---
title: "Fluent Bit"
description: "receive and optimize events collected by Fluent Bit via the Fluent Forward\
  \ protocol"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/fluentbit/module.yaml"
icon: "simple/fluentbit"

---
Runs 10x Engine as a [sidecar](https://doc.log10x.com/engine/launcher/sidecar) to Fluent Bit for reporting, receiving, and optimizing events before they ship to their destination (Elasticsearch, Splunk, S3, Kafka, …). In the VM/host recipe, Fluent Bit and Log10x run as peer processes and exchange events over the [Fluent Forward protocol](https://docs.fluentbit.io/manual/pipeline/outputs/forward){target="\_blank"} in both directions; works against any stock Fluent Bit build and the official Fluent Bit Helm chart on Kubernetes via a `log10x/edge-10x` sidecar container (`extraContainers` values overlay).

## Architecture

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>📂 Sources</div><div style='font-size: 10px;'>tail, http, k8s</div>"] --> F["<div style='font-size: 14px;'>🧪 Filters</div><div style='font-size: 10px;'>Match app.*</div>"]
    F --> B["<div style='font-size: 14px;'>📤 out_forward</div><div style='font-size: 10px;'>:24224</div>"]
    B --> E["<div style='font-size: 14px;'>⚡ 10x Engine</div><div style='font-size: 10px;'>Receive/Optimize</div>"]
    E --> C["<div style='font-size: 14px;'>📥 in_forward</div><div style='font-size: 10px;'>:24225 Tag_Prefix tenx.</div>"]
    C --> D["<div style='font-size: 14px;'>📤 Destinations</div><div style='font-size: 10px;'>ES, Splunk, S3, Kafka</div>"]

    classDef input fill:#2563eb,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef filter fill:#ea580c,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef engine fill:#7c3aed,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#16a34a,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A input
    class B filter
    class C filter
    class D output
    class E engine
    class F filter
```

</div>

### Data Flow

- 📂 **Sources**, Your existing Fluent Bit inputs (`tail`, `http`, `forward`, `systemd`, …) tag events with your normal scheme (e.g. `app.*`, `k8s.*`).
- 🧪 **Filters**, Your enrichment filters (`kubernetes`, `modify`, `parser`, `lua`, …) `Match` your source tags only (e.g. `Match app.*`). They run exactly once before the event is handed off to Log10x.
- 📤 **out\_forward** → Log10x, A `forward` output with `Match app.*` (or whatever your source tag pattern is) ships the enriched event to the Log10x sidecar over TCP `:24224`.
- ⚡ **10x Engine**, The Receiver app applies rate/policy-based filtering and optionally compacts events for volume reduction.
- 📥 **in\_forward → destinations**, Processed events come back to Fluent Bit on `:24225` via a `forward` input with `Tag_Prefix tenx.`, which prepends `tenx.` to every returning tag. Your destination outputs `Match tenx.*`; the `tenx.` namespace is what keeps filters from re-firing and the `out_forward` to Log10x from looping events back. Fluent Bit has no label/scope concept, so **tag-prefix namespacing is the bypass mechanism**.
- 📤 **Destinations**, Your destination outputs (`es`, `splunk`, `kafka`, `s3`, …) `Match tenx.*` and ship to the real destinations. The original tag is preserved after the prefix (`tenx.app.foo`), so destinations that route on the suffix still work.

### What an event looks like on the way back

The record structure of the original Fluent Bit event is preserved end-to-end, every field comes back to your destination outputs with the same name and same position. The wire tag has a `tenx.` prefix prepended on egress (the bypass mechanism); the original tag is the suffix. What changes in the record body depends on the Receiver app mode:

|Mode|Difference vs the event Fluent Bit sent in|
|---|---|
|Receive (default)|None. Same record. Tag is `tenx.<original>`.|
|Receive + `symbolMessageHashField <name>`|Adds one new field with the symbol-pattern hash (a stable identifier for the message pattern, usable as a dedup key, metric dimension, or correlation ID).|
|`receiverOptimize true`|The value of the message field (`log` by default, or whatever `fluentbitInputMessageField` is set to) is replaced with a compact encoded form. A separate `tenx-template` event is emitted with the template needed to decode it. All other fields stay verbatim.|
|`receiverOptimize true` + `symbolMessageHashField <name>`|Both of the above.|

`symbolMessageHashField` is unset by default, which is what makes the first row true: the receive path hands the record back exactly as it arrived. The pattern hash is still computed and still rides the event inside the engine as `tenx_hash` for metrics and aggregation, it just does not reach the wire. Naming a field opts in, either as a launch argument (`tenx @run/input/forwarder/fluentbit @apps/receiver symbolMessageHashField my_custom_hash`) or as an environment variable of the same name.

The original Fluent Bit tag is carried by the Forward protocol itself and surfaces on the event as its `source` inside Log10x, used for rate-based grouping and re-emitted as the wire tag on the return path (with `tenx.` prepended by the egress `forward` input). Internally, Log10x's Fluent Bit input module reads the message text from the field named by `fluentbitInputMessageField` (default `log`); when the Receiver app is configured with `k8sExtractorName: fluentK8s`, the `kubernetes.*` sub-object is also materialized as enrichment fields for use by message-pattern and rate filtering.

??? tenx-keyfiles "Key Files"

    | File | Purpose |
    |------|---------|
    | [`stream.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/fluentbit/stream.yaml) | Fluent Bit Forward input + output stream definitions |
    | [`conf/tenx-sidecar.conf`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/fluentbit/conf/tenx-sidecar.conf) | Reference Fluent Bit config showing tag-prefix bypass via `Tag_Prefix tenx.` |

## Quickstart

**1. Run Log10x:**

