---
title: "Fluentd"
description: "receive and optimize events collected by Fluentd via the Fluent Forward\
  \ protocol"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/fluentd/module.yaml"
icon: "simple/fluentd"

---
Runs 10x Engine as a [sidecar](https://doc.log10x.com/engine/launcher/sidecar) to Fluentd for reporting, receiving, and optimizing events before they ship to their destination (Elasticsearch, Splunk, S3, Kafka, …). In the VM/host recipe, Fluentd and Log10x run as peer processes and exchange events over the [Fluent Forward protocol](https://docs.fluentd.org/output/forward){target="\_blank"}; works against any stock Fluentd build (td-agent, fluent-package, OSS) and the official Fluentd Helm chart on Kubernetes via a `log10x/edge-10x` sidecar container (kustomize post-renderer overlay).

## Architecture

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>📂 Sources</div><div style='font-size: 10px;'>tail, http, k8s</div>"] --> F["<div style='font-size: 14px;'>🧪 @INGEST</div><div style='font-size: 10px;'>enrichment filters</div>"]
    F --> B["<div style='font-size: 14px;'>📤 out_forward</div><div style='font-size: 10px;'>:24224</div>"]
    B --> E["<div style='font-size: 14px;'>⚡ 10x Engine</div><div style='font-size: 10px;'>Report/Receive/Optimize</div>"]
    E --> C["<div style='font-size: 14px;'>📥 in_forward</div><div style='font-size: 10px;'>:24225 → @OUTPUT</div>"]
    C --> D["<div style='font-size: 14px;'>📤 Destinations</div><div style='font-size: 10px;'>ES, Splunk, S3, Kafka</div>"]

    classDef input fill:#2563eb,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef filter fill:#ea580c,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef engine fill:#7c3aed,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#16a34a,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A input
    class B filter
    class C filter
    class D output
    class E engine
    class F filter
```

</div>

### Data Flow

- 📂 **Sources**, Your existing Fluentd sources (`tail`, `http`, `forward`, syslog, etc.) route their events into the `@INGEST` label.
- 🧪 **@INGEST**, Your enrichment filters (`kubernetes_metadata`, `record_transformer`, parsers, …) run here exactly once before the event is handed off to Log10x.
- 📤 **out\_forward** → Log10x, Fluentd forwards the enriched event to the Log10x sidecar over TCP `:24224` (or a Unix socket on Linux/macOS).
- ⚡ **10x Engine**, The Receiver app applies rate/policy-based filtering and optionally compacts events for volume reduction.
- 📥 **in\_forward → @OUTPUT**, Processed events come back to Fluentd on `:24225` and are routed directly to the `@OUTPUT` label, which holds your destination `<match>` blocks. Filters defined under `@INGEST` are **not** re-applied, so each event is enriched exactly once.
- 📤 **Destinations**, The original Fluentd tag survives the round trip, so destinations that route on `$TAG` (Splunk index, S3 path, Kafka topic, …) behave the same as if Log10x weren't in the path.

### What an event looks like on the way back

The record structure of the original Fluentd event is preserved end-to-end, every field comes back to your `@OUTPUT` label with the same name and same position. What changes depends on the Receiver app mode:

|Mode|Difference vs the event Fluentd sent in|
|---|---|
|Receive (default)|None. Same record.|
|Receive + `symbolMessageHashField <name>`|Adds one new field with the symbol-pattern hash (a stable identifier for the message pattern, usable as a dedup key, metric dimension, or correlation ID).|
|`receiverOptimize true`|The value of the message field (`log` by default, or whatever `fluentdInputMessageField` is set to) is replaced with a compact encoded form. A separate `tenx-template` event is emitted with the template needed to decode it. All other fields stay verbatim.|
|`receiverOptimize true` + `symbolMessageHashField <name>`|Both of the above.|

`symbolMessageHashField` is unset by default, which is what makes the first row true: the receive path hands the record back exactly as it arrived. The pattern hash is still computed and still rides the event inside the engine as `tenx_hash` for metrics and aggregation, it just does not reach the wire. Naming a field opts in, either as a launch argument (`tenx @run/input/forwarder/fluentd @apps/receiver symbolMessageHashField my_custom_hash`) or as an environment variable of the same name.

The original Fluentd tag is carried by the Forward protocol itself and surfaces on the event as its `source` inside Log10x, used for rate-based grouping and emitted back to Fluentd as the wire tag on the return path. Internally, Log10x's Fluentd input module reads the message text from the field named by `fluentdInputMessageField` (default `log`); when the Receiver app is configured with `k8sExtractorName: fluentK8s`, the `kubernetes.*` sub-object is also materialized as enrichment fields for use by message-pattern and rate filtering.

??? tenx-keyfiles "Key Files"

    | File | Purpose |
    |------|---------|
    | [`stream.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/fluentd/stream.yaml) | Fluentd Forward input + output stream definitions |
    | [`conf/tenx-sidecar.conf`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/fluentd/conf/tenx-sidecar.conf) | Reference Fluentd config showing `@INGEST` / `@OUTPUT` label routing |

## Quickstart

**1. Run Log10x:**

