openapi: 3.1.0
servers:
- url: /
info:
title: Cribl API Reference
description: >-
This API Reference lists available REST endpoints, along with their
supported operations for accessing, creating, updating, or deleting
resources.
Base URL contexts for reference:
- Leader context: /api/v1
- Worker Group or Edge Fleet context: /api/v1/m/{groupName}
- Host (Worker or Edge Node) context: /api/v1/w/{nodeId}
- Search context: /api/v1/m/default_search
version: 4.20.0-cee79842
contact:
name: Support
url: https://portal.support.cribl.io
externalDocs:
description: See our complementary product documentation
url: https://docs.cribl.io
x-speakeasy-retries:
strategy: backoff
statusCodes:
- "429"
components:
securitySchemes:
bearerAuth:
type: http
scheme: bearer
bearerFormat: JWT
clientOauth:
type: oauth2
flows:
clientCredentials:
tokenUrl: https://login.cribl.cloud/oauth/token
x-speakeasy-token-endpoint-additional-properties:
audience:
type: string
example: https://api.cribl.cloud
scopes: {}
schemas:
Error:
type: object
required:
- status
- message
properties:
status:
type: string
description: Always "error" for API error responses.
const: error
message:
type: string
description: Human-readable message describing the error.
details:
description: Optional structured details about the error (e.g. validation
failures).
DiffLineDelete:
type: object
description: Deleted line in a Git diff hunk.
properties:
type:
type: string
enum:
- delete
description: Line change type. Always delete for deleted lines.
oldNumber:
type: integer
description: Line number in the original file.
content:
type: string
description: Full content of the line, including the diff prefix character.
required:
- type
- oldNumber
- content
DiffLineInsert:
type: object
description: Inserted line in a Git diff hunk.
properties:
type:
type: string
enum:
- insert
description: Line change type. Always insert for inserted lines.
newNumber:
type: integer
description: Line number in the new file.
content:
type: string
description: Full content of the line, including the diff prefix character.
required:
- type
- newNumber
- content
DiffLineContext:
type: object
description: Unchanged context line in a Git diff hunk.
properties:
type:
type: string
enum:
- context
description: Line change type. Always context for unchanged lines.
newNumber:
type: integer
description: Line number in the new file.
oldNumber:
type: integer
description: Line number in the original file.
content:
type: string
description: Full content of the line, including the diff prefix character.
required:
- type
- newNumber
- oldNumber
- content
DiffLine:
description: Array of lines in a Git diff hunk.
type: array
items:
oneOf:
- $ref: "#/components/schemas/DiffLineDelete"
- $ref: "#/components/schemas/DiffLineInsert"
- $ref: "#/components/schemas/DiffLineContext"
discriminator:
propertyName: type
mapping:
delete: "#/components/schemas/DiffLineDelete"
insert: "#/components/schemas/DiffLineInsert"
context: "#/components/schemas/DiffLineContext"
EventBreakerExistingOrNewNewTimestampTypeAuto:
type: object
properties:
type:
enum:
- auto
description: Method to use for timestamp extraction. Use auto for
automatic detection, format to specify a strptime
format, or current to use the current system time.
type: string
length:
type: number
title: Length
minimum: 2
description: Maximum number of characters to search for a timestamp value from
the beginning of the match.
required:
- length
EventBreakerExistingOrNewNewTimestampTypeFormat:
type: object
properties:
type:
enum:
- format
description: Method to use for timestamp extraction. Use auto for
automatic detection, format to specify a strptime
format, or current to use the current system time.
type: string
format:
type: string
title: Format
description: Strptime format string for parsing timestamps (for example,
%Y-%m-%d %H:%M:%S).
required:
- format
EventBreakerExistingOrNewNewTimestampTypeCurrent:
type: object
properties:
type:
enum:
- current
description: Method to use for timestamp extraction. Use auto for
automatic detection, format to specify a strptime
format, or current to use the current system time.
type: string
EventBreakerExistingOrNewNewRuleTypeRegex:
type: object
properties:
ruleType:
enum:
- regex
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
type: string
eventBreakerRegex:
type: string
title: Event Breaker
description: The regex used to break the stream into events at the beginning of
the match. Matched content will be consumed, unless you use a
lookahead regex such as (?=pattern) to keep it. Do NOT use capturing
groups in the pattern.
required:
- eventBreakerRegex
EventBreakerExistingOrNewNewRuleTypeJson:
type: object
properties:
ruleType:
enum:
- json
- timestamp
- aws_cloudtrail
- aws_vpcflow
- azure_flowlog
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
type: string
EventBreakerExistingOrNewNewRuleTypeJsonArray:
type: object
properties:
ruleType:
enum:
- json_array
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
type: string
jsonArrayField:
type: string
title: Array field
description: The path to an array in a JSON event with records to extract, such
as Records or level1.level2.events. Leave blank if result itself is
an array, such as [{...},{...}]
parentFieldsToCopy:
title: Parent fields to copy
description: Top-level fields to copy to the output events. Nested fields are
not supported. 'Array field' is always excluded. If 'Array field'
points to a nested array, the entire top-level object will be
excluded. Supports * wildcards. Enclose field names containing
special characters in single or double quotes.
type: array
items:
type: string
jsonExtractAll:
type: boolean
title: JSON extract fields
description: Automatically extract fields from JSON events. When disabled, only
_raw and _time are defined on extracted events.
fieldsToRemove:
title: Fields to remove
description: List of fields to remove from the output events. Supports *
wildcards. Enclose field names containing special characters in
single or double quotes.
type: array
items:
type: string
jsonTimeField:
type: string
title: Timestamp field
description: Optional path to timestamp field in extracted events, such as
eventTime or level1.level2.eventTime.
EventBreakerExistingOrNewNewRuleTypeHeader:
type: object
properties:
ruleType:
enum:
- header
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
type: string
delimiterRegex:
type: string
title: Field delimiter
description: Field delimiter regex
fieldsLineRegex:
type: string
title: Fields regex
description: Regex with one capturing group that captures all fields (and
delimiters) to be broken by field delimiter
headerLineRegex:
type: string
title: Header line
description: Regex matching a file header line
nullFieldVal:
type: string
title: Null value
description: Representation of a null value. Null fields are not added to events.
cleanFields:
type: boolean
title: Clean fields
description: Clean field names by replacing non [a-zA-Z0-9] characters with _
required:
- delimiterRegex
- fieldsLineRegex
- headerLineRegex
EventBreakerExistingOrNewNewRuleTypeCsv:
type: object
properties:
ruleType:
enum:
- csv
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
type: string
delimiter:
type: string
title: Delimiter
minLength: 1
description: Delimiter character to use to split values
quoteChar:
type: string
title: Quote char
minLength: 1
description: Character used to quote literal values
escapeChar:
type: string
title: Escape char
minLength: 1
description: Character used to escape the quote character in field values
timeField:
type: string
title: Timestamp field
description: Optional timestamp field name in extracted events
required:
- delimiter
- quoteChar
- escapeChar
EventBreakerExistingOrNewNew:
type: object
properties:
existingOrNew:
enum:
- new
description: Whether to use an existing Event Breaker Ruleset or create a new
one inline.
type: string
ruleType:
$ref: "#/components/schemas/EventBreakerTypeOptionsEventBreakerExistingOrNewNew"
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
maxEventBytes:
type: number
title: Event byte limit
description: The maximum number of bytes that an event can be before being
flushed to the Pipelines
minimum: 1
maximum: 134217728
timestampAnchorRegex:
type: string
title: Timestamp anchor
description: Regex to match before attempting timestamp extraction. Use $ (end
of string anchor) to not perform extraction.
timestamp:
$ref: "#/components/schemas/TimestampFormatTypeEventBreakerExistingOrNewNew"
description: Configuration for extracting and parsing timestamps from events.
timestampTimezone:
type: string
title: Default timezone
description: Timezone to assign to timestamps without timezone info
timestampEarliest:
title: Earliest timestamp allowed
description: The earliest timestamp value allowed relative to now, such as
-42years. Parsed values prior to this date will be set to current
time.
type: string
timestampLatest:
title: Future timestamp allowed
description: The latest timestamp value allowed relative to now, such as
+42days. Parsed values after this date will be set to current time.
type: string
allOf:
- oneOf:
- $ref: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeRegex"
- $ref: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeJson"
- $ref: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeJsonArray"
- $ref: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeHeader"
- $ref: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeCsv"
discriminator:
propertyName: ruleType
mapping:
regex: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeRegex"
json: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeJson"
json_array: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeJsonArray"
header: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeHeader"
csv: "#/components/schemas/EventBreakerExistingOrNewNewRuleTypeCsv"
EventBreakerExistingOrNewExisting:
type: object
properties:
existingOrNew:
enum:
- existing
description: Whether to use an existing Event Breaker Ruleset or create a new
one inline.
type: string
existingRule:
type: string
title: Existing ruleset
description: ID of an existing event breaker ruleset to apply.
minLength: 1
NumerifyFormatFix:
type: object
properties:
format:
enum:
- fix
description: Numeric format to apply after type conversion.
type: string
digits:
type: number
title: Digits
description: Number of digits after the decimal point, between 0 and 20. If left
blank, defaults to 2.
minimum: 0
maximum: 20
NumerifyFormatNone:
type: object
properties:
format:
enum:
- none
- floor
- ceil
description: Numeric format to apply after type conversion.
type: string
RedisDeploymentTypeStandalone:
type: object
properties:
deploymentType:
enum:
- standalone
description: How the Redis server is configured. Defaults to Standalone
type: string
url:
title: Redis URL
description: "Redis URL to connect to. Format: redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-number[&password=bar[&option=value]]]. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
type: string
tlsOptions:
$ref: "#/components/schemas/TlsOptionsTypeRedisDeploymentTypeStandalone"
description: TLS settings for encrypting the connection to Redis.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
required:
- url
RedisDeploymentTypeCluster:
type: object
properties:
deploymentType:
enum:
- cluster
description: How the Redis server is configured. Defaults to Standalone
type: string
rootNodes:
title: Root nodes
description: Root nodes to which the cluster connection should be initiated
type: array
minItems: 1
items:
$ref: "#/components/schemas/RootNodeConfRedisDeploymentTypeCluster"
tls:
title: TLS
type: boolean
description: Use TLS for connections to this cluster
scaleReads:
$ref: "#/components/schemas/ScaleReadsOptionsRedisDeploymentTypeCluster"
description: Which nodes read commands should be sent to
tlsOptions:
$ref: "#/components/schemas/TlsOptionsTypeRedisDeploymentTypeCluster"
description: TLS settings for encrypting the connection to Redis.
RedisDeploymentTypeSentinel:
type: object
properties:
deploymentType:
enum:
- sentinel
description: How the Redis server is configured. Defaults to Standalone
type: string
masterName:
title: Master group name
description: Name of the Redis Sentinel master group to connect to.
type: string
rootNodes:
title: Sentinels
description: List of sentinels to be used
type: array
minItems: 1
items:
type: object
required:
- host
- port
properties:
host:
type: string
title: Hostname
description: "Hostname of sentinel node. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`."
port:
type: number
title: Port
description: Port of sentinel node
tls:
title: TLS
type: boolean
description: Use TLS for connections to this cluster
tlsOptions:
$ref: "#/components/schemas/TlsOptionsTypeRedisDeploymentTypeCluster"
description: TLS settings for encrypting the connection to Redis.
required:
- masterName
RedisAuthTypeNone:
type: object
properties:
authType:
enum:
- none
description: Authentication method to use when connecting to Redis.
type: string
RedisAuthTypeManual:
type: object
properties:
authType:
enum:
- manual
description: Authentication method to use when connecting to Redis.
type: string
username:
title: Username
description: Username for Redis authentication.
type: string
password:
title: Password
description: Password for Redis authentication.
type: string
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
required:
- password
RedisAuthTypeCredentialsSecret:
type: object
properties:
authType:
enum:
- credentialsSecret
description: Authentication method to use when connecting to Redis.
type: string
credentialsSecret:
type: string
title: User secret
description: Secret that references Redis username and password
required:
- credentialsSecret
RedisAuthTypeTextSecret:
type: object
properties:
authType:
enum:
- textSecret
description: Authentication method to use when connecting to Redis.
type: string
textSecret:
type: string
title: Admin secret
description: Secret that references Redis admin password
required:
- textSecret
SerdeTypeAuto:
type: object
properties:
type:
enum:
- auto
description: Parser or formatter type to use.
type: string
SerdeTypeKvp:
type: object
properties:
type:
enum:
- kvp
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
keep:
title: Fields to keep
description: List of fields to keep. Supports wildcards (*). Takes precedence
over 'Fields to remove'.
type: array
items:
type: string
remove:
title: Fields to remove
description: List of fields to remove. Supports wildcards (*). Cannot remove
fields that match 'Fields to keep'.
type: array
items:
type: string
fieldFilterExpr:
title: Fields filter expression
description: Expression evaluated against {index, name, value} context. Return
truthy to keep a field, or falsy to remove it.
type: string
cleanFields:
type: boolean
title: Clean fields
description: Clean field names by replacing non [a-zA-Z0-9] characters with _
allowedKeyChars:
type: array
items:
type: string
title: Allowed key characters
description: A list of characters that may be present in a key name, even though
they are normally separator or control characters
allowedValueChars:
type: array
items:
type: string
title: Allowed value characters
description: A list of characters that may be present in a value, even though
they are normally separator or control characters
SerdeTypeDelim:
type: object
properties:
type:
enum:
- delim
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
fields:
title: List of fields
description: The fields to be extracted, listed in order. Will auto-generate if
empty.
type: array
items:
type: string
keep:
title: Fields to keep
description: List of fields to keep. Supports wildcards (*). Takes precedence
over 'Fields to remove'.
type: array
items:
type: string
remove:
title: Fields to remove
description: List of fields to remove. Supports wildcards (*). Cannot remove
fields that match 'Fields to keep'.
type: array
items:
type: string
fieldFilterExpr:
title: Fields filter expression
description: Expression evaluated against {index, name, value} context. Return
truthy to keep a field, or falsy to remove it.
type: string
delimChar:
type: string
title: Delimiter
minLength: 1
description: Delimiter character to use to split values
quoteChar:
type: string
title: Quote char
minLength: 1
description: Character used to quote literal values
escapeChar:
type: string
title: Escape char
minLength: 1
description: Escape character used to escape delimiter or quote character
nullValue:
type: string
title: Null value
description: Field value representing the null value. Null fields will be omitted.
SerdeTypeCsv:
type: object
properties:
type:
enum:
- csv
- elff
- clf
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
fields:
title: List of fields
description: The fields to be extracted, listed in order. Will auto-generate if
empty.
type: array
items:
type: string
keep:
title: Fields to keep
description: List of fields to keep. Supports wildcards (*). Takes precedence
over 'Fields to remove'.
type: array
items:
type: string
remove:
title: Fields to remove
description: List of fields to remove. Supports wildcards (*). Cannot remove
fields that match 'Fields to keep'.
type: array
items:
type: string
fieldFilterExpr:
title: Fields filter expression
description: Expression evaluated against {index, name, value} context. Return
truthy to keep a field, or falsy to remove it.
type: string
SerdeTypeJson:
type: object
properties:
type:
enum:
- json
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
keep:
title: Fields to keep
description: List of fields to keep. Supports wildcards (*). Takes precedence
over 'Fields to remove'.
type: array
items:
type: string
remove:
title: Fields to remove
description: List of fields to remove. Supports wildcards (*). Cannot remove
fields that match 'Fields to keep'.
type: array
items:
type: string
fieldFilterExpr:
title: Fields filter expression
description: Expression evaluated against {index, name, value} context. Return
truthy to keep a field, or falsy to remove it.
type: string
SerdeTypeRegex:
type: object
properties:
type:
enum:
- regex
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
regex:
type: string
title: Regex
description: Regex literal with named capturing groups, such as (?bar), or
_NAME_ and _VALUE_ capturing groups, such as(?<_NAME_0>[^
=]+)=(?<_VALUE_0>[^,]+)
regexList:
type: array
title: Additional regex
description: Additional regex patterns to apply for field extraction.
items:
$ref: "#/components/schemas/RegexListConfSerdeTypeRegex"
iterations:
type: number
title: Max exec
description: The maximum number of times to apply regex to source field when the
global flag is set, or when using _NAME_ and _VALUE_ capturing
groups
minimum: 1
fieldNameExpression:
title: Field name format expression
description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.."
type: string
overwrite:
type: boolean
title: Overwrite existing fields
description: Overwrite existing event fields with extracted values. If disabled,
existing fields will be converted to an array.
required:
- regex
SerdeTypeGrok:
type: object
properties:
type:
enum:
- grok
description: Parser or formatter type to use.
type: string
srcField:
title: Source field
description: Field containing text to be parsed
type: string
dstField:
title: Destination field
description: Name of the field to add fields to. Extract mode only.
type: string
pattern:
type: string
title: Pattern
description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}"
patternList:
type: array
title: Additional Grok patterns
description: Additional Grok patterns to apply to the source field.
items:
$ref: "#/components/schemas/PatternListConfSerdeTypeGrok"
required:
- pattern
SerializeTypeKvp:
type: object
properties:
type:
enum:
- kvp
description: Data output format.
type: string
cleanFields:
type: boolean
title: Clean fields
description: Clean field names by replacing non-[a-zA-Z0-9] characters with _
fields:
title: Fields to serialize
description: "Required for CSV, ELFF, and CLF. All other formats support wildcard field lists. Examples: host, myField, !source *"
type: array
items:
type: string
pairDelimiter:
type: string
title: Pair delimiter
minLength: 1
description: Delimiter used to separate key=value pairs. Defaults to a single
space character. Should not have common characters with key-value
delimiter.
keyValueDelimiter:
type: string
title: Key-Value delimiter
minLength: 1
description: Delimiter used to separate key and value in pair. Defaults to a
'='. Should not have common characters with pair delimiter.
SerializeTypeDelim:
type: object
properties:
type:
enum:
- delim
description: Data output format.
type: string
delimChar:
type: string
title: Delimiter
minLength: 1
description: Delimiter character to use to split values. If left blank, will
default to ','.
quoteChar:
type: string
title: Quote char
minLength: 1
description: Character used to quote literal values. If left blank, will default
to '"'.
escapeChar:
type: string
title: Escape char
minLength: 1
description: Escape character used to escape delimiter or quote character. If
left blank, will default to the Quote char.
nullValue:
type: string
title: Null value
description: Field value representing the null value. Null fields will be omitted.
SerializeTypeCsv:
type: object
properties:
type:
enum:
- csv
- elff
- clf
- json
description: Data output format.
type: string
SnmpTrapSerializeV3UserAuthProtocolNone:
type: object
properties:
authProtocol:
enum:
- none
description: Authentication protocol for the SNMPv3 user.
type: string
SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNone:
type: object
properties:
privProtocol:
enum:
- none
description: Privacy protocol used to encrypt SNMPv3 messages.
type: string
SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone:
type: object
properties:
privProtocol:
description: Privacy protocol used to encrypt SNMPv3 messages.
type: string
enum:
- des
- aes
- aes256b
- aes256r
x-speakeasy-unknown-values: allow
privKey:
type: string
title: V3 privacy key
description: Privacy key for SNMPv3 encryption. Required when a privacy protocol
is selected.
required:
- privKey
SnmpTrapSerializeV3UserAuthProtocolNotNone:
type: object
properties:
authProtocol:
description: Authentication protocol for the SNMPv3 user.
type: string
enum:
- md5
- sha
- sha224
- sha256
- sha384
- sha512
x-speakeasy-unknown-values: allow
authKey:
type: string
title: V3 authentication key
description: Authentication key for SNMPv3 user. Required when an authentication
protocol is selected.
privProtocol:
type: string
enum:
- none
- des
- aes
- aes256b
- aes256r
x-speakeasy-enum-descriptions:
- None
- DES
- AES128
- AES256b (Blumenthal)
- AES256r (Reeder)
title: Privacy protocol
description: Privacy protocol used to encrypt SNMPv3 messages.
x-speakeasy-unknown-values: allow
name:
title: Username
type: string
minLength: 1
description: Username for the SNMPv3 user.
required:
- authKey
- name
allOf:
- oneOf:
- $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNone"
- $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone"
discriminator:
propertyName: privProtocol
mapping:
none: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNone"
des: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone"
aes: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone"
aes256b: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone"
aes256r: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone"
FunctionConfSchemaAggregateMetrics:
type: object
properties:
passthrough:
type: boolean
title: Passthrough mode
description: Pass through the original events along with the aggregation events
preserveGroupBys:
type: boolean
title: Preserve group by fields
description: Preserve the structure of the original aggregation event's groupby
fields
sufficientStatsOnly:
type: boolean
title: Sufficient stats mode
description: Output only statistics that are sufficient for the supplied
aggregations
prefix:
type: string
title: Output prefix
description: A prefix that is prepended to all of the fields output by this
Aggregations Function
timeWindow:
pattern: \d+[sm]$
type: string
title: Time window
description: The time span of the tumbling window for aggregating events. Must
be a valid time string (such as 10s).
aggregations:
type: array
title: Aggregates
description: Combination of Aggregation function and output metric type
minItems: 1
items:
type: object
required:
- agg
- metricType
additionalProperties: false
properties:
metricType:
title: Metric type
description: The output metric type
type: string
enum:
- automatic
- counter
- distribution
- gauge
- histogram
- summary
- timer
x-speakeasy-unknown-values: allow
agg:
title: Aggregation
type: string
description: "Aggregate function to perform on events. Example: sum(bytes).where(action=='REJECT').as(TotalBytes)"
groupbys:
type: array
title: Group by dimensions
description: "Optional: One or more dimensions to group aggregates by. Supports wildcard expressions. Wrap dimension names in quotes if using literal identifiers, such as 'service.name'. Warning: Using wildcard '*' causes all dimensions in the event to be included, which can result in high cardinality and increased memory usage. Exclude dimensions that can result in high cardinality before using wildcards. Example: !_time, !_numericValue, *"
items:
type: string
flushEventLimit:
type: number
title: Aggregation event limit
description: The maximum number of events to include in any given aggregation
event
minimum: 1
flushMemLimit:
type: string
title: Aggregation memory limit
description: "The memory usage limit to impose upon aggregations. Defaults to 80% of the process memory; value configured above default limit is ignored. Accepts numerals with units like KB and MB (example: 128MB)."
pattern: ^\d+\s*(?:\w{2})?$
cumulative:
type: boolean
title: Cumulative aggregations
description: Enable to retain aggregations for cumulative aggregations when
flushing out an aggregation table event. When disabled (the
default), aggregations are reset to 0 on flush.
shouldTreatDotsAsLiterals:
type: boolean
title: Treat dots as literals
description: Treat dots in dimension names as literals. This is useful for
top-level dimensions that contain dots, such as 'service.name'.
add:
title: Evaluate fields
description: Set of key-value pairs to evaluate and add/set
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the field to set or add to the event.
value:
type: string
title: Value expression
description: JavaScript expression to compute the value (can be constant)
flushOnInputClose:
type: boolean
title: Flush on stream close
description: Flush aggregations when an input stream is closed. If disabled,
Time Window Settings control flush behavior.
lagTolerance:
type: string
title: Lag tolerance
description: The tumbling window tolerance to late events. Must be a valid time
string (such as 10s).
pattern: \d+[sm]$
idleTimeLimit:
type: string
title: Idle bucket time limit
description: How long to wait before flushing a bucket that has not received
events. Must be a valid time string (such as 10s).
pattern: \d+[sm]$
FunctionAggregateMetrics:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- aggregate_metrics
description: Identifier of the Function. Always aggregate_metrics
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaAggregation:
type: object
properties:
passthrough:
type: boolean
title: Passthrough mode
description: Pass through the original events along with the aggregation events
preserveGroupBys:
type: boolean
title: Preserve group by fields
description: Preserve the structure of the original aggregation event's groupby
fields
sufficientStatsOnly:
type: boolean
title: Sufficient stats mode
description: Output only statistics that are sufficient for the supplied
aggregations
metricsMode:
type: boolean
title: Metrics mode
description: Enable to output the aggregates as metrics. When disabled,
aggregates are output as events.
prefix:
type: string
title: Output prefix
description: A prefix that is prepended to all of the fields output by this
Aggregations Function
timeWindow:
pattern: \d+[sm]$
type: string
title: Time window
description: The time span of the tumbling window for aggregating events. Must
be a valid time string (such as 10s).
aggregations:
type: array
title: Aggregates
description: "Aggregate function to perform on events. Example: sum(bytes).where(action=='REJECT').as(TotalBytes)"
minItems: 1
items:
type: string
groupbys:
type: array
title: Group by fields
description: "Optional: One or more fields to group aggregates by. Supports wildcard expressions. Warning: Using wildcard '*' causes all fields in the event to be included, which can result in high cardinality and increased memory usage. Exclude fields that can result in high cardinality before using wildcards. Example: !_time, !_numericValue, *"
items:
type: string
flushEventLimit:
type: number
title: Aggregation event limit
description: The maximum number of events to include in any given aggregation
event
minimum: 1
flushMemLimit:
type: string
title: Aggregation memory limit
description: "The memory usage limit to impose upon aggregations. Defaults to 80% of the process memory; value configured above default limit is ignored. Accepts numerals with units like KB and MB (example: 128MB)."
pattern: ^\d+\s*(?:\w{2})?$
cumulative:
type: boolean
title: Cumulative aggregations
description: Enable to retain aggregations for cumulative aggregations when
flushing out an aggregation table event. When disabled (the
default), aggregations are reset to 0 on flush.
searchAggMode:
type: string
title: Search-specific aggregation mode
description: Allows Cribl Search-specific aggregation configuration
add:
title: Evaluate fields
description: Set of key-value pairs to evaluate and add/set
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the field to set or add to the event.
value:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
shouldTreatDotsAsLiterals:
type: boolean
title: Treat dots as literals
description: Treat dots in dimension names as literals. This is useful for
top-level dimensions that contain dots, such as 'service.name'.
flushOnInputClose:
type: boolean
title: Flush on stream close
description: Flush aggregations when an input stream is closed. If disabled,
Time Window Settings control flush behavior.
printUndefineds:
type: boolean
title: Print undefined as null
description: When enabled (e.g. for Cribl Search), convert undefined expression
results to null so requested-but-missing fields appear in JSON
output. When disabled (default), undefined is preserved.
lagTolerance:
type: string
title: Lag tolerance
description: The tumbling window tolerance to late events. Must be a valid time
string (such as 10s).
pattern: \d+[sm]$
idleTimeLimit:
type: string
title: Idle bucket time limit
description: How long to wait before flushing a bucket that has not received
events. Must be a valid time string (such as 10s).
pattern: \d+[sm]$
FunctionAggregation:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- aggregation
description: Identifier of the Function. Always aggregation
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaAutoTimestamp:
type: object
additionalProperties: false
properties:
srcField:
title: Source field
description: Field to search for a timestamp
type: string
dstField:
title: Destination field
description: Field to place timestamp in
type: string
defaultTimezone:
type: string
title: Default timezone
description: Timezone to assign to timestamps without timezone info
timeExpression:
title: Time expression
description: Expression to use to format time. Current time, as a JavaScript
Date object, is in global `time`. You can access other fields'
values via __e..
type: string
offset:
title: Start scan offset
description: The offset into the string from which to look for a timestamp
type: number
minimum: 0
maxLen:
title: Max timestamp scan depth
description: Maximum string length at which to look for a timestamp
type: number
minimum: 1
defaultTime:
title: Default time
description: How to set the time field if no timestamp is found
type: string
enum:
- now
- last
- none
x-speakeasy-enum-descriptions:
- Current Time
- Last Event's Time
- None
x-speakeasy-unknown-values: allow
latestDateAllowed:
title: Future timestamp allowed
description: The latest timestamp value allowed relative to now, such as
+42days. Parsed values after this date will be set to the Default
time.
type: string
spacer:
type: string
description: UI layout spacer; no effect on event processing.
earliestDateAllowed:
title: Earliest timestamp allowed
description: The earliest timestamp value allowed relative to now, such as
-42years. Parsed values prior to this date will be set to the
Default time.
type: string
timestamps:
title: Additional timestamps
description: Add regex/strptime pairs to extract additional timestamp formats
type: array
items:
type: object
required:
- regex
- strptime
properties:
regex:
type: string
title: Regex
description: Regex with first capturing group matching the timestamp
strptime:
type: string
title: Strptime format
description: Select or enter strptime format for the captured timestamp
FunctionAutoTimestamp:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- auto_timestamp
description: Identifier of the Function. Always auto_timestamp
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaCef:
type: object
additionalProperties: false
properties:
outputField:
title: Output field
description: The field to which the CEF formatted event will be output
type: string
header:
title: Header Fields
description: Set of header key/value pairs
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the CEF header field. Header names are predefined by the
CEF standard.
readOnly: true
value:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
extension:
title: Extension Fields
description: Set of extension key-value pairs
type: array
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Name
description: Name of the CEF extension field. Must contain only alphanumeric
characters.
pattern: ^[a-zA-Z0-9]+$
value:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
FunctionCef:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- cef
description: Identifier of the Function. Always cef
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaChain:
type: object
properties:
processor:
title: Processor
description: The data processor (Pack/Pipeline) to send events through
type: string
FunctionChain:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- chain
description: Identifier of the Function. Always chain
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaClone:
type: object
properties:
clones:
type: array
title: Clones
description: Create clones with the following fields set
minItems: 1
items:
type: object
title: Fields
description: Key-value pairs to set or overwrite in the clone
additionalProperties:
type: string
FunctionClone:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- clone
description: Identifier of the Function. Always clone
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaCode:
type: object
additionalProperties: false
properties:
code:
type: string
title: Code
description: "Caution: This Function will be evaluated in an unprotected context. This means that you will be able to execute almost any JavaScript code."
maxNumOfIterations:
type: number
title: Iteration limit
description: The maximum number of allowed iterations within this Function.