```bash
tenx @run/input/forwarder/fluentbit @apps/receiver
```

**2. Wire up your Fluent Bit config**, include the sidecar recipe and `Match` your sources with the recipe's tag conventions:

```ini title="fluent-bit.conf"
@INCLUDE ${TENX_MODULES}/pipelines/run/modules/input/forwarder/fluentbit/conf/tenx-sidecar.conf

[INPUT]
    Name         tail
    Path         /var/log/app.log
    Tag          app.logs           # any tag NOT starting with `tenx.`
    Parser       json
```

**3. Point destination outputs at the `tenx.*` namespace** (the recipe defaults to `stdout` for testing):

```ini
[OUTPUT]
    Name         your_output_plugin
    Match        tenx.*             # only matches events that came back from Log10x
    # ... destination config
```

For Splunk integration see the [10x for Splunk](https://doc.log10x.com/apps/receiver/compact/splunk/) documentation. For Kubernetes deployment, add the `log10x/edge-10x` sidecar on top of the official Fluent Bit chart via an `extraContainers` values overlay, see the [Helm chart overlay](https://doc.log10x.com/apps/receiver/deploy/#fluent-bit).

## :material-wrench-outline: Config Files

To configure the Fluent Bit module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [fluentbit/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/fluentbit/config.yaml "fluentbit/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/fluentbit/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/forwarder/fluentbit/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/forwarder/fluentbit/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/forwarder/fluentbit/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/forwarder/fluentbit/config.yaml">$TENX_CONFIG/run/input/forwarder/fluentbit/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/forwarder/fluentbit/config.yaml">./pipelines/run/input/forwarder/fluentbit/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICB9CiAgICB9LAogICAgInRlbngiIDogewogICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgfSwKICAgICJmbHVlbnRiaXQiIDogewogICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgImlucHV0IiA6IHsKICAgICAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgICAicG9ydCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRDUCBwb3J0IHRvIGxpc3RlbiBvbiBmb3IgZXZlbnRzIGZyb20gRmx1ZW50IEJpdCdzIGZvcndhcmQgb3V0cHV0XG5cblRDUCBwb3J0IHdoZXJlIExvZzEweCBsaXN0ZW5zIGZvciBldmVudHMgc2VudCBieSBGbHVlbnQgQml0J3MgYGZvcndhcmRgIG91dHB1dC4gTWF0Y2ggdGhpcyBhZ2FpbnN0IHRoZSBgUG9ydGAgaW4geW91ciBGbHVlbnQgQml0IGBbT1VUUFVUXWAgYmxvY2sgKGBOYW1lIGZvcndhcmRgKS4gKERlZmF1bHQ6IDI0MjI0KSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogIjI0MjI0IgogICAgICAgICAgICB9LAogICAgICAgICAgICAicGF0aCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJVbml4IGRvbWFpbiBzb2NrZXQgcGF0aCB0byBsaXN0ZW4gb24gKExpbnV4L21hY09TKVxuXG5XaGVuIHNldCwgTG9nMTB4IGxpc3RlbnMgb24gYSBVbml4IGRvbWFpbiBzb2NrZXQgaW5zdGVhZCBvZiBUQ1AsIHVzZWZ1bCBvbiBMaW51eC9tYWNPUyB0byBhdm9pZCBUQ1Agb3ZlcmhlYWQuIENvbmZpZ3VyZSBGbHVlbnQgQml0J3MgYGZvcndhcmRgIG91dHB1dCB3aXRoIGBVbml4X1BhdGhgIHNldCB0byBhIG1hdGNoaW5nIHBhdGguIElnbm9yZWQgb24gV2luZG93