---
title: "Vector"
description: "receive and optimize events collected by Vector via the socket sink\
  \ and fluent source"
source: "https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/vector/module.yaml"
icon: "simple/vector"

---
Runs 10x Engine as a [sidecar](https://doc.log10x.com/engine/launcher/sidecar) to [Vector](https://vector.dev "Receive and optimize events collected by Vector via the socket sink and fluent source"){target="\_blank"} for reporting, receiving, and optimizing events before they ship to their destination (Elasticsearch, Splunk, S3, Kafka, …). Vector and Log10x run as peer processes, Vector sends events to Log10x via its native `socket` sink (newline-delimited JSON over TCP or Unix socket) and receives processed events back via its native `fluent` source (Fluent Forward protocol). Works against any stock Vector build (Linux/macOS/Windows) and the official `vector/vector` Helm chart with a values overlay.

## Architecture

<div style="text-align: center;">

```mermaid
graph LR
    A["<div style='font-size: 14px;'>📂 Sources</div><div style='font-size: 10px;'>file, kubernetes_logs, journald</div>"] --> F["<div style='font-size: 14px;'>🧪 transforms</div><div style='font-size: 10px;'>enrichment</div>"]
    F --> B["<div style='font-size: 14px;'>📤 socket sink</div><div style='font-size: 10px;'>tcp/unix → :9000</div>"]
    B --> E["<div style='font-size: 14px;'>⚡ 10x Engine</div><div style='font-size: 10px;'>Receive/Optimize</div>"]
    E --> C["<div style='font-size: 14px;'>📥 fluent source</div><div style='font-size: 10px;'>:9001 (no transforms)</div>"]
    C --> D["<div style='font-size: 14px;'>📤 Destinations</div><div style='font-size: 10px;'>ES, Splunk, S3, Kafka</div>"]

    classDef input fill:#2563eb,stroke:#1d4ed8,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef filter fill:#ea580c,stroke:#c2410c,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef engine fill:#7c3aed,stroke:#6d28d9,color:#ffffff,stroke-width:2px,rx:8,ry:8
    classDef output fill:#16a34a,stroke:#15803d,color:#ffffff,stroke-width:2px,rx:8,ry:8

    class A input
    class B filter
    class C filter
    class D output
    class E engine
    class F filter
```

</div>

### Data Flow

- 📂 **Sources**, Your existing Vector sources (`file`, `kubernetes_logs`, `journald`, `socket`, …) feed events into the enrichment transforms.
- 🧪 **Transforms**, Your enrichment transforms (`remap`, `filter`, `route`, …) run here exactly once before the event is handed off to Log10x. The recipe places them between your sources and the `tenx_in` sink, so the bypass is structural, not configured.
- 📤 **socket sink** → Log10x, Vector forwards the enriched event to the Log10x sidecar over TCP `:9000` (or a Unix socket on Linux/macOS) as newline-delimited JSON.
- ⚡ **10x Engine**, The Receiver app applies rate/policy-based filtering and optionally compacts events for volume reduction.
- 📥 **fluent source**, Processed events come back to Vector on `:9001` over the Fluent Forward protocol. Only your destination sinks consume `tenx_out`; no transforms sit between them, so enrichment never re-fires.
- 📤 **Destinations**, Vector's destination sinks (`elasticsearch`, `splunk_hec`, `kafka`, `aws_s3`, …) consume `tenx_out` and ship to the real destinations.