Defaults to 5,000.
minimum: 1
maximum: 100000
activeLogSampleRate:
type: number
title: Error log sample rate
description: Rate at which this Function logs errors. For example, a value of 1
logs every error, a value of 1000 (the default) logs every
thousandth error, and so on.
minimum: 1
maximum: 5000
useUniqueLogChannel:
type: boolean
title: Use unique log channel
description: Logs from this Function will be sent to a unique channel in the
form `func:code:${pipelineName}:${functionIndex}`. Disable to use
the generic `func:code` log channel instead.
FunctionCode:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- code
description: Identifier of the Function. Always code
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaComment:
type: object
properties:
comment:
type: string
title: Comment
description: Optional, short description of this Function's purpose in the
Pipeline
maxLength: 1000
FunctionComment:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- comment
description: Identifier of the Function. Always comment
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDetectionRules:
type: object
title: Detection Rules
properties:
localOverrides:
title: Local Overrides
description: Instance-level tuning applied after the rule set is merged. Managed
by Cribl Security; not intended for direct editing.
type: object
properties:
disabled:
title: Disabled Rules
description: Rule IDs to silence entirely.
type: array
items:
type: string
fieldOverrides:
title: Field Overrides
description: Patch scalar fields of a rule without copying its full definition.
type: array
items:
type: object
required:
- id
properties:
id:
title: Rule ID
description: Unique identifier for the Detection Rule to override.
type: string
severityId:
title: Severity
description: Severity level to assign to the Detection Rule.
type: integer
enum:
- 1
- 2
- 3
- 4
- 5
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- SeverityIdOne
- SeverityIdTwo
- SeverityIdThree
- SeverityIdFour
- SeverityIdFive
confidenceId:
title: Confidence
description: Confidence level to assign to the Detection Rule.
type: integer
enum:
- 1
- 2
- 3
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- ConfidenceIdOne
- ConfidenceIdTwo
- ConfidenceIdThree
impactId:
title: Impact
description: Impact level to assign to the Detection Rule.
type: integer
enum:
- 1
- 2
- 3
- 4
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- ImpactIdOne
- ImpactIdTwo
- ImpactIdThree
- ImpactIdFour
isAlert:
title: Is Alert
description: If true, the Detection Rule creates an alert.
Otherwise, false.
type: boolean
message:
title: Message Override
description: Replacement alert message for the Detection Rule.
type: string
inlineRules:
title: Inline Rules
description: Full rule definitions authored here rather than delivered with the
corpus.
type: array
items:
type: object
required:
- id
- name
- condition
properties:
id:
type: string
title: Rule ID
description: Unique identifier for the Detection Rule.
name:
type: string
title: Rule Name
description: Display name for the Detection Rule.
condition:
type: string
title: Condition Expression
description: Expression that determines whether the Detection Rule matches an
event.
severityId:
type: integer
title: Severity
description: Severity level for the Detection Rule.
confidenceId:
type: integer
title: Confidence
description: Confidence level for the Detection Rule.
isAlert:
type: boolean
title: Is Alert
description: If true, the Detection Rule creates an alert.
Otherwise, false.
message:
type: string
title: Message
description: Alert message emitted when the Detection Rule matches.
tags:
type: array
title: Tags
description: Tags for filtering and grouping detection rules.
items:
type: string
FunctionDetectionRules:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- detection_rules
description: Identifier of the Function. Always detection_rules
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDistinct:
type: object
title: distinct configuration
properties:
groupBy:
type: array
title: Grouping properties
description: Defines the properties that are concatenated to produce distinct key
minItems: 1
items:
type: string
maxCombinations:
type: number
description: maximum number of tracked combinations
maxDepth:
type: number
description: maximum number of groupBy properties
isFederated:
type: boolean
description: indicator that the operator runs on a federated executor
suppressPreviews:
type: boolean
title: Suppress preview results
description: Toggle this on to suppress generating previews of intermediate
results
FunctionDistinct:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- distinct
description: Identifier of the Function. Always distinct
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDnsLookup:
type: object
additionalProperties: true
properties:
dnsLookupFields:
title: DNS lookup fields
description: List of field names on which to perform DNS lookup
type: array
items:
type: object
properties:
inFieldName:
type: string
title: Lookup field name
description: Name of the field containing the hostname or IP address to look up.
resourceRecordType:
title: Resource record type
description: The DNS record type (RR) to return. Defaults to 'A'.
type: string
enum:
- A
- AAAA
- ANY
- CNAME
- MX
- NAPTR
- NS
- PTR
- SOA
- SRV
- TXT
x-speakeasy-enum-descriptions:
- A
- AAAA
- ANY
- CNAME
- MX
- NAPTR
- NS
- PTR
- SOA
- SRV
- TXT
x-speakeasy-unknown-values: allow
outFieldName:
type: string
title: Output field name
description: Name of field to add lookup results to. Leave blank to overwrite
the lookup field.
reverseLookupFields:
title: Reverse DNS lookup fields
description: List of field names on which to perform reverse DNS lookup
type: array
items:
type: object
properties:
inFieldName:
type: string
title: Lookup field name
description: Name of the field containing the IP to look up. If the field value
is not in IPv4 or IPv6 format, the lookup is skipped.
outFieldName:
type: string
title: Output field name
description: Name of field to add the resolved domain to. Leave blank to
overwrite the lookup field.
dnsServers:
title: DNS server overrides
description: "IPs, in RFC 5952 format, of the DNS servers to use for resolution. Examples: IPv4 1.1.1.1, 4.2.2.2:53, or IPv6 [2001:4860:4860::8888], [2001:4860:4860::8888]:1053. If not specified, system's DNS will be used."
type: array
items:
type: string
cacheTTL:
type: number
title: Cache time to live (minutes)
description: How frequently to expire and refetch DNS cache. Use 0 to disable.
maxCacheSize:
type: number
title: Cache size limit
description: The maximum number of DNS resolutions to be cached locally. Leave
at default unless you understand the implications of changing.
maximum: 100000
useResolvConf:
title: Use /etc/resolv.conf
description: Attempt to resolve DNS short names using the search or domain
directive from /etc/resolv.conf
type: boolean
lookupFallback:
title: Fall back to DNS.lookup()
description: "If unable to resolve a DNS short name, make a DNS.lookup() call to resolve it. Caution: This might degrade performance in unrelated areas of @{product}."
type: boolean
domainOverrides:
title: Use search or domain fallbacks
description: Specify fallback values for the DNS resolver to use when it cannot
resolve a DNS short name
type: array
items:
type: string
title: fallback
lookupFailLogLevel:
title: Log level for failed lookups
description: Log level to use when a DNS lookup fails.
type: string
enum:
- silly
- debug
- info
- warn
- error
x-speakeasy-enum-descriptions:
- silly
- debug
- info
- warn
- error
x-speakeasy-unknown-values: allow
FunctionDnsLookup:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- dns_lookup
description: Identifier of the Function. Always dns_lookup
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDrop:
type: object
FunctionDrop:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- drop
description: Identifier of the Function. Always drop
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDropDimensions:
type: object
properties:
timeWindow:
pattern: \d+[sm]$
type: string
title: Aggregation time window
description: The time span of the tumbling window for aggregating events. Must
be a valid time string (such as 10s).
dropDimensions:
type: array
title: Dimensions to drop
description: "One or more dimensions to be dropped. Supports wildcard expressions. Warning: Using wildcard '*' causes all dimensions in the event to be dropped."
minItems: 1
items:
type: string
flushOnInputClose:
type: boolean
title: Flush on stream close
description: Flush aggregations when an input stream is closed. If disabled,
aggregations are flushed based on Time Window Settings instead.
FunctionDropDimensions:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- drop_dimensions
description: Identifier of the Function. Always drop_dimensions
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaDynamicSampling:
type: object
additionalProperties: false
properties:
mode:
title: Sample mode
type: string
description: "Defines how sample rate will be derived: log(previousPeriodCount) or sqrt(previousPeriodCount)"
enum:
- log
- sqrt
x-speakeasy-enum-descriptions:
- Logarithmic
- Square Root
x-speakeasy-unknown-values: allow
keyExpr:
title: Sample group key
description: Expression used to derive sample group key.
Example:`${domain}:${status}`. Each sample group will have its own
derived sampling rate based on volume. Defaults to `${host}`.
type: string
samplePeriod:
title: Sample period
description: How often (in seconds) sample rates will be adjusted
type: number
minEvents:
title: Minimum events
description: Minimum number of events that must be received in previous sample
period for sampling mode to be applied to current period. If the
number of events received for a sample group is less than this
minimum, a sample rate of 1:1 is used.
type: number
maxSampleRate:
title: Sampling rate limit
description: Maximum sampling rate. If computed sampling rate is above this
value, it will be limited to this value.
type: number
minimum: 1
FunctionDynamicSampling:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- dynamic_sampling
description: Identifier of the Function. Always dynamic_sampling
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaEval:
type: object
additionalProperties: false
properties:
add:
title: Evaluate fields
description: Set of key-value pairs to evaluate and add/set
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the field to set or add to the event.
value:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
disabled:
type: boolean
description: Set to No to disable the evaluation of an individual expression
keep:
title: Keep fields
description: List of fields to keep. Supports * wildcards. Takes precedence over
'Remove fields'.
type: array
items:
type: string
remove:
title: Remove fields
description: List of fields to remove. Supports * wildcards. Fields that match
'Keep fields' will not be removed. Enclose field names containing
special characters in single or double quotes.
type: array
items:
type: string
printUndefineds:
type: boolean
title: Print undefined as null
description: When enabled (e.g. for Cribl Search), convert undefined expression
results to null so requested-but-missing fields appear in JSON
output. When disabled (default), undefined is preserved.
FunctionEval:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- eval
description: Identifier of the Function. Always eval
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaEventBreaker:
type: object
properties:
existingOrNew:
title: Existing or new?
description: Whether to use an existing event breaker ruleset or create a new
one inline.
type: string
enum:
- existing
- new
x-speakeasy-enum-descriptions:
- Use Existing
- Create New
x-speakeasy-unknown-values: allow
shouldMarkCriblBreaker:
type: boolean
title: Add to cribl_breaker
description: Add this Function name to the cribl_breaker field
ruleType:
$ref: "#/components/schemas/EventBreakerTypeOptionsEventBreakerExistingOrNewNew"
description: Type of event-breaking rule to apply when creating a new inline
ruleset.
maxEventBytes:
type: number
title: Event byte limit
description: The maximum number of bytes that an event can be before being
flushed to the Pipelines
minimum: 1
maximum: 134217728
timestampAnchorRegex:
type: string
title: Timestamp anchor
description: Regex to match before attempting timestamp extraction. Use $ (end
of string anchor) to not perform extraction.
timestamp:
$ref: "#/components/schemas/TimestampFormatTypeEventBreakerExistingOrNewNew"
description: Configuration for extracting and parsing timestamps from events.
timestampTimezone:
type: string
title: Default timezone
description: Timezone to assign to timestamps without timezone info
timestampEarliest:
title: Earliest timestamp allowed
description: The earliest timestamp value allowed relative to now, such as
-42years. Parsed values prior to this date will be set to current
time.
type: string
timestampLatest:
title: Future timestamp allowed
description: The latest timestamp value allowed relative to now, such as
+42days. Parsed values after this date will be set to current time.
type: string
existingRule:
type: string
title: Existing ruleset
description: ID of an existing event breaker ruleset to apply.
minLength: 1
allOf:
- oneOf:
- $ref: "#/components/schemas/EventBreakerExistingOrNewNew"
- $ref: "#/components/schemas/EventBreakerExistingOrNewExisting"
discriminator:
propertyName: existingOrNew
mapping:
new: "#/components/schemas/EventBreakerExistingOrNewNew"
existing: "#/components/schemas/EventBreakerExistingOrNewExisting"
FunctionEventBreaker:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- event_breaker
description: Identifier of the Function. Always event_breaker
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaEventstats:
type: object
title: eventstats configuration
properties:
aggregations:
type: array
title: Aggregates
description: Aggregate function(s) to perform on events. E.g.,
sum(bytes).where(action=='REJECT').as(TotalBytes)
minItems: 1
items:
type: string
groupBys:
type: array
title: Group by fields
description: Fields to group aggregates by, supports wildcard expressions.
items:
type: string
maxEvents:
type: number
title: Maximum number of events
description: Specifies how many events are at max kept in memory to be enriched
with aggregations
flushOnInputClose:
type: boolean
title: Flush on stream close
description: Determines if aggregations should flush when an input stream is
closed. If disabled, time window settings will control flush
behavior.
FunctionEventstats:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- eventstats
description: Identifier of the Function. Always eventstats
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaExternaldata:
type: object
FunctionExternaldata:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- externaldata
description: Identifier of the Function. Always externaldata
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaFlatten:
type: object
properties:
fields:
type: array
title: Fields
description: List of top-level fields to include for flattening. Supports *
wildcards, except when used on internal fields. Defaults to empty
array, which means all fields.
items:
type: string
pattern: ^(?!__.*\*).*$
prefix:
type: string
title: Prefix
description: Prefix string for flattened field names. Defaults to empty.
depth:
type: number
title: Depth
description: Number representing the nested levels to consider for flattening.
Defaults to 5. Minimum should be 1.
minimum: 1
delimiter:
type: string
title: Delimiter
description: Delimiter to be used for flattening. Defaults to underscore.
FunctionFlatten:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- flatten
description: Identifier of the Function. Always flatten
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaFoldkeys:
type: object
properties:
deleteOriginal:
title: Delete original
description: When enabled (default), only the folded keys are kept. When
disabled, the original entries are retained alongside the folded
keys.
type: boolean
separator:
title: Separator string
description: Character or string used to separate key levels to be folded.
Defaults to the dot (.) character.
type: string
selectionRegExp:
title: Selection regular expression
description: Optional regular expression to select a subset of the keys to fold.
type: string
maxDepth:
title: Maximum depth
description: Maximum recursion depth when traversing nested objects. Prevents
infinite loops caused by cyclic references. Defaults to 20.
type: integer
minimum: 1
FunctionFoldkeys:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- foldkeys
description: Identifier of the Function. Always foldkeys
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaGenStats:
type: object
title: Gen stats configuration
additionalProperties: false
properties:
fields:
type: array
description: List of field names from which to generate statistics.
items:
type: string
FunctionGenStats:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- gen_stats
description: Identifier of the Function. Always gen_stats
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaGeoip:
type: object
additionalProperties: false
properties:
file:
type: string
title: GeoIP file (.mmdb)
description: Select an uploaded Maxmind database, or specify path to a Maxmind
database with .mmdb extension
minLength: 1
inField:
type: string
title: IP field
description: Field name in which to find an IP to look up. Can be nested.
outField:
type: string
title: Result field
description: Field name in which to store the GeoIP lookup results
additionalFields:
type: array
title: Additional fields
description: Additional IP fields on which to perform GeoIP lookups.
items:
type: object
required:
- extraInField
- extraOutField
properties:
extraInField:
type: string
title: IP Field
description: Field name in which to find an IP to look up. Can be nested.
extraOutField:
type: string
title: Result Field
description: Field name in which to store the GeoIP lookup results
outFieldMappings:
type: object
title: Output field mappings
description: Search-specific mappings for granular control over event enrichment
FunctionGeoip:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- geoip
description: Identifier of the Function. Always geoip
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaGrok:
type: object
properties:
pattern:
type: string
title: Pattern
description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}"
patternList:
type: array
title: Additional Grok patterns
description: Additional Grok patterns to apply to the source field.
items:
$ref: "#/components/schemas/PatternListConfSerdeTypeGrok"
source:
type: string
title: Source field
description: Field on which to perform Grok extractions
FunctionGrok:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- grok
description: Identifier of the Function. Always grok
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaHandlebars:
type: object
properties:
templates:
type: array
title: Templates
description: Array of template definitions. Uses event.__template_id to select
template at runtime.
items:
type: object
title: Template definition
required:
- id
- content
- type
additionalProperties: false
properties:
id:
type: string
title: Template ID
description: Unique identifier for this template
minLength: 1
content:
type: string
title: Template content
description: Handlebars template string
minLength: 1
description:
type: string
title: Description
description: Optional description of what this template is used for
type:
type: string
title: Template type
description: Type categorization for the template (e.g., Universal, Email,
Slack)
targetField:
type: string
title: Target field
description: Field name to store the rendered template result. Defaults to _raw.
parseJson:
type: boolean
title: Parse as JSON
description: Parse the rendered template as JSON and store as an object instead
of a string. Useful for building structured data like Slack blocks.
removeOnNull:
type: boolean
title: Remove field if empty
description: Remove the target field if the rendered result is empty or null.
FunctionHandlebars:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- handlebars
description: Identifier of the Function. Always handlebars
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaJoin:
type: object
title: Join Configuration
additionalProperties: false
properties:
kind:
type: string
title: Kind
description: Join kind, e.g. inner
hints:
type: object
title: Hint
description: Hints passed to the join function
additionalProperties:
type: string
fieldConditions:
title: Join Conditions
description: Fields to use when joining
type: array
minItems: 1
items:
type: object
required:
- leftFieldName
- rightFieldName
properties:
leftFieldName:
title: Left Field Name
description: The field name to join on, on the left side.
type: string
rightFieldName:
title: Right Field Name
description: The field name on the right side of the data, i.e. the stage
results, that we are joining with
type: string
searchJobId:
title: Search Job Id
description: The id for this search job.
type: string
stageId:
title: Stage Id
description: The stage we are joining with.
type: string
FunctionJoin:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- join
description: Identifier of the Function. Always join
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaJsonUnroll:
type: object
properties:
path:
type: string
title: Path
description: Path to array to unroll, such as foo.0.bar
name:
type: string
title: New name
description: Name of each exploded array element in each new event. Leave empty
to expand the array element with its original name.
FunctionJsonUnroll:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- json_unroll
description: Identifier of the Function. Always json_unroll
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLakeExport:
type: object
title: Lake export Configuration
additionalProperties: false
properties:
searchJobId:
title: Search Job Id
description: Id of the search job this function is running on.
type: string
dataset:
title: Dataset Name
description: Name of the dataset
type: string
lake:
title: Lake Name
description: Name of the lake
type: string
tee:
title: Tee
description: Tee results to search. When set to true results will be shipped
instead of stats
type: boolean
flushMs:
title: Flush period
description: How often are stats flushed in ms
type: number
suppressPreviews:
type: boolean
title: Suppress periodic stats
description: Disables generation of intermediate stats. When true stats will be
emitted only on end
FunctionLakeExport:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- lake_export
description: Identifier of the Function. Always lake_export
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLakehouseEngineMetricsNormalizer:
type: object
FunctionLakehouseEngineMetricsNormalizer:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- lakehouse_engine_metrics_normalizer
description: Identifier of the Function. Always
lakehouse_engine_metrics_normalizer
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLimit:
type: object
additionalProperties: false
properties:
limit:
title: Event limit
description: Number of qualifying events to pass through
type: integer
minimum: 0
FunctionLimit:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- limit
description: Identifier of the Function. Always limit
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLocalSearchDatatypeParser:
type: object
FunctionLocalSearchDatatypeParser:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- local_search_datatype_parser
description: Identifier of the Function. Always
local_search_datatype_parser
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLocalSearchRulesetRunner:
type: object
additionalProperties: false
properties:
rulesetType:
type: string
enum:
- dataset
- datatype
title: Ruleset Type
description: "Type of ruleset to apply: dataset or datatype."
x-speakeasy-unknown-values: allow
rulesetId:
type: string
title: Ruleset ID
description: ID of the ruleset to apply.
ruleset:
type: object
title: Full ruleset
description: Full ruleset definition, used with live data capture for draft or
unsaved rulesets.
markAndIncludeDroppedEvents:
type: boolean
title: Mark and include dropped events
description: Only for use with live data capture. Mark events that were dropped
by dataset rules and still include them for capture
FunctionLocalSearchRulesetRunner:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- local_search_ruleset_runner
description: Identifier of the Function. Always
local_search_ruleset_runner
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLocalSearchSchemaMapper:
type: object
FunctionLocalSearchSchemaMapper:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- local_search_schema_mapper
description: Identifier of the Function. Always
local_search_schema_mapper
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLocalSearchTimeRangeNormalizer:
type: object
FunctionLocalSearchTimeRangeNormalizer:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- local_search_time_range_normalizer
description: Identifier of the Function. Always
local_search_time_range_normalizer
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLocalSearchTransformer:
type: object
FunctionLocalSearchTransformer:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- local_search_transformer
description: Identifier of the Function. Always
local_search_transformer
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaLookup:
type: object
properties:
file:
type: string
title: Lookup file path (.csv, .csv.gz)
description: "Path to the lookup file. Reference environment variables via $. Example: $HOME/file.csv"
minLength: 1
dbLookup:
type: boolean
title: Use Disk-Based Lookup
description: Enable to use a disk-based lookup. This option displays only the
settings relevant to disk-based mode and hides those for in-memory
lookups.
matchMode:
title: Match mode
type: string
description: Specifies the matching method based on the format and logic used in
the lookup file
enum:
- exact
- cidr
- regex
x-speakeasy-enum-descriptions:
- Exact
- CIDR
- Regex
x-speakeasy-unknown-values: allow
matchType:
title: Match type
type: string
description: "Further defines how to handle multiple matches: return the first match, the most specific match, or all matches"
enum:
- first
- specific
- all
x-speakeasy-unknown-values: allow
reloadPeriodSec:
type: number
title: Reload period (sec)
description: Checks the lookup file periodically for changes and reloads it if
modified. Set to -1 to disable reloading (default). Useful for
lookups not managed by Stream or not updated by an external process.
[Learn
more](https://docs.cribl.io/stream/lookup-function/#advanced-settings)
inFields:
type: array
title: Lookup fields
description: Fields that should be used to key into the lookup table
minItems: 1
items:
type: object
required:
- eventField
properties:
eventField:
type: string
title: Lookup Field Name in Event
description: Field name as it appears in events
pattern: ^[a-zA-Z$_'"][a-zA-Z0-9$_\[\]\.'"]*$
lookupField:
type: string
title: Corresponding Field Name in Lookup
description: "Optional: The field name as it appears in the lookup file. Defaults to event field name"
outFields:
type: array
title: Output fields
description: Fields to add to events after matching lookup. Defaults to all if
not specified.
items:
type: object
required:
- lookupField
properties:
lookupField:
type: string
title: Output Field Name from Lookup
description: The field name as it appears in the lookup file
eventField:
type: string
title: Lookup Field Name in Event
description: "Optional: Field name to add to event. Defaults to lookup field name."
pattern: ^[a-zA-Z$_][a-zA-Z0-9$_\[\]\.'"]*$
defaultValue:
type: string
title: Default Value
description: "Optional: Value to assign if lookup entry is not found"
addToEvent:
type: boolean
title: Add to raw event
description: Add the looked-up values to _raw, as key=value pairs
ignoreCase:
type: boolean
title: Ignore case
description: "Whether to ignore case when performing lookups using Match Mode: Regex."
FunctionLookup:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- lookup
description: Identifier of the Function. Always lookup
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaMask:
type: object
properties:
rules:
type: array
title: Masking rules
description: List of masking rules, each specifying a regex to match and an
expression to replace matched content.
minItems: 1
items:
type: object
required:
- matchRegex
- replaceExpr
properties:
matchRegex:
type: string
title: Match Regex
description: Pattern to replace. Use /g to replace all matches.
minLength: 1
replaceExpr:
type: string
title: Replace Expression
description: A JavaScript expression or literal to replace the matching content.
Capturing groups can be referenced as g1, g2, and so on, and
event fields as event..
disabled:
type: boolean
description: Set to No to disable the evaluation of an individual rule
fields:
type: array
title: Apply to fields
description: Fields on which to apply the masking rules. Supports * wildcards,
except when used on internal fields.
items:
type: string
pattern: ^(?!__.*\*).*$
depth:
type: integer
title: Depth
description: Depth to which the Mask Function will search for fields to mask
minimum: 1
flags:
title: Evaluate fields
description: Fields to evaluate if one or more masking rules are matched
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the field to set when one or more masking rules match.
value:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
FunctionMask:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- mask
description: Identifier of the Function. Always mask
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaMetricsExport:
type: object
title: Metrics export Configuration
additionalProperties: true
properties:
searchJobId:
title: Search Job Id
description: Unique identifier for the Search Job that runs this Function.
type: string
dataset:
title: Dataset Id
description: Unique identifier for the metrics Dataset.
type: string
nameField:
$ref: "#/components/schemas/NameFieldType"
description: Reference to a field by its original text and parsed path segments.
timeField:
$ref: "#/components/schemas/NameFieldType"
description: Reference to a field by its original text and parsed path segments.
valueField:
$ref: "#/components/schemas/NameFieldType"
description: Reference to a field by its original text and parsed path segments.
typeField:
$ref: "#/components/schemas/NameFieldType"
description: Reference to a field by its original text and parsed path segments.
labelFields:
description: Field references to attach as labels to each exported metric.
Specify one field or a list of fields.
oneOf:
- type: object
description: Label configuration that reads key-value pairs from one object
field.
required:
- mode
- field
properties:
mode:
enum:
- object
description: Type of label configuration. Always object.
x-speakeasy-unknown-values: allow
field:
$ref: "#/components/schemas/NameFieldType"
description: Reference to a field by its original text and parsed path segments.
- type: object
description: Label configuration that reads values from a list of fields.
required:
- mode
- fields
properties:
mode:
enum:
- list
description: Type of label configuration. Always list.
x-speakeasy-unknown-values: allow
fields:
type: array
description: Field references to attach as labels to each exported metric.
items:
$ref: "#/components/schemas/NameFieldType"
tee:
title: Tee
description: If true, pass processed events to downstream
Functions. If false, emit export statistics.
type: boolean
flushMs:
title: Flush period
description: Interval, in milliseconds, between export statistics updates.
type: number
suppressPreviews:
type: boolean
title: Suppress periodic stats
description: If true, emit export statistics only when processing
completes. If false, emit periodic statistics.
FunctionMetricsExport:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- metrics_export
description: Identifier of the Function. Always metrics_export
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaMetricsTimeRangeGate:
type: object
FunctionMetricsTimeRangeGate:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- metrics_time_range_gate
description: Identifier of the Function. Always
metrics_time_range_gate
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaMvExpand:
type: object
additionalProperties: false
properties:
sourceFields:
title: Source fields
description: Array of property-/field-names to expand
type: array
minItems: 1
items:
type: string
targetNames:
title: Target field names
description: stores the value as new target field name
type: array
minItems: 1
items:
type: string
rowLimit:
title: Row limit
description: max. number of rows generated out of every source events
type: number
itemIndexName:
title: Item index name
description: name of an optional index property generated into the output
type: string
bagExpansionMode:
title: Bag expansion mode
description: decides if bag-values are expanded to bags or arrays
type: string
enum:
- bag
- array
x-speakeasy-enum-descriptions:
- Store as object
- Store as array
x-speakeasy-unknown-values: allow
FunctionMvExpand:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- mv_expand
description: Identifier of the Function. Always mv_expand
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaMvPull:
type: object
additionalProperties: false
properties:
arrayPath:
title: Field name of source array
description: Field name of the array within events that contains the data
objects of interest. Can be a path.
type: string
relativeKeyPath:
title: Field name of key
description: Extract the K-V pair's key from this field, relative to the data
object.
type: string
relativeValuePath:
title: Field name of value
description: Extract the K-V pair's value from this field, relative to the data
object.
type: string
targetBagPath:
title: Field name for pulled fields
description: Optionally, specify a bag as the target for K-V entries. If not
specified, these entries are stored on each top-level event.
type: string
deleteOriginal:
title: Delete source array after processing
description: Toggle this on to remove each original array of data objects after
extraction. If toggled off, arrays are retained.
type: boolean
FunctionMvPull:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- mv_pull
description: Identifier of the Function. Always mv_pull
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaNotificationPolicies:
type: object
title: Notification Policies Configuration
properties:
policies:
type: array
title: Policies
description: List of notification routing policies evaluated in order
items:
type: object
required:
- id
- templateTargetPairs
- order
properties:
id:
type: string
title: Policy ID
description: Unique identifier for this policy
minLength: 1
disabled:
type: boolean
title: Disabled
description: If true, this policy will be skipped during evaluation
waitToGroup:
type: integer
title: Wait to Group (Minutes)
description: Time to wait (in minutes) to group similar alerts before sending
minimum: 0
groupByLabels:
type: array
title: Group By Labels
description: Event fields to use for grouping
items:
type: string
conditions:
type: array
title: OR Conditions
description: List of conditions. If ANY condition matches (OR), the policy
applies. Each condition is a list of tags that must ALL match
(AND).
items:
type: array
title: AND Group
items:
type: object
required:
- key
- operator
- value
properties:
key:
type: string
title: Field Name
description: Event field name to match against
minLength: 1
operator:
type: string
title: Operator
description: Comparison operator
enum:
- "="
- "!="
- "=~"
- "!~"
x-speakeasy-enums:
- Equal
- NotEqual
- RegexMatch
- RegexNotMatch
x-speakeasy-unknown-values: allow
value:
title: Value
description: Value to compare against (string, number, boolean)
oneOf:
- type: string
- type: number
- type: boolean
templateTargetPairs:
type: array
title: Template & Target Pairs
description: List of targets to route to and the templates to use
minItems: 1
items:
type: object
required:
- templateId
- targetId
properties:
templateId:
type: string
title: Template ID
description: ID of the notification template to use
targetId:
type: string
title: Target ID
description: ID of the notification target (output)
final:
type: boolean
title: Final
description: If true, stop evaluating further policies after this one matches
order:
type: integer
title: Order
description: Evaluation order of this policy (lower numbers evaluated first)
minimum: 0
FunctionNotificationPolicies:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- notification_policies
description: Identifier of the Function. Always notification_policies
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaNotifications:
type: object
additionalProperties: false
properties:
id:
type: string
title: ID
description: Notification ID
field:
type: string
title: Field
description: Notification event state field name
deduplicate:
type: boolean
title: Deduplicate
description: Toggle deduplication.
