmQgdGhlIHZhbHVlIHRvIHdoaWNoIHRvIGFwcGx5IHRoZSAnYWN0aW9uVHlwZScuIFRoaXMgY2FuIGJlIGluIHRoZSBmb3JtIG9mICd4Lnkueicgd2hpY2ggd2lsbCBtYXRjaCBpbnRlcm5hbCBmaWVsZHMgaW4gdGhlIGpzb24uIEZvciBleGFtcGxlOiAnbWV0YWRhdGEuaWQnIHdpbGwgbWF0Y2ggdGhlICdpZCcgZmllbGQgb2YgdGhlICdtZXRhZGF0YScgb2JqZWN0IGluIHtcIm1ldGFkYXRhXCI6IHtcImlkXCI6IFwiMTIzNFwifX0gIEZvciByZWdleCBleHRyYWN0b3JzLCAnbmFtZScgcmVmZXJzIHRvIGEgW3JlZ2V4IHBhdHRlcm4gbWF0Y2ggZ3JvdXBdKGh0dHBzOi8vZGV2ZWxvcGVyLm1vemlsbGEub3JnL2VuLVVTL2RvY3MvV2ViL0phdmFTY3JpcHQvUmVmZXJlbmNlL1JlZ3VsYXJfZXhwcmVzc2lvbnMvTmFtZWRfY2FwdHVyaW5nX2dyb3VwKSBkZWZpbmVkIGJ5ICdleHRyYWN0b3JQYXR0ZXJuJyB0byB3aGljaCB0byBhcHBseSB0aGUgJ2FjdGlvblR5cGUnLiAgVGhpcyBzZXR0aW5nIG11c3QgYmUgc3BlY2lmaWVkIHdoZW4gW2V4dHJhY3RvclR5cGVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3RvcnR5cGUpID0gJ2pzb24nLiBJZiBub3Qgc3BlY2lmaWVkIGFuZCBleHRyYWN0b3JUeXBlIGlzICdwYXR0ZXJuJywgdGhlICdleHRyYWN0b3JQYXR0ZXJuJyBwYXR0ZXJuIHNjYW5zIGZvciByZWdleCBjYXB0dXJlIGdyb3VwcywgcGVyZm9ybWluZyBvbiBlYWNoIGFzJ2NhcHR1cmVBbGwnIGFjdGlvbi4gIFRoZSAnYWxpYXMnIHBhcnQgaXMgb3B0aW9uYWwsIGFuZCBpZiBwcm92aWRlZCBpcyB1c2VkIHRvIHJlZmVyZW5jZSB0aGUgb2JqZWN0IGFzIGl0J3MgbmFtZS4gVGhpcyBpcyB1c2VmdWwgd2hlbiBtdWx0aXBsZSBleHRyYWN0b3JzIGFyZSB1c2VkIHRvIGV4dHJhY3QgZGlmZmVyZW50IHRoaW5ncyB3aGljaCBhcmUgbGF0ZXIgdXNlZCBpbiB0aGUgc2FtZSB3YXkuICBJZiBubyBjYXB0dXJlIGdyb3VwcyBhcmUgZGVmaW5lZCwgYW55IG1hdGNoZXMgb2YgdGhlIHBhdHRlcm4gd2l0aGluIHRoZSBpbnB1dCB0ZXh0IGxpbmUgYXJlIGNhcHR1cmVkLiIsCiAgICAgICAgICAgICJpdGVtcyIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogInN0cmluZyIKICAgICAgICAgICAgfQogICAgICAgICAgfSwKICAgICAgICAgICJmb3JlYWNoIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTmFtZSBvZiBvcHRpb25zIGdyb3VwIGZvciB3aG9zZSBpbnN0YW5jZXMgdG8gY3JlYXRlIG1hdGNoaW5nIGV4dHJhY3RvcnNcblxuU3BlY2lmaWVzIHRoZSBuYW1lIG9mIGFuIG9wdGlvbnMgZ3JvdXAgZm9yIHdob3NlIGluc3RhbmNlcyB0byByZXBsaWNhdGUgdGhpcyBleHRyYWN0b3IuIEZvciBleGFtcGxlLCB0aGUgW0VsYXN0aWMgaW5wdXRdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2FuYWx5emVyL2VsYXN0aWNzZWFyY2gpIGRlZmluZXMgdGhlICdlbGFzdGljJyBvcHRpb25zIGdyb3VwIGFuZCBjb25maWd1cmVzIGFuIGV4dHJhY3RvciB0byBhcHBseSB0byBlYWNoIGlucHV0IHN0cmVhbSBjcmVhdGVkIGZyb20gaXRzIGNvbmZpZ3VyZWQgaW5zdGFuY2VzLiIKICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJyZXF1aXJlZCIgOiBbCiAgICAgICAgICAibmFtZSIsCiAgICAgICAgICAidHlwZSIKICAgICAgICBdCiAgICAgIH0KICAgIH0KICB9LAogICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZQp9</template>