### What an event looks like on the way back

The record structure of the original Vector event is preserved end-to-end, every field comes back to your destination sinks with the same name and same position. What changes depends on the Receiver app mode:

|Mode|Difference vs the event Vector sent in|
|---|---|
|Receive (default)|None. Same record.|
|Receive + `symbolMessageHashField <name>`|Adds one new field with the symbol-pattern hash (a stable identifier for the message pattern, usable as a dedup key, metric dimension, or correlation ID).|
|`receiverOptimize true`|The value of the message field (`message` by default, or whatever `vectorInputMessageField` is set to) is replaced with a compact encoded form. A separate `tenx-template` event is emitted with the template needed to decode it. All other fields stay verbatim.|
|`receiverOptimize true` + `symbolMessageHashField <name>`|Both of the above.|

`symbolMessageHashField` is unset by default, which is what makes the first row true: the receive path hands the record back exactly as it arrived. The pattern hash is still computed and still rides the event inside the engine as `tenx_hash` for metrics and aggregation, it just does not reach the wire. Naming a field opts in, either as a launch argument (`tenx @run/input/forwarder/vector @apps/receiver symbolMessageHashField my_custom_hash`) or as an environment variable of the same name.

The `tag` field stamped by Vector's ingest transform (typically from `.source_type`) is carried on the Forward wire as the Fluent tag, and surfaces as the event's `source` inside Log10x, used for rate-based grouping and emitted back to Vector on the return Forward record. Internally, Log10x's Vector input module reads the message text from the field named by `vectorInputMessageField` (default `message`); when the Receiver app is configured with `k8sExtractorName: fluentK8s`, the `kubernetes.*` sub-object is also materialized as enrichment fields for use by message-pattern and rate filtering.

??? tenx-keyfiles "Key Files"

    | File | Purpose |
    |------|---------|
    | [`stream.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/vector/stream.yaml) | Vector socket input + Fluent Forward output stream definitions |
    | [`conf/tenx-sidecar.yaml`](https://github.com/log-10x/modules/blob/main/pipelines/run/modules/input/forwarder/vector/conf/tenx-sidecar.yaml) | Reference Vector config showing the ingest sink + egress source with no return-path transforms |

## Quickstart

**1. Run Log10x:**

```bash
tenx @run/input/forwarder/vector @apps/receiver
```

**2. Wire up your Vector config**, start from the sidecar recipe and add your real sources + destinations:

```yaml title="vector.yaml"
sources:
  app_logs:
    type: file
    include: [/var/log/app.log]
    read_from: end

  # Receive processed events back from Log10x
  tenx_out:
    type: fluent
    mode: tcp
    address: 127.0.0.1:9001

transforms:
  # Enrichment runs here exactly once, the return path skips this block.
  ingest:
    type: remap
    inputs: [app_logs]
    source: |
      .cluster = get_env_var("CLUSTER_NAME") ?? "unset"
      .tag = .source_type

sinks:
  # Hand off to the Log10x sidecar
  tenx_in:
    type: socket
    inputs: [ingest]
    mode: tcp
    address: 127.0.0.1:9000
    encoding: { codec: json }
    framing: { method: newline_delimited }

  # Destinations consume tenx_out (not the raw sources or `ingest`) so
  # enrichment never re-fires on the return path.
  destinations:
    type: console
    inputs: [tenx_out]
    encoding: { codec: json }
```

For Splunk integration see the [10x for Splunk](https://doc.log10x.com/apps/receiver/compact/splunk/) documentation. For Kubernetes deployment via the official Vector Helm chart see the [Helm sidecar overlay](https://doc.log10x.com/apps/receiver/deploy/#vector).

## :material-wrench-outline: Config Files

To configure the Vector module, [:material-cog: Edit](https://doc.log10x.com/config/app/#module-config "Learn how to edit app and module configurations") these files.  

Below is the default configuration from: [vector/config.yaml](https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/vector/config.yaml "vector/config.yaml"){target="\_blank"}.  
  