FunctionNotifications:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- notifications
description: Identifier of the Function. Always notifications
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaNotify:
type: object
title: Notify Configuration
additionalProperties: false
properties:
group:
title: Group
description: Group the notification belongs to
type: string
notificationId:
title: Workspace
description: Workspace within the deployment to send the search results to.
type: string
searchId:
title: Search Id
description: Id of the search this function is running on.
type: string
savedQueryId:
title: Saved query Id
description: Id of the saved query
type: string
trigger:
title: Trigger condition expression
description: Js expression that filters events, a greater than 'Trigger Count'
events will trigger the notification
type: string
triggerType:
type: string
title: Trigger type
description: Type of the trigger condition. custom applies a kusto expression
over the results, and results count applies a comparison over
results count
enum:
- custom
- resultsCount
x-speakeasy-enum-descriptions:
- Where
- Count of Results
x-speakeasy-unknown-values: allow
triggerComparator:
type: string
title: Count comparator
description: Operation to be applied over the results count
enum:
- ">"
- "<"
- "==="
- "!=="
- ">="
- "<="
x-speakeasy-enum-descriptions:
- greater than
- less than
- equals
- not equal to
- greater than or equal to
- less than or equal to
x-speakeasy-unknown-values: allow
triggerCount:
title: Trigger Count
description: How many results that match trigger the condition
type: number
resultsLimit:
title: Top number results
description: Number of results to include in the notification event
type: number
searchUrl:
title: Search url
description: Url of the search results
type: string
message:
title: Message content
description: "Message content template, available fields: searchId, resultSet, savedQueryId, notificationId, searchResultsUrl"
type: string
authToken:
title: Api Auth Token
description: Auth token for sending notification messages
type: string
messagesEndpoint:
title: Messages api endpoint
description: System messages api endpoint
type: string
tenantId:
title: Tenant Id
description: Current tenant id
type: string
FunctionNotify:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- notify
description: Identifier of the Function. Always notify
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaNumerify:
type: object
properties:
depth:
type: integer
title: Depth
description: Depth to which the Numerify Function will search within a nested
event. Depth greater than 5 (the default) could decrease
performance.
minimum: 0
maximum: 10
ignoreFields:
title: Ignore fields
description: "Fields to NOT numerify. Takes precedence over 'Include expression' when set. Supports wildcards. A '!' before field name(s) means: numerify all fields EXCEPT these. For syntax details, see [Wildcard Lists](https://docs.cribl.io/stream/introduction-reference/#wildcard-lists)."
type: array
items:
type: string
description: Field to ignore
filterExpr:
title: Include expression
description: "Optional JavaScript expression to determine whether a field should be numerified. If left blank, all fields will be numerified. Use the 'name' and 'value' global variables to access fields' names/values. Examples: `value != null`, `name=='fieldname'`. You can access other fields' values via `__e.`."
type: string
format:
title: Format
description: Numeric format to apply after type conversion.
type: string
enum:
- none
- fix
- floor
- ceil
x-speakeasy-enum-descriptions:
- None
- Fix
- Floor
- Ceil
x-speakeasy-unknown-values: allow
digits:
type: number
title: Digits
description: Number of digits after the decimal point, between 0 and 20. If left
blank, defaults to 2.
minimum: 0
maximum: 20
allOf:
- oneOf:
- $ref: "#/components/schemas/NumerifyFormatFix"
- $ref: "#/components/schemas/NumerifyFormatNone"
discriminator:
propertyName: format
mapping:
fix: "#/components/schemas/NumerifyFormatFix"
none: "#/components/schemas/NumerifyFormatNone"
FunctionNumerify:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- numerify
description: Identifier of the Function. Always numerify
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaOtlpLogs:
type: object
properties:
dropNonLogEvents:
type: boolean
title: Drop non-log events
description: Drop events that are not OTLP log records.
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Body and attribute values already in OTLP AnyValue form (e.g.
{string_value: "..."}) are preserved rather than being re-wrapped'
batchOTLPLogs:
type: boolean
title: Batch OTLP logs
description: Batch OTLP log records by shared top-level `resource` attributes
sendBatchSize:
type: number
title: Batch size
description: Number of log records after which a batch will be sent, regardless
of the timeout
timeout:
type: number
title: Batch timeout (ms)
description: Time duration after which a batch will be sent, regardless of size
sendBatchMaxSize:
type: number
title: Batch size limit (kb)
description: Maximum batch size. Enter 0 for no maximum.
metadataKeys:
type: array
title: Batch log metadata keys
description: When set, this processor will create one batcher instance per
distinct combination of values in the metadata
items:
type: string
metadataCardinalityLimit:
type: number
title: Metadata cardinality limit
description: "Limit the number of unique combinations of metadata key values that will be processed over the lifetime of the process. After the limit is reached, events with new metadata key value combinations will be dropped. "
FunctionOtlpLogs:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- otlp_logs
description: Identifier of the Function. Always otlp_logs
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaOtlpMetrics:
type: object
properties:
resourceAttributes:
type: array
title: Resource attributes
description: Top-level event fields to promote as OTLP resource attributes.
Entries without `*` match the attribute name exactly (`cluster`
matches only `cluster`). Append `*` for prefix matching (`cluster*`
also matches `cluster_id` and `cluster.name`). Use `!` to exclude
names; list exclusions before broader patterns (for example
`!k8s.internal.*`, `k8s.*`). Matching is by whole top-level field
name only; it does not walk nested objects. Use Eval to copy nested
fields to the top level first.
items:
type: string
resourceAttributePrefixes:
type: array
title: Resource attribute prefixes (deprecated)
description: Deprecated. Prefer 'Resource attributes', which supports exact and
wildcard matching. This field lists prefixes of top-level attributes
to add as resource attributes. Every entry is treated as a prefix,
so `cluster` also matches `cluster_foo`, with no way to match an
attribute name exactly. This field applies only when 'Resource
attributes' is empty. Use Eval to copy nested attributes to the top
level for matching.
items:
type: string
pattern: ^[a-zA-Z0-9_\.]+$
dropNonMetricEvents:
type: boolean
title: Drop non-metric events
description: Drop events that are not OTLP metric data points.
otlpVersion:
type: string
title: OTLP version
description: OpenTelemetry Protocol (OTLP) version to use for metric
serialization.
enum:
- 0.10.0
- 1.3.1
x-speakeasy-enum-descriptions:
- 0.10.0
- 1.3.1
x-speakeasy-unknown-values: allow
batchOTLPMetrics:
type: boolean
title: Batch OTLP metrics
description: Batch OTLP metrics by shared top-level `resource` attributes
sendBatchSize:
type: number
title: Batch size
description: Number of metric data points after which a batch will be sent,
regardless of the timeout
timeout:
type: number
title: Batch timeout (ms)
description: Time duration after which a batch will be sent, regardless of size
sendBatchMaxSize:
type: number
title: Batch size limit (kb)
description: Maximum batch size. Enter 0 for no maximum.
metadataKeys:
type: array
title: Batch metrics metadata keys
description: When set, this processor will create one batcher instance per
distinct combination of values in the metadata
items:
type: string
metadataCardinalityLimit:
type: number
title: Metadata cardinality limit
description: Limit the number of unique combinations of metadata key values that
will be processed over the lifetime of the process. After the limit
is reached, events with new metadata key value combinations will be
dropped.
FunctionOtlpMetrics:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- otlp_metrics
description: Identifier of the Function. Always otlp_metrics
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaOtlpTraces:
type: object
properties:
dropNonTraceEvents:
type: boolean
title: Drop non-trace events
description: Drop events that are not OTLP trace spans.
otlpVersion:
type: string
title: OTLP version
description: OpenTelemetry Protocol (OTLP) version to use for trace serialization.
enum:
- 0.10.0
- 1.3.1
x-speakeasy-enum-descriptions:
- 0.10.0
- 1.3.1
x-speakeasy-unknown-values: allow
batchOTLPTraces:
type: boolean
title: Batch OTLP traces
description: Batch OTLP traces by shared top-level `resource` attributes
sendBatchSize:
type: number
title: Batch size
description: Number of spans after which a batch will be sent, regardless of the
timeout
timeout:
type: number
title: Batch timeout (ms)
description: Time duration after which a batch will be sent, regardless of size
sendBatchMaxSize:
type: number
title: Batch size limit (kb)
description: Maximum batch size. Enter 0 for no maximum.
metadataKeys:
type: array
title: Batch traces metadata keys
description: When set, this processor will create one batcher instance per
distinct combination of values in the metadata
items:
type: string
metadataCardinalityLimit:
type: number
title: Metadata cardinality limit
description: Limit the number of unique combinations of metadata key values that
will be processed over the lifetime of the process. After the limit
is reached, events with new metadata key value combinations will be
dropped.
FunctionOtlpTraces:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- otlp_traces
description: Identifier of the Function. Always otlp_traces
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaPack:
type: object
properties:
unpackedFields:
title: Unpacked fields
description: List of fields to keep, everything else will be packed
type: array
items:
type: string
target:
type: string
title: Packed target Field
description: Name of the (packed) target field
FunctionPack:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- pack
description: Identifier of the Function. Always pack
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaPivot:
type: object
title: Simple Pivot Configuration
additionalProperties: false
properties:
labelField:
title: Labeling field
description: Fields to be used for the left-most column.
type: string
dataFields:
title: Data fields
description: Fields with the cell values (i.e. aggregates)
type: array
minItems: 1
items:
type: string
qualifierFields:
title: Qualifier fields
description: Fields to qualify or group data fields
type: array
minItems: 1
items:
type: string
FunctionPivot:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- pivot
description: Identifier of the Function. Always pivot
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaPublishMetrics:
type: object
additionalProperties: false
properties:
fields:
title: Add metrics
description: List of metrics from event to extract and format. Formatted metrics
can be used by a destination to pass metrics to a metrics
aggregation platform.
type: array
minItems: 0
items:
type: object
required:
- inFieldName
- metricType
properties:
inFieldName:
type: string
title: Event Field Name
description: The name of the field in the event that contains the metric value
outFieldExpr:
type: string
title: Metric Name Expression
description: JavaScript expression to evaluate the metric field name. Defaults
to Event Field Name.
metricType:
type: string
title: Metric Type
description: The type of metric to publish (counter, timer, gauge, distribution,
summary, or histogram).
enum:
- counter
- timer
- gauge
- distribution
- summary
- histogram
x-speakeasy-enum-descriptions:
- Counter
- Timer
- Gauge
- Distribution
- Summary
- Histogram
x-speakeasy-unknown-values: allow
overwrite:
type: boolean
title: Overwrite
description: Overwrite previous metric specs. Leave disabled to append.
dimensions:
type: array
title: Add dimensions
description: Optional list of dimensions to include in events. Wildcards
supported. If you don't specify metrics, values will be appended to
every metric found in the event. When you add a new metric,
dimensions will be present only in those new metrics.
items:
type: string
removeMetrics:
title: Remove metrics
description: Optional list of metric field names to look for when removing
metrics. When a metric's field name matches an element in this list,
the metric will be removed from the event.
type: array
items:
type: string
removeDimensions:
type: array
title: Remove dimensions
description: Optional list of dimensions to remove from every metric found in
the event. Wildcards supported.
items:
type: string
FunctionPublishMetrics:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- publish_metrics
description: Identifier of the Function. Always publish_metrics
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaRedis:
type: object
properties:
commands:
type: array
minItems: 1
title: Commands
description: List of Redis commands to execute against the specified keys.
items:
type: object
required:
- keyExpr
- command
properties:
outField:
title: Result field
description: Name of the field in which to store the returned value. Leave blank
to discard returned value.
type: string
command:
title: Command
description: "Redis command to perform. For a complete list visit: https://redis.io/commands"
type: string
keyExpr:
title: Key
description: A JavaScript expression to compute the value of the key to operate
on. Can also be a constant such as 'username'.
type: string
argsExpr:
title: Args
description: A JavaScript expression to compute arguments to the operation. Can
return an array.
type: string
deploymentType:
title: Deployment type
type: string
description: How the Redis server is configured. Defaults to Standalone
enum:
- standalone
- cluster
- sentinel
x-speakeasy-enum-descriptions:
- Standalone
- Cluster
- Sentinel
x-speakeasy-unknown-values: allow
authType:
type: string
title: Authentication method
description: Authentication method to use when connecting to Redis.
enum:
- none
- manual
- credentialsSecret
- textSecret
x-speakeasy-enum-descriptions:
- None
- Manual
- User Secret
- Admin Secret
x-speakeasy-unknown-values: allow
maxBlockSecs:
type: number
title: Blocking time limit
description: Maximum amount of time (seconds) to wait before assuming that Redis
is down and passing events through. Use 0 to disable.
enableClientSideCaching:
type: boolean
title: Client-side cache
description: Enable client-side cache. Redundant when using Redis write
operations. See more options at Settings > General > Limits > Redis
Cache.
url:
title: Redis URL
description: "Redis URL to connect to. Format: redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-number[&password=bar[&option=value]]]. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
type: string
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
tlsOptions:
$ref: "#/components/schemas/TlsOptionsTypeRedisDeploymentTypeStandalone"
description: TLS settings for encrypting the connection to Redis.
rootNodes:
title: Root nodes
description: Root nodes to which the cluster connection should be initiated
type: array
minItems: 1
items:
$ref: "#/components/schemas/RootNodeConfRedisDeploymentTypeCluster"
tls:
title: TLS
type: boolean
description: Use TLS for connections to this cluster
scaleReads:
$ref: "#/components/schemas/ScaleReadsOptionsRedisDeploymentTypeCluster"
description: Which nodes read commands should be sent to
masterName:
title: Master group name
description: Name of the Redis Sentinel master group to connect to.
type: string
username:
title: Username
description: Username for Redis authentication.
type: string
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
password:
title: Password
description: Password for Redis authentication.
type: string
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
credentialsSecret:
type: string
title: User secret
description: Secret that references Redis username and password
textSecret:
type: string
title: Admin secret
description: Secret that references Redis admin password
allOf:
- oneOf:
- $ref: "#/components/schemas/RedisDeploymentTypeStandalone"
- $ref: "#/components/schemas/RedisDeploymentTypeCluster"
- $ref: "#/components/schemas/RedisDeploymentTypeSentinel"
discriminator:
propertyName: deploymentType
mapping:
standalone: "#/components/schemas/RedisDeploymentTypeStandalone"
cluster: "#/components/schemas/RedisDeploymentTypeCluster"
sentinel: "#/components/schemas/RedisDeploymentTypeSentinel"
- oneOf:
- $ref: "#/components/schemas/RedisAuthTypeNone"
- $ref: "#/components/schemas/RedisAuthTypeManual"
- $ref: "#/components/schemas/RedisAuthTypeCredentialsSecret"
- $ref: "#/components/schemas/RedisAuthTypeTextSecret"
discriminator:
propertyName: authType
mapping:
none: "#/components/schemas/RedisAuthTypeNone"
manual: "#/components/schemas/RedisAuthTypeManual"
credentialsSecret: "#/components/schemas/RedisAuthTypeCredentialsSecret"
textSecret: "#/components/schemas/RedisAuthTypeTextSecret"
FunctionRedis:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- redis
description: Identifier of the Function. Always redis
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaRegexExtract:
type: object
properties:
regex:
type: string
title: Regex
description: Regex literal with named capturing groups, such as (?bar), or
_NAME_ and _VALUE_ capturing groups, such as (?<_NAME_0>[^
=]+)=(?<_VALUE_0>[^,]+)
regexList:
type: array
title: Additional regex
description: Additional regex patterns to apply for field extraction.
items:
$ref: "#/components/schemas/RegexListConfSerdeTypeRegex"
source:
type: string
title: Source field
description: Field on which to perform regex field extraction
iterations:
type: number
title: Max exec
description: The maximum number of times to apply regex to source field when the
global flag is set, or when using _NAME_ and _VALUE_ capturing
groups
minimum: 1
fieldNameExpression:
title: Field name format expression
description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.."
type: string
overwrite:
type: boolean
title: Overwrite existing fields
description: Overwrite existing event fields with extracted values. If disabled,
existing fields will be converted to an array.
FunctionRegexExtract:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- regex_extract
description: Identifier of the Function. Always regex_extract
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaRegexFilter:
type: object
properties:
regex:
title: Regex
description: Regex to test against
type: string
regexList:
type: array
title: Additional regex
description: Additional regex patterns to test against the field.
items:
type: object
required:
- regex
properties:
regex:
type: string
title: Regex
description: Regex to test against
minLength: 1
field:
title: Field
description: Name of the field to apply the regex on (defaults to _raw)
type: string
FunctionRegexFilter:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- regex_filter
description: Identifier of the Function. Always regex_filter
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaRename:
type: object
properties:
baseFields:
title: Parent fields
description: Fields whose children will inherit the Rename fields and Rename
expression operations. Supports wildcards. If empty, only top-level
fields will be renamed.
type: array
items:
type: string
rename:
title: Rename fields
description: Set of key-value pairs to rename fields, where key is the current
name and value is the new name. Does not support internal fields.
type: array
items:
type: object
required:
- currentName
- newName
properties:
currentName:
type: string
title: Current Name
description: Name of the field to rename. Literal identifiers must be quoted.
pattern: ^(?!__).+
newName:
type: string
title: New Name
description: The name the field will be renamed to. Literal identifiers must be
quoted.
pattern: ^(?!__).+
renameExpr:
title: Rename expression
description: "Optional JavaScript expression whose returned value will be used to rename fields. Use the 'name' and 'value' global variables to access field names/values. Example: `name.startsWith('data') ? name.toUpperCase() : name`. You can access other field values via __e.."
type: string
wildcardDepth:
type: integer
title: Parent field wildcard depth
description: For wildcards specified in Parent fields, sets the maximum depth
within events to match and rename fields. Enter `0` to match only
top-level fields. Defaults to `5` levels down.
minimum: 0
FunctionRename:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- rename
description: Identifier of the Function. Always rename
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaRollupMetrics:
type: object
properties:
dimensions:
title: Dimensions
description: List of dimensions across which to perform rollups. Supports
wildcards. Defaults to all original dimensions.
type: array
items:
type: string
timeWindow:
pattern: \d+[sm]$
type: string
title: Time window
description: The time span of the rollup window. Must be a valid time string
(such as 10s).
gaugeRollup:
title: Gauge update
description: The operation to use when rolling up gauge metrics. Defaults to last.
type: string
enum:
- last
- max
- min
- avg
x-speakeasy-enum-descriptions:
- Last
- Maximum
- Minimum
- Average
x-speakeasy-unknown-values: allow
FunctionRollupMetrics:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- rollup_metrics
description: Identifier of the Function. Always rollup_metrics
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSampling:
type: object
properties:
rules:
type: array
title: Sampling rules
description: Events matching these rules will be sampled at the given rate
items:
type: object
required:
- filter
- rate
additionalProperties: false
properties:
filter:
title: Filter
type: string
description: JavaScript filter expression matching events to be sampled. Use
true to match all.
rate:
title: Sampling Rate
type: integer
description: Sampling rate; picks one out of N matching events
FunctionSampling:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- sampling
description: Identifier of the Function. Always sampling
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSearchEngineExport:
type: object
title: Search engine export Configuration
additionalProperties: false
properties:
searchJobId:
title: Search Job Id
description: Id of the search job this function is running on.
type: string
dataset:
title: Dataset Id
description: Id of the dataset
type: string
tee:
title: Tee
description: Tee results to search. When set to true results will be shipped
instead of stats
type: boolean
flushMs:
title: Flush period
description: How often are stats flushed in ms
type: number
suppressPreviews:
type: boolean
title: Suppress periodic stats
description: Disables generation of intermediate stats. When true stats will be
emitted only on end
FunctionSearchEngineExport:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- search_engine_export
description: Identifier of the Function. Always search_engine_export
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSend:
type: object
title: Send Configuration
additionalProperties: false
properties:
url:
title: URL
description: Full URL to send search to.
type: string
group:
title: Group
description: Group within the workspace we're sending to.
type: string
workspace:
title: Workspace
description: Workspace within the deployment to send the search results to.
type: string
sendUrlTemplate:
title: URL Template
description: Template to build the URL to send from.
type: string
searchId:
title: Search Id
description: Id of the search this function is running on.
type: string
tee:
title: Tee
description: Tee results to search. When set to true results will be shipped
instead of stats
type: boolean
flushMs:
title: Flush period
description: How often are stats flushed in ms
type: number
suppressPreviews:
type: boolean
title: Suppress periodic stats
description: Disables generation of intermediate stats. When true stats will be
emitted only on end
mode:
type: string
title: Mode
description: In Sender mode, forwards search results directly to the
destination. In Metrics mode, accumulates metrics from federated
send operators, and forwards the aggregate metrics.
enum:
- sender
- metrics
x-speakeasy-unknown-values: allow
FunctionSend:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- send
description: Identifier of the Function. Always send
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSensitiveDataScanner:
type: object
properties:
rules:
type: array
title: Scanning Rulesets
description: List of scanning rulesets to apply, each with a ruleset ID and a
mitigation expression.
minItems: 1
items:
type: object
required:
- rulesetId
- replaceExpr
properties:
rulesetId:
type: string
title: Ruleset ID
description: The ID of the ruleset to use for the scan
replaceExpr:
type: string
title: Mitigation Expression
description: A JavaScript expression or literal to replace the matching content.
Capturing groups can be referenced as g1, g2, and so on, and
event fields as event..
disabled:
type: boolean
description: If true, disable this rule so that it is not applied
during scanning.
fields:
type: array
title: Apply to fields
description: Rulesets act on the events contained in these fields. Mitigation
expressions apply to the scan results. Supports wildcards (*).
items:
type: string
pattern: ^(?!__.*\*).*$
excludeFields:
type: array
title: Fields to ignore
description: Fields that the mitigation expression will not be applied to.
Supports wildcards (*).
items:
type: string
pattern: ^(?!__.*\*).*$
flags:
title: Add fields
description: Fields to add when mitigation is applied to an event
type: array
items:
type: object
required:
- value
properties:
name:
type: string
title: Name
description: Name of the field to set when one or more scanning rules match.
value:
type: string
title: Value
description: JavaScript expression to compute the value to assign to this field.
includeDetectedRules:
type: boolean
title: Include detected rules
description: Add matching ruleset IDs to a field called "__detected"
backgroundDetection:
type: boolean
title: Background detection
description: Run detection in the background without blocking event processing.
FunctionSensitiveDataScanner:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- sensitive_data_scanner
description: Identifier of the Function. Always
sensitive_data_scanner
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSerde:
type: object
properties:
mode:
title: Operation mode
type: string
description: Extract creates new fields. Reserialize extracts and filters
fields, and then reserializes.
enum:
- extract
- reserialize
x-speakeasy-enum-descriptions:
- Extract
- Reserialize
x-speakeasy-unknown-values: allow
type:
title: Type
description: Parser or formatter type to use.
type: string
enum:
- auto
- csv
- elff
- clf
- kvp
- json
- delim
- regex
- grok
x-speakeasy-enum-descriptions:
- Auto
- CSV
- Extended Log File Format
- Common Log Format
- Key=Value Pairs
- JSON Object
- Delimited values
- Regular Expression
- Grok
x-speakeasy-unknown-values: allow
keep:
title: Fields to keep
description: List of fields to keep. Supports wildcards (*). Takes precedence
over 'Fields to remove'.
type: array
items:
type: string
remove:
title: Fields to remove
description: List of fields to remove. Supports wildcards (*). Cannot remove
fields that match 'Fields to keep'.
type: array
items:
type: string
fieldFilterExpr:
title: Fields filter expression
description: Expression evaluated against {index, name, value} context. Return
truthy to keep a field, or falsy to remove it.
type: string
allowedKeyChars:
type: array
items:
type: string
title: Allowed key characters
description: A list of characters that may be present in a key name, even though
they are normally separator or control characters
allowedValueChars:
type: array
items:
type: string
title: Allowed value characters
description: A list of characters that may be present in a value, even though
they are normally separator or control characters
fields:
title: List of fields
description: The fields to be extracted, listed in order. Will auto-generate if
empty.
type: array
items:
type: string
regex:
type: string
title: Regex
description: Regex literal with named capturing groups, such as (?bar), or
_NAME_ and _VALUE_ capturing groups, such as(?<_NAME_0>[^
=]+)=(?<_VALUE_0>[^,]+)
regexList:
type: array
title: Additional regex
description: Additional regex patterns to apply for field extraction.
items:
$ref: "#/components/schemas/RegexListConfSerdeTypeRegex"
iterations:
type: number
title: Max exec
description: The maximum number of times to apply regex to source field when the
global flag is set, or when using _NAME_ and _VALUE_ capturing
groups
minimum: 1
fieldNameExpression:
title: Field name format expression
description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.."
type: string
overwrite:
type: boolean
title: Overwrite existing fields
description: Overwrite existing event fields with extracted values. If disabled,
existing fields will be converted to an array.
pattern:
type: string
title: Pattern
description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}"
patternList:
type: array
title: Additional Grok patterns
description: Additional Grok patterns to apply to the source field.
items:
$ref: "#/components/schemas/PatternListConfSerdeTypeGrok"
allOf:
- oneOf:
- $ref: "#/components/schemas/SerdeTypeAuto"
- $ref: "#/components/schemas/SerdeTypeKvp"
- $ref: "#/components/schemas/SerdeTypeDelim"
- $ref: "#/components/schemas/SerdeTypeCsv"
- $ref: "#/components/schemas/SerdeTypeJson"
- $ref: "#/components/schemas/SerdeTypeRegex"
- $ref: "#/components/schemas/SerdeTypeGrok"
discriminator:
propertyName: type
mapping:
auto: "#/components/schemas/SerdeTypeAuto"
kvp: "#/components/schemas/SerdeTypeKvp"
delim: "#/components/schemas/SerdeTypeDelim"
csv: "#/components/schemas/SerdeTypeCsv"
json: "#/components/schemas/SerdeTypeJson"
regex: "#/components/schemas/SerdeTypeRegex"
grok: "#/components/schemas/SerdeTypeGrok"
FunctionSerde:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- serde
description: Identifier of the Function. Always serde
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSerialize:
type: object
properties:
type:
title: Type
description: Data output format.
type: string
enum:
- csv
- elff
- clf
- kvp
- json
- delim
x-speakeasy-enum-descriptions:
- CSV
- Extended Log File Format
- Common Log Format
- Key=Value Pairs
- JSON Object
- Delimited values
x-speakeasy-unknown-values: allow
fields:
title: Fields to serialize
description: "Required for CSV, ELFF, CLF, and Delimited values. All other formats support wildcard field lists. Examples: host, array*, !host *"
type: array
items:
type: string
srcField:
title: Source field
description: Field containing object to serialize. Leave blank to serialize
top-level event fields.
type: string
dstField:
title: Destination field
description: Field to serialize data to
type: string
cleanFields:
type: boolean
title: Clean fields
description: Clean field names by replacing non-[a-zA-Z0-9] characters with _
pairDelimiter:
type: string
title: Pair delimiter
minLength: 1
description: Delimiter used to separate key=value pairs. Defaults to a single
space character. Should not have common characters with key-value
delimiter.
keyValueDelimiter:
type: string
title: Key-Value delimiter
minLength: 1
description: Delimiter used to separate key and value in pair. Defaults to a
'='. Should not have common characters with pair delimiter.
allOf:
- oneOf:
- $ref: "#/components/schemas/SerializeTypeKvp"
- $ref: "#/components/schemas/SerializeTypeDelim"
- $ref: "#/components/schemas/SerializeTypeCsv"
discriminator:
propertyName: type
mapping:
kvp: "#/components/schemas/SerializeTypeKvp"
delim: "#/components/schemas/SerializeTypeDelim"
csv: "#/components/schemas/SerializeTypeCsv"
FunctionSerialize:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- serialize
description: Identifier of the Function. Always serialize
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSidlookup:
type: object
properties:
fields:
title: Lookup fields
description: Set of expressions matched to lookup responses
type: array
items:
type: object
required:
- expr
properties:
name:
type: string
title: Name
description: Name of the field to set or add to the event.
expr:
type: string
title: Value Expression
description: JavaScript expression to compute the value (can be constant)
disabled:
type: boolean
description: Set to No to disable the evaluation of an individual expression
FunctionSidlookup:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- sidlookup
description: Identifier of the Function. Always sidlookup
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSnmpTrapSerialize:
type: object
properties:
strict:
type: boolean
title: Enforce required fields
description: Prevent event serialization if any required fields are missing.
