---
title: "Logstash"
description: "receive and optimize events collected by Logstash via newline-delimited\
  \ JSON"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/logstash/module.yaml"
icon: "simple/logstash"

---
Runs 10x Engine as a [sidecar](https://doc.log10x.com/engine/launcher/sidecar) to Logstash for reporting, receiving, and optimizing events before they ship to their destination (Elasticsearch, OpenSearch, Splunk, S3, Kafka, …). Logstash and Log10x run as peer processes and exchange events as newline-delimited JSON over TCP, Logstash's built-in `tcp` input and output plugins with `codec => json_lines` on both legs. Works against any stock Logstash build (OSS or Elastic distribution) and the official `elastic/logstash` Helm chart with a values overlay.

## Architecture

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>📂 Sources</div><div style='font-size: 10px;'>file, beats, http</div>"] --> F["<div style='font-size: 14px;'>🧪 ingest pipeline</div><div style='font-size: 10px;'>enrichment filters</div>"]
    F --> B["<div style='font-size: 14px;'>📤 tcp output</div><div style='font-size: 10px;'>json_lines :5044</div>"]
    B --> E["<div style='font-size: 14px;'>⚡ 10x Engine</div><div style='font-size: 10px;'>Report/Receive/Optimize</div>"]
    E --> C["<div style='font-size: 14px;'>📥 tcp input</div><div style='font-size: 10px;'>json_lines :5045</div>"]
    C --> D["<div style='font-size: 14px;'>📤 Destinations</div><div style='font-size: 10px;'>ES, Splunk, S3, Kafka</div>"]

    classDef input fill:#2563eb,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef filter fill:#ea580c,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef engine fill:#7c3aed,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#16a34a,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A input
    class B filter
    class C filter
    class D output
    class E engine
    class F filter
```

</div>

### Data Flow

- 📂 **Sources**, Your existing Logstash inputs (`file`, `beats`, `tcp`, `http`, …) feed into the `ingest` pipeline.
- 🧪 **ingest pipeline**, Your enrichment filters (`grok`, `mutate`, `kv`, `geoip`, `date`, …) run here exactly once before the event is handed off to Log10x. The pipeline also stamps a `tag` field that survives the round trip and surfaces as the event's source inside Log10x.
- 📤 **tcp output** → Log10x, Logstash's `tcp` output plugin (`codec => json_lines`) ships the enriched event to the Log10x sidecar on TCP `:5044` (or a Unix socket on Linux/macOS via the `unix` output plugin).
- ⚡ **10x Engine**, The Receiver app applies rate/policy-based filtering and optionally compacts events for volume reduction.
- 📥 **tcp input → destinations pipeline**, Processed events come back to Logstash on `:5045` and are picked up by a separate `destinations` pipeline whose `output` block holds your real destinations. Filters defined under `ingest` are **not** re-applied, Logstash's [multi-pipeline routing](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html){target="\_blank"} keeps each pipeline's filter chain isolated.
- 📤 **Destinations**, The original `tag` field survives the round trip, so destinations that route on it (Splunk index, S3 prefix, Kafka topic, …) behave the same as if Log10x weren't in the path.

### What an event looks like on the way back

The record structure of the original Logstash event is preserved end-to-end, every field comes back to your `destinations` pipeline with the same name and same position. What changes depends on the Receiver app mode:

|Mode|Difference vs the event Logstash sent in|
|---|---|
|Receive (default)|None. Same record.|
|Receive + `symbolMessageHashField <name>`|Adds one new field with the symbol-pattern hash (a stable identifier for the message pattern, usable as a dedup key, metric dimension, or correlation ID).|
|`receiverOptimize true`|The value of the message field (`message` by default, or whatever `logstashInputMessageField` is set to) is replaced with a compact encoded form. A separate event with `tag` set to `tenx-template` is emitted with the template needed to decode it. All other fields stay verbatim.|
|`receiverOptimize true` + `symbolMessageHashField <name>`|Both of the above.|

`symbolMessageHashField` is unset by default, which is what makes the first row true: the receive path hands the record back exactly as it arrived. The pattern hash is still computed and still rides the event inside the engine as `tenx_hash` for metrics and aggregation, it just does not reach the wire. Naming a field opts in, either as a launch argument (`tenx @run/input/forwarder/logstash @apps/receiver symbolMessageHashField my_custom_hash`) or as an environment variable of the same name.

The `tag` field that the ingest pipeline stamps becomes the event's `source` inside Log10x, used for rate-based grouping and preserved on each event as it returns to Logstash. The message text is read from the `message` field by default (override with `logstashInputMessageField`). When the Receiver app is configured with `k8sExtractorName: fluentK8s`, the `kubernetes.*` sub-object is also lifted into pod/container metadata fields used by message-pattern and rate filtering.

??? tenx-keyfiles "Key Files"

    | File | Purpose |
    |------|---------|
    | [`stream.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/logstash/stream.yaml) | Logstash JSON socket input + output stream definitions |
    | [`conf/pipelines.yml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/logstash/conf/pipelines.yml) | Two-pipeline driver that wires the `ingest` and `destinations` legs together |
    | [`conf/tenx-ingest.conf`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/logstash/conf/tenx-ingest.conf) | Sources, enrichment filters, and the `tcp` handoff to Log10x on `:5044` |
    | [`conf/tenx-destinations.conf`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/logstash/conf/tenx-destinations.conf) | `tcp` input on `:5045` for processed events, plus the `output` block holding your real destinations |

## Quickstart

**1. Run Log10x:**