<div class="edit-options">
    <a class="md-button tenx-edit-online-button" data-tooltip="Edit online on github.dev" href="https://github.dev/log-10x/config/blob/main/pipelines/run/input/forwarder/vector/config.yaml" target="_blank" rel="noopener noreferrer">
        <span class="twemoji" style="margin-right: 0.3rem;">
            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                <path d="M12 .297c-6.63 0-12 5.373-12 12 0 5.303 3.438 9.8 8.205 11.385.6.113.82-.258.82-.577 0-.285-.01-1.04-.015-2.04-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729 1.205.084 1.838 1.236 1.838 1.236 1.07 1.835 2.809 1.305 3.495.998.108-.776.417-1.305.76-1.605-2.665-.3-5.466-1.332-5.466-5.93 0-1.31.465-2.38 1.235-3.22-.135-.303-.54-1.523.105-3.176 0 0 1.005-.322 3.3 1.23.96-.267 1.98-.399 3-.405 1.02.006 2.04.138 3 .405 2.28-1.552 3.285-1.23 3.285-1.23.645 1.653.24 2.873.12 3.176.765.84 1.23 1.91 1.23 3.22 0 4.61-2.805 5.625-5.475 5.92.42.36.81 1.096.81 2.22 0 1.606-.015 2.896-.015 3.286 0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12"></path>
            </svg>
        </span> Edit Online
    </a>
    <button class="md-button tenx-config.yaml0-edit-button" data-tooltip="Edit configuration file" data-dialog-id="config-yaml0-dialog">
        <span style="margin-right: 0.3rem;">
            <span class="twemoji">
                <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24">
                    <path d="M20.71,7.04C21.1,6.65 21.1,6 20.71,5.63L18.37,3.29C18,2.9 17.35,2.9 16.96,3.29L15.12,5.12L18.87,8.87M3,17.25V21H6.75L17.81,9.93L14.06,6.18L3,17.25Z"></path>
                </svg>
            </span>
        </span>Edit Locally
    </button>
</div>