    ```yaml
    # 🔟❎ 'run' Regex extractor configuration
    
    # Configure input regex pattern extractors.
    # To learn more see: https://doc.log10x.com/run/input/extract
    
    # Set the 10x pipeline to 'run'
    tenx: run
    
    # ============================= Extractor Options =============================
    
    # multiple extractors can be defined below
    extractor:
    
        # 'name' provides a unique name for this extractor that is referenced
        #  by any inputs to which it is applied 
      - name: patternExtractor
       
        # 'type' controls the method for parsing input stream text (json or pattern)
        type: pattern
        
        # 'targetInput' sets a regex pattern to match all inputs to which the extractor is applied.
        #  For example, to apply this extractor to an input named 'datadog', set: 'targetInput: datadog'
        targetInput: myInput
    
        # 'filter' specifies a regex pattern that must match input events to scan them for capture groups.
        #  For example, the pattern below will filter out syslog events that are not errors
        filter: "error: "
    
        # 'pattern' sets regex pattern whose capture groups to apply extractor actions below.
        #  To learn more about capture groups, see: https://regexone.com/lesson/capturing_groups
        #  If the pattern does not define capture groups, matches are captured as events to transform into TenXObjects.
       
        #  The example pattern below uses capture groups to parse a syslog event's 'message' field,
        #  and drop 'password' values. 
        #  For an explanation, see: https://chat.openai.com/share/003ead39-421c-489a-a52f-ee8846028887
        pattern: "/(error|info|debug): (?<message>.+?)(\\s+password=(?<password>\\S+))?(\\s+username=(?<username>\\S+))?$?"
           
        # 'actions' specifies the actions taken by this extractor on a matching capture group. 
        #  Actions are defined by their type followed by ':' and the regex capture group they target.
        #  The following action types are supported (comment in/out the ones needed for your use case):
        actions: 
    
          # Capture 
    
          # 'captureAll' transforms all instances of a matching capture group (i.e., 'message')
          #  within the current event into TenXObjects
          - captureAll:message
    
          # 'captureFirst' transforms only the first instance of a matching capture group (i.e., 'message')
          #  within the current event into an TenXObject
          - captureFirst:message
    
          # 'captureLast' transforms only the last instance of a matching capture group (i.e., 'message')
          #  within the current event into an TenXObject      
          - captureLast:message
    
          # Filter 
    
          # 'redact' removes all matching capture groups (i.e., 'password') found in the event
          - redact:password
    
          # Advanced 
    
          # 'captureDefault' serves as a sink for events that fail to match the 'filter' pattern
          #  or do not contain any of the capture group names specified by 'actions'. These events are
          #  transformed into TenXObjects whose 'extractorKey' field returns this action's name (i.e., 'other')
          - captureDefault:other
    
          # 'noTransform' is the same as 'captureDefault' (see above), except captured events are not
          #  transformed into TenXObjects and remain as 'plain text' objects.
          #  This is useful when the events need to be routed by the 10x pipeline to a specific
          #  output, but do not require access to structured elements (e.g., the intrinsic 'vars' and 'timestamp' fields).
          - noTransform:other
    ```

=== "Json"

    Below is the default configuration from: [extract/json.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/extract/json.yaml "extract/json.yaml"){target="\_blank"}.  
  
    <div class="edit-options">
        <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/extract/json.yaml" target="_blank" rel="noopener noreferrer">
            <span class="twemoji" style="margin-right: 0.3rem;">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
                </svg>
            </span> Edit Online
        </a>
        <button class="md-button tenx-json.yaml1-edit-button" data-tooltip="Edit configuration file" data-dialog-id="json-yaml1-dialog">
            <span style="margin-right: 0.3rem;">
                <span class="twemoji">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                        <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                    </svg>
                </span>
            </span>Edit Locally
        </button>
    </div>
    