When disabled, @{product} will attempt to serialize the event even
if required fields are missing, which could cause unexpected
behavior at the downstream receiver.
dropFailedEvents:
type: boolean
title: Drop failed events
description: When disabled, `snmpSerializeErrors` will be set on the event, and
the `__snmpRaw` field will be removed to prevent @{product} from
sending the event from the SNMP Trap Destination
v3User:
type: object
description: SNMPv3 user configuration, including authentication and privacy
protocol settings.
properties:
name:
title: Username
type: string
minLength: 1
description: Username for the SNMPv3 user.
authProtocol:
type: string
enum:
- none
- md5
- sha
- sha224
- sha256
- sha384
- sha512
x-speakeasy-enum-descriptions:
- None
- MD5
- SHA1
- SHA224
- SHA256
- SHA384
- SHA512
title: Authentication protocol
description: Authentication protocol for the SNMPv3 user.
x-speakeasy-unknown-values: allow
privProtocol:
type: string
description: Privacy protocol for SNMPv3 encryption.
allOf:
- oneOf:
- $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNone"
- $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
discriminator:
propertyName: authProtocol
mapping:
none: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNone"
md5: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
sha: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
sha224: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
sha256: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
sha384: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
sha512: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNone"
FunctionSnmpTrapSerialize:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- snmp_trap_serialize
description: Identifier of the Function. Always snmp_trap_serialize
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSort:
type: object
title: Sort Configuration
additionalProperties: false
properties:
sortId:
title: Identifier for the specific sort operation
description: Has to be unique if there are multiple sorts on the pipeline.
type: string
comparisonExpression:
title: Expression to compare two events
description: The expression can access the events via the 'left' and 'right'
properties.
type: string
topN:
title: The amount of events to return sorted
description: Limits the output to N (highest/lowest) events
type: number
maxEvents:
title: The maximum number of events in input
description: Specifies the number of events that can flow into this function
type: number
suppressPreviews:
type: boolean
title: Disable intermediate results
description: Toggle this on to suppress generating previews of intermediate
results
FunctionSort:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- sort
description: Identifier of the Function. Always sort
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaStore:
type: object
title: Store Function Configuration
additionalProperties: false
properties:
type:
title: Output type
description: The type of knowledge object, generated by the function (i.e.,
'lookup')
type: string
destination:
title: Configuration for store destination
description: Configures where and how the data should be stored
type: string
description:
title: Description for object
description: The knowledge object's description
type: string
fieldMapping:
title: Mapping of field names
description: Mapping event property names to output field names
type: object
separator:
title: Separator for CSV output
description: Character to be used as value delimiter in output
type: string
overwrite:
title: Overwrite destination
description: For existing files, an error is thrown if overwrite is false or the
file is replaced if overwrite is true
type: boolean
compress:
title: Compress the output
description: True will compress output, false leaves it as it is and auto
decides based on size
type: string
tee:
title: Tee Results
description: Tee results to the next operator
type: boolean
maxEvents:
title: Maximum number of events
description: Limits how many events can be stored
type: number
suppressPreviews:
title: Suppress previews
description: Suppresses the timer-based export stats generating
type: boolean
FunctionStore:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- store
description: Identifier of the Function. Always store
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaSuppress:
type: object
properties:
keyExpr:
type: string
title: Key expression
description: Suppression key expression used to uniquely identify events to
suppress. For example, `${ip}:${port}` will use fields ip and port
from each event to generate the key.
allow:
type: number
title: Number to allow
minimum: 1
description: The number of events to allow per time period
suppressPeriodSec:
type: number
title: Suppression period (sec)
minimum: 0
description: The number of seconds to suppress events after 'Number to allow'
events are received
dropEventsMode:
type: boolean
title: Drop suppressed events
description: If disabled, suppressed events will be tagged with suppress=1 but
not dropped
maxCacheSize:
type: number
title: Cache size limit
description: The maximum number of keys that can be cached before idle entries
are removed. Leave at default unless you understand the implications
of changing.
cacheIdleTimeoutPeriods:
type: number
title: Suppression period timeout
description: The number of suppression periods 'Suppression Period' of
inactivity before a cache entry is considered idle. Leave at default
unless you understand the implications of changing.
numEventsIdleTimeoutTrigger:
type: number
title: Num events to trigger cache clean-up
description: Check cache for idle sessions every N events when cache size is >
'Maximum Cache Size'. Leave at default unless you understand the
implications of changing.
FunctionSuppress:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- suppress
description: Identifier of the Function. Always suppress
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaTee:
type: object
properties:
command:
type: string
title: Command
description: Command to execute and feed events to, via stdin. One
JSON-formatted event per line.
args:
type: array
title: Command arguments
description: Command-line arguments to pass to the command.
items:
type: string
restartOnExit:
type: boolean
title: Restart on exit
description: Restart the process if it exits and/or we fail to write to it
env:
type: object
title: Environment variables
description: Environment variables to overwrite or set
additionalProperties:
type: string
FunctionTee:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- tee
description: Identifier of the Function. Always tee
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaTrimTimestamp:
type: object
properties:
field:
type: string
title: Field name
description: Name of field in which to save the timestamp. (If empty, timestamp
will not be saved to a field.)
FunctionTrimTimestamp:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- trim_timestamp
description: Identifier of the Function. Always trim_timestamp
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaUnion:
type: object
title: Union Configuration
additionalProperties: false
properties:
searchJobId:
title: Search Job Id
description: The id for this search job.
type: string
stageIds:
title: Stage Ids
description: The stages we are unioning with.
type: array
minItems: 1
items:
type: string
FunctionUnion:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- union
description: Identifier of the Function. Always union
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaUnroll:
type: object
properties:
srcExpr:
type: string
title: Source field expression
description: "Field in which to find/calculate the array to unroll. Example: _raw, _raw.split(/\\n/)"
dstField:
type: string
title: Destination field
description: Field in destination event in which to place the unrolled value
FunctionUnroll:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- unroll
description: Identifier of the Function. Always unroll
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaWindow:
type: object
additionalProperties: false
properties:
eventWindowId:
title: Unique Identifier
description: Identifies the unique ID, used for a event window
type: number
registeredFunctions:
title: Registered Window Functions
description: All window functions, tracked by this event window
type: array
minItems: 1
items:
type: string
tailEventCount:
title: Tail Event Count
description: Number of events to keep before the current event in the window
type: number
headEventCount:
title: Head Event Count
description: Number of events to keep after the current event in the window
type: number
FunctionWindow:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- window
description: Identifier of the Function. Always window
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionConfSchemaXmlUnroll:
type: object
properties:
unroll:
type: string
title: Unroll elements regex
description: "Path to array to unroll. Example: ^root\\.child\\.ElementToUnroll$"
inherit:
type: string
title: Copy elements regex
description: "Regex matching elements to copy into each unrolled event. Example: ^root\\.(childA|childB|childC)$"
unrollIdxField:
type: string
title: Unroll index field
description: Add a field with this name, containing the index at which the item
was located, starting from 0
pretty:
type: boolean
title: Pretty print
description: Pretty print the output XML
FunctionXmlUnroll:
type: object
properties:
__filename:
type: string
description: Path to the JavaScript file that implements the Function.
asyncTimeout:
type: number
description: Maximum time, in milliseconds, that the Function is allowed to run
asynchronously before timing out.
cribl_version:
type: string
description: Minimum Cribl version required by the Function, if applicable.
disabled:
type: boolean
description: If true, the Function is disabled and will not execute
in a Pipeline. Otherwise, false.
group:
type: string
description: Category group the Function belongs to.
handleSignals:
type: boolean
description: If true, the Function handles stream signals such as
flush and close. Otherwise,
false.
id:
type: string
enum:
- xml_unroll
description: Identifier of the Function. Always xml_unroll
loadTime:
type: number
description: Time the Function module was loaded, in milliseconds since the Unix
epoch.
modTime:
type: number
description: Time the Function module was last modified, in milliseconds since
the Unix epoch.
name:
type: string
description: Display name of the Function.
sync:
type: boolean
description: If true, the Function executes synchronously.
Otherwise, false.
uischema:
type: object
additionalProperties: true
description: UI Schema that controls how the Function's configuration form is
rendered.
version:
type: string
description: Version string of the Function.
schema:
type: object
additionalProperties: true
description: JSON Schema document that describes the Function configuration.
required:
- __filename
- group
- id
- loadTime
- modTime
- name
- uischema
- version
FunctionResponse:
oneOf:
- $ref: "#/components/schemas/FunctionAggregateMetrics"
- $ref: "#/components/schemas/FunctionAggregation"
- $ref: "#/components/schemas/FunctionAutoTimestamp"
- $ref: "#/components/schemas/FunctionCef"
- $ref: "#/components/schemas/FunctionChain"
- $ref: "#/components/schemas/FunctionClone"
- $ref: "#/components/schemas/FunctionCode"
- $ref: "#/components/schemas/FunctionComment"
- $ref: "#/components/schemas/FunctionDetectionRules"
- $ref: "#/components/schemas/FunctionDistinct"
- $ref: "#/components/schemas/FunctionDnsLookup"
- $ref: "#/components/schemas/FunctionDrop"
- $ref: "#/components/schemas/FunctionDropDimensions"
- $ref: "#/components/schemas/FunctionDynamicSampling"
- $ref: "#/components/schemas/FunctionEval"
- $ref: "#/components/schemas/FunctionEventBreaker"
- $ref: "#/components/schemas/FunctionEventstats"
- $ref: "#/components/schemas/FunctionExternaldata"
- $ref: "#/components/schemas/FunctionFlatten"
- $ref: "#/components/schemas/FunctionFoldkeys"
- $ref: "#/components/schemas/FunctionGenStats"
- $ref: "#/components/schemas/FunctionGeoip"
- $ref: "#/components/schemas/FunctionGrok"
- $ref: "#/components/schemas/FunctionHandlebars"
- $ref: "#/components/schemas/FunctionJoin"
- $ref: "#/components/schemas/FunctionJsonUnroll"
- $ref: "#/components/schemas/FunctionLakeExport"
- $ref: "#/components/schemas/FunctionLakehouseEngineMetricsNormalizer"
- $ref: "#/components/schemas/FunctionLimit"
- $ref: "#/components/schemas/FunctionLocalSearchDatatypeParser"
- $ref: "#/components/schemas/FunctionLocalSearchRulesetRunner"
- $ref: "#/components/schemas/FunctionLocalSearchSchemaMapper"
- $ref: "#/components/schemas/FunctionLocalSearchTimeRangeNormalizer"
- $ref: "#/components/schemas/FunctionLocalSearchTransformer"
- $ref: "#/components/schemas/FunctionLookup"
- $ref: "#/components/schemas/FunctionMask"
- $ref: "#/components/schemas/FunctionMetricsExport"
- $ref: "#/components/schemas/FunctionMetricsTimeRangeGate"
- $ref: "#/components/schemas/FunctionMvExpand"
- $ref: "#/components/schemas/FunctionMvPull"
- $ref: "#/components/schemas/FunctionNotificationPolicies"
- $ref: "#/components/schemas/FunctionNotifications"
- $ref: "#/components/schemas/FunctionNotify"
- $ref: "#/components/schemas/FunctionNumerify"
- $ref: "#/components/schemas/FunctionOtlpLogs"
- $ref: "#/components/schemas/FunctionOtlpMetrics"
- $ref: "#/components/schemas/FunctionOtlpTraces"
- $ref: "#/components/schemas/FunctionPack"
- $ref: "#/components/schemas/FunctionPivot"
- $ref: "#/components/schemas/FunctionPublishMetrics"
- $ref: "#/components/schemas/FunctionRedis"
- $ref: "#/components/schemas/FunctionRegexExtract"
- $ref: "#/components/schemas/FunctionRegexFilter"
- $ref: "#/components/schemas/FunctionRename"
- $ref: "#/components/schemas/FunctionRollupMetrics"
- $ref: "#/components/schemas/FunctionSampling"
- $ref: "#/components/schemas/FunctionSearchEngineExport"
- $ref: "#/components/schemas/FunctionSend"
- $ref: "#/components/schemas/FunctionSensitiveDataScanner"
- $ref: "#/components/schemas/FunctionSerde"
- $ref: "#/components/schemas/FunctionSerialize"
- $ref: "#/components/schemas/FunctionSidlookup"
- $ref: "#/components/schemas/FunctionSnmpTrapSerialize"
- $ref: "#/components/schemas/FunctionSort"
- $ref: "#/components/schemas/FunctionStore"
- $ref: "#/components/schemas/FunctionSuppress"
- $ref: "#/components/schemas/FunctionTee"
- $ref: "#/components/schemas/FunctionTrimTimestamp"
- $ref: "#/components/schemas/FunctionUnion"
- $ref: "#/components/schemas/FunctionUnroll"
- $ref: "#/components/schemas/FunctionWindow"
- $ref: "#/components/schemas/FunctionXmlUnroll"
discriminator:
propertyName: id
mapping:
aggregate_metrics: "#/components/schemas/FunctionAggregateMetrics"
aggregation: "#/components/schemas/FunctionAggregation"
auto_timestamp: "#/components/schemas/FunctionAutoTimestamp"
cef: "#/components/schemas/FunctionCef"
chain: "#/components/schemas/FunctionChain"
clone: "#/components/schemas/FunctionClone"
code: "#/components/schemas/FunctionCode"
comment: "#/components/schemas/FunctionComment"
detection_rules: "#/components/schemas/FunctionDetectionRules"
distinct: "#/components/schemas/FunctionDistinct"
dns_lookup: "#/components/schemas/FunctionDnsLookup"
drop: "#/components/schemas/FunctionDrop"
drop_dimensions: "#/components/schemas/FunctionDropDimensions"
dynamic_sampling: "#/components/schemas/FunctionDynamicSampling"
eval: "#/components/schemas/FunctionEval"
event_breaker: "#/components/schemas/FunctionEventBreaker"
eventstats: "#/components/schemas/FunctionEventstats"
externaldata: "#/components/schemas/FunctionExternaldata"
flatten: "#/components/schemas/FunctionFlatten"
foldkeys: "#/components/schemas/FunctionFoldkeys"
gen_stats: "#/components/schemas/FunctionGenStats"
geoip: "#/components/schemas/FunctionGeoip"
grok: "#/components/schemas/FunctionGrok"
handlebars: "#/components/schemas/FunctionHandlebars"
join: "#/components/schemas/FunctionJoin"
json_unroll: "#/components/schemas/FunctionJsonUnroll"
lake_export: "#/components/schemas/FunctionLakeExport"
lakehouse_engine_metrics_normalizer: "#/components/schemas/FunctionLakehouseEngineMetricsNormalizer"
limit: "#/components/schemas/FunctionLimit"
local_search_datatype_parser: "#/components/schemas/FunctionLocalSearchDatatypeParser"
local_search_ruleset_runner: "#/components/schemas/FunctionLocalSearchRulesetRunner"
local_search_schema_mapper: "#/components/schemas/FunctionLocalSearchSchemaMapper"
local_search_time_range_normalizer: "#/components/schemas/FunctionLocalSearchTimeRangeNormalizer"
local_search_transformer: "#/components/schemas/FunctionLocalSearchTransformer"
lookup: "#/components/schemas/FunctionLookup"
mask: "#/components/schemas/FunctionMask"
metrics_export: "#/components/schemas/FunctionMetricsExport"
metrics_time_range_gate: "#/components/schemas/FunctionMetricsTimeRangeGate"
mv_expand: "#/components/schemas/FunctionMvExpand"
mv_pull: "#/components/schemas/FunctionMvPull"
notification_policies: "#/components/schemas/FunctionNotificationPolicies"
notifications: "#/components/schemas/FunctionNotifications"
notify: "#/components/schemas/FunctionNotify"
numerify: "#/components/schemas/FunctionNumerify"
otlp_logs: "#/components/schemas/FunctionOtlpLogs"
otlp_metrics: "#/components/schemas/FunctionOtlpMetrics"
otlp_traces: "#/components/schemas/FunctionOtlpTraces"
pack: "#/components/schemas/FunctionPack"
pivot: "#/components/schemas/FunctionPivot"
publish_metrics: "#/components/schemas/FunctionPublishMetrics"
redis: "#/components/schemas/FunctionRedis"
regex_extract: "#/components/schemas/FunctionRegexExtract"
regex_filter: "#/components/schemas/FunctionRegexFilter"
rename: "#/components/schemas/FunctionRename"
rollup_metrics: "#/components/schemas/FunctionRollupMetrics"
sampling: "#/components/schemas/FunctionSampling"
search_engine_export: "#/components/schemas/FunctionSearchEngineExport"
send: "#/components/schemas/FunctionSend"
sensitive_data_scanner: "#/components/schemas/FunctionSensitiveDataScanner"
serde: "#/components/schemas/FunctionSerde"
serialize: "#/components/schemas/FunctionSerialize"
sidlookup: "#/components/schemas/FunctionSidlookup"
snmp_trap_serialize: "#/components/schemas/FunctionSnmpTrapSerialize"
sort: "#/components/schemas/FunctionSort"
store: "#/components/schemas/FunctionStore"
suppress: "#/components/schemas/FunctionSuppress"
tee: "#/components/schemas/FunctionTee"
trim_timestamp: "#/components/schemas/FunctionTrimTimestamp"
union: "#/components/schemas/FunctionUnion"
unroll: "#/components/schemas/FunctionUnroll"
window: "#/components/schemas/FunctionWindow"
xml_unroll: "#/components/schemas/FunctionXmlUnroll"
PipelineFunctionAggregateMetrics:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always aggregate_metrics
type: string
enum:
- aggregate_metrics
examples:
- aggregate_metrics
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaAggregateMetrics"
required:
- timeWindow
- aggregations
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionAggregation:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always aggregation
type: string
enum:
- aggregation
examples:
- aggregation
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaAggregation"
required:
- timeWindow
- aggregations
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionAutoTimestamp:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always auto_timestamp
type: string
enum:
- auto_timestamp
examples:
- auto_timestamp
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaAutoTimestamp"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionCef:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always cef
type: string
enum:
- cef
examples:
- cef
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaCef"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionChain:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always chain
type: string
enum:
- chain
examples:
- chain
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaChain"
required:
- processor
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionClone:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always clone
type: string
enum:
- clone
examples:
- clone
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaClone"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionCode:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always code
type: string
enum:
- code
examples:
- code
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaCode"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionComment:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always comment
type: string
enum:
- comment
examples:
- comment
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaComment"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDetectionRules:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always detection_rules
type: string
enum:
- detection_rules
examples:
- detection_rules
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaDetectionRules"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDistinct:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always distinct
type: string
enum:
- distinct
examples:
- distinct
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaDistinct"
required:
- groupBy
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDnsLookup:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always dns_lookup
type: string
enum:
- dns_lookup
examples:
- dns_lookup
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaDnsLookup"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDrop:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always drop
type: string
enum:
- drop
examples:
- drop
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaDrop"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDropDimensions:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always drop_dimensions
type: string
enum:
- drop_dimensions
examples:
- drop_dimensions
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaDropDimensions"
required:
- timeWindow
- dropDimensions
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionDynamicSampling:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always dynamic_sampling
type: string
enum:
- dynamic_sampling
examples:
- dynamic_sampling
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaDynamicSampling"
required:
- mode
- keyExpr
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionEval:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always eval
type: string
enum:
- eval
examples:
- eval
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaEval"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionEventBreaker:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always event_breaker
type: string
enum:
- event_breaker
examples:
- event_breaker
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaEventBreaker"
required:
- existingOrNew
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionEventstats:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always eventstats
type: string
enum:
- eventstats
examples:
- eventstats
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaEventstats"
required:
- aggregations
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionExternaldata:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always externaldata
type: string
enum:
- externaldata
examples:
- externaldata
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaExternaldata"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionFlatten:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always flatten
type: string
enum:
- flatten
examples:
- flatten
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaFlatten"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionFoldkeys:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always foldkeys
type: string
enum:
- foldkeys
examples:
- foldkeys
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaFoldkeys"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionGenStats:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always gen_stats
type: string
enum:
- gen_stats
examples:
- gen_stats
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaGenStats"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionGeoip:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always geoip
type: string
enum:
- geoip
examples:
- geoip
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaGeoip"
required:
- file
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionGrok:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always grok
type: string
enum:
- grok
examples:
- grok
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaGrok"
required:
- pattern
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionHandlebars:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always handlebars
type: string
enum:
- handlebars
examples:
- handlebars
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaHandlebars"
required:
- templates
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionJoin:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always join
type: string
enum:
- join
examples:
- join
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaJoin"
required:
- fieldConditions
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionJsonUnroll:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always json_unroll
type: string
enum:
- json_unroll
examples:
- json_unroll
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaJsonUnroll"
required:
- path
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLakeExport:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always lake_export
type: string
enum:
- lake_export
examples:
- lake_export
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaLakeExport"
required:
- dataset
- searchJobId
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLakehouseEngineMetricsNormalizer:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
lakehouse_engine_metrics_normalizer
type: string
enum:
- lakehouse_engine_metrics_normalizer
examples:
- lakehouse_engine_metrics_normalizer
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLakehouseEngineMetricsNormalizer"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLimit:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always limit
type: string
enum:
- limit
examples:
- limit
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLimit"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLocalSearchDatatypeParser:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
local_search_datatype_parser
type: string
enum:
- local_search_datatype_parser
examples:
- local_search_datatype_parser
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLocalSearchDatatypeParser"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLocalSearchRulesetRunner:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
local_search_ruleset_runner
type: string
enum:
- local_search_ruleset_runner
examples:
- local_search_ruleset_runner
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLocalSearchRulesetRunner"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLocalSearchSchemaMapper:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
local_search_schema_mapper
type: string
enum:
- local_search_schema_mapper
examples:
- local_search_schema_mapper
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLocalSearchSchemaMapper"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLocalSearchTimeRangeNormalizer:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
local_search_time_range_normalizer
type: string
enum:
- local_search_time_range_normalizer
examples:
- local_search_time_range_normalizer
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLocalSearchTimeRangeNormalizer"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLocalSearchTransformer:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
local_search_transformer
type: string
enum:
- local_search_transformer
examples:
- local_search_transformer
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaLocalSearchTransformer"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionLookup:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always lookup
type: string
enum:
- lookup
examples:
- lookup
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaLookup"
required:
- file
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionMask:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always mask
type: string
enum:
- mask
examples:
- mask
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaMask"
required:
- rules
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionMetricsExport:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always metrics_export
type: string
enum:
- metrics_export
examples:
- metrics_export
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaMetricsExport"
required:
- dataset
- searchJobId
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionMetricsTimeRangeGate:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
metrics_time_range_gate
type: string
enum:
- metrics_time_range_gate
examples:
- metrics_time_range_gate
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaMetricsTimeRangeGate"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionMvExpand:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always mv_expand
type: string
enum:
- mv_expand
examples:
- mv_expand
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaMvExpand"
required:
- sourceFields
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionMvPull:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always mv_pull
type: string
enum:
- mv_pull
examples:
- mv_pull
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaMvPull"
required:
- arrayPath
- relativeKeyPath
- relativeValuePath
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionNotificationPolicies:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always notification_policies
type: string
enum:
- notification_policies
examples:
- notification_policies
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaNotificationPolicies"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionNotifications:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always notifications
type: string
enum:
- notifications
examples:
- notifications
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaNotifications"
required:
- id
- field
- deduplicate
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionNotify:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always notify
type: string
enum:
- notify
examples:
- notify
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaNotify"
required:
- searchId
- notificationId
- savedQueryId
- group
- searchUrl
- messagesEndpoint
- authToken
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionNumerify:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always numerify
type: string
enum:
- numerify
examples:
- numerify
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaNumerify"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionOtlpLogs:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always otlp_logs
type: string
enum:
- otlp_logs
examples:
- otlp_logs
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaOtlpLogs"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionOtlpMetrics:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always otlp_metrics
type: string
enum:
- otlp_metrics
examples:
- otlp_metrics
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaOtlpMetrics"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionOtlpTraces:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always otlp_traces
type: string
enum:
- otlp_traces
examples:
- otlp_traces
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaOtlpTraces"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionPack:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always pack
type: string
enum:
- pack
examples:
- pack
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaPack"
required:
- unpackedFields
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionPivot:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always pivot
type: string
enum:
- pivot
examples:
- pivot
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaPivot"
required:
- labelField
- dataFields
- qualifierFields
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionPublishMetrics:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always publish_metrics
type: string
enum:
- publish_metrics
examples:
- publish_metrics
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaPublishMetrics"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionRedis:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always redis
type: string
enum:
- redis
examples:
- redis
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaRedis"
required:
- commands
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionRegexExtract:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always regex_extract
type: string
enum:
- regex_extract
examples:
- regex_extract
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaRegexExtract"
required:
- regex
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionRegexFilter:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always regex_filter
type: string
enum:
- regex_filter
examples:
- regex_filter
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaRegexFilter"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionRename:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always rename
type: string
enum:
- rename
examples:
- rename
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaRename"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionRollupMetrics:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always rollup_metrics
type: string
enum:
- rollup_metrics
examples:
- rollup_metrics
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaRollupMetrics"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSampling:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always sampling
type: string
enum:
- sampling
examples:
- sampling
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaSampling"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSearchEngineExport:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always search_engine_export
type: string
enum:
- search_engine_export
examples:
- search_engine_export
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSearchEngineExport"
required:
- dataset
- searchJobId
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSend:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always send
type: string
enum:
- send
examples:
- send
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSend"
required:
- searchId
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSensitiveDataScanner:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always
sensitive_data_scanner
type: string
enum:
- sensitive_data_scanner
examples:
- sensitive_data_scanner
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSensitiveDataScanner"
required:
- rules
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSerde:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always serde
type: string
enum:
- serde
examples:
- serde
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSerde"
required:
- mode
- type
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSerialize:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always serialize
type: string
enum:
- serialize
examples:
- serialize
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSerialize"
required:
- type
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSidlookup:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always sidlookup
type: string
enum:
- sidlookup
examples:
- sidlookup
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaSidlookup"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSnmpTrapSerialize:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always snmp_trap_serialize
type: string
enum:
- snmp_trap_serialize
examples:
- snmp_trap_serialize
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaSnmpTrapSerialize"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSort:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always sort
type: string
enum:
- sort
examples:
- sort
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSort"
required:
- comparisonExpression
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionStore:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always store
type: string
enum:
- store
examples:
- store
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaStore"
required:
- type
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionSuppress:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always suppress
type: string
enum:
- suppress
examples:
- suppress
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaSuppress"
required:
- keyExpr
- allow
- suppressPeriodSec
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionTee:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always tee
type: string
enum:
- tee
examples:
- tee
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaTee"
required:
- command
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionTrimTimestamp:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always trim_timestamp
type: string
enum:
- trim_timestamp
examples:
- trim_timestamp
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
$ref: "#/components/schemas/FunctionConfSchemaTrimTimestamp"
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionUnion:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always union
type: string
enum:
- union
examples:
- union
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaUnion"
required:
- searchJobId
- stageIds
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionUnroll:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always unroll
type: string
enum:
- unroll
examples:
- unroll
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaUnroll"
required:
- srcExpr
- dstField
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionWindow:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always window
type: string
enum:
- window
examples:
- window
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaWindow"
required:
- eventWindowId
- registeredFunctions
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionXmlUnroll:
type: object
required:
- id
- conf
additionalProperties: false
properties:
filter:
title: Filter
description: JavaScript expression that selects data to pass through the Function.
type: string
id:
title: ID
description: Identifier of the Function. Always xml_unroll
type: string
enum:
- xml_unroll
examples:
- xml_unroll
description:
title: Description
description: Brief description of the Pipeline function.
type: string
disabled:
title: Disabled
description: If true, disable the Pipeline function so that events
are not passed through it. Otherwise, false.