<dialog id="config-yaml0-dialog" class="md-dialog md-dialog--editor">
    <div class="editor-dialog-wrapper">
        <div class="editor-dialog-header">
            <span class="editor-dialog-title">Edit config.yaml Locally</span>
            <div class="editor-header-actions">
                <button class="editor-toolbar-btn yaml-editor-locations" data-tooltip="Save">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-reset" data-tooltip="Reset to default">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M12.5 8c-2.65 0-5.05 1-6.9 2.6L2 7v9h9l-3.62-3.62c1.39-1.16 3.16-1.88 5.12-1.88 3.54 0 6.55 2.31 7.6 5.5l2.37-.78C21.08 11.03 17.15 8 12.5 8z"></path></svg>
                </button>
                <button class="editor-toolbar-btn yaml-editor-copy" data-tooltip="Copy to clipboard">
                    <svg class="icon-copy" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path></svg>
                    <svg class="icon-check" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn yaml-editor-fullscreen" data-tooltip="Fullscreen">
                    <svg class="icon-maximize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M5,5H10V7H7V10H5V5M14,5H19V10H17V7H14V5M17,14H19V19H14V17H17V14M10,17V19H5V14H7V17H10Z"></path></svg>
                    <svg class="icon-minimize" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" style="display:none;"><path fill="currentColor" d="M5,16H8V19H10V14H5V16M14,14V19H16V16H19V14H14M16,5V8H19V10H14V5H16M10,5V10H5V8H8V5H10Z"></path></svg>
                </button>
                <span class="header-divider"></span>
                <button class="editor-toolbar-btn editor-dialog-close" onclick="closeDialog('config-yaml0-dialog')" data-tooltip="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path></svg>
                </button>
            </div>
        </div>
        <div class="editor-dialog-content">
            <div class="yaml-editor-container"></div>
        </div>
        <div class="yaml-editor-statusbar">
            <span class="yaml-editor-status"></span>
        </div>
    </div>
    <!-- Locations Popup -->
    <div class="locations-popup" style="display: none;">
        <div class="locations-popup-content">
            <div class="locations-popup-header">
                <span class="locations-header-label">Download and save to:</span>
                <button class="locations-popup-close" aria-label="Close">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="16" height="16">
                        <path fill="currentColor" d="M19,6.41L17.59,5L12,10.59L6.41,5L5,6.41L10.59,12L5,17.59L6.41,19L12,13.41L17.59,19L19,17.59L13.41,12L19,6.41Z"></path>
                    </svg>
                </button>
            </div>
            <ul class="locations-list">
                <li>
                    <span class="location-label">Linux / Docker / macOS
                        <span class="help-icon" data-tooltip="Default system location. The engine automatically reads configs from here at startup. Best for production deployments.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="default-path location-path" data-tooltip=""
                            data-copy-osx="/etc/log10x/config/run/input/forwarder/vector/config.yaml"
                            data-copy-nix="/etc/log10x/config/run/input/forwarder/vector/config.yaml"
                            data-copy-win="C:\log10x\configs/run/input/forwarder/vector/config.yaml"></code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Custom directory
                        <span class="help-icon" data-tooltip="Set TENX_CONFIG environment variable to point to a custom config directory. Useful when you want configs in a non-standard location.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="$TENX_CONFIG/run/input/forwarder/vector/config.yaml">$TENX_CONFIG/run/input/forwarder/vector/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
                <li>
                    <span class="location-label">Within cloned repo
                        <span class="help-icon" data-tooltip="First run: git clone github.com/log-10x/config. Then save the file to this path within the cloned folder. Use for version control.">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="12" height="12"><path fill="currentColor" d="M11 18h2v-2h-2v2m1-16A10 10 0 0 0 2 12a10 10 0 0 0 10 10 10 10 0 0 0 10-10A10 10 0 0 0 12 2m0 18c-4.41 0-8-3.59-8-8s3.59-8 8-8 8 3.59 8 8-3.59 8-8 8m0-14a4 4 0 0 0-4 4h2a2 2 0 0 1 2-2 2 2 0 0 1 2 2c0 2-3 1.75-3 5h2c0-2.25 3-2.5 3-5a4 4 0 0 0-4-4Z"/></svg>
                        </span>
                    </span>
                    <div class="location-path-row">
                        <code class="location-path" data-tooltip="./pipelines/run/input/forwarder/vector/config.yaml">./pipelines/run/input/forwarder/vector/config.yaml</code>
                        <button class="copy-btn" data-tooltip="Copy path">
                            <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                                <path fill="currentColor" d="M19 21H8V7h11m0-2H8a2 2 0 0 0-2 2v14a2 2 0 0 0 2 2h11a2 2 0 0 0 2-2V7a2 2 0 0 0-2-2m-3-4H4a2 2 0 0 0-2 2v14h2V3h12V1Z"></path>
                            </svg>
                        </button>
                    </div>
                </li>
            </ul>
            <div class="locations-popup-footer">
                <button class="locations-download-btn" title="Download config file">
                    <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" width="14" height="14">
                        <path fill="currentColor" d="M5 20h14v-2H5v2m14-9h-4V3H9v8H5l7 7 7-7Z"></path>
                    </svg>
                    <span>Download</span>
                </button>
            </div>
        </div>
    </div>
</dialog>