cy4iCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJtZXNzYWdlRmllbGQiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTmFtZSBvZiB0aGUgSlNPTiBmaWVsZCBjYXJyeWluZyB0aGUgb3JpZ2luYWwgbG9nIGxpbmVcblxuTmFtZSBvZiB0aGUgZmllbGQgaW4gZWFjaCBGbHVlbnQgQml0IHJlY29yZCB0aGF0IGNvbnRhaW5zIHRoZSBhY3R1YWwgbG9nIG1lc3NhZ2UgdGV4dC4gVGhlIGRlZmF1bHQgKGBsb2dgKSBtYXRjaGVzIEZsdWVudCBCaXQncyBgdGFpbGAgaW5wdXQgY29udmVudGlvbiBmb3IgY29udGFpbmVyIGFuZCBmaWxlIGxvZ3MuIFNldCB0byBlLmcuIGBtZXNzYWdlYCBpZiB5b3VyIHNvdXJjZXMgZW1pdCB0aGUgbG9nIGxpbmUgdW5kZXIgYSBkaWZmZXJlbnQga2V5LiAoRGVmYXVsdDogbG9nKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogImxvZyIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgIm91dHB1dCIgOiB7CiAgICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAgICAgImhvc3QiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIGhvc3Qgb2YgdGhlIEZsdWVudCBCaXQgZm9yd2FyZCBpbnB1dCByZWNlaXZpbmcgcHJvY2Vzc2VkIGV2ZW50c1xuXG5Ib3N0bmFtZSBvciBJUCB3aGVyZSBGbHVlbnQgQml0J3MgYGZvcndhcmRgIGlucHV0IGlzIGxpc3RlbmluZyBmb3IgcHJvY2Vzc2VkIGV2ZW50cyBmcm9tIExvZzEweC4gUGFpcnMgd2l0aCBgZmx1ZW50Yml0T3V0cHV0UG9ydGAuIChEZWZhdWx0OiAxMjcuMC4wLjEpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAiMTI3LjAuMC4xIgogICAgICAgICAgICB9LAogICAgICAgICAgICAicG9ydCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRDUCBwb3J0IG9mIHRoZSBGbHVlbnQgQml0IGZvcndhcmQgaW5wdXQgcmVjZWl2aW5nIHByb2Nlc3NlZCBldmVudHNcblxuVENQIHBvcnQgd2hlcmUgRmx1ZW50IEJpdCdzIGBmb3J3YXJkYCBpbnB1dCBpcyBsaXN0ZW5pbmcgZm9yIHByb2Nlc3NlZCBldmVudHMgZnJvbSBMb2cxMHguIE1VU1QgZGlmZmVyIGZyb20gdGhlIHBvcnQgTG9nMTB4J3Mgb3duIEZvcndhcmQgaW5wdXQgbGlzdGVucyBvbiAoZGVmYXVsdCBgMjQyMjRgKSBvciB0aGUgdHdvIHdvdWxkIGNvbGxpZGUgb24gdGhlIHNhbWUgc29ja2V0LiAoRGVmYXVsdDogMjQyMjUpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAiMjQyMjUiCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJwYXRoIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlVuaXggZG9tYWluIHNvY2tldCBwYXRoIG9mIHRoZSBGbHVlbnQgQml0IGZvcndhcmQgaW5wdXQgKExpbnV4L21hY09TKVxuXG5PcHRpb25hbCBVbml4IGRvbWFpbiBzb2NrZXQgcGF0aCBmb3IgRmx1ZW50IEJpdCdzIGBmb3J3YXJkYCBpbnB1dC4gV2hlbiBzZXQsIHRha2VzIHByZWNlZGVuY2Ugb3ZlciBgZmx1ZW50Yml0T3V0cHV0SG9zdGAgLyBgZmx1ZW50Yml0T3V0cHV0UG9ydGAuIExpbnV4L21hY09TIG9ubHksIGlnbm9yZWQgb24gV2luZG93cy4iCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJlbmNvZGVUeXBlIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk91dHB1dCBmb3JtYXQgd2hlbiBvdXRwdXRGaWVsZHMgYXJlIHNldC4gUG9zc2libGUgdmFsdWVzOiBbanNvbiwgZGVsaW1pdGVkXVxuXG5TcGVjaWZpZXMgaG93IHRoZSBjb21iaW5lZCBvdXRwdXQgKG1haW4gZXZlbnQgZmllbGQgcGx1cyBvdXRwdXRGaWVsZHMpIGlzIGVuY29kZWQgd2hlbiB3cml0aW5nIGJhY2sgdG8gRmx1ZW50IEJpdC4gUG9zc2libGUgdmFsdWVzOiAtICoqanNvbioqOiBmb3JtYXRzIGFsbCBmaWVsZHMgYXMgYSBKU09OIG9iamVjdCAtICoqZGVsaW1pdGVkKio6IGZvcm1hdHMgZmllbGQgdmFsdWVzIHNlcGFyYXRlZCBieSB0aGUgb3V0cHV0IGRlbGltaXRlciBPbmx5IHRha2VzIGVmZmVjdCB3aGVuIGZsdWVudGJpdE91dHB1dEZpZWxkcyBpcyBzZXQuIChEZWZhdWx0OiBkZWxpbWl0ZWQpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAiZGVsaW1pdGVkIgogICAgICAgICAgICB9CiAgICAgICAgICB9CiAgICAgICAgfQogICAgICB9CiAgICB9CiAgfSwKICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogdHJ1ZQp9</template>