```bash
tenx @run/input/forwarder/logstash @apps/receiver
```

**2. Wire up your Logstash config**, the recipe ships a `pipelines.yml` that runs the two legs side by side, an ingest leg that ends in `tcp { codec => json_lines }` and a destinations leg that starts with `tcp { codec => json_lines }`:

```yaml title="pipelines.yml"
- pipeline.id: ingest
  path.config: "${TENX_MODULES}/pipelines/run/modules/input/forwarder/logstash/conf/tenx-ingest.conf"

- pipeline.id: destinations
  path.config: "${TENX_MODULES}/pipelines/run/modules/input/forwarder/logstash/conf/tenx-destinations.conf"
```

**3. Point the `ingest` pipeline at your own sources** (the recipe defaults to a `file` input over `/var/log/containers/*.log`). Keep the `mutate` that stamps `tag`, Log10x reads it as the event's source, and keep the `tcp` output on `:5044`:

```ruby title="tenx-ingest.conf"
input {
  # ... your real sources ...
}
filter {
  mutate {
    add_field => { "tag" => "logstash" }
  }
}
output {
  tcp {
    host  => "127.0.0.1"
    port  => 5044
    codec => json_lines
  }
}
```

**4. Point the `destinations` pipeline at your real outputs** (the recipe defaults to `stdout` for testing):