    <dialog id="json-yaml1-dialog" class="md-dialog md-dialog--editor">
        <div class="editor-dialog-wrapper">
            <div class="editor-dialog-header">
                <span class="editor-dialog-title">Edit json.yaml Locally</span>
                <div class="editor-header-actions">
                    <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                    </button>
                    <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                    </button>
                    <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                        <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                        <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                    </button>
                    <span class="header-divider"></span>
                    <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                        <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                        <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                    </button>
                    <span class="header-divider"></span>
                    <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('json-yaml1-dialog')" data-tooltip="Close">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                    </button>
                </div>
            </div>
            <div class="editor-dialog-content">
                <div class="yaml-editor-container"></div>
            </div>
            <div class="yaml-editor-statusbar">
                <span class="yaml-editor-status"></span>
            </div>
        </div>
        <!-- Locations Popup -->
        <div class="locations-popup" style="display: none;">
            <div class="locations-popup-content">
                <div class="locations-popup-header">
                    <span class="locations-header-label">Download and save to:</span>
                    <button class="locations-popup-close" aria-label="Close">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                            <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                        </svg>
                    </button>
                </div>
                <ul class="locations-list">
                    <li>
                        <span class="location-label">Linux / Docker / macOS
                            <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="default-path location-path" data-tooltip=""
                                data-copy-osx="/etc/log10x/config/run/input/extract/json.yaml"
                                data-copy-nix="/etc/log10x/config/run/input/extract/json.yaml"
                                data-copy-win="C:\log10x\configs/run/input/extract/json.yaml"></code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                    <li>
                        <span class="location-label">Custom directory
                            <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/extract/json.yaml">$TENX_CONFIG/run/input/extract/json.yaml</code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                    <li>
                        <span class="location-label">Within cloned repo
                            <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                            </span>
                        </span>
                        <div class="location-path-row">
                            <code class="location-path" data-tooltip="./pipelines/run/input/extract/json.yaml">./pipelines/run/input/extract/json.yaml</code>
                            <button class="copy-btn" data-tooltip="Copy path">
                                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                    <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                                </svg>
                            </button>
                        </div>
                    </li>
                </ul>
                <div class="locations-popup-footer">
                    <button class="locations-download-btn" title="Download config file">
                        <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                            <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                        </svg>
                        <span>Download</span>
                    </button>
                </div>
            </div>
        </div>
    </dialog>
    