type: boolean
final:
title: Final
description: If true, stop passing events to downstream Pipeline
Functions after the Function executes. Otherwise,
false.
type: boolean
conf:
allOf:
- $ref: "#/components/schemas/FunctionConfSchemaXmlUnroll"
required:
- unroll
description: Configuration specific to the Pipeline Function.
groupId:
title: Group ID
description: Unique identifier of the group that contains the Pipeline Function.
type: string
PipelineFunctionConf:
oneOf:
- $ref: "#/components/schemas/PipelineFunctionAggregateMetrics"
- $ref: "#/components/schemas/PipelineFunctionAggregation"
- $ref: "#/components/schemas/PipelineFunctionAutoTimestamp"
- $ref: "#/components/schemas/PipelineFunctionCef"
- $ref: "#/components/schemas/PipelineFunctionChain"
- $ref: "#/components/schemas/PipelineFunctionClone"
- $ref: "#/components/schemas/PipelineFunctionCode"
- $ref: "#/components/schemas/PipelineFunctionComment"
- $ref: "#/components/schemas/PipelineFunctionDetectionRules"
- $ref: "#/components/schemas/PipelineFunctionDistinct"
- $ref: "#/components/schemas/PipelineFunctionDnsLookup"
- $ref: "#/components/schemas/PipelineFunctionDrop"
- $ref: "#/components/schemas/PipelineFunctionDropDimensions"
- $ref: "#/components/schemas/PipelineFunctionDynamicSampling"
- $ref: "#/components/schemas/PipelineFunctionEval"
- $ref: "#/components/schemas/PipelineFunctionEventBreaker"
- $ref: "#/components/schemas/PipelineFunctionEventstats"
- $ref: "#/components/schemas/PipelineFunctionExternaldata"
- $ref: "#/components/schemas/PipelineFunctionFlatten"
- $ref: "#/components/schemas/PipelineFunctionFoldkeys"
- $ref: "#/components/schemas/PipelineFunctionGenStats"
- $ref: "#/components/schemas/PipelineFunctionGeoip"
- $ref: "#/components/schemas/PipelineFunctionGrok"
- $ref: "#/components/schemas/PipelineFunctionHandlebars"
- $ref: "#/components/schemas/PipelineFunctionJoin"
- $ref: "#/components/schemas/PipelineFunctionJsonUnroll"
- $ref: "#/components/schemas/PipelineFunctionLakeExport"
- $ref: "#/components/schemas/PipelineFunctionLakehouseEngineMetricsNormalizer"
- $ref: "#/components/schemas/PipelineFunctionLimit"
- $ref: "#/components/schemas/PipelineFunctionLocalSearchDatatypeParser"
- $ref: "#/components/schemas/PipelineFunctionLocalSearchRulesetRunner"
- $ref: "#/components/schemas/PipelineFunctionLocalSearchSchemaMapper"
- $ref: "#/components/schemas/PipelineFunctionLocalSearchTimeRangeNormalizer"
- $ref: "#/components/schemas/PipelineFunctionLocalSearchTransformer"
- $ref: "#/components/schemas/PipelineFunctionLookup"
- $ref: "#/components/schemas/PipelineFunctionMask"
- $ref: "#/components/schemas/PipelineFunctionMetricsExport"
- $ref: "#/components/schemas/PipelineFunctionMetricsTimeRangeGate"
- $ref: "#/components/schemas/PipelineFunctionMvExpand"
- $ref: "#/components/schemas/PipelineFunctionMvPull"
- $ref: "#/components/schemas/PipelineFunctionNotificationPolicies"
- $ref: "#/components/schemas/PipelineFunctionNotifications"
- $ref: "#/components/schemas/PipelineFunctionNotify"
- $ref: "#/components/schemas/PipelineFunctionNumerify"
- $ref: "#/components/schemas/PipelineFunctionOtlpLogs"
- $ref: "#/components/schemas/PipelineFunctionOtlpMetrics"
- $ref: "#/components/schemas/PipelineFunctionOtlpTraces"
- $ref: "#/components/schemas/PipelineFunctionPack"
- $ref: "#/components/schemas/PipelineFunctionPivot"
- $ref: "#/components/schemas/PipelineFunctionPublishMetrics"
- $ref: "#/components/schemas/PipelineFunctionRedis"
- $ref: "#/components/schemas/PipelineFunctionRegexExtract"
- $ref: "#/components/schemas/PipelineFunctionRegexFilter"
- $ref: "#/components/schemas/PipelineFunctionRename"
- $ref: "#/components/schemas/PipelineFunctionRollupMetrics"
- $ref: "#/components/schemas/PipelineFunctionSampling"
- $ref: "#/components/schemas/PipelineFunctionSearchEngineExport"
- $ref: "#/components/schemas/PipelineFunctionSend"
- $ref: "#/components/schemas/PipelineFunctionSensitiveDataScanner"
- $ref: "#/components/schemas/PipelineFunctionSerde"
- $ref: "#/components/schemas/PipelineFunctionSerialize"
- $ref: "#/components/schemas/PipelineFunctionSidlookup"
- $ref: "#/components/schemas/PipelineFunctionSnmpTrapSerialize"
- $ref: "#/components/schemas/PipelineFunctionSort"
- $ref: "#/components/schemas/PipelineFunctionStore"
- $ref: "#/components/schemas/PipelineFunctionSuppress"
- $ref: "#/components/schemas/PipelineFunctionTee"
- $ref: "#/components/schemas/PipelineFunctionTrimTimestamp"
- $ref: "#/components/schemas/PipelineFunctionUnion"
- $ref: "#/components/schemas/PipelineFunctionUnroll"
- $ref: "#/components/schemas/PipelineFunctionWindow"
- $ref: "#/components/schemas/PipelineFunctionXmlUnroll"
discriminator:
propertyName: id
mapping:
aggregate_metrics: "#/components/schemas/PipelineFunctionAggregateMetrics"
aggregation: "#/components/schemas/PipelineFunctionAggregation"
auto_timestamp: "#/components/schemas/PipelineFunctionAutoTimestamp"
cef: "#/components/schemas/PipelineFunctionCef"
chain: "#/components/schemas/PipelineFunctionChain"
clone: "#/components/schemas/PipelineFunctionClone"
code: "#/components/schemas/PipelineFunctionCode"
comment: "#/components/schemas/PipelineFunctionComment"
detection_rules: "#/components/schemas/PipelineFunctionDetectionRules"
distinct: "#/components/schemas/PipelineFunctionDistinct"
dns_lookup: "#/components/schemas/PipelineFunctionDnsLookup"
drop: "#/components/schemas/PipelineFunctionDrop"
drop_dimensions: "#/components/schemas/PipelineFunctionDropDimensions"
dynamic_sampling: "#/components/schemas/PipelineFunctionDynamicSampling"
eval: "#/components/schemas/PipelineFunctionEval"
event_breaker: "#/components/schemas/PipelineFunctionEventBreaker"
eventstats: "#/components/schemas/PipelineFunctionEventstats"
externaldata: "#/components/schemas/PipelineFunctionExternaldata"
flatten: "#/components/schemas/PipelineFunctionFlatten"
foldkeys: "#/components/schemas/PipelineFunctionFoldkeys"
gen_stats: "#/components/schemas/PipelineFunctionGenStats"
geoip: "#/components/schemas/PipelineFunctionGeoip"
grok: "#/components/schemas/PipelineFunctionGrok"
handlebars: "#/components/schemas/PipelineFunctionHandlebars"
join: "#/components/schemas/PipelineFunctionJoin"
json_unroll: "#/components/schemas/PipelineFunctionJsonUnroll"
lake_export: "#/components/schemas/PipelineFunctionLakeExport"
lakehouse_engine_metrics_normalizer: "#/components/schemas/PipelineFunctionLakehouseEngineMetricsNormalizer"
limit: "#/components/schemas/PipelineFunctionLimit"
local_search_datatype_parser: "#/components/schemas/PipelineFunctionLocalSearchDatatypeParser"
local_search_ruleset_runner: "#/components/schemas/PipelineFunctionLocalSearchRulesetRunner"
local_search_schema_mapper: "#/components/schemas/PipelineFunctionLocalSearchSchemaMapper"
local_search_time_range_normalizer: "#/components/schemas/PipelineFunctionLocalSearchTimeRangeNormalizer"
local_search_transformer: "#/components/schemas/PipelineFunctionLocalSearchTransformer"
lookup: "#/components/schemas/PipelineFunctionLookup"
mask: "#/components/schemas/PipelineFunctionMask"
metrics_export: "#/components/schemas/PipelineFunctionMetricsExport"
metrics_time_range_gate: "#/components/schemas/PipelineFunctionMetricsTimeRangeGate"
mv_expand: "#/components/schemas/PipelineFunctionMvExpand"
mv_pull: "#/components/schemas/PipelineFunctionMvPull"
notification_policies: "#/components/schemas/PipelineFunctionNotificationPolicies"
notifications: "#/components/schemas/PipelineFunctionNotifications"
notify: "#/components/schemas/PipelineFunctionNotify"
numerify: "#/components/schemas/PipelineFunctionNumerify"
otlp_logs: "#/components/schemas/PipelineFunctionOtlpLogs"
otlp_metrics: "#/components/schemas/PipelineFunctionOtlpMetrics"
otlp_traces: "#/components/schemas/PipelineFunctionOtlpTraces"
pack: "#/components/schemas/PipelineFunctionPack"
pivot: "#/components/schemas/PipelineFunctionPivot"
publish_metrics: "#/components/schemas/PipelineFunctionPublishMetrics"
redis: "#/components/schemas/PipelineFunctionRedis"
regex_extract: "#/components/schemas/PipelineFunctionRegexExtract"
regex_filter: "#/components/schemas/PipelineFunctionRegexFilter"
rename: "#/components/schemas/PipelineFunctionRename"
rollup_metrics: "#/components/schemas/PipelineFunctionRollupMetrics"
sampling: "#/components/schemas/PipelineFunctionSampling"
search_engine_export: "#/components/schemas/PipelineFunctionSearchEngineExport"
send: "#/components/schemas/PipelineFunctionSend"
sensitive_data_scanner: "#/components/schemas/PipelineFunctionSensitiveDataScanner"
serde: "#/components/schemas/PipelineFunctionSerde"
serialize: "#/components/schemas/PipelineFunctionSerialize"
sidlookup: "#/components/schemas/PipelineFunctionSidlookup"
snmp_trap_serialize: "#/components/schemas/PipelineFunctionSnmpTrapSerialize"
sort: "#/components/schemas/PipelineFunctionSort"
store: "#/components/schemas/PipelineFunctionStore"
suppress: "#/components/schemas/PipelineFunctionSuppress"
tee: "#/components/schemas/PipelineFunctionTee"
trim_timestamp: "#/components/schemas/PipelineFunctionTrimTimestamp"
union: "#/components/schemas/PipelineFunctionUnion"
unroll: "#/components/schemas/PipelineFunctionUnroll"
window: "#/components/schemas/PipelineFunctionWindow"
xml_unroll: "#/components/schemas/PipelineFunctionXmlUnroll"
CollectorBase:
type: object
required:
- type
- conf
properties:
type:
type: string
description: Collector type
conf:
type: object
description: Collector configuration
destructive:
type: boolean
description: Delete any files collected (where applicable)
encoding:
type: string
description: Character encoding to use when parsing ingested data.
description: Base collector schema
AzureBlobAuthTypeManual:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeManual"
description: Discriminator value.
connectionString:
type: string
title: Connection string
description: Enter your Azure storage account Connection String. If left blank,
Cribl Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.
__template_connectionString:
type: string
description: Binds 'connectionString' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'connectionString' at runtime.
required:
- connectionString
AzureBlobAuthTypeSecret:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeSecret"
description: Discriminator value.
textSecret:
type: string
title: Connection string (text secret)
description: Text secret
required:
- textSecret
AzureBlobAuthTypeClientSecret:
type: object
properties:
authType:
enum:
- clientSecret
type: string
description: Discriminator value.
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
clientTextSecret:
type: string
title: Client secret (text secret)
description: Text secret containing the client secret
endpointSuffix:
type: string
title: Endpoint suffix
description: The endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'storageAccountName' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_endpointSuffix:
type: string
description: Binds 'endpointSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpointSuffix' at
runtime.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at runtime.
required:
- storageAccountName
- tenantId
- clientId
- clientTextSecret
AzureBlobAuthTypeClientCert:
type: object
properties:
authType:
enum:
- clientCert
type: string
description: Discriminator value.
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
certificate:
$ref: "#/components/schemas/CertificateTypeAzureBlobAuthTypeClientCert"
description: Certificate credentials for the service principal.
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
endpointSuffix:
type: string
title: Endpoint suffix
description: The endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
required:
- storageAccountName
- tenantId
- clientId
- certificate
AzureBlobCollectorConf:
type: object
title: ""
required:
- containerName
properties:
outputName:
type: string
title: Auto-populate from
description: An optional predefined Destination that will be used to
auto-populate Collector settings
authType:
title: Authentication method
type: string
enum:
- manual
- secret
- clientSecret
- clientCert
description: Enter authentication data directly, or select a secret referencing
your auth data
x-speakeasy-unknown-values: allow
containerName:
type: string
title: Container name
minLength: 1
description: Container to collect from. This value can be a constant, or a
JavaScript expression that can only be evaluated at init time.
Example referencing a Global Variable: myBucket-${C.vars.myVar}
path:
type: string
title: Path
description: The directory from which to collect data. Templating is supported,
such as myDir/${datacenter}/${host}/${app}/. Time-based tokens are
supported, such as myOtherDir/${_time:%Y}/${_time:%m}/${_time:%d}/.
minLength: 1
extractors:
type: array
title: Path extractors
additionalProperties: false
items:
type: object
required:
- key
- expression
properties:
key:
type: string
title: Token
description: A token from the template path, such as epoch
expression:
type: string
title: Extractor Expression
description: "A JavaScript expression that accesses a corresponding through the value variable and evaluates the token to populate event fields. Example: {date: new Date(+value*1000)}"
description: 'Extractors allow use of template tokens as context for expressions
that enrich discovery results. For example, given a template
/path/${epoch}, an extractor under key "epoch" with an expression
{date: new Date(+value*1000)} will enrich discovery results with a
human-readable "date" field.'
recurse:
type: boolean
title: Recursive
description: Recurse through subdirectories
includeMetadata:
type: boolean
title: Include metadata
description: "Include Azure Blob metadata in collected events. In each event, metadata will be located at: __collectible.metadata."
includeTags:
type: boolean
title: Include tags
description: "Include Azure Blob tags in collected events. In each event, tags will be located at: __collectible.tags. Disable this feature when using a Shared Access Signature Connection String, to prevent errors."
maxBatchSize:
type: number
title: Batch size limit
description: Maximum number of metadata objects to batch before recording as
results
minimum: 1
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disable Collector event time filtering when a date range is specified
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will abort if a chunk cannot be downloaded within the
time specified.
maximum: 3600
minimum: 1
connectionString:
type: string
title: Connection string
description: Enter your Azure storage account Connection String. If left blank,
Cribl Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.
__template_connectionString:
type: string
description: Binds 'connectionString' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'connectionString' at runtime.
textSecret:
type: string
title: Connection string (text secret)
description: Text secret
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'storageAccountName' at runtime.
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
clientId:
type: string
title: Client ID
description: The service principal's client ID
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
clientTextSecret:
type: string
title: Client secret (text secret)
description: Text secret containing the client secret
endpointSuffix:
type: string
title: Endpoint suffix
description: The endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
__template_endpointSuffix:
type: string
description: Binds 'endpointSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpointSuffix' at
runtime.
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at runtime.
certificate:
$ref: "#/components/schemas/CertificateTypeAzureBlobAuthTypeClientCert"
description: Certificate credentials for the service principal.
__template_containerName:
type: string
description: Binds 'containerName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'containerName' at runtime.
__template_path:
type: string
description: Binds 'path' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'path' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/AzureBlobAuthTypeManual"
- $ref: "#/components/schemas/AzureBlobAuthTypeSecret"
- $ref: "#/components/schemas/AzureBlobAuthTypeClientSecret"
- $ref: "#/components/schemas/AzureBlobAuthTypeClientCert"
discriminator:
propertyName: authType
mapping:
manual: "#/components/schemas/AzureBlobAuthTypeManual"
secret: "#/components/schemas/AzureBlobAuthTypeSecret"
clientSecret: "#/components/schemas/AzureBlobAuthTypeClientSecret"
clientCert: "#/components/schemas/AzureBlobAuthTypeClientCert"
CollectorAzureBlob:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- azure_blob
description: Collector type
conf:
$ref: "#/components/schemas/AzureBlobCollectorConf"
description: Configuration specific to the AzureBlob Collector.
description: AzureBlob collector configuration
CriblLakeCollectorConf:
type: object
title: ""
required:
- dataset
properties:
storageLocationId:
type: string
title: Storage location
description: Storage location for the Lake Dataset
dataset:
type: string
title: Lake Dataset
description: Lake dataset to collect data from.
__template_dataset:
type: string
description: Binds 'dataset' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'dataset' at runtime.
CollectorCriblLake:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- cribl_lake
description: Collector type
conf:
$ref: "#/components/schemas/CriblLakeCollectorConf"
description: Configuration specific to the CriblLake Collector.
description: CriblLake collector configuration
DatabaseCollectorConf:
type: object
title: ""
required:
- connectionId
- query
properties:
connectionId:
type: string
title: Connection
description: Select an existing Connection, or go to Knowledge > Database
Connections to add one
query:
type: string
title: SQL Query
description: An expression that resolves to the query string for selecting data
from the database. Has access to the special ${earliest} and
${latest} variables, which will resolve to the Collector run's start
and end time.
minLength: 1
queryValidationEnabled:
type: boolean
title: Validate Query
description: "Enforces a basic query validation that allows only a single 'select' statement. Disable for more complex queries or when using semicolons. Caution: Disabling query validation allows DDL and DML statements to be executed, which could be destructive to your database."
defaultBreakers:
$ref: "#/components/schemas/HiddenDefaultBreakersOptionsDatabaseCollectorConf"
description: Hidden Default Breakers
__scheduling:
type: object
description: Internal settings for scheduled execution of this Collector.
properties:
stateTracking:
type: object
description: Settings for tracking collection state between consecutive
scheduled executions.
properties:
enabled:
type: boolean
title: Enabled
description: Enable tracking of collection progress between consecutive
scheduled executions.
__template_query:
type: string
description: Binds 'query' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'query' at runtime.
CollectorDatabase:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- database
description: Collector type
conf:
$ref: "#/components/schemas/DatabaseCollectorConf"
description: Configuration specific to the Database Collector.
description: Database collector configuration
FilesystemCollectorConf:
type: object
title: ""
required:
- path
properties:
outputName:
type: string
title: Auto-populate from
description: Select a predefined configuration (a Destination) to auto-populate
Collector settings
path:
type: string
title: Directory
description: The directory from which to collect data. Templating is supported,
such as /myDir/${datacenter}/${host}/${app}/. Time-based tokens are
also supported, such as
/myOtherDir/${_time:%Y}/${_time:%m}/${_time:%d}/.
minLength: 1
extractors:
type: array
title: Path extractors
additionalProperties: false
items:
type: object
required:
- key
- expression
properties:
key:
type: string
title: Token
description: A token from the template directory, such as epoch
expression:
type: string
title: Extractor expression
description: 'JavaScript expression that receives token under "value" variable,
and evaluates to populate event fields, such as {date: new
Date(+value*1000)}'
description: 'Allows using template tokens as context for expressions that
enrich discovery results. For example, given a template
/path/${epoch}, an extractor under key "epoch" with an expression
{date: new Date(+value*1000)}, will enrich discovery results with a
human readable "date" field.'
recurse:
type: boolean
title: Recursive
description: Recurse through subdirectories
maxBatchSize:
type: number
title: Batch size limit (files)
description: Maximum number of metadata files to batch before recording as results
minimum: 1
__template_path:
type: string
description: Binds 'path' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'path' at runtime.
CollectorFilesystem:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- filesystem
description: Collector type
conf:
$ref: "#/components/schemas/FilesystemCollectorConf"
description: Configuration specific to the Filesystem Collector.
description: Filesystem collector configuration
GoogleCloudStorageAuthTypeAuto:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsGoogleCloudStorageAuthTypeAuto"
description: Discriminator value.
GoogleCloudStorageAuthTypeManual:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeManual"
description: Discriminator value.
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of Google Cloud service account credentials (JSON keys)
file. To upload a file, click the upload button at this field's
upper right.
required:
- serviceAccountCredentials
GoogleCloudStorageAuthTypeSecret:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeSecret"
description: Discriminator value.
textSecret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret that references your
credentials
required:
- textSecret
GoogleCloudStorageCollectorConf:
type: object
title: ""
required:
- bucket
properties:
outputName:
type: string
title: Auto-populate from
description: Name of the predefined Destination that will be used to
auto-populate Collector settings
bucket:
type: string
title: Bucket name
minLength: 1
description: "Name of the bucket to collect from. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`."
path:
type: string
title: Path
description: The directory from which to collect data. Templating is supported,
such as myDir/${datacenter}/${host}/${app}/. Time-based tokens are
also supported, such as
myOtherDir/${_time:%Y}/${_time:%m}/${_time:%d}/.
minLength: 1
extractors:
type: array
title: Path extractors
additionalProperties: false
items:
type: object
required:
- key
- expression
properties:
key:
type: string
title: Token
description: A token from the template path, such as epoch
expression:
type: string
title: Extractor Expression
description: 'JavaScript expression that receives token under "value" variable,
and evaluates to populate event fields, such as {date: new
Date(+value*1000)}'
description: 'Allows using template tokens as context for expressions that
enrich discovery results. For example, given a template
/path/${epoch}, an extractor under key "epoch" with an expression
{date: new Date(+value*1000)}, will enrich discovery results with a
human readable "date" field.'
endpoint:
type: string
title: Endpoint
description: Google Cloud Storage service endpoint. If empty, the endpoint will
default to https://storage.googleapis.com.
disableTimeFilter:
type: boolean
title: Disable time filter
description: Used to disable Collector event time filtering when a date range is
specified
recurse:
type: boolean
title: Recursive
description: Recurse through subdirectories
maxBatchSize:
type: number
title: Batch size limit (objects)
description: Maximum number of metadata objects to batch before recording as
results
minimum: 1
authType:
title: Authentication method
type: string
enum:
- auto
- manual
- secret
description: Enter account credentials manually, select a secret that references
your credentials, or use Google Application Default Credentials
x-speakeasy-unknown-values: allow
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will abort if a chunk cannot be downloaded within the
time specified.
maximum: 3600
minimum: 1
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of Google Cloud service account credentials (JSON keys)
file. To upload a file, click the upload button at this field's
upper right.
textSecret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret that references your
credentials
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_path:
type: string
description: Binds 'path' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'path' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/GoogleCloudStorageAuthTypeAuto"
- $ref: "#/components/schemas/GoogleCloudStorageAuthTypeManual"
- $ref: "#/components/schemas/GoogleCloudStorageAuthTypeSecret"
discriminator:
propertyName: authType
mapping:
auto: "#/components/schemas/GoogleCloudStorageAuthTypeAuto"
manual: "#/components/schemas/GoogleCloudStorageAuthTypeManual"
secret: "#/components/schemas/GoogleCloudStorageAuthTypeSecret"
CollectorGoogleCloudStorage:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- google_cloud_storage
description: Collector type
conf:
$ref: "#/components/schemas/GoogleCloudStorageCollectorConf"
description: Configuration specific to the GoogleCloudStorage Collector.
description: GoogleCloudStorage collector configuration
HealthCheckCollectMethodGet:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodGet"
description: Discriminator value.
collectRequestParams:
title: Health check parameters
description: Optional health check request parameters.
type: array
items:
type: object
required:
- name
- value
properties:
name:
title: Name
type: string
description: Parameter name
value:
title: Value
type: string
description: JavaScript expression to compute the parameter value (can be a
constant).
HealthCheckCollectMethodPost:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPost"
description: Discriminator value.
collectRequestParams:
title: Health check parameters
description: Optional health check request parameters.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfHealthCheckCollectMethodPost"
HealthCheckCollectMethodPostWithBody:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody"
description: Discriminator value.
collectBody:
type: string
title: Health check POST Body
description: "Template for POST body to send with the health check request. You can reference parameters from the Discover response, using template params of the form: ${variable}."
HealthCheckAuthenticationNone:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
HealthCheckAuthenticationBasic:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic"
description: Discriminator value.
username:
type: string
title: Username
description: Basic authentication username
password:
type: string
title: Password
description: Basic authentication password
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
required:
- username
- password
HealthCheckAuthenticationBasicSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret"
description: Discriminator value.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
required:
- credentialsSecret
HealthCheckAuthenticationLogin:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLogin"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
username:
type: string
title: Username
description: Login username
minLength: 1
password:
type: string
title: Password
description: Login password
minLength: 1
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request, ${username} and
${password} are used to specify location of these attributes in the
message
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
authHeaderExpr:
type: string
title: Authorize Expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication Headers
description: Optional authentication request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationLogin"
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
__template_tokenRespAttribute:
type: string
description: Binds 'tokenRespAttribute' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'tokenRespAttribute' at runtime.
required:
- loginUrl
- username
- password
- loginBody
- authHeaderExpr
HealthCheckAuthenticationLoginSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLoginSecret"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for login API call, this call is expected to be a POST.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your login
credentials
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request, ${username} and
${password} are used to specify location of these attributes in the
message
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. If left blank, the entire response body will be used to
derive the authorization header.
authHeaderExpr:
type: string
title: Authorize Expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication Headers
description: Optional authentication request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationLogin"
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_tokenRespAttribute:
type: string
description: Binds 'tokenRespAttribute' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'tokenRespAttribute' at runtime.
required:
- loginUrl
- credentialsSecret
- loginBody
- authHeaderExpr
HealthCheckAuthenticationOauth:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauth"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for the OAuth API call. This call is expected to be a
POST.
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
clientSecretParamName:
type: string
title: Client secret parameter
description: Parameter name that contains client secret. Defaults to
'client_secret', and is automatically added to request parameters.
clientSecretParamValue:
type: string
title: Client secret value
description: Secret value to add to HTTP requests as the 'client secret'
parameter. Stored on disk encrypted, and is automatically added to
request parameters
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/AuthRequestParamConfHealthCheckAuthenticationOauth"
authRequestHeaders:
title: Authentication headers
description: Optional authentication request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationOauth"
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth"
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_tokenRespAttribute:
type: string
description: Binds 'tokenRespAttribute' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'tokenRespAttribute' at runtime.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
required:
- loginUrl
- clientSecretParamName
- clientSecretParamValue
- authHeaderExpr
HealthCheckAuthenticationOauthSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauthSecret"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for the OAuth API call. This call is expected to be a
POST.
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
clientSecretParamName:
type: string
title: Client secret parameter
description: Parameter name that contains client secret. Defaults to
'client_secret', and is automatically added to request parameters.
textSecret:
type: string
title: Client secret value (text secret)
description: Select or create a text secret that contains the client secret's
value.
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/AuthRequestParamConfHealthCheckAuthenticationOauth"
authRequestHeaders:
title: Authentication headers
description: Optional authentication request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationOauth"
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_tokenRespAttribute:
type: string
description: Binds 'tokenRespAttribute' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'tokenRespAttribute' at runtime.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
required:
- loginUrl
- clientSecretParamName
- textSecret
- authHeaderExpr
HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGet:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodGet"
description: Discriminator value.
discoverRequestParams:
title: Discover parameters
description: Optional discover request parameters.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfHealthCheckCollectMethodPost"
HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPost:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPost"
description: Discriminator value.
discoverRequestParams:
title: Discover parameters
description: Optional discover request parameters.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfHealthCheckCollectMethodPost"
HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody"
description: Discriminator value.
discoverBody:
type: string
title: Discover POST body
description: Template for POST body to send with the discover request.
HealthCheckDiscoveryDiscoverTypeHttp:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeHttp"
description: Discriminator value.
discoverUrl:
type: string
title: Discover URL
description: Expression to derive URL to use for the Discover operation (can be
a constant).
discoverMethod:
$ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTypeHttp"
description: Discover HTTP method.
discoverRequestHeaders:
title: Discover Headers
description: Optional discover request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationLogin"
discoverDataField:
type: string
title: Discover Data Field
description: "Path to field in the response object which contains discover results (e.g.: level1.name), leave blank if the result is an array."
__template_discoverUrl:
type: string
description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'discoverUrl' at runtime.
__template_discoverDataField:
type: string
description: Binds 'discoverDataField' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'discoverDataField' at runtime.
required:
- discoverUrl
- discoverMethod
allOf:
- oneOf:
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGet"
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPost"
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody"
discriminator:
propertyName: discoverMethod
mapping:
get: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGet"
post: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPost"
post_with_body: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody"
HealthCheckDiscoveryDiscoverTypeJson:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeJson"
description: Discriminator value.
manualDiscoverResult:
type: string
title: Discover result
description: Allows hard-coding the Discover result. Must be a JSON object.