```ruby title="tenx-destinations.conf"
input {
  tcp {
    host  => "0.0.0.0"
    port  => 5045
    codec => json_lines
  }
}
output {
  # ... your real destinations ...
}
```

For Kubernetes deployment via the official `elastic/logstash` Helm chart see the [Helm sidecar overlay](https://doc.log10x.com/apps/receiver/deploy/#logstash).

## :material-wrench-outline: Config Files

To configure the Logstash module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [logstash/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/logstash/config.yaml "logstash/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/logstash/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/forwarder/logstash/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/forwarder/logstash/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/forwarder/logstash/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/forwarder/logstash/config.yaml">$TENX_CONFIG/run/input/forwarder/logstash/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/forwarder/logstash/config.yaml">./pipelines/run/input/forwarder/logstash/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICB9CiAgICB9LAogICAgInRlbngiIDogewogICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgfSwKICAgICJsb2dzdGFzaCIgOiB7CiAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAiaW5wdXQiIDogewogICAgICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgICAgICJwb3J0IiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIHBvcnQgdG8gbGlzdGVuIG9uIGZvciBldmVudHMgZnJvbSBMb2dzdGFzaCdzIHRjcCBvdXRwdXRcblxuVENQIHBvcnQgd2hlcmUgTG9nMTB4IGxpc3RlbnMgZm9yIGV2ZW50cyBzZW50IGJ5IExvZ3N0YXNoJ3MgYHRjcGAgb3V0cHV0IHdpdGggYGNvZGVjID0+IGpzb25fbGluZXNgLiBNYXRjaCB0aGlzIGFnYWluc3QgdGhlIGBwb3J0YCBpbiB5b3VyIExvZ3N0YXNoIGBvdXRwdXQgeyB0Y3AgeyAuLi4gfSB9YCBibG9jay4gKERlZmF1bHQ6IDUwNDQpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAiNTA0NCIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgInBhdGgiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVW5peCBkb21haW4gc29ja2V0IHBhdGggdG8gbGlzdGVuIG9uIChMaW51eC9tYWNPUylcblxuV2hlbiBzZXQsIExvZzEweCBsaXN0ZW5zIG9uIGEgVW5peCBkb21haW4gc29ja2V0IGluc3RlYWQgb2YgVENQLCB1c2VmdWwgb24gTGludXgvbWFjT1MgdG8gYXZvaWQgVENQIG92ZXJoZWFkLiBDb25maWd1cmUgTG9nc3Rhc2gncyBgdW5peGAgb3V0cHV0IHBsdWdpbiB3aXRoIGBjb2RlYyA9PiBqc29uX2xpbmVzYCBhbmQgYSBtYXRjaGluZyBgcGF0aGAuIElnbm9yZWQgb24gV2luZG93cy4iCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJtZXNzYWdlRmllbGQiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiTmFtZSBvZiB0aGUgSlNPTiBmaWVsZCBjYXJyeWluZyB0aGUgb3JpZ2luYWwgbG9nIGxpbmVcblxuTmFtZSBvZiB0aGUgZmllbGQgaW4gZWFjaCBMb2dzdGFzaCBldmVudCB0aGF0IGNvbnRhaW5zIHRoZSBhY3R1YWwgbG9nIG1lc3NhZ2UgdGV4dC4gVGhlIGRlZmF1bHQgKGBtZXNzYWdlYCkgbWF0Y2hlcyBMb2dzdGFzaCdzIGNvbnZlbnRpb24gZm9yIHRoZSBgZmlsZWAsIGBiZWF0c2AsIGB0Y3BgLCBhbmQgYGh0dHBgIGlucHV0cy4gU2V0IHRvIGUuZy4gYGxvZ2AgaWYgeW91ciBzb3VyY2VzIGVtaXQgdGhlIGxvZyBsaW5lIHVuZGVyIGEgZGlmZmVyZW50IGtleS4gKERlZmF1bHQ6IG1lc3NhZ2UpIiwKICAgICAgICAgICAgICAiZGVmYXVsdCIgOiAibWVzc2FnZSIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0sCiAgICAgICAgIm91dHB1dCIgOiB7CiAgICAgICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgICAgICJhZGRpdGlvbmFsUHJvcGVydGllcyIgOiBmYWxzZSwKICAgICAgICAgICJwcm9wZXJ0aWVzIiA6IHsKICAgICAgICAgICAgImhvc3QiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIGhvc3Qgb2YgdGhlIExvZ3N0YXNoIHRjcCBpbnB1dCByZWNlaXZpbmcgcHJvY2Vzc2VkIGV2ZW50c1xuXG5Ib3N0bmFtZSBvciBJUCB3aGVyZSB0aGUgTG9nc3Rhc2ggYHRjcGAgaW5wdXQgaXMgbGlzdGVuaW5nIGZvciBwcm9jZXNzZWQgZXZlbnRzIGZyb20gTG9nMTB4LiBQYWlycyB3aXRoIGBsb2dzdGFzaE91dHB1dFBvcnRgLiAoRGVmYXVsdDogMTI3LjAuMC4xKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogIjEyNy4wLjAuMSIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgInBvcnQiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bWJlciIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJUQ1AgcG9ydCBvZiB0aGUgTG9nc3Rhc2ggdGNwIGlucHV0IHJlY2VpdmluZyBwcm9jZXNzZWQgZXZlbnRzXG5cblRDUCBwb3J0IHdoZXJlIHRoZSBMb2dzdGFzaCBgdGNwYCBpbnB1dCBpcyBsaXN0ZW5pbmcgZm9yIHByb2Nlc3NlZCBldmVudHMgZnJvbSBMb2cxMHguIE1VU1QgZGlmZmVyIGZyb20gdGhlIHBvcnQgTG9nMTB4J3Mgb3duIGlucHV0IGxpc3RlbnMgb24gKGRlZmF1bHQgYDUwNDRgKSBvciB0aGUgdHdvIHdvdWxkIGNvbGxpZGUgb24gdGhlIHNhbWUgc29ja2V0LiAoRGVmYXVsdDogNTA0NSkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICI1MDQ1IgogICAgICAgICAgICB9LAogICAgICAgICAgICAiZW5jb2RlVHlwZSIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJPdXRwdXQgZm9ybWF0IHdoZW4gb3V0cHV0RmllbGRzIGFyZSBzZXQuIFBvc3NpYmxlIHZhbHVlczogW2pzb24sIGRlbGltaXRlZF1cblxuU3BlY2lmaWVzIGhvdyB0aGUgY29tYmluZWQgb3V0cHV0IChtYWluIGV2ZW50IGZpZWxkIHBsdXMgb3V0cHV0RmllbGRzKSBpcyBlbmNvZGVkIHdoZW4gd3JpdGluZyBiYWNrIHRvIExvZ3N0YXNoLiBQb3NzaWJsZSB2YWx1ZXM6IC0gKipqc29uKio6IGZvcm1hdHMgYWxsIGZpZWxkcyBhcyBhIEpTT04gb2JqZWN0IC0gKipkZWxpbWl0ZWQqKjogZm9ybWF0cyBmaWVsZCB2YWx1ZXMgc2VwYXJhdGVkIGJ5IHRoZSBvdXRwdXQgZGVsaW1pdGVyIE9ubHkgdGFrZXMgZWZmZWN0IHdoZW4gbG9nc3Rhc2hPdXRwdXRGaWVsZHMgaXMgc2V0LiAoRGVmYXVsdDogZGVsaW1pdGVkKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogImRlbGltaXRlZCIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0KICAgICAgfQogICAgfQogIH0sCiAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IHRydWUKfQ==</template>