<template class="tenx-config-schema" data-encoding="base64">ewogICJ0eXBlIiA6ICJvYmplY3QiLAogICJwcm9wZXJ0aWVzIiA6IHsKICAgICJpbmNsdWRlIiA6IHsKICAgICAgInR5cGUiIDogImFycmF5IiwKICAgICAgIml0ZW1zIiA6IHsKICAgICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgICB9CiAgICB9LAogICAgInRlbngiIDogewogICAgICAidHlwZSIgOiAic3RyaW5nIgogICAgfSwKICAgICJ2ZWN0b3IiIDogewogICAgICAidHlwZSIgOiAib2JqZWN0IiwKICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgImlucHV0IiA6IHsKICAgICAgICAgICJ0eXBlIiA6ICJvYmplY3QiLAogICAgICAgICAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IGZhbHNlLAogICAgICAgICAgInByb3BlcnRpZXMiIDogewogICAgICAgICAgICAicG9ydCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVtYmVyIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRDUCBwb3J0IHRvIGxpc3RlbiBvbiBmb3IgZXZlbnRzIGZyb20gVmVjdG9yJ3Mgc29ja2V0IHNpbmtcblxuVENQIHBvcnQgd2hlcmUgTG9nMTB4IGxpc3RlbnMgZm9yIGV2ZW50cyBzZW50IGJ5IFZlY3RvcidzIGBzb2NrZXRgIHNpbmsgKGBtb2RlOiB0Y3BgLCBgZW5jb2RpbmcuY29kZWM6IGpzb25gLCBgZnJhbWluZy5tZXRob2Q6IG5ld2xpbmVfZGVsaW1pdGVkYCkuIE1hdGNoIHRoaXMgYWdhaW5zdCB0aGUgYGFkZHJlc3NgIGluIHlvdXIgVmVjdG9yIHNpbmsuIChEZWZhdWx0OiA5MDAwKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogIjkwMDAiCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJwYXRoIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlVuaXggZG9tYWluIHNvY2tldCBwYXRoIHRvIGxpc3RlbiBvbiAoTGludXgvbWFjT1MpXG5cbldoZW4gc2V0LCBMb2cxMHggbGlzdGVucyBvbiBhIFVuaXggZG9tYWluIHNvY2tldCBpbnN0ZWFkIG9mIFRDUCwgdXNlZnVsIG9uIExpbnV4L21hY09TIHRvIGF2b2lkIFRDUCBvdmVyaGVhZC4gQ29uZmlndXJlIFZlY3RvcidzIGBzb2NrZXRgIHNpbmsgd2l0aCBgbW9kZTogdW5peGAgYW5kIGEgbWF0Y2hpbmcgYHBhdGhgLiBJZ25vcmVkIG9uIFdpbmRvd3MuIgogICAgICAgICAgICB9LAogICAgICAgICAgICAibWVzc2FnZUZpZWxkIiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIk5hbWUgb2YgdGhlIEpTT04gZmllbGQgY2FycnlpbmcgdGhlIG9yaWdpbmFsIGxvZyBsaW5lXG5cbk5hbWUgb2YgdGhlIGZpZWxkIGluIGVhY2ggVmVjdG9yIHJlY29yZCB0aGF0IGNvbnRhaW5zIHRoZSBhY3R1YWwgbG9nIG1lc3NhZ2UgdGV4dC4gVGhlIGRlZmF1bHQgKGBtZXNzYWdlYCkgbWF0Y2hlcyBWZWN0b3IncyBjb252ZW50aW9uIGZvciB0aGUgYGZpbGVgLCBga3ViZXJuZXRlc19sb2dzYCwgYGpvdXJuYWxkYCwgYW5kIGBzb2NrZXRgIHNvdXJjZXMuIFNldCB0byBlLmcuIGBsb2dgIGlmIHlvdXIgc291cmNlcyBlbWl0IHRoZSBsb2cgbGluZSB1bmRlciBhIGRpZmZlcmVudCBrZXkuIChEZWZhdWx0OiBtZXNzYWdlKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogIm1lc3NhZ2UiCiAgICAgICAgICAgIH0KICAgICAgICAgIH0KICAgICAgICB9LAogICAgICAgICJvdXRwdXQiIDogewogICAgICAgICAgInR5cGUiIDogIm9iamVjdCIsCiAgICAgICAgICAiYWRkaXRpb25hbFByb3BlcnRpZXMiIDogZmFsc2UsCiAgICAgICAgICAicHJvcGVydGllcyIgOiB7CiAgICAgICAgICAgICJob3N0IiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudWxsIgogICAgICAgICAgICAgIF0sCiAgICAgICAgICAgICAgIm1hcmtkb3duRGVzY3JpcHRpb24iIDogIlRDUCBob3N0IG9mIHRoZSBWZWN0b3IgZmx1ZW50IHNvdXJjZSByZWNlaXZpbmcgcHJvY2Vzc2VkIGV2ZW50c1xuXG5Ib3N0bmFtZSBvciBJUCB3aGVyZSBWZWN0b3IncyBgZmx1ZW50YCBzb3VyY2UgaXMgbGlzdGVuaW5nIGZvciBwcm9jZXNzZWQgZXZlbnRzIGZyb20gTG9nMTB4LiBQYWlycyB3aXRoIGB2ZWN0b3JPdXRwdXRQb3J0YC4gKERlZmF1bHQ6IDEyNy4wLjAuMSkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICIxMjcuMC4wLjEiCiAgICAgICAgICAgIH0sCiAgICAgICAgICAgICJwb3J0IiA6IHsKICAgICAgICAgICAgICAidHlwZSIgOiBbCiAgICAgICAgICAgICAgICAic3RyaW5nIiwKICAgICAgICAgICAgICAgICJudW1iZXIiLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiVENQIHBvcnQgb2YgdGhlIFZlY3RvciBmbHVlbnQgc291cmNlIHJlY2VpdmluZyBwcm9jZXNzZWQgZXZlbnRzXG5cblRDUCBwb3J0IHdoZXJlIFZlY3RvcidzIGBmbHVlbnRgIHNvdXJjZSBpcyBsaXN0ZW5pbmcgZm9yIHByb2Nlc3NlZCBldmVudHMgZnJvbSBMb2cxMHguIE1VU1QgZGlmZmVyIGZyb20gdGhlIHBvcnQgTG9nMTB4J3Mgb3duIHNvY2tldCBpbnB1dCBsaXN0ZW5zIG9uIChkZWZhdWx0IGA5MDAwYCkgb3IgdGhlIHR3byB3b3VsZCBjb2xsaWRlIG9uIHRoZSBzYW1lIGxpc3RlbmVyLiAoRGVmYXVsdDogOTAwMSkiLAogICAgICAgICAgICAgICJkZWZhdWx0IiA6ICI5MDAxIgogICAgICAgICAgICB9LAogICAgICAgICAgICAicGF0aCIgOiB7CiAgICAgICAgICAgICAgInR5cGUiIDogWwogICAgICAgICAgICAgICAgInN0cmluZyIsCiAgICAgICAgICAgICAgICAibnVsbCIKICAgICAgICAgICAgICBdLAogICAgICAgICAgICAgICJtYXJrZG93bkRlc2NyaXB0aW9uIiA6ICJVbml4IGRvbWFpbiBzb2NrZXQgcGF0aCBvZiB0aGUgVmVjdG9yIGZsdWVudCBzb3VyY2UgKExpbnV4L21hY09TKVxuXG5PcHRpb25hbCBVbml4IGRvbWFpbiBzb2NrZXQgcGF0aCBmb3IgVmVjdG9yJ3MgYGZsdWVudGAgc291cmNlLiBXaGVuIHNldCwgdGFrZXMgcHJlY2VkZW5jZSBvdmVyIGB2ZWN0b3JPdXRwdXRIb3N0YCAvIGB2ZWN0b3JPdXRwdXRQb3J0YC4gTGludXgvbWFjT1Mgb25seSwgaWdub3JlZCBvbiBXaW5kb3dzLiIKICAgICAgICAgICAgfSwKICAgICAgICAgICAgImVuY29kZVR5cGUiIDogewogICAgICAgICAgICAgICJ0eXBlIiA6IFsKICAgICAgICAgICAgICAgICJzdHJpbmciLAogICAgICAgICAgICAgICAgIm51bGwiCiAgICAgICAgICAgICAgXSwKICAgICAgICAgICAgICAibWFya2Rvd25EZXNjcmlwdGlvbiIgOiAiT3V0cHV0IGZvcm1hdCB3aGVuIG91dHB1dEZpZWxkcyBhcmUgc2V0LiBQb3NzaWJsZSB2YWx1ZXM6IFtqc29uLCBkZWxpbWl0ZWRdXG5cblNwZWNpZmllcyBob3cgdGhlIGNvbWJpbmVkIG91dHB1dCAobWFpbiBldmVudCBmaWVsZCBwbHVzIG91dHB1dEZpZWxkcykgaXMgZW5jb2RlZCB3aGVuIHdyaXRpbmcgYmFjayB0byBWZWN0b3IuIFBvc3NpYmxlIHZhbHVlczogLSAqKmpzb24qKjogZm9ybWF0cyBhbGwgZmllbGRzIGFzIGEgSlNPTiBvYmplY3QgLSAqKmRlbGltaXRlZCoqOiBmb3JtYXRzIGZpZWxkIHZhbHVlcyBzZXBhcmF0ZWQgYnkgdGhlIG91dHB1dCBkZWxpbWl0ZXIgT25seSB0YWtlcyBlZmZlY3Qgd2hlbiB2ZWN0b3JPdXRwdXRGaWVsZHMgaXMgc2V0LiAoRGVmYXVsdDogZGVsaW1pdGVkKSIsCiAgICAgICAgICAgICAgImRlZmF1bHQiIDogImRlbGltaXRlZCIKICAgICAgICAgICAgfQogICAgICAgICAgfQogICAgICAgIH0KICAgICAgfQogICAgfQogIH0sCiAgImFkZGl0aW9uYWxQcm9wZXJ0aWVzIiA6IHRydWUKfQ==</template>