Works with the Discover Data field.
discoverDataField:
type: string
title: Discover data field
description: "Within the response JSON, name of the field or array element to pull results from. Leave blank if the result is an array of values. Sample entry: items, json: { items: [{id: 'first'},{id: 'second'}] }"
required:
- manualDiscoverResult
HealthCheckDiscoveryDiscoverTypeList:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeList"
description: Discriminator value.
itemList:
type: array
title: Discover items
description: Comma-separated list of items to return from the Discover task.
Each item returned will generate a collect task, and can be
referenced using `${id}` in the collect URL, headers, or parameters.
minItems: 1
items:
type: string
title: Items
description: List of items to return from discovery.
required:
- itemList
HealthCheckDiscoveryDiscoverTypeNone:
type: object
properties:
discoverType:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
HealthCheckRetryRulesTypeNone:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeNone"
description: Resource type identifier.
HealthCheckRetryRulesTypeStatic:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeStatic"
description: Resource type identifier.
interval:
type: number
title: Wait (ms)
description: Time interval between retries. Maximum allowed value is 20,000 ms
(1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: The maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to 20 seconds, even if the Retry-After header specifies a longer
delay. When disabled, all Retry-After headers are ignored.
HealthCheckRetryRulesTypeBackoff:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeBackoff"
description: Resource type identifier.
interval:
type: number
title: Initial retry interval (ms)
description: Time interval between failed request and first retry (kickoff).
Maximum allowed value is 20,000 ms (1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: The maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
multiplier:
type: number
title: Backoff multiplier
description: Base for exponential backoff, e.g., base 2 means that retries will
occur after 2, then 4, then 8 seconds, and so on
minimum: 1
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to 20 seconds, even if the Retry-After header specifies a longer
delay. When disabled, all Retry-After headers are ignored.
HealthCheckCollectorConf:
type: object
title: ""
required:
- collectUrl
- collectMethod
- authentication
properties:
discovery:
type: object
description: Settings that control how the Collector discovers Collect tasks.
required:
- discoverType
properties:
discoverType:
type: string
title: Discover Type
description: Defines how task discovery will be performed. Use None to skip the
discovery. Use HTTP Request to make a REST call to discover
tasks. Use Item List to enumerate items for collect to retrieve.
Use JSON Response to manually define discover tasks as a JSON
array of objects. Each entry returned by the discover operation
will result in a collect task.
enum:
- http
- json
- list
- none
x-speakeasy-enum-descriptions:
- HTTP Request
- JSON Response
- Item List
- None
x-speakeasy-unknown-values: allow
discoverUrl:
type: string
title: Discover URL
description: Expression to derive URL to use for the Discover operation (can be
a constant).
__template_discoverUrl:
type: string
description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'discoverUrl' at
runtime.
discoverMethod:
$ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTypeHttp"
description: Discover HTTP method.
discoverRequestHeaders:
title: Discover Headers
description: Optional discover request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationLogin"
discoverDataField:
type: string
title: Discover Data Field
description: "Path to field in the response object which contains discover results (e.g.: level1.name), leave blank if the result is an array."
__template_discoverDataField:
type: string
description: Binds 'discoverDataField' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'discoverDataField' at runtime.
manualDiscoverResult:
type: string
title: Discover result
description: Allows hard-coding the Discover result. Must be a JSON object.
Works with the Discover Data field.
itemList:
type: array
title: Discover items
description: Comma-separated list of items to return from the Discover task.
Each item returned will generate a collect task, and can be
referenced using `${id}` in the collect URL, headers, or
parameters.
minItems: 1
items:
type: string
title: Items
description: List of items to return from discovery.
allOf:
- oneOf:
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttp"
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeJson"
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeList"
- $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeNone"
discriminator:
propertyName: discoverType
mapping:
http: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttp"
json: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeJson"
list: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeList"
none: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeNone"
collectUrl:
type: string
title: Health check URL
description: Expression to derive URL to use for the health check operation (can
be a constant).
collectMethod:
type: string
title: Health check method
description: Health check HTTP method.
enum:
- get
- post
- post_with_body
x-speakeasy-enum-descriptions:
- GET
- POST
- POST with Body
x-speakeasy-unknown-values: allow
collectRequestHeaders:
title: Health check headers
description: Optional health check request headers.
type: array
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Name
description: Header Name
value:
type: string
title: Value
description: JavaScript expression to compute the header value (can be a
constant).
authenticateCollect:
type: boolean
title: Authenticate health check
description: Enable to make auth health check call.
authentication:
type: string
title: Authentication
description: Authentication method for Discover and Collect REST calls. You can
specify API Key–based authentication by adding the appropriate
Collect headers.
enum:
- none
- basic
- basicSecret
- login
- loginSecret
- oauth
- oauthSecret
x-speakeasy-unknown-values: allow
timeout:
type: number
title: Request Timeout (secs)
description: HTTP request inactivity timeout, use 0 to disable
minimum: 0
maximum: 1800
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Whether to reject certificates that cannot be verified against a
valid CA (e.g., self-signed certificates).
defaultBreakers:
$ref: "#/components/schemas/HiddenDefaultBreakersOptionsDatabaseCollectorConf"
description: Hidden Default Breakers
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text.
items:
type: string
retryRules:
type: object
description: Settings that control how the Collector retries failed HTTP requests.
required:
- type
properties:
type:
$ref: "#/components/schemas/RetryTypeOptionsHealthCheckCollectorConfRetryRules"
description: The algorithm to use when performing HTTP retries
allOf:
- oneOf:
- $ref: "#/components/schemas/HealthCheckRetryRulesTypeNone"
- $ref: "#/components/schemas/HealthCheckRetryRulesTypeStatic"
- $ref: "#/components/schemas/HealthCheckRetryRulesTypeBackoff"
discriminator:
propertyName: type
mapping:
none: "#/components/schemas/HealthCheckRetryRulesTypeNone"
static: "#/components/schemas/HealthCheckRetryRulesTypeStatic"
backoff: "#/components/schemas/HealthCheckRetryRulesTypeBackoff"
username:
type: string
title: Username
description: Basic authentication username
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
password:
type: string
title: Password
description: Basic authentication password
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request, ${username} and
${password} are used to specify location of these attributes in the
message
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
__template_tokenRespAttribute:
type: string
description: Binds 'tokenRespAttribute' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'tokenRespAttribute' at runtime.
authHeaderExpr:
type: string
title: Authorize Expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication Headers
description: Optional authentication request headers.
type: array
items:
$ref: "#/components/schemas/AuthRequestHeaderConfHealthCheckAuthenticationLogin"
clientSecretParamName:
type: string
title: Client secret parameter
description: Parameter name that contains client secret. Defaults to
'client_secret', and is automatically added to request parameters.
clientSecretParamValue:
type: string
title: Client secret value
description: Secret value to add to HTTP requests as the 'client secret'
parameter. Stored on disk encrypted, and is automatically added to
request parameters
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/AuthRequestParamConfHealthCheckAuthenticationOauth"
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth"
textSecret:
type: string
title: Client secret value (text secret)
description: Select or create a text secret that contains the client secret's
value.
__template_collectUrl:
type: string
description: Binds 'collectUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'collectUrl' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/HealthCheckCollectMethodGet"
- $ref: "#/components/schemas/HealthCheckCollectMethodPost"
- $ref: "#/components/schemas/HealthCheckCollectMethodPostWithBody"
discriminator:
propertyName: collectMethod
mapping:
get: "#/components/schemas/HealthCheckCollectMethodGet"
post: "#/components/schemas/HealthCheckCollectMethodPost"
post_with_body: "#/components/schemas/HealthCheckCollectMethodPostWithBody"
- oneOf:
- $ref: "#/components/schemas/HealthCheckAuthenticationNone"
- $ref: "#/components/schemas/HealthCheckAuthenticationBasic"
- $ref: "#/components/schemas/HealthCheckAuthenticationBasicSecret"
- $ref: "#/components/schemas/HealthCheckAuthenticationLogin"
- $ref: "#/components/schemas/HealthCheckAuthenticationLoginSecret"
- $ref: "#/components/schemas/HealthCheckAuthenticationOauth"
- $ref: "#/components/schemas/HealthCheckAuthenticationOauthSecret"
discriminator:
propertyName: authentication
mapping:
none: "#/components/schemas/HealthCheckAuthenticationNone"
basic: "#/components/schemas/HealthCheckAuthenticationBasic"
basicSecret: "#/components/schemas/HealthCheckAuthenticationBasicSecret"
login: "#/components/schemas/HealthCheckAuthenticationLogin"
loginSecret: "#/components/schemas/HealthCheckAuthenticationLoginSecret"
oauth: "#/components/schemas/HealthCheckAuthenticationOauth"
oauthSecret: "#/components/schemas/HealthCheckAuthenticationOauthSecret"
CollectorHealthCheck:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- health_check
description: Collector type
conf:
$ref: "#/components/schemas/HealthCheckCollectorConf"
description: Configuration specific to the HealthCheck Collector.
description: HealthCheck collector configuration
RestCollectMethodGet:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodGet"
description: Discriminator value.
collectRequestParams:
title: Collect parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Collect parameters
RestCollectMethodPost:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPost"
description: Discriminator value.
collectRequestParams:
title: Collect parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Collect parameters
RestCollectMethodPostWithBody:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody"
description: Discriminator value.
collectBody:
type: string
title: Collect POST body
description: "Template for POST body to send with the Collect request. Reference global variables, functions, or parameters from the Discover response using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`"
required:
- collectBody
RestCollectMethodOther:
type: object
properties:
collectMethod:
$ref: "#/components/schemas/CollectMethodOptionsRestCollectMethodOther"
description: Discriminator value.
collectVerb:
type: string
title: Collect verb
description: Custom HTTP method to use for the Collect operation
collectBody:
type: string
title: Collect body
description: "Template for body to send with the Collect request. Reference global variables, functions, or parameters from the Discover response using template parameters: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`"
collectRequestParams:
title: Collect parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Collect parameters
required:
- collectVerb
RestAuthenticationNone:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
RestAuthenticationBasic:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic"
description: Discriminator value.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
required:
- username
- password
RestAuthenticationBasicSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret"
description: Discriminator value.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
required:
- credentialsSecret
RestAuthenticationLogin:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLogin"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
username:
type: string
title: Login username
minLength: 1
description: Login username
password:
type: string
title: Login password
minLength: 1
description: Login password
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request. ${username} and
${password} are used to specify location of these attributes in the
message. For x-www-form-urlencoded bodies, wrap values with
${C.Encode.uri(password)} to preserve special characters like +, &,
and =.
getAuthTokenFromHeader:
type: boolean
title: Get auth token from header
description: Extract the auth token from the HTTP 'Authorization' response
header instead of the standard JSON body of the login response
authHeaderKey:
type: string
title: Authorization header
description: Authorization header key to pass in Discover and Collect calls.
Defaults to the literal name 'Authorization'.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression used to compute the Authorization header to
pass in Discover and Collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Authentication headers
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
required:
- loginUrl
- username
- password
- loginBody
- authHeaderExpr
RestAuthenticationLoginSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLoginSecret"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your login
credentials
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request. ${username} and
${password} are used to specify location of these attributes in the
message. For x-www-form-urlencoded bodies, wrap values with
${C.Encode.uri(password)} to preserve special characters like +, &,
and =.
getAuthTokenFromHeader:
type: boolean
title: Get auth token from header
description: Extract the auth token from the HTTP 'Authorization' response
header instead of the standard JSON body of the login response
authHeaderKey:
type: string
title: Authorization header
description: Authorization header key to pass in Discover and Collect calls.
Defaults to the literal name 'Authorization'.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression to compute the Authorization header to pass
in Discover and Collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Authentication headers
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
required:
- loginUrl
- credentialsSecret
- loginBody
- authHeaderExpr
RestAuthenticationOauth:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauth"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for the OAuth API call. This call is expected to be a
POST.
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
authHeaderKey:
type: string
title: Authorization header
description: Authorization header key to pass in Discover and Collect calls.
Defaults to the literal name 'Authorization'.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression to compute the Authorization header to pass
in Discover and Collect calls. The value ${token} is used to
reference the token obtained from login.
clientSecretParamName:
type: string
title: Client secret parameter
description: Defaults to 'client_secret'. Automatically added to request
parameters using the value specified.
clientSecretParamValue:
type: string
title: Client secret value
description: Secret value to add to HTTP requests as the 'client secret'
parameter. Value is stored encrypted on disk and automatically added
to request parameters.
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
authRequestHeaders:
title: Authentication headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Authentication headers
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth"
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_clientSecretParamValue:
type: string
description: Binds 'clientSecretParamValue' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'clientSecretParamValue' at runtime.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
required:
- loginUrl
- clientSecretParamName
- clientSecretParamValue
- authHeaderExpr
RestAuthenticationOauthSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauthSecret"
description: Discriminator value.
loginUrl:
type: string
title: Login URL
description: URL to use for the OAuth API call. This call is expected to be a
POST.
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
authHeaderKey:
type: string
title: Authorization header
description: Authorization header key to pass in Discover and Collect calls.
Defaults to the literal name 'Authorization'.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression to compute the Authorization header to pass
in Discover and Collect calls. The value ${token} is used to
reference the token obtained from login.
clientSecretParamName:
type: string
title: Client secret parameter
description: Defaults to 'client_secret'. Automatically added to request
parameters using the value specified.
textSecret:
type: string
title: Client secret value (text secret)
description: Select or create a text secret that contains the client secret's
value
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
authRequestHeaders:
title: Authentication headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Authentication headers
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
required:
- loginUrl
- clientSecretParamName
- textSecret
- authHeaderExpr
RestAuthenticationGoogleOauth:
type: object
properties:
authentication:
enum:
- google_oauth
type: string
description: Discriminator value.
scopes:
type: array
title: Scopes
description: Scopes to use during authentication. See [Google's
docs](https://developers.google.com/identity/protocols/oauth2/scopes)
for more information.
minItems: 1
items:
type: string
minLength: 1
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of Google Cloud service account credentials (JSON keys)
file. To upload a file, click the upload icon in this field's upper
right.
minLength: 1
subject:
type: string
title: Impersonated account's email address
description: Email address of a user account with Super Admin permissions to the
resources the collector will retrieve
__template_serviceAccountCredentials:
type: string
description: Binds 'serviceAccountCredentials' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serviceAccountCredentials' at runtime.
__template_subject:
type: string
description: Binds 'subject' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'subject' at runtime.
required:
- scopes
- serviceAccountCredentials
- subject
RestAuthenticationGoogleOauthSecret:
type: object
properties:
authentication:
enum:
- google_oauthSecret
type: string
description: Discriminator value.
scopes:
type: array
title: Scopes
description: Scopes to use during authentication. See [Google's
docs](https://developers.google.com/identity/protocols/oauth2/scopes)
for more information.
minItems: 1
items:
type: string
minLength: 1
textSecret:
type: string
title: Service account credentials (text secret)
description: Select or create a text secret that contains the Google service
account credentials value
subject:
type: string
title: Impersonated account's email address
description: Email address of a user account with Super Admin permissions to the
resources the collector will retrieve
__template_subject:
type: string
description: Binds 'subject' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'subject' at runtime.
required:
- scopes
- textSecret
- subject
RestAuthenticationHmac:
type: object
properties:
authentication:
enum:
- hmac
type: string
description: Discriminator value.
hmacFunctionId:
type: string
title: HMAC Function
description: Select or create an HMAC Function to use with authentication
required:
- hmacFunctionId
RestDiscoveryDiscoverTypeHttpPaginationTypeNone:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeNone"
description: Resource type identifier.
RestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody"
description: Resource type identifier.
attribute:
type:
- array
- string
title: Response attributes
description: Names of attributes within the response that contain next-page
information
items:
type: string
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve for the discover task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
lastPageExpr:
type: string
title: Last-page expression
description: JavaScript expression used to determine when the last page has been
reached. The values tested by this expression must be in the
Response attributes section.
required:
- attribute
- maxPages
RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader"
description: Resource type identifier.
attribute:
type:
- array
- string
title: Response attributes
description: Names of attributes within the response that contain next-page
information
items:
type: string
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve for the discover task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
required:
- attribute
- maxPages
RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink"
description: Resource type identifier.
nextRelationAttribute:
type: string
title: Next page relation name
description: 'Relation name used in the link header that refers to the next page
in the result set. Example: rel="next" refers to the next page of
results: ; rel="next"'
curRelationAttribute:
type: string
title: Current page relation name
description: 'Relation name used in the link header that refers to the current
result set. Example: rel="self" refers to the current page of
results: ; rel="self" '
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve for the discover task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
required:
- nextRelationAttribute
- maxPages
RestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset"
description: Resource type identifier.
offsetField:
type: string
title: Offset field name
description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0"
offset:
type: number
title: Starting offset
description: Offset index from which to start request. Defaults to undefined,
which will start discovery from the first record.
limitField:
type: string
title: Limit field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0"
limit:
type: number
title: Record limit
description: Maximum number of records to retrieve per request
minimum: 1
totalRecordField:
type: string
title: Total record count field name
description: Name of the attribute in the response that contains the total
number of records for the query
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve for the discover task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
zeroIndexed:
type: boolean
title: Zero-based index
description: Enable to indicate that the first page in the requested data is at
index 0. Disabled by default, which indicates index 1.
required:
- maxPages
- zeroIndexed
- offsetField
- limitField
- limit
RestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage"
description: Resource type identifier.
pageField:
type: string
title: Page number field name
description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
page:
type: number
title: Starting page number
description: Page number from which to start request. Defaults to undefined,
which will start discovery from the first page.
sizeField:
type: string
title: Page size field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
size:
type: number
title: Record limit
description: Maximum number of records to retrieve per page
minimum: 1
totalPageField:
type: string
title: Total page count field name
description: Name of the attribute in the response that contains the total
number of pages for the query
totalRecordField:
type: string
title: Total record count field name
description: Name of the attribute in the response that contains the total
number of records for the query
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve for the discover task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
zeroIndexed:
type: boolean
title: Zero-based index
description: Enable to indicate that the first page in the requested data is at
index 0. Disabled by default, which indicates index 1.
required:
- maxPages
- zeroIndexed
- pageField
- sizeField
- size
RestDiscoveryDiscoverTypeHttpDiscoverMethodGet:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodGet"
description: Discriminator value.
discoverRequestParams:
title: Discover parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Discover parameters
RestDiscoveryDiscoverTypeHttpDiscoverMethodPost:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPost"
description: Discriminator value.
discoverRequestParams:
title: Discover parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Discover parameters
RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody"
description: Discriminator value.
discoverBody:
type: string
title: Discover POST body
description: "Template for POST body to send with the discover request. To reference global variables or functions, use template parameters: `{ myVar: ${C.vars.myVar}, secret: ${C.Secret('mySecret','text').value} }`"
required:
- discoverBody
RestDiscoveryDiscoverTypeHttpDiscoverMethodOther:
type: object
properties:
discoverMethod:
$ref: "#/components/schemas/CollectMethodOptionsRestCollectMethodOther"
description: Discriminator value.
discoverVerb:
type: string
title: Discover verb
description: Custom HTTP method to use for the Discover operation
discoverBody:
type: string
title: Discover body
description: Template for body to send with the discover request
discoverRequestParams:
title: Discover parameters
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Discover parameters
required:
- discoverVerb
RestDiscoveryDiscoverTypeHttp:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeHttp"
description: Discriminator value.
discoverUrl:
type: string
title: Discover URL
description: URL to use for the Discover operation. Can be a constant URL, or a
JavaScript expression to derive the URL.
discoverMethod:
$ref: "#/components/schemas/DiscoverMethodOptionsRestDiscoveryDiscoverTypeHttp"
description: Discover method
discoverRequestHeaders:
title: Discover headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Discover headers
pagination:
$ref: "#/components/schemas/PaginationTypeRestDiscoveryDiscoverTypeHttp"
description: Settings that control how the Collector paginates through Discover
results.
discoverDataField:
type: string
title: Discover data field
description: "Path to field in the response object that contains discovery results (ex: level1.name). Leave blank if the result is an array."
enableStrictDiscoverParsing:
type: boolean
title: Strict discover response parsing
description: Explicitly set the discover response format. When disabled, best
effort parsing is used.
discoverResponseFormat:
type: string
title: Discover response format
description: If 'Strict discover response parsing' parsing is enabled, provide
the response format
enableDiscoverCode:
type: boolean
title: Format discover result with custom code
description: Format discover result with custom code
formatResultCode:
type: string
title: Format discover result
description: "Custom JavaScript code to format the discover result through the __e variable which is a JSON object or array containing the original discover results. The object or array passed should be manipulated to contain the desired discover results, i.e.: __e['myResult'] = [{lat: -1.1234, long: 2.345, zip: 11111},{lat: -1.235, long 2.346, zip: 22222}] or ['11111','22222']. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code."
__template_discoverUrl:
type: string
description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'discoverUrl' at runtime.
required:
- discoverUrl
- discoverMethod
allOf:
- oneOf:
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodGet"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPost"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodOther"
discriminator:
propertyName: discoverMethod
mapping:
get: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodGet"
post: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPost"
post_with_body: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody"
other: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodOther"
RestDiscoveryDiscoverTypeJson:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeJson"
description: Discriminator value.
manualDiscoverResult:
type: string
title: Discover result
description: Allows hard-coding the Discover result. Must be a JSON object or
array. Works with Discover data field.
discoverDataField:
type: string
title: Discover data field
description: "Within the response JSON, the name of the field to pull results from, typically a JSON array. Leave blank if the result itself is an array of values. Sample entry: items, json: { items: [{id: 'first'},{id: 'second'}] }"
required:
- manualDiscoverResult
RestDiscoveryDiscoverTypeList:
type: object
properties:
discoverType:
$ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeList"
description: Discriminator value.
itemList:
type: array
title: Discover items
description: Comma-separated list of items to return from the Discover task.
Each item returned generates a Collect task and can be referenced
using `${id}` in the Collect URL, headers, or parameters.
minItems: 1
items:
type: string
title: Items
description: List of items to return from discovery
required:
- itemList
RestDiscoveryDiscoverTypeNone:
type: object
properties:
discoverType:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
RestPaginationTypeNone:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeNone"
description: Resource type identifier.
RestPaginationTypeResponseBody:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody"
description: Resource type identifier.
attribute:
type:
- array
- string
title: Response attributes
description: Names of attributes within the response that contain next-page
information
items:
type: string
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
lastPageExpr:
type: string
title: Last-page expression
description: JavaScript expression used to determine when the last page has been
reached. The values tested by this expression must be in the
Response attributes section.
required:
- attribute
- maxPages
RestPaginationTypeResponseHeader:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader"
description: Resource type identifier.
attribute:
type:
- array
- string
title: Response attributes
description: Names of attributes within the response that contain next-page
information
items:
type: string
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
required:
- attribute
- maxPages
RestPaginationTypeResponseHeaderLink:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink"
description: Resource type identifier.
nextRelationAttribute:
type: string
title: Next page relation name
description: 'Relation name used in the link header that refers to the next page
in the result set. Example: rel="next" refers to the next page of
results: ; rel="next"'
curRelationAttribute:
type: string
title: Current page relation name
description: 'Relation name used in the link header that refers to the current
result set. Example: rel="self" refers to the current page of
results: ; rel="self" '
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
required:
- nextRelationAttribute
- maxPages
RestPaginationTypeRequestOffset:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset"
description: Resource type identifier.
offsetField:
type: string
title: Offset field name
description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0"
offset:
type: number
title: Starting offset
description: Offset index from which to start request. Defaults to undefined,
which will start collection from the first record.
limitField:
type: string
title: Limit field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0"
limit:
type: number
title: Record limit
description: Maximum number of records to collect per request
minimum: 1
totalRecordField:
type: string
title: Total record count field name
description: Name of the attribute in the response that contains the total
number of records for the query
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
zeroIndexed:
type: boolean
title: Zero-based index
description: Enable to indicate that the first page in the requested data is at
index 0. Disabled by default, which indicates index 1.
required:
- maxPages
- zeroIndexed
- offsetField
- limitField
- limit
RestPaginationTypeRequestPage:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage"
description: Resource type identifier.
pageField:
type: string
title: Page number field name
description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
page:
type: number
title: Starting page number
description: Page number from which to start request. Defaults to undefined,
which will start collection from the first page.
sizeField:
type: string
title: Page size field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
size:
type: number
title: Record limit
description: Maximum number of records to collect per page
minimum: 1
totalPageField:
type: string
title: Total page count field name
description: Name of the attribute in the response that contains the total
number of pages for the query
totalRecordField:
type: string
title: Total record count field name
description: Name of the attribute in the response that contains the total
number of records for the query
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
zeroIndexed:
type: boolean
title: Zero-based index
description: Enable to indicate that the first page in the requested data is at
index 0. Disabled by default, which indicates index 1.
required:
- maxPages
- zeroIndexed
- pageField
- sizeField
- size
RestRetryRulesTypeNone:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeNone"
description: Resource type identifier.
RestRetryRulesTypeStatic:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeStatic"
description: Resource type identifier.
interval:
type: number
title: Wait (ms)
description: Time interval between retries. Maximum allowed value is 20,000 ms
(1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: Maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to the `Longest interval between retries (ms)` value, even if the
Retry-After header specifies a longer delay. When disabled, all
Retry-After headers are ignored.
retryConnectTimeout:
type: boolean
title: Retry connection timeout
description: Make a single retry attempt when a connection timeout (ETIMEDOUT)
error occurs
retryConnectReset:
type: boolean
title: Retry connection reset
description: Retry request when a connection reset (ECONNRESET) error occurs
retryHeaderName:
type: string
title: Retry-After header name
description: Retry-After header name
RestRetryRulesTypeBackoff:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeBackoff"
description: Resource type identifier.
interval:
type: number
title: Initial retry interval (ms)
description: Time interval between a failed request and the first retry
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: Maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
multiplier:
type: number
title: Backoff multiplier
description: "Base for exponential backoff. Example: base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on."
minimum: 1
maximum: 20
maxIntervalMs:
type: number
title: Longest interval between retries (ms)
minimum: 0
description: Longest interval between retries (ms)
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to the `Longest interval between retries (ms)` value, even if the
Retry-After header specifies a longer delay. When disabled, all
Retry-After headers are ignored.
retryConnectTimeout:
type: boolean
title: Retry connection timeout
description: Make a single retry attempt when a connection timeout (ETIMEDOUT)
error occurs
retryConnectReset:
type: boolean
title: Retry connection reset
description: Retry request when a connection reset (ECONNRESET) error occurs
retryHeaderName:
type: string
title: Retry-After header name
description: Retry-After header name
RestCollectorConf:
type: object
title: ""
required:
- collectUrl
- collectMethod
- authentication
properties:
discovery:
type: object
description: Settings that control how the Collector discovers Collect tasks.
required:
- discoverType
properties:
discoverType:
type: string
title: Discover type
description: Defines how task discovery will be performed. Each entry returned
by the Discover operation will result in a Collect task.
enum:
- http
- json
- list
- none
x-speakeasy-unknown-values: allow
discoverUrl:
type: string
title: Discover URL
description: URL to use for the Discover operation. Can be a constant URL, or a
JavaScript expression to derive the URL.
__template_discoverUrl:
type: string
description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'discoverUrl' at
runtime.
discoverMethod:
$ref: "#/components/schemas/DiscoverMethodOptionsRestDiscoveryDiscoverTypeHttp"
description: Discover method
discoverRequestHeaders:
title: Discover headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Discover headers
pagination:
$ref: "#/components/schemas/PaginationTypeRestDiscoveryDiscoverTypeHttp"
description: Settings that control how the Collector paginates through Discover
results.
discoverDataField:
type: string
title: Discover data field
description: "Path to field in the response object that contains discovery results (ex: level1.name). Leave blank if the result is an array."
enableStrictDiscoverParsing:
type: boolean
title: Strict discover response parsing
description: Explicitly set the discover response format. When disabled, best
effort parsing is used.
enableDiscoverCode:
type: boolean
title: Format discover result with custom code
description: Format discover result with custom code
manualDiscoverResult:
type: string
title: Discover result
description: Allows hard-coding the Discover result. Must be a JSON object or
array. Works with Discover data field.
itemList:
type: array
title: Discover items
description: Comma-separated list of items to return from the Discover task.