    <template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJ0ZW54IiA6IHsKICAgICAgInR5cGUiIDogInN0cmluZyIKICAgIH0sCiAgICAiZXh0cmFjdG9yIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgIm5hbWUiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJMb2dpY2FsIG5hbWUgaWRlbnRpZnlpbmcgdGhpcyBleHRyYWN0b3JcblxuUHJvdmlkZXMgYSBsb2dpY2FsIG5hbWUgKGUuZy4sICdtZXNzYWdlJykgZm9yIHRoaXMgSlNPTi9yZWdleCBleHRyYWN0b3IgdGhhdCB0YXJnZXQgaW5wdXQocykgY2FuIHJlZmVyZW5jZSB0byBhcHBseSB0aGlzIGV4dHJhY3RvciB0byBldmVudHMgd2hpY2ggdGhlIHByb2R1Y2UiCiAgICAgICAgICB9LAogICAgICAgICAgImVuYWJsZWQiIDogewogICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgImJvb2xlYW4iLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQSBKYXZhU2NyaXB0IGV4cHJlc3Npb24gdGhhdCBtdXN0IGJlIGV2YWx1YXRlZCBhcyAndHJ1dGh5JyB0byBlbmFibGUgdGhlIGV4dHJhY3RvclxuXG5FbmFibGVzL2Rpc2FibGVzIHRoaXMgZXh0cmFjdG9yLiBJZiBzZXQsIHRoZSBKYXZhU2NyaXB0IGV4cHJlc3Npb24gcmV0dXJucyBhIHRydXRoeSB2YWx1ZSB0byBlbmFibGUgdGhlIGV4dHJhY3Rvci4gRm9yIGV4YW1wbGUsIHRvIGNvbmZpZ3VyZSB0aGlzIHZhbHVlIHRvIHVzZSBhIHN0YXJ0dXAgYXJndW1lbnQvc2hlbGwgdmFyaWFibGUsIHVzZTogIGBgYCB5YW1sIGV4dHJhY3RvcjogICAgbmFtZTogbXlFeHRyYWN0b3IgICAgZW5hYmxlZDogVGVuWEVudi5nZXQoXCJwZXJmb3JtRXh0cmFjdGlvblwiKSAgICAuLi4gIGBgYCAoQWNjZXB0cyBib29sZWFuIG9yIHN0cmluZyB3aXRoICQ9IHByZWZpeCBmb3IgcnVudGltZSBldmFsdWF0aW9uKSAoRGVmYXVsdDogdHJ1ZSkiLAogICAgICAgICAgICAiZGVmYXVsdCIgOiB0cnVlCiAgICAgICAgICB9LAogICAgICAgICAgInRhcmdldElucHV0IiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiUmVnZXggcGF0dGVybiBpZGVudGlmeWluZyBhbGwgaW5wdXRzIHRvIHdoaWNoIHRoaXMgZXh0cmFjdG9yIHNob3VsZCBiZSBhcHBsaWVkXG5cbkRlZmluZXMgYSByZWdleCBwYXR0ZXJuIGlkZW50aWZ5aW5nIGFsbCBpbnB1dHMgdG8gd2hpY2ggdGhpcyBleHRyYWN0b3Igc2hvdWxkIGJlIGFwcGxpZWQuIEZvciBleGFtcGxlLCB0byBhcHBseSBhbiBleHRyYWN0b3IgdG8gYSBbZGF0YWRvZyBpbnB1dF0oaHR0cHM6Ly9kb2MubG9nMTB4LmNvbS9ydW4vaW5wdXQvYW5hbHl6ZXIvZGF0YWRvZ0xvZ3MpLCBzcGVjaWZ5OiAgYGBgIHlhbWwgZXh0cmFjdG9yOiAgIG5hbWU6IG1lc3NhZ2UgICB0eXBlOiBqc29uICAgdGFyZ2V0SW5wdXQ6IGRhdGFkb2cgICBhY3Rpb25zOiAgIC0gY2FwdHVyZUFsbDptZXNzYWdlICBgYGAgIFRoaXMgYXJndW1lbnQgZW5hYmxlcyBhcHBseWluZyB0aGlzIGV4dHJhY3RvciB0byBpbnB1dChzKSB3aXRob3V0IGNoYW5naW5nIHRoZWlyIGRlZmluaXRpb24uIHZzLiBkaXJlY3RseSB0aGUgaW5wdXQgcmVmZXJlbmNpbmcgdGhlIGV4dHJhY3RvciBkaXJlY3RseSB2aWEgW2V4dHJhY3Rvck5hbWVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3Rvcm5hbWUpLiIKICAgICAgICAgIH0sCiAgICAgICAgICAidHlwZSIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRoZSBtZXRob2QgdXNlZCB0byBleHRyYWN0IHZhbHVlcyBmcm9tIHRoZSBldmVudC4gUG9zc2libGUgdmFsdWVzOltqc29uLCBwYXR0ZXJuXVxuXG5TZXRzIHRoZSB0eXBlIG9mIGV4dHJhY3Rpb24gbWV0aG9kIHRvIHNlbGVjdCwgZHJvcCBhbmQgcmVkYWN0IHZhbHVlcyBmcm9tIGEgdGFyZ2V0IGlucHV0IHN0cmVhbS4gUG9zc2libGUgdmFsdWVzOiAtIGpzb246IHNjYW4gZXZlbnRzIGZvciBKU09OIG9iamVjdHMgY29udGFpbmluZyBmaWVsZHMgc3BlY2lmaWVkIGluIFtleHRyYWN0b3JBY3Rpb25zXShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNleHRyYWN0b3JhY3Rpb25zKS4gLSBwYXR0ZXJuOiBzY2FuIGV2ZW50cyBmb3IgcmVnZXggbmFtZWQgY2FwdHVyZSBncm91cHMgb2YgdGhlIHBhdHRlcm4gc2V0IGJ5IFtleHRyYWN0b3JQYXR0ZXJuXShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNleHRyYWN0b3JwYXR0ZXJuKS4gKERlZmF1bHQ6IGpzb24pIiwKICAgICAgICAgICAgImRlZmF1bHQiIDogImpzb24iCiAgICAgICAgICB9LAogICAgICAgICAgImZpbHRlciIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlJlZ2V4IHBhdHRlcm4gdG8gbWF0Y2ggZm9yIHRoZSBleHRyYWN0b3IgdG8gYmUgYXBwbGllZFxuXG5TcGVjaWZpZXMgYSByZWdleCBwYXR0ZXJuIGFuIGV2ZW50IG11c3QgbWF0Y2ggdG8gc2NhbiBmb3IgSlNPTiBmaWVsZHMvcmVnZXggcGF0dGVybiBjYXB0dXJlIGdyb3Vwcy4gVGhpcyBhcmd1bWVudCBwcm92aWRlcyBhIHdheSB0byBydWxlIG91dCBldmVudHMgZnJvbSBiZWluZyB0cmFuc2Zvcm1lZCBpbnRvIFRlblhPYmplY3QuICBUbyBzZWxlY3QgZXZlbnRzIGZhaWxpbmcgdG8gbWVldCB0aGlzIGZpbHRlciwgZGVmaW5lIGEgW2NhcHR1cmVEZWZhdWx0XShodHRwczovL2RvYy5sb2cxMHguY29tL3J1bi9pbnB1dC9leHRyYWN0LyNkZWZhdWx0KSBhY3Rpb24uIgogICAgICAgICAgfSwKICAgICAgICAgICJwYXR0ZXJuIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiRm9yIHJlZ2V4IGV4dHJhY3RvcnMsIHRoZSBwYXR0ZXJuIGZvciBjYXB0dXJpbmcgbmFtZWQgbWF0Y2ggZ3JvdXBzLiBGb3IgSlNPTiwgdGhlIHNlZ21lbnQgb2YgdGV4dCB3aXRoaW4gZXZlbnRzIHRvIHNjYW4gZm9yIG9iamVjdHNcblxuRGVmaW5lcyBhIHJlZ2V4IHBhdHRlcm4gdGhhdCBhcHBsaWVzIHRvIGV2ZW50cyByZWFkIGZyb20gYW4gaW5wdXQgc3RyZWFtLiBGb3IgW2V4dHJhY3RvclR5cGVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3RvcnR5cGUpID0gcGF0dGVybiwgW21hdGNoaW5nIGdyb3Vwc10oaHR0cHM6Ly9kZXZlbG9wZXIubW96aWxsYS5vcmcvZW4tVVMvZG9jcy9XZWIvSmF2YVNjcmlwdC9SZWZlcmVuY2UvUmVndWxhcl9leHByZXNzaW9ucy9OYW1lZF9jYXB0dXJpbmdfZ3JvdXApIGFyZSB1c2VkIGFzIHRoZSAnbmFtZScgcG9ydGlvbnMgb2YgYWN0aW9ucyBzcGVjaWZpZWQgYnkgJ2V4dHJhY3RvckFjdGlvbnMnLiAgSWYgZXh0cmFjdG9yVHlwZSA9IGpzb24sIG9ubHkgc2NhbiBldmVudHMgZm9yIEpTT05zIHdpdGhpbiB0aGUgYm91bmRhcmllcyBvZiB0aGUgcGF0dGVybidzIG1hdGNoZXMuIgogICAgICAgICAgfSwKICAgICAgICAgICJncm91cCIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk5hbWUgb2YgZ3JvdXAgb2YgZXh0cmFjdG9ycyB3aGljaCB3aWxsIHJ1biB0b2dldGhlclxuXG5EZWZpbmVzIHRoZSBuYW1lIG9mIGV4dHJhY3RvciBncm91cCB0aGlzIGV4dHJhY3RvciB3aWxsIGJlbG9uZyB0by4gZXh0cmFjdG9ycyBvZiB0aGUgc2FtZSBncm91cCB3aWxsIGF0dGVtcHQgdG8gcnVuIHRvZ2V0aGVyIG9uIGV2ZW50cyBpbiBhIHNpbmdsZSBwcm9jZXNzaW5nIHBhc3MgdG8gaW1wcm92ZSBwZXJmb3JtYW5jZSIKICAgICAgICAgIH0sCiAgICAgICAgICAiYWN0aW9ucyIgOiB7CiAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAiYXJyYXkiLAogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiQWN0aW9ucyBpbiB0aGUgZm9ybSBvZiBhY3Rpb25UeXBlOm5hbWUuIFBvc3NpYmxlIHZhbHVlczpbY2FwdHVyZUFsbCwgY2FwdHVyZUZpcnN0LCBjYXB0dXJlTGFzdCwgY2FwdHVyZUFycmF5cywgY2FwdHVyZUZpcnN0QXJyYXksIGNhcHR1cmVMYXN0QXJyYXksIGNhcHR1cmVEZWZhdWx0LCBjYXB0dXJlRmllbGQsIHNldE91dGVyVGV4dCwgZHJvcCwgcmVkYWN0LCBub1RyYW5zZm9ybV1cblxuXG5EZWZpbmVzIGEgbGlzdCBvZiBhY3Rpb25zIGRlZmluZWQgYXM6ICdhY3Rpb25UeXBlOm5hbWU6YWxpYXMnIChlLmcuLCAnY2FwdHVyZUFsbDptZXNzYWdlOmFsaWFzJykgdG8gY2FwdHVyZSBhbmQgcmVkYWN0IHZhbHVlcyB0byB0cmFuc2Zvcm0gaW50byBUZW5YT2JqZWN0cy4gRm9yIEpTT04gZXh0cmFjdG9ycywgJ25hbWUnIHJlZmVycyB0byBhIGZpZWxkIHRvIGxvb2sgZm9yIGluIGV2ZW50cyBhbmQgdGhlIHZhbHVlIHRvIHdoaWNoIHRvIGFwcGx5IHRoZSAnYWN0aW9uVHlwZScuIFRoaXMgY2FuIGJlIGluIHRoZSBmb3JtIG9mICd4Lnkueicgd2hpY2ggd2lsbCBtYXRjaCBpbnRlcm5hbCBmaWVsZHMgaW4gdGhlIGpzb24uIEZvciBleGFtcGxlOiAnbWV0YWRhdGEuaWQnIHdpbGwgbWF0Y2ggdGhlICdpZCcgZmllbGQgb2YgdGhlICdtZXRhZGF0YScgb2JqZWN0IGluIHtcIm1ldGFkYXRhXCI6IHtcImlkXCI6IFwiMTIzNFwifX0gIEZvciByZWdleCBleHRyYWN0b3JzLCAnbmFtZScgcmVmZXJzIHRvIGEgW3JlZ2V4IHBhdHRlcm4gbWF0Y2ggZ3JvdXBdKGh0dHBzOi8vZGV2ZWxvcGVyLm1vemlsbGEub3JnL2VuLVVTL2RvY3MvV2ViL0phdmFTY3JpcHQvUmVmZXJlbmNlL1JlZ3VsYXJfZXhwcmVzc2lvbnMvTmFtZWRfY2FwdHVyaW5nX2dyb3VwKSBkZWZpbmVkIGJ5ICdleHRyYWN0b3JQYXR0ZXJuJyB0byB3aGljaCB0byBhcHBseSB0aGUgJ2FjdGlvblR5cGUnLiAgVGhpcyBzZXR0aW5nIG11c3QgYmUgc3BlY2lmaWVkIHdoZW4gW2V4dHJhY3RvclR5cGVdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2V4dHJhY3QvI2V4dHJhY3RvcnR5cGUpID0gJ2pzb24nLiBJZiBub3Qgc3BlY2lmaWVkIGFuZCBleHRyYWN0b3JUeXBlIGlzICdwYXR0ZXJuJywgdGhlICdleHRyYWN0b3JQYXR0ZXJuJyBwYXR0ZXJuIHNjYW5zIGZvciByZWdleCBjYXB0dXJlIGdyb3VwcywgcGVyZm9ybWluZyBvbiBlYWNoIGFzJ2NhcHR1cmVBbGwnIGFjdGlvbi4gIFRoZSAnYWxpYXMnIHBhcnQgaXMgb3B0aW9uYWwsIGFuZCBpZiBwcm92aWRlZCBpcyB1c2VkIHRvIHJlZmVyZW5jZSB0aGUgb2JqZWN0IGFzIGl0J3MgbmFtZS4gVGhpcyBpcyB1c2VmdWwgd2hlbiBtdWx0aXBsZSBleHRyYWN0b3JzIGFyZSB1c2VkIHRvIGV4dHJhY3QgZGlmZmVyZW50IHRoaW5ncyB3aGljaCBhcmUgbGF0ZXIgdXNlZCBpbiB0aGUgc2FtZSB3YXkuICBJZiBubyBjYXB0dXJlIGdyb3VwcyBhcmUgZGVmaW5lZCwgYW55IG1hdGNoZXMgb2YgdGhlIHBhdHRlcm4gd2l0aGluIHRoZSBpbnB1dCB0ZXh0IGxpbmUgYXJlIGNhcHR1cmVkLiIsCiAgICAgICAgICAgICJpdGVtcyIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogInN0cmluZyIKICAgICAgICAgICAgfQogICAgICAgICAgfSwKICAgICAgICAgICJmb3JlYWNoIiA6IHsKICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICBdLAogICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTmFtZSBvZiBvcHRpb25zIGdyb3VwIGZvciB3aG9zZSBpbnN0YW5jZXMgdG8gY3JlYXRlIG1hdGNoaW5nIGV4dHJhY3RvcnNcblxuU3BlY2lmaWVzIHRoZSBuYW1lIG9mIGFuIG9wdGlvbnMgZ3JvdXAgZm9yIHdob3NlIGluc3RhbmNlcyB0byByZXBsaWNhdGUgdGhpcyBleHRyYWN0b3IuIEZvciBleGFtcGxlLCB0aGUgW0VsYXN0aWMgaW5wdXRdKGh0dHBzOi8vZG9jLmxvZzEweC5jb20vcnVuL2lucHV0L2FuYWx5emVyL2VsYXN0aWNzZWFyY2gpIGRlZmluZXMgdGhlICdlbGFzdGljJyBvcHRpb25zIGdyb3VwIGFuZCBjb25maWd1cmVzIGFuIGV4dHJhY3RvciB0byBhcHBseSB0byBlYWNoIGlucHV0IHN0cmVhbSBjcmVhdGVkIGZyb20gaXRzIGNvbmZpZ3VyZWQgaW5zdGFuY2VzLiIKICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJyZXF1aXJlZCIgOiBbCiAgICAgICAgICAibmFtZSIsCiAgICAgICAgICAidHlwZSIKICAgICAgICBdCiAgICAgIH0KICAgIH0KICB9LAogICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZQp9</template>