```yaml
# 🔟❎ 'run' Vector receiver configuration
#
# Every endpoint setting below reads an environment variable first and falls
# back to the shipped default, so a deployment can move a port, a host or a
# socket path without editing this file. The variable name is the launch
# option name in upper snake case with a TENX_ prefix, for example the
# `vectorInputPort` option reads TENX_VECTOR_INPUT_PORT.
#
# To learn more see https://doc.log10x.com/run/input/forwarder/vector/

tenx: run

# =============================== Dependencies ================================

include:
  - run/input/forwarder/config.yaml
  - run/modules/input/forwarder/vector

# =============================== Vector Options ==============================

vector:

  # ----------------------------- Input Options -----------------------------

  input:

    # 'port' specifies the TCP port to listen on for events from Vector's
    #  `socket` sink (`mode: tcp`, `encoding.codec: json`,
    #  `framing.method: newline_delimited`).
    #  Env var: TENX_VECTOR_INPUT_PORT
    port: $=TenXEnv.get("TENX_VECTOR_INPUT_PORT", 9000)

    # 'path' switches the input to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'port'. Empty means TCP.
    #  Env var: TENX_VECTOR_INPUT_PATH
    path: $=TenXEnv.get("TENX_VECTOR_INPUT_PATH", "")

    # 'messageField' is the name of the JSON field in each Vector record
    #  carrying the log line text.
    messageField: message

  # ----------------------------- Output Options ----------------------------

  output:

    # 'host' specifies the TCP host of Vector's `fluent` source receiving
    #  processed events from Log10x.
    #  Env var: TENX_VECTOR_OUTPUT_HOST
    host: $=TenXEnv.get("TENX_VECTOR_OUTPUT_HOST", "127.0.0.1")

    # 'port' specifies the TCP port of Vector's `fluent` source. MUST differ
    #  from input.port or the two would collide on the same listener.
    #  Env var: TENX_VECTOR_OUTPUT_PORT
    port: $=TenXEnv.get("TENX_VECTOR_OUTPUT_PORT", 9001)

    # 'path' switches the output to a Unix domain socket instead of TCP.
    #  When set, takes precedence over 'host'/'port'. Empty means TCP.
    #  Env var: TENX_VECTOR_OUTPUT_PATH
    path: $=TenXEnv.get("TENX_VECTOR_OUTPUT_PATH", "")

    # 'encodeType' is the on-wire format for the Forward record.
    #  - 'delimited': each top-level field of the rendered record becomes its
    #    own Forward record field, preserves the original record's structure.
    #  - 'json': the whole record is wrapped as one stringified field.
    encodeType: delimited
```