Each item returned generates a Collect task and can be
referenced using `${id}` in the Collect URL, headers, or
parameters.
minItems: 1
items:
type: string
title: Items
description: List of items to return from discovery
allOf:
- oneOf:
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttp"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeJson"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeList"
- $ref: "#/components/schemas/RestDiscoveryDiscoverTypeNone"
discriminator:
propertyName: discoverType
mapping:
http: "#/components/schemas/RestDiscoveryDiscoverTypeHttp"
json: "#/components/schemas/RestDiscoveryDiscoverTypeJson"
list: "#/components/schemas/RestDiscoveryDiscoverTypeList"
none: "#/components/schemas/RestDiscoveryDiscoverTypeNone"
collectUrl:
type: string
title: Collect URL
description: URL (constant or JavaScript expression) to use for the Collect
operation
collectMethod:
type: string
title: Collect method
enum:
- get
- post
- post_with_body
- other
x-speakeasy-enum-descriptions:
- GET
- POST
- POST with Body
- Other
description: Collect method
x-speakeasy-unknown-values: allow
collectRequestHeaders:
title: Collect headers
description: Headers to send with each Collect request.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
pagination:
type: object
description: Settings that control how the Collector paginates through Collect
results.
required:
- type
properties:
type:
$ref: "#/components/schemas/PaginationOptionsRestDiscoveryDiscoverTypeHttpPagination"
description: Pagination
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 50 pages. Set to 0 to retrieve all pages.
minimum: 0
lastPageExpr:
type: string
title: Last-page expression
description: JavaScript expression used to determine when the last page has been
reached. The values tested by this expression must be in the
Response attributes section.
nextRelationAttribute:
type: string
title: Next page relation name
description: 'Relation name used in the link header that refers to the next page
in the result set. Example: rel="next" refers to the next page
of results: ; rel="next"'
curRelationAttribute:
type: string
title: Current page relation name
description: 'Relation name used in the link header that refers to the current
result set. Example: rel="self" refers to the current page of
results: ; rel="self" '
offsetField:
type: string
title: Offset field name
description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0"
offset:
type: number
title: Starting offset
description: Offset index from which to start request. Defaults to undefined,
which will start collection from the first record.
limitField:
type: string
title: Limit field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0"
limit:
type: number
title: Record limit
description: Maximum number of records to collect per request
minimum: 1
totalRecordField:
type: string
title: Total record count field name
description: Name of the attribute in the response that contains the total
number of records for the query
zeroIndexed:
type: boolean
title: Zero-based index
description: Enable to indicate that the first page in the requested data is at
index 0. Disabled by default, which indicates index 1.
pageField:
type: string
title: Page number field name
description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
page:
type: number
title: Starting page number
description: Page number from which to start request. Defaults to undefined,
which will start collection from the first page.
sizeField:
type: string
title: Page size field name
description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0"
size:
type: number
title: Record limit
description: Maximum number of records to collect per page
minimum: 1
totalPageField:
type: string
title: Total page count field name
description: Name of the attribute in the response that contains the total
number of pages for the query
allOf:
- oneOf:
- $ref: "#/components/schemas/RestPaginationTypeNone"
- $ref: "#/components/schemas/RestPaginationTypeResponseBody"
- $ref: "#/components/schemas/RestPaginationTypeResponseHeader"
- $ref: "#/components/schemas/RestPaginationTypeResponseHeaderLink"
- $ref: "#/components/schemas/RestPaginationTypeRequestOffset"
- $ref: "#/components/schemas/RestPaginationTypeRequestPage"
discriminator:
propertyName: type
mapping:
none: "#/components/schemas/RestPaginationTypeNone"
response_body: "#/components/schemas/RestPaginationTypeResponseBody"
response_header: "#/components/schemas/RestPaginationTypeResponseHeader"
response_header_link: "#/components/schemas/RestPaginationTypeResponseHeaderLink"
request_offset: "#/components/schemas/RestPaginationTypeRequestOffset"
request_page: "#/components/schemas/RestPaginationTypeRequestPage"
authentication:
type: string
title: Authentication
description: Authentication method for Discover and Collect REST calls. You can
specify API key–based authentication by adding the appropriate
Collect headers.
enum:
- none
- basic
- basicSecret
- login
- loginSecret
- oauth
- oauthSecret
- google_oauth
- google_oauthSecret
- hmac
x-speakeasy-unknown-values: allow
timeout:
type: number
title: Request timeout (secs)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 1800
maxResponseBodySize:
type: string
title: Max response body size
description: Maximum amount of data to buffer from a single response body.
Responses exceeding this limit will be rejected. Maximum allowed
value is 512 MB. Leave unset to rely on default error handling.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Use round-robin DNS lookup. Suitable when DNS server returns
multiple addresses in sort order.
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disable Collector event time filtering when a date range is specified
decodeUrl:
type: boolean
title: Decode URL
description: Decode the URL before sending requests (including pagination
requests)
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as self-signed certificates)
captureHeaders:
type: boolean
title: Capture response headers
description: Enable to add response headers to the resHeaders field under the
__collectible object
stopOnEmptyResults:
type: boolean
title: Stop on empty results
description: Stop pagination when the Event Breaker produces no events
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
retryRules:
type: object
description: Settings that control how the Collector retries failed HTTP requests.
required:
- type
properties:
type:
$ref: "#/components/schemas/RetryTypeOptionsHealthCheckCollectorConfRetryRules"
description: The algorithm to use when performing HTTP retries
allOf:
- oneOf:
- $ref: "#/components/schemas/RestRetryRulesTypeNone"
- $ref: "#/components/schemas/RestRetryRulesTypeStatic"
- $ref: "#/components/schemas/RestRetryRulesTypeBackoff"
discriminator:
propertyName: type
mapping:
none: "#/components/schemas/RestRetryRulesTypeNone"
static: "#/components/schemas/RestRetryRulesTypeStatic"
backoff: "#/components/schemas/RestRetryRulesTypeBackoff"
microsoftGraphDelta:
type: object
description: Internal opt-in for the Microsoft Graph deltaLink state-tracking
hook. Set programmatically by the Microsoft Graph source when the
configured URL targets a /delta endpoint; not user-configurable.
properties:
deltaLinkAttribute:
type: string
description: Response-body field name to extract as the delta link (typically
'@odata.deltaLink')
__scheduling:
type: object
description: Internal settings for scheduled execution of this Collector.
properties:
stateTracking:
type: object
description: Settings for tracking collection state between consecutive
scheduled executions.
properties:
enabled:
type: boolean
title: Enabled
description: Track collection progress between consecutive scheduled executions
username:
type: string
title: Username
description: Username
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
password:
type: string
title: Password
description: Password
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request. ${username} and
${password} are used to specify location of these attributes in the
message. For x-www-form-urlencoded bodies, wrap values with
${C.Encode.uri(password)} to preserve special characters like +, &,
and =.
getAuthTokenFromHeader:
type: boolean
title: Get auth token from header
description: Extract the auth token from the HTTP 'Authorization' response
header instead of the standard JSON body of the login response
authHeaderKey:
type: string
title: Authorization header
description: Authorization header key to pass in Discover and Collect calls.
Defaults to the literal name 'Authorization'.
authHeaderExpr:
type: string
title: Authorize expression
description: JavaScript expression used to compute the Authorization header to
pass in Discover and Collect calls. The value ${token} is used to
reference the token obtained from login.
authRequestHeaders:
title: Authentication headers
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
description: Authentication headers
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are OK. Leave blank if the response content type is text/plain; the
entire response body will be used to derive the authorization
header.
clientSecretParamName:
type: string
title: Client secret parameter
description: Defaults to 'client_secret'. Automatically added to request
parameters using the value specified.
clientSecretParamValue:
type: string
title: Client secret value
description: Secret value to add to HTTP requests as the 'client secret'
parameter. Value is stored encrypted on disk and automatically added
to request parameters.
__template_clientSecretParamValue:
type: string
description: Binds 'clientSecretParamValue' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'clientSecretParamValue' at runtime.
authRequestParams:
title: Extra authentication parameters
description: OAuth request parameters added to the POST body. The Content-Type
header will automatically be set to
application/x-www-form-urlencoded.
type: array
items:
$ref: "#/components/schemas/CollectRequestParamConfRestCollectMethodGet"
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: The Collector will update its stored value on each successful
refresh. Enable if the server issues a new refresh token on every
use.
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, the Collector sends
only grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth"
textSecret:
type: string
title: Client secret value (text secret)
description: Select or create a text secret that contains the client secret's
value
scopes:
type: array
title: Scopes
description: Scopes to use during authentication. See [Google's
docs](https://developers.google.com/identity/protocols/oauth2/scopes)
for more information.
minItems: 1
items:
type: string
minLength: 1
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of Google Cloud service account credentials (JSON keys)
file. To upload a file, click the upload icon in this field's upper
right.
minLength: 1
__template_serviceAccountCredentials:
type: string
description: Binds 'serviceAccountCredentials' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serviceAccountCredentials' at runtime.
subject:
type: string
title: Impersonated account's email address
description: Email address of a user account with Super Admin permissions to the
resources the collector will retrieve
__template_subject:
type: string
description: Binds 'subject' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'subject' at runtime.
hmacFunctionId:
type: string
title: HMAC Function
description: Select or create an HMAC Function to use with authentication
__template_collectUrl:
type: string
description: Binds 'collectUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'collectUrl' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/RestCollectMethodGet"
- $ref: "#/components/schemas/RestCollectMethodPost"
- $ref: "#/components/schemas/RestCollectMethodPostWithBody"
- $ref: "#/components/schemas/RestCollectMethodOther"
discriminator:
propertyName: collectMethod
mapping:
get: "#/components/schemas/RestCollectMethodGet"
post: "#/components/schemas/RestCollectMethodPost"
post_with_body: "#/components/schemas/RestCollectMethodPostWithBody"
other: "#/components/schemas/RestCollectMethodOther"
- oneOf:
- $ref: "#/components/schemas/RestAuthenticationNone"
- $ref: "#/components/schemas/RestAuthenticationBasic"
- $ref: "#/components/schemas/RestAuthenticationBasicSecret"
- $ref: "#/components/schemas/RestAuthenticationLogin"
- $ref: "#/components/schemas/RestAuthenticationLoginSecret"
- $ref: "#/components/schemas/RestAuthenticationOauth"
- $ref: "#/components/schemas/RestAuthenticationOauthSecret"
- $ref: "#/components/schemas/RestAuthenticationGoogleOauth"
- $ref: "#/components/schemas/RestAuthenticationGoogleOauthSecret"
- $ref: "#/components/schemas/RestAuthenticationHmac"
discriminator:
propertyName: authentication
mapping:
none: "#/components/schemas/RestAuthenticationNone"
basic: "#/components/schemas/RestAuthenticationBasic"
basicSecret: "#/components/schemas/RestAuthenticationBasicSecret"
login: "#/components/schemas/RestAuthenticationLogin"
loginSecret: "#/components/schemas/RestAuthenticationLoginSecret"
oauth: "#/components/schemas/RestAuthenticationOauth"
oauthSecret: "#/components/schemas/RestAuthenticationOauthSecret"
google_oauth: "#/components/schemas/RestAuthenticationGoogleOauth"
google_oauthSecret: "#/components/schemas/RestAuthenticationGoogleOauthSecret"
hmac: "#/components/schemas/RestAuthenticationHmac"
CollectorRest:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- rest
description: Collector type
conf:
$ref: "#/components/schemas/RestCollectorConf"
description: Configuration specific to the Rest Collector.
description: Rest collector configuration
S3PartitioningSchemeDdss:
type: object
properties:
partitioningScheme:
enum:
- ddss
type: string
description: Discriminator value.
S3PartitioningSchemeNone:
type: object
properties:
partitioningScheme:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
recurse:
type: boolean
title: Recursive
description: Traverse and include files from subdirectories. Leave this option
enabled to ensure that all nested directories are searched and their
contents collected.
S3AwsAuthenticationMethodAuto:
type: object
properties:
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthTypeOptionsGoogleCloudStorageAuthTypeAuto"
description: Discriminator value.
S3AwsAuthenticationMethodManual:
type: object
properties:
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeManual"
description: Discriminator value.
awsApiKey:
type: string
title: Access key
description: Access key. If not present, will fall back to
env.AWS_ACCESS_KEY_ID, or to the metadata endpoint for IAM creds.
Optional when running on AWS. This value can be a constant or a
JavaScript expression.
awsSecretKey:
type: string
title: Secret key
description: Secret key. If not present, will fall back to
env.AWS_SECRET_ACCESS_KEY, or to the metadata endpoint for IAM
creds. Optional when running on AWS. This value can be a constant or
a JavaScript expression.
S3AwsAuthenticationMethodSecret:
type: object
properties:
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthTypeOptionsAzureBlobAuthTypeSecret"
description: Discriminator value.
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references AWS access key and
secret key.
S3CollectorConf:
type: object
title: ""
required:
- bucket
properties:
outputName:
type: string
title: Auto-populate from
description: Name of the predefined Destination that will be used to
auto-populate Collector settings
bucket:
type: string
title: S3 bucket
minLength: 1
description: S3 Bucket from which to collect data
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: Maximum time allowed for downloading a Parquet chunk. Processing
will stop if a chunk cannot be downloaded within the time specified.
maximum: 3600
minimum: 1
region:
type: string
title: Region
description: Region from which to retrieve data
path:
type: string
title: Path
description: Directory where data will be collected. Templating (such as
'myDir/${datacenter}/${host}/${app}/') and time-based tokens (such
as 'myOtherDir/${_time:%Y}/${_time:%m}/${_time:%d}/') are supported.
Can be a constant (enclosed in quotes) or a JavaScript expression.
minLength: 1
partitioningScheme:
type: string
title: Partitioning scheme
description: Partitioning scheme used for this dataset. Using a known scheme
like DDSS enables more efficient data reading and retrieval.
enum:
- none
- ddss
x-speakeasy-enum-descriptions:
- Defined in Path
- DDSS
x-speakeasy-unknown-values: allow
extractors:
type: array
title: Path extractors
additionalProperties: false
items:
type: object
required:
- key
- expression
properties:
key:
type: string
title: Token
description: A token from the template path, such as epoch
expression:
type: string
title: Extractor Expression
description: 'JavaScript expression that receives token under "value" variable,
and evaluates to populate event fields. Example: {date: new
Date(+value*1000)}'
description: 'Allows using template tokens as context for expressions that
enrich discovery results. For example, given a template
/path/${epoch}, an extractor under key "epoch" with an expression
{date: new Date(+value*1000)}, will enrich discovery results with a
human readable "date" field.'
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
endpoint:
type: string
title: Endpoint
description: "Must point to an S3-compatible endpoint. If empty, defaults to an AWS region-specific endpoint. "
enableAssumeRole:
type: boolean
title: Enable Assume Role
description: Use AssumeRole credentials
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the Assumed Role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
maxBatchSize:
type: number
title: Batch size limit (objects)
description: Maximum number of metadata objects to batch before recording as
results
minimum: 1
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests to improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as a self-signed certificate)
verifyPermissions:
type: boolean
title: Verify bucket permissions
description: 'Disable if you can access files within the bucket but not the
bucket itself. Resolves errors of the form "discover task
initialization failed...error: Forbidden".'
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disable Collector event time filtering when a date range is specified
awsApiKey:
type: string
title: Access key
description: Access key. If not present, will fall back to
env.AWS_ACCESS_KEY_ID, or to the metadata endpoint for IAM creds.
Optional when running on AWS. This value can be a constant or a
JavaScript expression.
awsSecretKey:
type: string
title: Secret key
description: Secret key. If not present, will fall back to
env.AWS_SECRET_ACCESS_KEY, or to the metadata endpoint for IAM
creds. Optional when running on AWS. This value can be a constant or
a JavaScript expression.
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references AWS access key and
secret key.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/S3PartitioningSchemeDdss"
- $ref: "#/components/schemas/S3PartitioningSchemeNone"
discriminator:
propertyName: partitioningScheme
mapping:
ddss: "#/components/schemas/S3PartitioningSchemeDdss"
none: "#/components/schemas/S3PartitioningSchemeNone"
- oneOf:
- $ref: "#/components/schemas/S3AwsAuthenticationMethodAuto"
- $ref: "#/components/schemas/S3AwsAuthenticationMethodManual"
- $ref: "#/components/schemas/S3AwsAuthenticationMethodSecret"
discriminator:
propertyName: awsAuthenticationMethod
mapping:
auto: "#/components/schemas/S3AwsAuthenticationMethodAuto"
manual: "#/components/schemas/S3AwsAuthenticationMethodManual"
secret: "#/components/schemas/S3AwsAuthenticationMethodSecret"
CollectorS3:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- s3
description: Collector type
conf:
$ref: "#/components/schemas/S3CollectorConf"
description: Configuration specific to the S3 Collector.
description: S3 collector configuration
ScriptCollectorConf:
type: object
title: ""
required:
- discoverScript
- collectScript
properties:
discoverScript:
type: string
title: Discover Script
minLength: 1
description: Script to discover what to collect. Should output one task per line
in stdout.
collectScript:
type: string
title: Collect Script
minLength: 1
description: Script to run to perform data collections. Task passed in as
$CRIBL_COLLECT_ARG. Should output results to stdout.
shell:
type: string
title: Shell
description: Shell to use to execute scripts.
envVars:
type: array
title: Environment Variables
description: Environment variables to expose to the discover and collect scripts.
additionalProperties: false
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Name
description: Environment variable name
pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$
value:
type: string
title: Value
description: JavaScript expression to compute environment variable's value,
enclosed in quotes or backticks. (Can evaluate to a constant.)
CollectorScript:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- script
description: Collector type
conf:
$ref: "#/components/schemas/ScriptCollectorConf"
description: Configuration specific to the Script Collector.
description: Script collector configuration
SplunkAuthenticationNone:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationNone"
description: Discriminator value.
SplunkAuthenticationBasic:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic"
description: Discriminator value.
username:
type: string
title: Username
description: Basic authentication username
password:
type: string
title: Password
description: Basic authentication password
required:
- username
- password
SplunkAuthenticationBasicSecret:
type: object
properties:
authentication:
$ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret"
description: Discriminator value.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
required:
- credentialsSecret
SplunkAuthenticationToken:
type: object
properties:
authentication:
enum:
- token
type: string
description: Discriminator value.
token:
type: string
title: Bearer token
description: Bearer token
required:
- token
SplunkAuthenticationTokenSecret:
type: object
properties:
authentication:
enum:
- tokenSecret
type: string
description: Discriminator value.
tokenSecret:
type: string
title: Bearer token secret
description: Select or create a stored secret that references your Bearer token
required:
- tokenSecret
SplunkRetryRulesTypeNone:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeNone"
description: Resource type identifier.
SplunkRetryRulesTypeStatic:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeStatic"
description: Resource type identifier.
interval:
type: number
title: Wait (ms)
description: Time interval between retries. Maximum allowed value is 20,000 ms
(1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: The maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to 20 seconds, even if the Retry-After header specifies a longer
delay. When disabled, all Retry-After headers are ignored.
retryConnectTimeout:
type: boolean
title: Retry connection timeout
description: Make a single retry attempt when a connection timeout (ETIMEDOUT)
error occurs
retryConnectReset:
type: boolean
title: Retry connection reset
description: Retry request when a connection reset error (ECONNRESET) error occurs
SplunkRetryRulesTypeBackoff:
type: object
properties:
type:
$ref: "#/components/schemas/TypeOptionsHealthCheckRetryRulesTypeBackoff"
description: Resource type identifier.
interval:
type: number
title: Initial retry interval (ms)
description: Time interval between failed request and first retry (kickoff).
Maximum allowed value is 20,000 ms (1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: The maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
multiplier:
type: number
title: Backoff multiplier
description: Base for exponential backoff. For example, base 2 means that
retries will occur after 2, then 4, then 8 seconds, and so on.
minimum: 1
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429 and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is limited
to 20 seconds, even if the Retry-After header specifies a longer
delay. When disabled, all Retry-After headers are ignored.
retryConnectTimeout:
type: boolean
title: Retry connection timeout
description: Make a single retry attempt when a connection timeout (ETIMEDOUT)
error occurs
retryConnectReset:
type: boolean
title: Retry connection reset
description: Retry request when a connection reset error (ECONNRESET) error occurs
SplunkCollectorConf:
type: object
title: ""
required:
- search
- searchHead
- endpoint
- authentication
- outputMode
properties:
searchHead:
type: string
title: Search head
description: Search head base URL. Can be an expression. Default is
https://localhost:8089.
search:
type: string
title: Search
description: "Examples: 'index=myAppLogs level=error channel=myApp' OR '| mstats avg(myStat) as myStat WHERE index=myStatsIndex.'"
earliest:
title: Earliest
type: string
description: "The earliest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'"
latest:
title: Latest
type: string
description: "The latest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'"
endpoint:
type: string
title: Search endpoint
description: REST API used to create a search
outputMode:
$ref: "#/components/schemas/OutputModeOptionsSplunkCollectorConf"
description: Format of the returned output
collectRequestParams:
title: Extra parameters
description: Optional collect request parameters
type: array
items:
type: object
required:
- name
- value
properties:
name:
title: Parameter Name
type: string
description: Parameter Name
value:
title: Value
type: string
description: JavaScript expression to compute the parameter's value, normally
enclosed in backticks (`${earliest}`). If a constant, use
single quotes ('earliest'). Values without delimiters
(earliest) are evaluated as strings.
collectRequestHeaders:
title: Extra headers
description: Optional collect request headers
type: array
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Header Name
description: Header Name
value:
type: string
title: Value
description: JavaScript expression to compute the header's value, normally
enclosed in backticks (`${earliest}`). If a constant, use
single quotes ('earliest'). Values without delimiters
(earliest) are evaluated as strings.
authentication:
type: string
title: Authentication
description: Authentication method for Discover and Collect REST calls
enum:
- none
- basic
- basicSecret
- token
- tokenSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Bearer Token
- Bearer Token (text secret)
x-speakeasy-unknown-values: allow
timeout:
type: number
title: Request timeout (secs)
description: HTTP request inactivity timeout. Use 0 for no timeout.
minimum: 0
maximum: 1800
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Use round-robin DNS lookup. Suitable when DNS server returns
multiple addresses in sort order.
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disable collector event time filtering when a date range is specified
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as self-signed certificates)
handleEscapedChars:
type: boolean
title: Preserve escaped characters
description: Escape characters (\") in search queries will be passed directly to
Splunk
retryRules:
type: object
description: Settings that control how the Collector retries failed HTTP requests.
required:
- type
properties:
type:
$ref: "#/components/schemas/RetryTypeOptionsHealthCheckCollectorConfRetryRules"
description: The algorithm to use when performing HTTP retries
allOf:
- oneOf:
- $ref: "#/components/schemas/SplunkRetryRulesTypeNone"
- $ref: "#/components/schemas/SplunkRetryRulesTypeStatic"
- $ref: "#/components/schemas/SplunkRetryRulesTypeBackoff"
discriminator:
propertyName: type
mapping:
none: "#/components/schemas/SplunkRetryRulesTypeNone"
static: "#/components/schemas/SplunkRetryRulesTypeStatic"
backoff: "#/components/schemas/SplunkRetryRulesTypeBackoff"
username:
type: string
title: Username
description: Basic authentication username
password:
type: string
title: Password
description: Basic authentication password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a stored secret that references your credentials
token:
type: string
title: Bearer token
description: Bearer token
tokenSecret:
type: string
title: Bearer token secret
description: Select or create a stored secret that references your Bearer token
loginUrl:
type: string
title: Login URL
description: URL to use for login API call. This call is expected to be a POST.
loginBody:
type: string
title: POST body
description: Template for POST body to send with login request. ${username} and
${password} are used to specify location of these attributes in the
message.
tokenRespAttribute:
type: string
title: Token attribute
description: Path to token attribute in login response body. Nested attributes
are allowed.
authHeaderExpr:
type: string
title: Authorize Expression
description: JavaScript expression to compute the Authorization header to pass
in discover and collect calls. The value ${token} is used to
reference the token obtained from login.
__template_searchHead:
type: string
description: Binds 'searchHead' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'searchHead' at runtime.
__template_search:
type: string
description: Binds 'search' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'search' at runtime.
__template_earliest:
type: string
description: Binds 'earliest' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'earliest' at runtime.
__template_latest:
type: string
description: Binds 'latest' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'latest' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_outputMode:
type: string
description: Binds 'outputMode' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'outputMode' at runtime.
allOf:
- oneOf:
- $ref: "#/components/schemas/SplunkAuthenticationNone"
- $ref: "#/components/schemas/SplunkAuthenticationBasic"
- $ref: "#/components/schemas/SplunkAuthenticationBasicSecret"
- $ref: "#/components/schemas/SplunkAuthenticationToken"
- $ref: "#/components/schemas/SplunkAuthenticationTokenSecret"
discriminator:
propertyName: authentication
mapping:
none: "#/components/schemas/SplunkAuthenticationNone"
basic: "#/components/schemas/SplunkAuthenticationBasic"
basicSecret: "#/components/schemas/SplunkAuthenticationBasicSecret"
token: "#/components/schemas/SplunkAuthenticationToken"
tokenSecret: "#/components/schemas/SplunkAuthenticationTokenSecret"
CollectorSplunk:
allOf:
- $ref: "#/components/schemas/CollectorBase"
- type: object
properties:
type:
type: string
enum:
- splunk
description: Collector type
conf:
$ref: "#/components/schemas/SplunkCollectorConf"
description: Configuration specific to the Splunk Collector.
description: Splunk collector configuration
Collector:
description: Collector configuration
oneOf:
- $ref: "#/components/schemas/CollectorAzureBlob"
- $ref: "#/components/schemas/CollectorCriblLake"
- $ref: "#/components/schemas/CollectorDatabase"
- $ref: "#/components/schemas/CollectorFilesystem"
- $ref: "#/components/schemas/CollectorGoogleCloudStorage"
- $ref: "#/components/schemas/CollectorHealthCheck"
- $ref: "#/components/schemas/CollectorRest"
- $ref: "#/components/schemas/CollectorS3"
- $ref: "#/components/schemas/CollectorScript"
- $ref: "#/components/schemas/CollectorSplunk"
discriminator:
propertyName: type
mapping:
azure_blob: "#/components/schemas/CollectorAzureBlob"
cribl_lake: "#/components/schemas/CollectorCriblLake"
database: "#/components/schemas/CollectorDatabase"
filesystem: "#/components/schemas/CollectorFilesystem"
google_cloud_storage: "#/components/schemas/CollectorGoogleCloudStorage"
health_check: "#/components/schemas/CollectorHealthCheck"
rest: "#/components/schemas/CollectorRest"
s3: "#/components/schemas/CollectorS3"
script: "#/components/schemas/CollectorScript"
splunk: "#/components/schemas/CollectorSplunk"
RbacResource:
type: string
enum:
- groups
- insights-apps
- datasets
- dataset-providers
- projects
- dashboards
- macros
- notebooks
- notebook-templates
- apps
- secret-folders
title: RbacResource
x-speakeasy-unknown-values: allow
ResourcePolicy:
type: object
properties:
gid:
type: string
description: Unique identifier for the group that owns the resource.
id:
type: string
description: Unique identifier for the resource. Omitted for resource type
groups.
policy:
type: string
description: String that defines the access control policy for the resource.
type:
$ref: "#/components/schemas/RbacResource"
description: Resource type that the access control policy applies to.
examples:
- projects
required:
- gid
- policy
- type
title: ResourcePolicy
UserAccessControlList:
type: object
properties:
perms:
type: array
items:
$ref: "#/components/schemas/ResourcePolicy"
description: List of resource policies that define the access permissions for
this member.
user:
type: string
description: Username of the member whose access control entries are listed.
required:
- perms
- user
title: UserAccessControlList
TeamAccessControlList:
type: object
properties:
perms:
type: array
items:
$ref: "#/components/schemas/ResourcePolicy"
description: List of resource policies that define the access permissions for
this team.
team:
type: string
description: Name of the team whose access control entries are listed.
required:
- perms
- team
title: TeamAccessControlList
DatabaseConnectionAuthType:
type: string
enum:
- configObj
- connectionString
- secret
- secrets
title: DatabaseConnectionAuthType
x-speakeasy-unknown-values: allow
DatabaseConnectionType:
type: string
enum:
- mysql
- oracle
- postgres
- sqlserver
- teradata
title: DatabaseConnectionType
x-speakeasy-unknown-values: allow
SecureVersion:
type: string
enum:
- TLSv1.3
- TLSv1.2
- TLSv1.1
- TLSv1
title: SecureVersion
x-speakeasy-unknown-values: allow
TLSClientParams:
type: object
properties:
caPath:
type: string
description: Path to the Certificate Authority (CA) certificate file in PEM
format.
certPath:
type: string
description: Path to the client certificate file in PEM format.
certificateName:
type: string
description: Name of a certificate stored in Cribl.
disabled:
type: boolean
description: If true, TLS is disabled for the connection.
maxVersion:
$ref: "#/components/schemas/SecureVersion"
description: Maximum TLS version to allow for the connection.
minVersion:
$ref: "#/components/schemas/SecureVersion"
description: Minimum TLS version to allow for the connection.
passphrase:
type: string
description: Passphrase for the private key.
privKeyPath:
type: string
description: Path to the private key file in PEM format.
rejectUnauthorized:
type: boolean
description: If true, reject connections to servers with unverified
TLS certificates.
servername:
type: string
description: Server name for TLS Server Name Indication (SNI) extension.
required:
- disabled
description: TLS client connection settings.
title: TLSClientParams
DatabaseConnectionConfig:
type: object
properties:
authType:
$ref: "#/components/schemas/DatabaseConnectionAuthType"
description: Authentication method for the Database Connection. Determines how
credentials are provided.
examples:
- connectionString
configObj:
type: string
description: JSON configuration object for advanced SQL Server connection
settings.
examples:
- server: sqlserver.example.com
database: Reporting
user: yourUsername
password: yourPassword
options:
connectTimeout: 20000
connectionString:
type: string
description: Database connection string with embedded credentials or server
information.
examples:
- mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true
connectionTimeout:
type: integer
description: Maximum time (in milliseconds) to wait when establishing the
database connection.
examples:
- 10000
minimum: 1000
maximum: 60000
credentialsSecret:
type: string
description: Name of the stored credentials secret containing username and
password for SQL Server configObj authentication.
examples:
- mssql-production-credentials
credsSecrets:
type: string
description: Name of the stored credentials secret containing username and
password. Used with Oracle connections.
examples:
- oracle-production-credentials
database:
type: string
description: Database to connect to instead of the server default.
databaseType:
$ref: "#/components/schemas/DatabaseConnectionType"
description: Type of database engine for the connection.
examples:
- mysql
description:
type: string
description: Brief description of the Database Connection.
examples:
- Production MySQL database for customer data
host:
type: string
description: Hostname of the server to connect to.
examples:
- |-
'myId-dt5egqq7iq1hj6kh.env.trial.example.com'
Hostname, currently intended for Teradata
id:
type: string
description: Unique identifier for the Database Connection.
examples:
- mysql-prod-db
pattern: ^[a-zA-Z0-9_\\-]+$
logOnMechanism:
type: string
description: Log On Mechanism for databases that support multiple, like Teradata.
password:
type: string
description: Database password for authentication. Used with Oracle connections.
examples:
- yourPassword
requestTimeout:
type: integer
description: Maximum time (in milliseconds) to wait for a database query to
complete. Applies to SQL Server connections only.
examples:
- 30000
minimum: 1000
sslmode:
type: string
description: HTTPS/TLS connection mode for Teradata. Controls certificate
verification behavior.
examples:
- VERIFY-FULL
tags:
type: string
description: Comma-separated list of tags for categorizing and filtering
Database Connections.
examples:
- production,mysql,customer-data
textSecret:
type: string
description: Name of the stored text secret containing the connection string.
examples:
- mysql-production-connection
tls:
$ref: "#/components/schemas/TLSClientParams"
user:
type: string
description: Database username for authentication. Used with Oracle connections.
examples:
- yourUsername
required:
- authType
- databaseType
- description
- id
title: DatabaseConnectionConfig
DatabaseConnectionResponseEnvelope:
type: object
properties:
count:
type: integer
description: Number of Database Connections returned in the response envelope.
examples:
- 1
minimum: 0
items:
type: array
items:
$ref: "#/components/schemas/DatabaseConnectionConfig"
description: Database Connections returned in the response envelope.
required:
- count
- items
title: DatabaseConnectionResponseEnvelope
RestApiJsonError:
type: object
properties:
details:
type: object
additionalProperties: true
description: Optional structured details about the error (e.g. validation
failures).
message:
type: string
description: Human-readable message or serialized validation details for the
error.
status:
type: string
const: error
description: Always error for API error responses.
required:
- message
- status
description: JSON body returned for many REST failures that use
RESTEndpoint.sendError (and similar handlers).
title: RestApiJsonError
CountedFunctionResponse:
type: object
required:
- items
- count
properties:
count:
type: integer
description: Number of items returned in the items array.
items:
type: array
description: The list of items returned in this response.
items:
$ref: "#/components/schemas/FunctionResponse"
PaginatedFunctionResponse:
type: object
required:
- items
- count
properties:
items:
type: array
description: The items returned in this response, after any offset/limit
pagination has been applied.
items:
$ref: "#/components/schemas/FunctionResponse"
count:
type: integer
description: Number of items returned in the items array.
offset:
type: integer
description: Pagination offset. Returned when offset/limit query parameters are
provided.
limit:
type: integer
description: Pagination limit. Returned when offset/limit query parameters are
provided.
totalCount:
type: integer
description: Total number of items available. Returned when offset/limit query
parameters are provided.