```bash
tenx @run/input/forwarder/fluentd @apps/receiver
```

**2. Wire up your Fluentd config**, include the sidecar recipe and route your sources to `@INGEST`:

```xml title="fluentd.conf"
@include "#{ENV['TENX_MODULES']}/pipelines/run/modules/input/forwarder/fluentd/conf/tenx-sidecar.conf"

<source>
  @type tail
  path /var/log/app.log
  tag app.logs
  @label @INGEST          # routes the source into the sidecar
  <parse>
    @type json
  </parse>
</source>
```

**3. Point `@OUTPUT` at your real destinations** (the recipe defaults to `stdout` for testing):

```xml
<label @OUTPUT>
  <match **>
    @type your_output_plugin
    # ... destination config
  </match>
</label>
```

For Splunk integration see the [10x for Splunk](https://doc.log10x.com/apps/receiver/compact/splunk/) documentation. For Kubernetes deployment, add the `log10x/edge-10x` sidecar on top of the official Fluentd chart via a kustomize post-renderer overlay, see the [Helm chart overlay](https://doc.log10x.com/apps/receiver/deploy/#fluentd).

## :material-wrench-outline: Config Files

To configure the Fluentd module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [fluentd/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/fluentd/config.yaml "fluentd/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/fluentd/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/forwarder/fluentd/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/forwarder/fluentd/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/forwarder/fluentd/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/forwarder/fluentd/config.yaml">$TENX_CONFIG/run/input/forwarder/fluentd/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/forwarder/fluentd/config.yaml">./pipelines/run/input/forwarder/fluentd/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICB9CiAgICB9LAogICAgInRlbngiIDogewogICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgfSwKICAgICJmbHVlbnRkIiA6IHsKICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICJpbnB1dCIgOiB7CiAgICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAgICAgInBvcnQiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJUQ1AgcG9ydCB0byBsaXN0ZW4gb24gZm9yIGV2ZW50cyBmcm9tIEZsdWVudGQncyBvdXRfZm9yd2FyZCBwbHVnaW5cblxuVENQIHBvcnQgd2hlcmUgTG9nMTB4IGxpc3RlbnMgZm9yIGV2ZW50cyBzZW50IGJ5IEZsdWVudGQncyBgb3V0X2ZvcndhcmRgIHBsdWdpbi4gTWF0Y2ggdGhpcyBhZ2FpbnN0IHRoZSBgcG9ydGAgaW4geW91ciBGbHVlbnRkIGA8c2VydmVyPmAgYmxvY2suIChEZWZhdWx0OiAyNDIyNCkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICIyNDIyNCIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgInBhdGgiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVW5peCBkb21haW4gc29ja2V0IHBhdGggdG8gbGlzdGVuIG9uIChMaW51eC9tYWNPUylcblxuV2hlbiBzZXQsIExvZzEweCBsaXN0ZW5zIG9uIGEgVW5peCBkb21haW4gc29ja2V0IGluc3RlYWQgb2YgVENQLCB1c2VmdWwgb24gTGludXgvbWFjT1MgdG8gYXZvaWQgVENQIG92ZXJoZWFkLiBDb25maWd1cmUgRmx1ZW50ZCdzIGBvdXRfZm9yd2FyZGAgd2l0aCBgPHRyYW5zcG9ydCB1bml4PmAgKyBhIG1hdGNoaW5nIGBwYXRoYC4gSWdub3JlZCBvbiBXaW5kb3dzLiIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgIm1lc3NhZ2VGaWVsZCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJOYW1lIG9mIHRoZSBKU09OIGZpZWxkIGNhcnJ5aW5nIHRoZSBvcmlnaW5hbCBsb2cgbGluZVxuXG5OYW1lIG9mIHRoZSBmaWVsZCBpbiBlYWNoIEZsdWVudGQgcmVjb3JkIHRoYXQgY29udGFpbnMgdGhlIGFjdHVhbCBsb2cgbWVzc2FnZSB0ZXh0LiBUaGUgZGVmYXVsdCAoYGxvZ2ApIG1hdGNoZXMgRmx1ZW50ZCdzIGBpbl90YWlsYCBwbHVnaW4gY29udmVudGlvbiBmb3IgY29udGFpbmVyIGFuZCBmaWxlIGxvZ3MuIFNldCB0byBlLmcuIGBtZXNzYWdlYCBpZiB5b3VyIHNvdXJjZXMgZW1pdCB0aGUgbG9nIGxpbmUgdW5kZXIgYSBkaWZmZXJlbnQga2V5LiAoRGVmYXVsdDogbG9nKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogImxvZyIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgIm91dHB1dCIgOiB7CiAgICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAgICAgImhvc3QiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIGhvc3Qgb2YgdGhlIEZsdWVudGQgaW5fZm9yd2FyZCBzb3VyY2UgcmVjZWl2aW5nIHByb2Nlc3NlZCBldmVudHNcblxuSG9zdG5hbWUgb3IgSVAgd2hlcmUgdGhlIEZsdWVudGQgYGluX2ZvcndhcmRgIHNvdXJjZSBpcyBsaXN0ZW5pbmcgZm9yIHByb2Nlc3NlZCBldmVudHMgZnJvbSBMb2cxMHguIFBhaXJzIHdpdGggYGZsdWVudGRPdXRwdXRQb3J0YC4gKERlZmF1bHQ6IDEyNy4wLjAuMSkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICIxMjcuMC4wLjEiCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJwb3J0IiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIHBvcnQgb2YgdGhlIEZsdWVudGQgaW5fZm9yd2FyZCBzb3VyY2UgcmVjZWl2aW5nIHByb2Nlc3NlZCBldmVudHNcblxuVENQIHBvcnQgd2hlcmUgdGhlIEZsdWVudGQgYGluX2ZvcndhcmRgIHNvdXJjZSBpcyBsaXN0ZW5pbmcgZm9yIHByb2Nlc3NlZCBldmVudHMgZnJvbSBMb2cxMHguIE1VU1QgZGlmZmVyIGZyb20gdGhlIHBvcnQgTG9nMTB4J3Mgb3duIEZvcndhcmQgaW5wdXQgbGlzdGVucyBvbiAoZGVmYXVsdCBgMjQyMjRgKSBvciB0aGUgdHdvIHdvdWxkIGNvbGxpZGUgb24gdGhlIHNhbWUgc29ja2V0LiAoRGVmYXVsdDogMjQyMjUpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAiMjQyMjUiCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJwYXRoIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlVuaXggZG9tYWluIHNvY2tldCBwYXRoIG9mIHRoZSBGbHVlbnRkIGluX2ZvcndhcmQgc291cmNlIChMaW51eC9tYWNPUylcblxuT3B0aW9uYWwgVW5peCBkb21haW4gc29ja2V0IHBhdGggZm9yIHRoZSBGbHVlbnRkIGBpbl9mb3J3YXJkYCBzb3VyY2UuIFdoZW4gc2V0LCB0YWtlcyBwcmVjZWRlbmNlIG92ZXIgYGZsdWVudGRPdXRwdXRIb3N0YCAvIGBmbHVlbnRkT3V0cHV0UG9ydGAuIExpbnV4L21hY09TIG9ubHksIGlnbm9yZWQgb24gV2luZG93cy4iCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJlbmNvZGVUeXBlIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk91dHB1dCBmb3JtYXQgZm9yIHRoZSBGb3J3YXJkIHJlY29yZC4gUG9zc2libGUgdmFsdWVzOiBbanNvbiwgZGVsaW1pdGVkXVxuXG5Ib3cgdGhlIHJlbmRlcmVkIGV2ZW50IGZpZWxkKHMpIGFyZSBlbmNvZGVkIG9uIHRoZSBvdXRnb2luZyBGb3J3YXJkIHJlY29yZC4gUG9zc2libGUgdmFsdWVzOiAtICoqZGVsaW1pdGVkKio6IGVhY2ggdG9wLWxldmVsIGZpZWxkIG9mIHRoZSByZW5kZXJlZCByZWNvcmQgYmVjb21lcyAgIGl0cyBvd24gRm9yd2FyZCByZWNvcmQgZmllbGQsIHByZXNlcnZlcyB0aGUgb3JpZ2luYWwgcmVjb3JkJ3MgICBzdHJ1Y3R1cmUgb24gdGhlIHdpcmUuIC0gKipqc29uKio6IHRoZSB3aG9sZSByZW5kZXJlZCByZWNvcmQgaXMgd3JhcHBlZCBhcyBvbmUgc3RyaW5naWZpZWQgICBmaWVsZC4gRGVmYXVsdHMgdG8gYGRlbGltaXRlZGAsIHdoaWNoIGlzIGFsbW9zdCBhbHdheXMgd2hhdCB5b3Ugd2FudC4gKERlZmF1bHQ6IGRlbGltaXRlZCkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICJkZWxpbWl0ZWQiCiAgICAgICAgICAgIH0KICAgICAgICAgIH0KICAgICAgICB9CiAgICAgIH0KICAgIH0KICB9LAogICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiB0cnVlCn0=</template>