```yaml
# 🔟❎ 'run' Fluent Bit receiver configuration
#
# Every endpoint setting below reads an environment variable first and falls
# back to the shipped default, so a deployment can move a port, a host or a
# socket path without editing this file. The variable name is the launch
# option name in upper snake case with a TENX_ prefix, for example the
# `fluentbitInputPort` option reads TENX_FLUENTBIT_INPUT_PORT.
#
# To learn more see https://doc.log10x.com/run/input/forwarder/fluentbit/

tenx: run

# =============================== Dependencies ================================

include:
  - run/input/forwarder/config.yaml
  - run/modules/input/forwarder/fluentbit

# ============================= Fluent Bit Options ============================

fluentbit:

  # ----------------------------- Input Options -----------------------------

  input:

    # 'port' specifies the TCP port to listen on for events from Fluent Bit's
    #  forward output plugin.
    #  Env var: TENX_FLUENTBIT_INPUT_PORT
    port: $=TenXEnv.get("TENX_FLUENTBIT_INPUT_PORT", 24224)

    # 'path' switches the input to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'port'. Empty means TCP.
    #  Env var: TENX_FLUENTBIT_INPUT_PATH
    path: $=TenXEnv.get("TENX_FLUENTBIT_INPUT_PATH", "")

    # 'messageField' is the name of the JSON field in each Fluent Bit record
    #  carrying the log line text.
    messageField: log

  # ----------------------------- Output Options ----------------------------

  output:

    # 'host' specifies the TCP host of Fluent Bit's forward input receiving
    #  processed events from Log10x.
    #  Env var: TENX_FLUENTBIT_OUTPUT_HOST
    host: $=TenXEnv.get("TENX_FLUENTBIT_OUTPUT_HOST", "127.0.0.1")

    # 'port' specifies the TCP port of Fluent Bit's forward input. MUST differ
    #  from input.port or the two would collide on the same listener.
    #  Env var: TENX_FLUENTBIT_OUTPUT_PORT
    port: $=TenXEnv.get("TENX_FLUENTBIT_OUTPUT_PORT", 24225)

    # 'path' switches the output to a Unix domain socket of TCP.
    #  When set, takes precedence over 'host'/'port'. Empty means TCP.
    #  Env var: TENX_FLUENTBIT_OUTPUT_PATH
    path: $=TenXEnv.get("TENX_FLUENTBIT_OUTPUT_PATH", "")