    ```yaml
    # 🔟❎ 'run' JSON extractor configuration
    
    # Configure input JSON extractors.
    # To learn more see: https://doc.log10x.com/run/input/extract
    
    # Set the 10x pipeline to 'run'
    tenx: run
    
    # ============================= Extractor Options =============================
    
    # multiple extractors can be defined below
    extractor:
    
        # 'name' provides a unique name for this extractor that is referenced
        #  by any inputs to which it is applied 
      - name: jsonExtractor
       
        # 'type' controls the method for parsing input stream text (json or pattern)
        type: json
        
        # 'targetInput' sets a regex pattern to match all inputs to which the extractor is applied.
        #  For example, to apply this extractor to an input named 'datadog', set: 'targetInput: datadog'
        targetInput: myInput
    
        # 'filter' specifies a regex pattern the current event must match to scan for JSON objects.
        #  For example, the pattern below will filter out events that contain "level":"TRACE"
        filter: ^((?!"level":"TRACE").)*$
       
        # 'actions' specifies the actions taken by this extractor. 
        #  Define actions using <type> followed by ':' and the JSON field they target.
        #  The following action types are supported (comment in/out the ones needed for your use case):
        actions: 
    
          # Capture
    
          # 'captureAll' transforms all instances of a matching JSON field (i.e., 'message')
          #  within the current event into TenXObjects
          - captureAll:message
    
          # 'captureFirst' transforms only the first instance of a matching JSON field (i.e., 'message')
          #  within the current event into an TenXObject
          - captureFirst:message
    
          # 'captureLast' transforms only the last instance matching JSON field (i.e., 'message')
          #  within the current event into an TenXObject    
          - captureLast:message
          
          #  Filter
    
          # 'redact' resets the value of any matching JSON field (i.e., 'username') found in the event
          #  based on its JSON value type:
          #  - number -> 0
          #  - string -> ""
          #  - boolean -> true
          #  - object -> {}
          #  - array -> [] 
          - redact:username
    
            # 'drop' removes both field name and value of any matching 
            #  JSON field (i.e., 'password') found in the event. This action applies to JSON extractors only.
          - drop:password
    
          # Advanced
    
          # 'captureDefault' serves as a sink for events that fail to match the 'filter' pattern
          #  or do not contain any of the capture group names specified by 'actions'. These events are
          #  transformed into TenXObjects whose 'extractorKey' field returns this action's name (i.e., 'other')
          - captureDefault:other
    
          # 'noTransform' is the same as 'captureDefault' (see above), except captured events are not
          #  transformed into TenXObjects and remain as 'plain text' objects.
          #  This is useful when the events need to be routed by the 10x pipeline to a specific
          #  output, but do not require access to structured elements (e.g., the intrinsic 'vars' and 'timestamp' fields).
          - noTransform:other
          
    ```

## :material-menu: Options

Specify the options below to [configure](/config "configure") multiple Input extractor:

|Name|Description|Category|
|---|---|---|
|[extractorName](#extractorname "logical name identifying this extractor")|Logical name identifying this extractor|General|
|[extractorEnabled](#extractorenabled "a JavaScript expression that must be evaluated as 'truthy' to enable the extractor")|A JavaScript expression that must be evaluated as 'truthy' to enable the extractor|General|
|[extractorTargetInput](#extractortargetinput "regex pattern identifying all inputs to which this extractor should be applied")|Regex pattern identifying all inputs to which this extractor should be applied|General|
|[extractorType](#extractortype "the method used to extract values from the event. Possible values:[json, pattern]")|The method used to extract values from the event. Possible values:\[json, pattern\]|General|
|[extractorGroup](#extractorgroup "name of group of extractors which will run together")|Name of group of extractors which will run together|General|
|[extractorActions](#extractoractions "actions in the form of actionType:name. Possible values:[captureAll, captureFirst, captureLast, captureArrays, captureFirstArray, captureLastArray, captureDefault, captureField, setOuterText, drop, redact, noTransform]&#10;")|Actions in the form of actionType:name. Possible values:\[captureAll, captureFirst, captureLast, captureArrays, captureFirstArray, captureLastArray, captureDefault, captureField, setOuterText, drop, redact, noTransform\]&#10;|General|
|[extractorFilter](#extractorfilter "regex pattern to match for the extractor to be applied")|Regex pattern to match for the extractor to be applied|Pattern|
|[extractorPattern](#extractorpattern "for regex extractors, the pattern for capturing named match groups. For JSON, the segment of text within events to scan for objects")|For regex extractors, the pattern for capturing named match groups. For JSON, the segment of text within events to scan for objects|Pattern|
|[extractorForeach](#extractorforeach "name of options group for whose instances to create matching extractors")|Name of options group for whose instances to create matching extractors|Advanced|

### General

#### :material-menu-right-outline:**`extractorName`**

Logical name identifying this extractor.

|Type|Required|Category|
|---|---|---|
|String|✔|General|

Provides a logical name (e.g., 'message') for this JSON/regex extractor
that target input(s) can reference to apply this extractor to events which the produce.


#### :material-menu-right-outline:**`extractorEnabled`**

A JavaScript expression that must be evaluated as 'truthy' to enable the extractor.

|Type|Default|Category|
|---|---|---|
|Boolean|true|General|

enables/disables this extractor. If set, the JavaScript expression returns a truthy value
to enable the extractor. For example, to configure this value to use a startup argument/shell variable, use:

```yaml
extractor:
   name: myExtractor
   enabled: TenXEnv.get("performExtraction") 
  ... 
```


#### :material-menu-right-outline:**`extractorTargetInput`**

Regex pattern identifying all inputs to which this extractor should be applied.

|Type|Default|Category|
|---|---|---|
|String|""|General|

Defines a regex pattern identifying all inputs to which this extractor should be applied.