```yaml
# 🔟❎ 'run' Fluentd receiver configuration
#
# Every endpoint setting below reads an environment variable first and falls
# back to the shipped default, so a deployment can move a port, a host or a
# socket path without editing this file. The variable name is the launch
# option name in upper snake case with a TENX_ prefix, for example the
# `fluentdInputPort` option reads TENX_FLUENTD_INPUT_PORT.
#
# To learn more see https://doc.log10x.com/run/input/forwarder/fluentd/

tenx: run

# =============================== Dependencies ================================

include:
  - run/input/forwarder/config.yaml
  - run/modules/input/forwarder/fluentd

# =============================== Fluentd Options =============================

fluentd:

  # ----------------------------- Input Options -----------------------------

  input:

    # 'port' specifies the TCP port to listen on for events from Fluentd's
    #  out_forward plugin.
    #  Env var: TENX_FLUENTD_INPUT_PORT
    port: $=TenXEnv.get("TENX_FLUENTD_INPUT_PORT", 24224)

    # 'path' switches the input to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'port'. Empty means TCP.
    #  Env var: TENX_FLUENTD_INPUT_PATH
    path: $=TenXEnv.get("TENX_FLUENTD_INPUT_PATH", "")

    # 'messageField' is the name of the JSON field in each Fluentd record
    #  carrying the log line text.
    messageField: log

  # ----------------------------- Output Options ----------------------------

  output:

    # 'host' specifies the TCP host of Fluentd's in_forward source receiving
    #  processed events from Log10x.
    #  Env var: TENX_FLUENTD_OUTPUT_HOST
    host: $=TenXEnv.get("TENX_FLUENTD_OUTPUT_HOST", "127.0.0.1")

    # 'port' specifies the TCP port of Fluentd's in_forward source. MUST differ
    #  from input.port or the two would collide on the same listener.
    #  Env var: TENX_FLUENTD_OUTPUT_PORT
    port: $=TenXEnv.get("TENX_FLUENTD_OUTPUT_PORT", 24225)

    # 'path' switches the output to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'host'/'port'. Empty means TCP.
    #  Env var: TENX_FLUENTD_OUTPUT_PATH
    path: $=TenXEnv.get("TENX_FLUENTD_OUTPUT_PATH", "")