## :material-menu: Options

Specify the options below to [configure](/config "configure") the Vector:

|Name|Description|Category|
|---|---|---|
|[vectorInputPort](#vectorinputport "TCP port to listen on for events from Vector's socket sink")|TCP port to listen on for events from Vector's socket sink|Input|
|[vectorInputPath](#vectorinputpath "Unix domain socket path to listen on (Linux/macOS)")|Unix domain socket path to listen on (Linux/macOS)|Input|
|[vectorInputMessageField](#vectorinputmessagefield "name of the JSON field carrying the original log line")|Name of the JSON field carrying the original log line|Input|
|[vectorOutputHost](#vectoroutputhost "TCP host of the Vector fluent source receiving processed events")|TCP host of the Vector fluent source receiving processed events|Output|
|[vectorOutputPort](#vectoroutputport "TCP port of the Vector fluent source receiving processed events")|TCP port of the Vector fluent source receiving processed events|Output|
|[vectorOutputPath](#vectoroutputpath "Unix domain socket path of the Vector fluent source (Linux/macOS)")|Unix domain socket path of the Vector fluent source (Linux/macOS)|Output|
|[vectorOutputEncodeType](#vectoroutputencodetype "output format when outputFields are set. Possible values: [json, delimited]")|Output format when outputFields are set. Possible values: \[json, delimited\]|Output|

### Input

#### :material-menu-right-outline:**`vectorInputPort`**

TCP port to listen on for events from Vector's socket sink.

|Type|Default|Category|
|---|---|---|
|String|9000|Input|

TCP port where Log10x listens for events sent by Vector's `socket`
sink (`mode: tcp`, `encoding.codec: json`, `framing.method: newline_delimited`).
Match this against the `address` in your Vector sink.


#### :material-menu-right-outline:**`vectorInputPath`**

Unix domain socket path to listen on (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Input|

When set, Log10x listens on a Unix domain socket instead of TCP, useful
on Linux/macOS to avoid TCP overhead. Configure Vector's `socket` sink
with `mode: unix` and a matching `path`. Ignored on Windows.


#### :material-menu-right-outline:**`vectorInputMessageField`**

Name of the JSON field carrying the original log line.

|Type|Default|Category|
|---|---|---|
|String|message|Input|

Name of the field in each Vector record that contains the actual log
message text. The default (`message`) matches Vector's convention for
the `file`, `kubernetes_logs`, `journald`, and `socket` sources. Set
to e.g. `log` if your sources emit the log line under a different key.


### Output

#### :material-menu-right-outline:**`vectorOutputHost`**

TCP host of the Vector fluent source receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|127.0.0.1|Output|

Hostname or IP where Vector's `fluent` source is listening for
processed events from Log10x. Pairs with `vectorOutputPort`.


#### :material-menu-right-outline:**`vectorOutputPort`**

TCP port of the Vector fluent source receiving processed events.

|Type|Default|Category|
|---|---|---|
|String|9001|Output|

TCP port where Vector's `fluent` source is listening for processed
events from Log10x. MUST differ from the port Log10x's own socket
input listens on (default `9000`) or the two would collide on the
same listener.


#### :material-menu-right-outline:**`vectorOutputPath`**

Unix domain socket path of the Vector fluent source (Linux/macOS).

|Type|Default|Category|
|---|---|---|
|String|""|Output|

Optional Unix domain socket path for Vector's `fluent` source.
When set, takes precedence over `vectorOutputHost` / `vectorOutputPort`.
Linux/macOS only, ignored on Windows.


#### :material-menu-right-outline:**`vectorOutputEncodeType`**

Output format when outputFields are set. Possible values: \[json, delimited\].

|Type|Default|Category|
|---|---|---|
|String|delimited|Output|

Specifies how the combined output (main event field plus outputFields)
is encoded when writing back to Vector. Possible values:

- **json**: formats all fields as a JSON object
- **delimited**: formats field values separated by the output delimiter
  Only takes effect when vectorOutputFields is set.


<br/>:material-github: This module is defined in [vector/module.yaml](https://github.com/log-10x/modules/tree/main/pipelines/run/modules/input/forwarder/vector/module.yaml "vector/module.yaml"){target="\_blank"}.