```yaml
# 🔟❎ 'run' Logstash receiver configuration
#
# Every endpoint setting below reads an environment variable first and falls
# back to the shipped default, so a deployment can move a port, a host or a
# socket path without editing this file. The variable name is the launch
# option name in upper snake case with a TENX_ prefix, for example the
# `logstashInputPort` option reads TENX_LOGSTASH_INPUT_PORT.
#
# To learn more see https://doc.log10x.com/run/input/forwarder/logstash/

tenx: run

# =============================== Dependencies ================================

include:
  - run/input/forwarder/config.yaml
  - run/modules/input/forwarder/logstash

# ============================== Logstash Options =============================

logstash:

  # ----------------------------- Input Options -----------------------------

  input:

    # 'port' specifies the TCP port to listen on for events from Logstash's
    #  `tcp` output with `codec => json_lines`.
    #  Env var: TENX_LOGSTASH_INPUT_PORT
    port: $=TenXEnv.get("TENX_LOGSTASH_INPUT_PORT", 5044)

    # 'path' switches the input to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'port'. Empty means TCP.
    #  Env var: TENX_LOGSTASH_INPUT_PATH
    path: $=TenXEnv.get("TENX_LOGSTASH_INPUT_PATH", "")

    # 'messageField' is the name of the JSON field in each Logstash event
    #  carrying the log line text.
    messageField: message

  # ----------------------------- Output Options ----------------------------

  output:

    # 'host' specifies the TCP host of Logstash's `tcp` input receiving
    #  processed events from Log10x.
    #  Env var: TENX_LOGSTASH_OUTPUT_HOST
    host: $=TenXEnv.get("TENX_LOGSTASH_OUTPUT_HOST", "127.0.0.1")