    # 'encodeType' is the on-wire format for the Forward record.
    #  - 'delimited': each top-level field of the rendered record becomes its
    #    own Forward record field, preserves the original record's structure.
    #  - 'json': the whole record is wrapped as one stringified field.
    encodeType: delimited
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the Fluentd:

|Name|Description|Category|
|---|---|---|
|[fluentdInputPort](#fluentdinputport "TCP port to listen on for events from Fluentd's out_forward plugin")|TCP port to listen on for events from Fluentd's out\_forward plugin|Input|
|[fluentdInputPath](#fluentdinputpath "Unix domain socket path to listen on (Linux/macOS)")|Unix domain socket path to listen on (Linux/macOS)|Input|
|[fluentdInputMessageField](#fluentdinputmessagefield "name of the JSON field carrying the original log line")|Name of the JSON field carrying the original log line|Input|
|[fluentdOutputHost](#fluentdoutputhost "TCP host of the Fluentd in_forward source receiving processed events")|TCP host of the Fluentd in\_forward source receiving processed events|Output|
|[fluentdOutputPort](#fluentdoutputport "TCP port of the Fluentd in_forward source receiving processed events")|TCP port of the Fluentd in\_forward source receiving processed events|Output|
|[fluentdOutputPath](#fluentdoutputpath "Unix domain socket path of the Fluentd in_forward source (Linux/macOS)")|Unix domain socket path of the Fluentd in\_forward source (Linux/macOS)|Output|
|[fluentdOutputEncodeType](#fluentdoutputencodetype "output format for the Forward record. Possible values: [json, delimited]")|Output format for the Forward record. Possible values: \[json, delimited\]|Output|

### Input

#### :material-menu-right-outline:**`fluentdInputPort`**

TCP port to listen on for events from Fluentd's out\_forward plugin.

|Type|Default|Category|
|---|---|---|
|String|24224|Input|

TCP port where Log10x listens for events sent by Fluentd's `out_forward`
plugin. Match this against the `port` in your Fluentd `<server>` block.


#### :material-menu-right-outline:**`fluentdInputPath`**

Unix domain socket path to listen on (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Input|

When set, Log10x listens on a Unix domain socket instead of TCP, useful
on Linux/macOS to avoid TCP overhead. Configure Fluentd's `out_forward`
with `<transport unix>` + a matching `path`. Ignored on Windows.


#### :material-menu-right-outline:**`fluentdInputMessageField`**

Name of the JSON field carrying the original log line.

|Type|Default|Category|
|---|---|---|
|String|log|Input|

Name of the field in each Fluentd record that contains the actual log
message text. The default (`log`) matches Fluentd's `in_tail` plugin
convention for container and file logs. Set to e.g. `message` if your
sources emit the log line under a different key.


### Output

#### :material-menu-right-outline:**`fluentdOutputHost`**

TCP host of the Fluentd in\_forward source receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|127.0.0.1|Output|

Hostname or IP where the Fluentd `in_forward` source is listening for
processed events from Log10x. Pairs with `fluentdOutputPort`.


#### :material-menu-right-outline:**`fluentdOutputPort`**

TCP port of the Fluentd in\_forward source receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|24225|Output|

TCP port where the Fluentd `in_forward` source is listening for
processed events from Log10x. MUST differ from the port Log10x's own
Forward input listens on (default `24224`) or the two would collide
on the same socket.


#### :material-menu-right-outline:**`fluentdOutputPath`**

Unix domain socket path of the Fluentd in\_forward source (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Output|

Optional Unix domain socket path for the Fluentd `in_forward` source.
When set, takes precedence over `fluentdOutputHost` / `fluentdOutputPort`.
Linux/macOS only, ignored on Windows.


#### :material-menu-right-outline:**`fluentdOutputEncodeType`**

Output format for the Forward record. Possible values: \[json, delimited\].

|Type|Default|Category|
|---|---|---|
|String|delimited|Output|

How the rendered event field(s) are encoded on the outgoing Forward
record. Possible values:

- **delimited**: each top-level field of the rendered record becomes
  its own Forward record field, preserves the original record's
  structure on the wire.
- **json**: the whole rendered record is wrapped as one stringified
  field.
  Defaults to `delimited`, which is almost always what you want.


<br/>:material-github: This module is defined in [fluentd/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/fluentd/module.yaml "fluentd/module.yaml"){target="\_blank"}.