For example, to apply an extractor to a [datadog input](https://doc.log10x.com/run/input/analyzer/datadogLogs "Read events from Datadog Logs"), specify:

```yaml
extractor:
  name: message
  type: json
  targetInput: datadog
  actions:
  - captureAll:message 
```

This argument enables applying this extractor to input(s) without changing their definition.
vs. directly the input referencing the extractor directly via [extractorName](https://doc.log10x.com/run/input/extract/#extractorname "logical name identifying this extractor").


#### :material-menu-right-outline:**`extractorType`**

The method used to extract values from the event. Possible values:\[json, pattern\].

|Type|Required|Category|
|---|---|---|
|String|✔|General|

Sets the type of extraction method to select, drop and redact values from a target input stream.
Possible values:

- json: scan events for JSON objects containing fields specified in [extractorActions](https://doc.log10x.com/run/input/extract/#extractoractions "actions in the form of actionType:name. Possible values:[captureAll, captureFirst, captureLast, captureArrays, captureFirstArray, captureLastArray, captureDefault, captureField, setOuterText, drop, redact, noTransform]&#10;").
- pattern: scan events for regex named capture groups of the pattern set by [extractorPattern](https://doc.log10x.com/run/input/extract/#extractorpattern "for regex extractors, the pattern for capturing named match groups. For JSON, the segment of text within events to scan for objects").


#### :material-menu-right-outline:**`extractorGroup`**

Name of group of extractors which will run together.

|Type|Default|Category|
|---|---|---|
|String|""|General|

Defines the name of extractor group this extractor will belong to.
extractors of the same group will attempt to run together on events in a single processing pass to improve
performance.


#### :material-menu-right-outline:**`extractorActions`**

Actions in the form of actionType:name. Possible values:\[captureAll, captureFirst, captureLast, captureArrays, captureFirstArray, captureLastArray, captureDefault, captureField, setOuterText, drop, redact, noTransform\].

|Type|Default|Category|
|---|---|---|
|List|\[\]|General|

Defines a list of actions defined as: 'actionType:name:alias' (e.g., 'captureAll:message:alias') to capture and redact values to transform into TenXObjects.

For JSON extractors, 'name' refers to a field to look for in events and the value to which to apply the 'actionType'.
This can be in the form of 'x.y.z' which will match internal fields in the json.
For example: 'metadata.id' will match the 'id' field of the 'metadata' object in {"metadata": {"id": "1234"}}

For regex extractors, 'name' refers to a [regex pattern match group](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Regular_expressions/Named_capturing_group){target="\_blank"}
defined by 'extractorPattern' to which to apply the 'actionType'.

This setting must be specified when [extractorType](https://doc.log10x.com/run/input/extract/#extractortype "the method used to extract values from the event. Possible values:[json, pattern]") = 'json'.
If not specified and extractorType is 'pattern',
the 'extractorPattern' pattern scans for regex capture groups, performing on each as'captureAll' action.

The 'alias' part is optional, and if provided is used to reference the object as it's name.
This is useful when multiple extractors are used to extract different things which are later used in the same way.

If no capture groups are defined, any matches of the pattern within the input text line are captured.


### Pattern

#### :material-menu-right-outline:**`extractorFilter`**

Regex pattern to match for the extractor to be applied.

|Type|Default|Category|
|---|---|---|
|String|""|Pattern|

Specifies a regex pattern an event must match to scan for JSON fields/regex pattern capture groups.
This argument provides a way to rule out events from being transformed into TenXObject.
To select events failing to meet this filter, define a [captureDefault](https://doc.log10x.com/run/input/extract/#default) action.


#### :material-menu-right-outline:**`extractorPattern`**

For regex extractors, the pattern for capturing named match groups. For JSON, the segment of text within events to scan for objects.

|Type|Default|Category|
|---|---|---|
|String|""|Pattern|

Defines a regex pattern that applies to events read from an input stream.

For [extractorType](https://doc.log10x.com/run/input/extract/#extractortype "the method used to extract values from the event. Possible values:[json, pattern]") = pattern, [matching groups](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Regular_expressions/Named_capturing_group){target="\_blank"}
are used as the 'name' portions of actions specified by 'extractorActions'.

If extractorType = json, only scan events for JSONs within the boundaries of the pattern's matches.


### Advanced

#### :material-menu-right-outline:**`extractorForeach`**

Name of options group for whose instances to create matching extractors.

|Type|Default|Category|
|---|---|---|
|String|""|Advanced|

Specifies the name of an options group for whose instances to replicate this extractor.
For example, the [Elastic input](https://doc.log10x.com/run/input/analyzer/elasticsearch "Read events from an ElasticSearch hosted/on-premises cluster")
defines the 'elastic' options group and configures an extractor to apply to each
input stream created from its configured instances.


<br/>:material-github: This unit is defined in [extract/unit.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/units/input/extract/unit.yaml "extract/unit.yaml"){target="\_blank"}.