    # 'port' specifies the TCP port of Logstash's `tcp` input. MUST differ
    #  from input.port or the two would collide on the same listener.
    #  Env var: TENX_LOGSTASH_OUTPUT_PORT
    port: $=TenXEnv.get("TENX_LOGSTASH_OUTPUT_PORT", 5045)

    # 'encodeType' is the on-wire format for the socket record.
    #  - 'delimited': each top-level field of the rendered record becomes its
    #    own emitted field, preserves the original record's structure.
    #  - 'json': the whole record is wrapped as one stringified field.
    encodeType: delimited
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the Logstash:

|Name|Description|Category|
|---|---|---|
|[logstashInputPort](#logstashinputport "TCP port to listen on for events from Logstash's tcp output")|TCP port to listen on for events from Logstash's tcp output|Input|
|[logstashInputPath](#logstashinputpath "Unix domain socket path to listen on (Linux/macOS)")|Unix domain socket path to listen on (Linux/macOS)|Input|
|[logstashInputMessageField](#logstashinputmessagefield "name of the JSON field carrying the original log line")|Name of the JSON field carrying the original log line|Input|
|[logstashOutputHost](#logstashoutputhost "TCP host of the Logstash tcp input receiving processed events")|TCP host of the Logstash tcp input receiving processed events|Output|
|[logstashOutputPort](#logstashoutputport "TCP port of the Logstash tcp input receiving processed events")|TCP port of the Logstash tcp input receiving processed events|Output|
|[logstashOutputEncodeType](#logstashoutputencodetype "output format when outputFields are set. Possible values: [json, delimited]")|Output format when outputFields are set. Possible values: \[json, delimited\]|Output|

### Input

#### :material-menu-right-outline:**`logstashInputPort`**

TCP port to listen on for events from Logstash's tcp output.

|Type|Default|Category|
|---|---|---|
|String|5044|Input|

TCP port where Log10x listens for events sent by Logstash's `tcp` output
with `codec => json_lines`. Match this against the `port` in your
Logstash `output { tcp { ... } }` block.


#### :material-menu-right-outline:**`logstashInputPath`**

Unix domain socket path to listen on (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Input|

When set, Log10x listens on a Unix domain socket instead of TCP, useful
on Linux/macOS to avoid TCP overhead. Configure Logstash's `unix` output
plugin with `codec => json_lines` and a matching `path`. Ignored on Windows.


#### :material-menu-right-outline:**`logstashInputMessageField`**

Name of the JSON field carrying the original log line.

|Type|Default|Category|
|---|---|---|
|String|message|Input|

Name of the field in each Logstash event that contains the actual log
message text. The default (`message`) matches Logstash's convention for
the `file`, `beats`, `tcp`, and `http` inputs. Set to e.g. `log` if your
sources emit the log line under a different key.


### Output

#### :material-menu-right-outline:**`logstashOutputHost`**

TCP host of the Logstash tcp input receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|127.0.0.1|Output|

Hostname or IP where the Logstash `tcp` input is listening for
processed events from Log10x. Pairs with `logstashOutputPort`.


#### :material-menu-right-outline:**`logstashOutputPort`**

TCP port of the Logstash tcp input receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|5045|Output|

TCP port where the Logstash `tcp` input is listening for processed
events from Log10x. MUST differ from the port Log10x's own input
listens on (default `5044`) or the two would collide on the same
socket.


#### :material-menu-right-outline:**`logstashOutputEncodeType`**

Output format when outputFields are set. Possible values: \[json, delimited\].

|Type|Default|Category|
|---|---|---|
|String|delimited|Output|

Specifies how the combined output (main event field plus outputFields)
is encoded when writing back to Logstash. Possible values:

- **json**: formats all fields as a JSON object
- **delimited**: formats field values separated by the output delimiter
  Only takes effect when logstashOutputFields is set.


<br/>:material-github: This module is defined in [logstash/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/logstash/module.yaml "logstash/module.yaml"){target="\_blank"}.