    # 'encodeType' is the on-wire format for the Forward record.
    #  - 'delimited': each top-level field of the rendered record becomes its
    #    own Forward record field, preserves the original record's structure.
    #  - 'json': the whole record is wrapped as one stringified field.
    encodeType: delimited
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the Fluent Bit:

|Name|Description|Category|
|---|---|---|
|[fluentbitInputPort](#fluentbitinputport "TCP port to listen on for events from Fluent Bit's forward output")|TCP port to listen on for events from Fluent Bit's forward output|Input|
|[fluentbitInputPath](#fluentbitinputpath "Unix domain socket path to listen on (Linux/macOS)")|Unix domain socket path to listen on (Linux/macOS)|Input|
|[fluentbitInputMessageField](#fluentbitinputmessagefield "name of the JSON field carrying the original log line")|Name of the JSON field carrying the original log line|Input|
|[fluentbitOutputHost](#fluentbitoutputhost "TCP host of the Fluent Bit forward input receiving processed events")|TCP host of the Fluent Bit forward input receiving processed events|Output|
|[fluentbitOutputPort](#fluentbitoutputport "TCP port of the Fluent Bit forward input receiving processed events")|TCP port of the Fluent Bit forward input receiving processed events|Output|
|[fluentbitOutputPath](#fluentbitoutputpath "Unix domain socket path of the Fluent Bit forward input (Linux/macOS)")|Unix domain socket path of the Fluent Bit forward input (Linux/macOS)|Output|
|[fluentbitOutputEncodeType](#fluentbitoutputencodetype "output format when outputFields are set. Possible values: [json, delimited]")|Output format when outputFields are set. Possible values: \[json, delimited\]|Output|

### Input

#### :material-menu-right-outline:**`fluentbitInputPort`**

TCP port to listen on for events from Fluent Bit's forward output.

|Type|Default|Category|
|---|---|---|
|String|24224|Input|

TCP port where Log10x listens for events sent by Fluent Bit's `forward`
output. Match this against the `Port` in your Fluent Bit `[OUTPUT]`
block (`Name forward`).


#### :material-menu-right-outline:**`fluentbitInputPath`**

Unix domain socket path to listen on (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Input|

When set, Log10x listens on a Unix domain socket instead of TCP, useful
on Linux/macOS to avoid TCP overhead. Configure Fluent Bit's `forward`
output with `Unix_Path` set to a matching path. Ignored on Windows.


#### :material-menu-right-outline:**`fluentbitInputMessageField`**

Name of the JSON field carrying the original log line.

|Type|Default|Category|
|---|---|---|
|String|log|Input|

Name of the field in each Fluent Bit record that contains the actual
log message text. The default (`log`) matches Fluent Bit's `tail`
input convention for container and file logs. Set to e.g. `message`
if your sources emit the log line under a different key.


### Output

#### :material-menu-right-outline:**`fluentbitOutputHost`**

TCP host of the Fluent Bit forward input receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|127.0.0.1|Output|

Hostname or IP where Fluent Bit's `forward` input is listening for
processed events from Log10x. Pairs with `fluentbitOutputPort`.


#### :material-menu-right-outline:**`fluentbitOutputPort`**

TCP port of the Fluent Bit forward input receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|24225|Output|

TCP port where Fluent Bit's `forward` input is listening for processed
events from Log10x. MUST differ from the port Log10x's own Forward
input listens on (default `24224`) or the two would collide on the
same socket.


#### :material-menu-right-outline:**`fluentbitOutputPath`**

Unix domain socket path of the Fluent Bit forward input (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Output|

Optional Unix domain socket path for Fluent Bit's `forward` input.
When set, takes precedence over `fluentbitOutputHost` /
`fluentbitOutputPort`. Linux/macOS only, ignored on Windows.


#### :material-menu-right-outline:**`fluentbitOutputEncodeType`**

Output format when outputFields are set. Possible values: \[json, delimited\].

|Type|Default|Category|
|---|---|---|
|String|delimited|Output|

Specifies how the combined output (main event field plus outputFields)
is encoded when writing back to Fluent Bit. Possible values:

- **json**: formats all fields as a JSON object
- **delimited**: formats field values separated by the output delimiter
  Only takes effect when fluentbitOutputFields is set.


<br/>:material-github: This module is defined in [fluentbit/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/fluentbit/module.yaml "fluentbit/module.yaml"){target="\_blank"}.