InputCollection:
type: object
description: Input settings for a collection job, including event breaking,
routing, and preprocessing options.
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- collection
description: Resource type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process results
sendToRoutes:
type: boolean
title: Send to Routes
description: Send events to normal routing and event processing. Disable to
select a specific Pipeline/Destination combination.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
output:
type: string
title: Destination
description: Destination to send results to
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputCollection
InputKafka:
type: object
required:
- type
- brokers
- topics
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptions"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
brokers:
type: array
title: Bootstrap servers
description: Enter each Kafka bootstrap server you want to use. Specify the
hostname and port (such as mykafkabroker:9092) or just the hostname
(in which case @{product} will assign port 9092).
minItems: 1
items:
type: string
minLength: 1
topics:
type: array
title: Topic
description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only."
minItems: 1
items:
type: string
minLength: 1
groupId:
type: string
title: Group ID
description: The consumer group to which this instance belongs. Defaults to
'Cribl'.
fromBeginning:
type: boolean
title: From beginning
description: Leave enabled if you want the Source, upon first subscribing to a
topic, to read starting with the earliest available message
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationType"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationType"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
sessionTimeout:
type: number
title: Session timeout (ms)
description: >2-
Timeout used to detect client failures when using Kafka's group-management facilities.
If the client sends no heartbeats to the broker before the timeout expires,
the broker will remove the client from the group and initiate a rebalance.
Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms.
See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details.
minimum: 1000
maximum: 3600000
rebalanceTimeout:
type: number
title: Rebalance timeout (ms)
description: |-
Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details.
minimum: 1000
maximum: 3600000
heartbeatInterval:
type: number
title: Heartbeat interval (ms)
description: |-
Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details.
minimum: 1000
maximum: 3600000
autoCommitInterval:
type: number
title: Offset commit interval (ms)
description: How often to commit offsets. If both this and Offset commit
threshold are set, @{product} commits offsets when either condition
is met. If both are empty, @{product} commits offsets after each
batch.
minimum: 1000
maximum: 3600000
autoCommitThreshold:
type: number
title: Offset commit threshold
description: How many events are needed to trigger an offset commit. If both
this and Offset commit interval are set, @{product} commits offsets
when either condition is met. If both are empty, @{product} commits
offsets after each batch.
minimum: 1
maximum: 10000
maxBytesPerPartition:
type: number
title: Byte limit, per partition
description: Maximum amount of data that Kafka will return per partition, per
fetch request. Must equal or exceed the maximum message size
(maxBytesPerPartition) that Kafka is configured to allow. Otherwise,
@{product} can get stuck trying to retrieve messages. Defaults to
1048576 (1 MB).
minimum: 1
maximum: 10000000
maxBytes:
type: number
title: Byte limit
description: Maximum number of bytes that Kafka will return per fetch request.
Defaults to 10485760 (10 MB).
minimum: 1
maximum: 1000000000
maxSocketErrors:
type: number
title: Error limit, per socket
description: Maximum number of network errors before the consumer re-creates a
socket
minimum: 0
maximum: 100
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topics:
type: string
description: Binds 'topics' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topics' at runtime.
__template_groupId:
type: string
description: Binds 'groupId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'groupId' at runtime.
title: InputKafka
InputMsk:
type: object
required:
- type
- brokers
- topics
- region
- awsAuthenticationMethod
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsMsk"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
brokers:
type: array
title: Bootstrap servers
description: Enter each Kafka bootstrap server you want to use. Specify the
hostname and port (such as mykafkabroker:9092) or just the hostname
(in which case @{product} will assign port 9092).
minItems: 1
items:
type: string
minLength: 1
topics:
type: array
title: Topic
description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only."
minItems: 1
items:
type: string
minLength: 1
groupId:
type: string
title: Group ID
description: The consumer group to which this instance belongs. Defaults to
'Cribl'.
fromBeginning:
type: boolean
title: From beginning
description: Leave enabled if you want the Source, upon first subscribing to a
topic, to read starting with the earliest available message
sessionTimeout:
type: number
title: Session timeout (ms)
description: >2-
Timeout used to detect client failures when using Kafka's group-management facilities.
If the client sends no heartbeats to the broker before the timeout expires,
the broker will remove the client from the group and initiate a rebalance.
Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms.
See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details.
minimum: 1000
maximum: 3600000
rebalanceTimeout:
type: number
title: Rebalance timeout (ms)
description: |-
Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details.
minimum: 1000
maximum: 3600000
heartbeatInterval:
type: number
title: Heartbeat interval (ms)
description: |-
Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details.
minimum: 1000
maximum: 3600000
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationType"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the MSK cluster is located
endpoint:
type: string
title: Endpoint
description: MSK cluster service endpoint. If empty, defaults to the AWS
Region-specific endpoint. Otherwise, it must point to MSK
cluster-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for MSK
description: Use Assume Role credentials to access MSK
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
autoCommitInterval:
type: number
title: Offset commit interval (ms)
description: How often to commit offsets. If both this and Offset commit
threshold are set, @{product} commits offsets when either condition
is met. If both are empty, @{product} commits offsets after each
batch.
minimum: 1000
maximum: 3600000
autoCommitThreshold:
type: number
title: Offset commit threshold
description: How many events are needed to trigger an offset commit. If both
this and Offset commit interval are set, @{product} commits offsets
when either condition is met. If both are empty, @{product} commits
offsets after each batch.
minimum: 1
maximum: 10000
maxBytesPerPartition:
type: number
title: Byte limit, per partition
description: Maximum amount of data that Kafka will return per partition, per
fetch request. Must equal or exceed the maximum message size
(maxBytesPerPartition) that Kafka is configured to allow. Otherwise,
@{product} can get stuck trying to retrieve messages. Defaults to
1048576 (1 MB).
minimum: 1
maximum: 10000000
maxBytes:
type: number
title: Byte limit
description: Maximum number of bytes that Kafka will return per fetch request.
Defaults to 10485760 (10 MB).
minimum: 1
maximum: 1000000000
maxSocketErrors:
type: number
title: Error limit, per socket
description: Maximum number of network errors before the consumer re-creates a
socket
minimum: 0
maximum: 100
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topics:
type: string
description: Binds 'topics' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topics' at runtime.
__template_groupId:
type: string
description: Binds 'groupId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'groupId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: InputMsk
InputHttp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- http
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
criblAPI:
type: string
title: Cribl HTTP event API
description: Absolute path on which to listen for the Cribl HTTP API requests.
Only _bulk (default /cribl/_bulk) is available. Use empty string to
disable.
pattern: ^/|^$
elasticAPI:
type: string
title: Elasticsearch API endpoint (Bulk API)
description: Absolute path on which to listen for the Elasticsearch API
requests. Only _bulk (default /elastic/_bulk) is available. Use
empty string to disable.
pattern: ^/|^$
splunkHecAPI:
type: string
title: Splunk HEC endpoint
description: Absolute path on which listen for the Splunk HTTP Event Collector
API requests. Use empty string to disable.
pattern: ^/|^$
splunkHecAcks:
type: boolean
title: Enable Splunk HEC acknowledgements
description: Enable Splunk HEC acknowledgements
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
authTokensExt:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: object
oneOf:
- $ref: "#/components/schemas/InputHttpAuthTokensExtItemsType"
- $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint"
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: "Shared secret to be provided by any client (Authorization: )"
description:
type: string
title: Description
description: Description
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
__template_criblAPI:
type: string
description: Binds 'criblAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'criblAPI' at runtime.
__template_elasticAPI:
type: string
description: Binds 'elasticAPI' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'elasticAPI' at runtime.
__template_splunkHecAPI:
type: string
description: Binds 'splunkHecAPI' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'splunkHecAPI' at runtime.
title: InputHttp
InputSplunk:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsSplunk"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to establish a
connection
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: Socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: Forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports proxy
protocol v1 or v2
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
authTokens:
type: array
title: Auth tokens
description: Shared secrets to be provided by any Splunk forwarder. If empty,
unauthorized access is permitted.
items:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: Shared secrets to be provided by any Splunk forwarder. If empty,
unauthorized access is permitted.
description:
type: string
title: Description
description: Description
maxS2Sversion:
type: string
title: Max S2S version
description: The highest S2S protocol version to advertise during handshake
enum:
- v3
- v4
x-speakeasy-enum-descriptions:
- v3
- v4
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
useFwdTimezone:
type: boolean
title: Use Universal Forwarder time zone
description: Event Breakers will determine events' time zone from UF-provided
metadata, when TZ can't be inferred from the raw event
dropControlFields:
type: boolean
title: Drop control fields
description: Drop Splunk control fields such as `crcSalt` and `_savedPort`. If
disabled, control fields are stored in the internal field
`__ctrlFields`.
extractMetrics:
type: boolean
title: Extract metrics
description: Extract and process Splunk-generated metrics as Cribl metrics
compress:
type: string
title: Compression
description: Controls whether to support reading compressed data from a
forwarder. Select 'Automatic' to match the forwarder's
configuration, or 'Disabled' to reject compressed connections.
enum:
- disabled
- auto
- always
x-speakeasy-enum-descriptions:
- Disabled
- Automatic
- Always
x-speakeasy-unknown-values: allow
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_maxS2Sversion:
type: string
description: Binds 'maxS2Sversion' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'maxS2Sversion' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
title: InputSplunk
InputSplunkSearch:
type: object
required:
- type
- authType
- searchHead
- search
- cronSchedule
- endpoint
- outputMode
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- splunk_search
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
searchHead:
title: Search head
type: string
description: Search head base URL. Can be an expression. Default is
https://localhost:8089.
search:
type: string
title: Search
description: "Enter Splunk search here. Examples: 'index=myAppLogs level=error channel=myApp' OR '| mstats avg(myStat) as myStat WHERE index=myStatsIndex.'"
earliest:
title: Earliest
type: string
description: "The earliest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'"
latest:
title: Latest
type: string
description: "The latest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'"
cronSchedule:
type: string
title: Cron schedule
description: A cron schedule on which to run this job
endpoint:
type: string
title: Search endpoint
description: REST API used to create a search
outputMode:
$ref: "#/components/schemas/OutputModeOptionsSplunkCollectorConf"
description: Format of the returned output
endpointParams:
title: Endpoint parameters
type: array
description: Optional request parameters to send to the endpoint
items:
type: object
required:
- name
- value
properties:
name:
title: Parameter Name
type: string
description: Parameter Name
value:
title: Value
type: string
description: JavaScript expression to compute the parameter's value, normally
enclosed in backticks (e.g., `${earliest}`). If a constant,
use single quotes (e.g., 'earliest'). Values without
delimiters (e.g., earliest) are evaluated as strings.
endpointHeaders:
title: Endpoint headers
description: Optional request headers to send to the endpoint
type: array
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Header Name
description: Header Name
value:
type: string
title: Value
description: JavaScript expression to compute the header's value, normally
enclosed in backticks (e.g., `${earliest}`). If a constant,
use single quotes (e.g., 'earliest'). Values without
delimiters (e.g., earliest) are evaluated as strings.
logLevel:
type: string
title: Log level
enum:
- error
- warn
- info
- debug
description: Collector runtime log level (verbosity)
x-speakeasy-unknown-values: allow
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 for no timeout.
minimum: 0
maximum: 2400
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: When a DNS server returns multiple addresses, @{product} will cycle
through them in the order returned
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as self-signed certificates)
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
authType:
type: string
title: Authentication type
description: Splunk Search authentication type
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_searchHead:
type: string
description: Binds 'searchHead' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'searchHead' at runtime.
__template_search:
type: string
description: Binds 'search' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'search' at runtime.
__template_earliest:
type: string
description: Binds 'earliest' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'earliest' at runtime.
__template_latest:
type: string
description: Binds 'latest' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'latest' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_logLevel:
type: string
description: Binds 'logLevel' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logLevel' at runtime.
title: InputSplunkSearch
InputSplunkHec:
type: object
required:
- type
- host
- port
- splunkHecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- splunk_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: object
required:
- token
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: "Shared secret to be provided by any client (Authorization: )"
enabled:
type: boolean
title: Enable token
description: If true, the token is active and can be used for authentication.
description:
type: string
title: Description
description: Optional token description
allowedIndexesAtToken:
type: array
title: Allowed indexes
description: Enter the values you want to allow in the HEC event index field at
the token level. Supports wildcards. To skip validation, leave
blank.
minItems: 0
items:
type: string
minLength: 1
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
splunkHecAPI:
type: string
title: Splunk HEC endpoint
description: Absolute path on which to listen for the Splunk HTTP Event
Collector API requests. This input supports the /event, /raw and
/s2s endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. Overrides fields added at the token
or request level. See [the Source
documentation](https://docs.cribl.io/stream/sources-splunk-hec/#fields)
for more info.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
splunkHecAcks:
type: boolean
title: Splunk HEC acks
description: Enable Splunk HEC acknowledgements
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
useFwdTimezone:
type: boolean
title: Use Universal Forwarder time zone (S2S only)
description: Event Breakers will determine events' time zone from UF-provided
metadata, when TZ can't be inferred from the raw event
dropControlFields:
type: boolean
title: Drop control fields (S2S only)
description: Drop Splunk control fields such as `crcSalt` and `_savedPort`. If
disabled, control fields are stored in the internal field
`__ctrlFields`.
extractMetrics:
type: boolean
title: Extract metrics (S2S only)
description: Extract and process Splunk-generated metrics as Cribl metrics
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: Optionally, list HTTP origins to which @{product} should send CORS
(cross-origin resource sharing) Access-Control-Allow-* headers.
Supports wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: Optionally, list HTTP headers that @{product} will send to allowed
origins as "Access-Control-Allow-Headers" in a CORS preflight
response. Use "*" to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_splunkHecAPI:
type: string
description: Binds 'splunkHecAPI' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'splunkHecAPI' at runtime.
title: InputSplunkHec
InputAzureBlob:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsAzureblob"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`"
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
visibilityTimeout:
type: number
title: Visibility timeout (secs)
description: The duration (in seconds) that the received messages are hidden
from subsequent retrieve requests after being retrieved by a
ReceiveMessage request.
minimum: 0
maximum: 604800
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32."
minimum: 1
maximum: 32
servicePeriodSecs:
type: number
title: Service period (secs)
description: The duration (in seconds) which pollers should be validated and
restarted if exited
minimum: 1
maximum: 10
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will stop if a chunk cannot be downloaded within the time
specified.
maximum: 3600
minimum: 1
authType:
$ref: "#/components/schemas/AuthenticationMethodOptions"
description: Authentication method
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
connectionString:
type: string
title: Connection string
description: Enter your Azure Storage account connection string. If left blank,
Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.
textSecret:
type: string
title: Connection string (text secret)
description: Select or create a stored text secret
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
endpointSuffix:
type: string
title: Endpoint suffix
description: Endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
clientTextSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
certificate:
$ref: "#/components/schemas/CertificateType"
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_connectionString:
type: string
description: Binds 'connectionString' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'connectionString' at runtime.
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'storageAccountName' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at runtime.
title: InputAzureBlob
InputAzureVnetFlowLog:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- azure_vnet_flow_log
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`"
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
visibilityTimeout:
type: number
title: Visibility timeout (secs)
description: The duration (in seconds) that the received messages are hidden
from subsequent retrieve requests after being retrieved by a
ReceiveMessage request.
minimum: 0
maximum: 604800
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32."
minimum: 1
maximum: 32
maxDequeueCount:
type: number
title: Max dequeue count
description: Number of times a non-matching message can be dequeued before it is
permanently deleted. At the default of 1, non-matching messages are
deleted immediately (same as standard Azure Blob source behavior).
Set higher to leave messages in the queue for other consumers.
minimum: 1
maximum: 100
servicePeriodSecs:
type: number
title: Service period (secs)
description: The duration (in seconds) which pollers should be validated and
restarted if exited
minimum: 1
maximum: 10
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsClientAssertionClientAssertionrpc"
description: Authentication method
description:
type: string
title: Description
description: Optional description for this configuration.
textSecret:
type: string
title: Connection string (text secret)
description: Select or create a stored text secret
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
endpointSuffix:
type: string
title: Endpoint suffix
description: Endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
clientTextSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
certificate:
$ref: "#/components/schemas/CertificateType"
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'storageAccountName' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at runtime.
title: InputAzureVnetFlowLog
InputElastic:
type: object
required:
- type
- host
- port
- elasticAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- elastic
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
elasticAPI:
type: string
title: Elasticsearch API endpoint
description: Absolute path on which to listen for Elasticsearch API requests.
Defaults to /. _bulk will be appended automatically. For example,
/myPath becomes /myPath/_bulk. Requests can then be made to either
/myPath/_bulk or /myPath//_bulk. Other entries are
faked as success.
pattern: ^/
authType:
type: string
title: Authentication type
enum:
- none
- basic
- credentialsSecret
- authTokens
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Auth Tokens
description: Authentication type
x-speakeasy-unknown-values: allow
apiVersion:
type: string
title: API version
description: The API version to use for communicating with the server
enum:
- 6.8.4
- 8.3.2
- custom
x-speakeasy-enum-descriptions:
- 6.8.4
- 8.3.2
- Custom
x-speakeasy-unknown-values: allow
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
proxyMode:
type: object
title: ""
required:
- enabled
properties:
enabled:
type: boolean
title: Enable proxy mode
description: Enable proxying of non-bulk API requests to an external Elastic
server. Enable this only if you understand the implications. See
[Cribl
Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode)
for more details.
authType:
enum:
- none
- manual
- secret
title: Authentication method
type: string
description: Enter credentials directly, or select a stored secret
x-speakeasy-unknown-values: allow
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
url:
type: string
title: Proxy URL
description: URL of the Elastic server to proxy non-bulk requests to, such as
http://elastic:9200
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as self-signed certificates)
removeHeaders:
type: array
title: Remove headers
description: List of headers to remove from the request to proxy
minItems: 0
items:
type: string
minLength: 1
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Proxy request timeout
description: Amount of time, in seconds, to wait for a proxy request to complete
before canceling it
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
authTokens:
type: array
title: Token
description: Bearer tokens to include in the authorization header
items:
type: string
customAPIVersion:
type: string
title: Custom API Version
description: Custom version information to respond to requests
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_elasticAPI:
type: string
description: Binds 'elasticAPI' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'elasticAPI' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
title: InputElastic
InputConfluentCloud:
type: object
required:
- type
- brokers
- topics
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsConfluentcloud"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
brokers:
type: array
title: Bootstrap servers
description: List of Confluent Cloud bootstrap servers to use, such as
yourAccount.confluent.cloud:9092
minItems: 1
items:
type: string
minLength: 1
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
topics:
type: array
title: Topic
description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only."
minItems: 1
items:
type: string
minLength: 1
groupId:
type: string
title: Group ID
description: The consumer group to which this instance belongs. Defaults to
'Cribl'.
fromBeginning:
type: boolean
title: From beginning
description: Leave enabled if you want the Source, upon first subscribing to a
topic, to read starting with the earliest available message
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationType"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationType"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
sessionTimeout:
type: number
title: Session timeout (ms)
description: >2-
Timeout used to detect client failures when using Kafka's group-management facilities.
If the client sends no heartbeats to the broker before the timeout expires,
the broker will remove the client from the group and initiate a rebalance.
Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms.
See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details.
minimum: 1000
maximum: 3600000
rebalanceTimeout:
type: number
title: Rebalance timeout (ms)
description: |-
Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details.
minimum: 1000
maximum: 3600000
heartbeatInterval:
type: number
title: Heartbeat interval (ms)
description: |-
Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details.
minimum: 1000
maximum: 3600000
autoCommitInterval:
type: number
title: Offset commit interval (ms)
description: How often to commit offsets. If both this and Offset commit
threshold are set, @{product} commits offsets when either condition
is met. If both are empty, @{product} commits offsets after each
batch.
minimum: 1000
maximum: 3600000
autoCommitThreshold:
type: number
title: Offset commit threshold
description: How many events are needed to trigger an offset commit. If both
this and Offset commit interval are set, @{product} commits offsets
when either condition is met. If both are empty, @{product} commits
offsets after each batch.
minimum: 1
maximum: 10000
maxBytesPerPartition:
type: number
title: Byte limit, per partition
description: Maximum amount of data that Kafka will return per partition, per
fetch request. Must equal or exceed the maximum message size
(maxBytesPerPartition) that Kafka is configured to allow. Otherwise,
@{product} can get stuck trying to retrieve messages. Defaults to
1048576 (1 MB).
minimum: 1
maximum: 10000000
maxBytes:
type: number
title: Byte limit
description: Maximum number of bytes that Kafka will return per fetch request.
Defaults to 10485760 (10 MB).
minimum: 1
maximum: 1000000000
maxSocketErrors:
type: number
title: Error limit, per socket
description: Maximum number of network errors before the consumer re-creates a
socket
minimum: 0
maximum: 100
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topics:
type: string
description: Binds 'topics' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topics' at runtime.
__template_groupId:
type: string
description: Binds 'groupId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'groupId' at runtime.
title: InputConfluentCloud
InputGrafana:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- grafana
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep alive timeout (seconds)
description: Maximum time to wait for additional data, after the last response
was sent, before closing a socket connection. This can be very
useful when Grafana Agent remote write's request frequency is high
so, reusing connections, would help mitigating the cost of creating
a new connection per request. Note that Grafana Agent's embedded
Prometheus would attempt to keep connections open for up to 5
minutes.
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
prometheusAPI:
type: string
title: Remote Write API endpoint
description: "Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured."
pattern: ^/
lokiAPI:
type: string
title: Logs API endpoint
description: "Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured."
pattern: ^/
prometheusAuth:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuth"
description: Remote Write authentication type
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
lokiAuth:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthenticationTypeOptionsLokiAuth"
description: Loki logs authentication type
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_prometheusAPI:
type: string
description: Binds 'prometheusAPI' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'prometheusAPI' at runtime.
__template_lokiAPI:
type: string
description: Binds 'lokiAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'lokiAPI' at runtime.
anyOf:
- required:
- prometheusAPI
- required:
- lokiAPI
title: InputGrafana
InputLoki:
type: object
required:
- type
- host
- port
- lokiAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- loki
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
lokiAPI:
type: string
title: Logs API endpoint
description: "Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'."
pattern: ^/
authType:
$ref: "#/components/schemas/AuthenticationTypeOptionsLokiAuth"
description: Loki logs authentication type
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_lokiAPI:
type: string
description: Binds 'lokiAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'lokiAPI' at runtime.
title: InputLoki
InputPrometheusRw:
type: object
required:
- type
- host
- port
- prometheusAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- prometheus_rw
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
prometheusAPI:
type: string
title: Remote Write API endpoint
description: "Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write."
pattern: ^/
authType:
$ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuth"
description: Remote Write authentication type
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_prometheusAPI:
type: string
description: Binds 'prometheusAPI' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'prometheusAPI' at runtime.
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
title: InputPrometheusRw
InputPrometheus:
type: object
required:
- type
- interval
- logLevel
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsPrometheus"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
dimensionList:
type: array
title: Extra dimensions
minItems: 0
description: Other dimensions to include in events
items:
type: string
title: dimension
fieldPerMetric:
type: boolean
title: Use field per metric
description: "When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format."
discoveryType:
title: Discovery type
type: string
enum:
- static
- dns
- ec2
- http_sd
x-speakeasy-enum-descriptions:
- Static
- DNS
- AWS EC2
- HTTP SD
description: Target discovery mechanism. Use static to manually enter a list of
targets.
x-speakeasy-unknown-values: allow
interval:
type: number
title: Poll interval
description: How often, in minutes, to scrape targets for metrics. Maximum of 60
minutes. 60 must be evenly divisible by the value you enter.
minimum: 1
maximum: 60
logLevel:
$ref: "#/components/schemas/LogLevelOptions"
description: Collector runtime log level
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
timeout:
type: number
title: HTTP connection timeout
description: Time, in seconds, before aborting HTTP connection attempts; use 0
for no timeout
minimum: 0
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsSasl"
description: Enter credentials directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
targetList:
type: array
title: Targets
minItems: 1
description: "List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'."
items:
type: string
title: Targets
recordType:
$ref: "#/components/schemas/RecordTypeOptions"
description: DNS record type to resolve
scrapePort:
type: number
title: Metrics port
description: The port number in the metrics URL for discovered targets
minimum: 1
maximum: 65535
nameList:
type: array
title: DNS names
minItems: 1
description: List of DNS names to resolve
items:
type: string
title: DNS names
scrapeProtocol:
type: string
title: Metrics protocol
enum:
- http
- https
description: Protocol to use when collecting metrics
x-speakeasy-unknown-values: allow
scrapePath:
type: string
title: Metrics path
description: Path to use when collecting metrics from discovered targets
pattern: ^/.*
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
usePublicIp:
type: boolean
title: Use public IP
description: Use public IP address for discovered targets. Disable to use the
private IP address.
searchFilter:
title: Search filter
description: Filter to apply when searching for EC2 instances
type: array
items:
$ref: "#/components/schemas/SearchFilterConfInputPrometheus"
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the EC2 is located
endpoint:
type: string
title: Endpoint
description: EC2 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to EC2-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
enableAssumeRole:
type: boolean
title: Enable for EC2
description: Use Assume Role credentials to access EC2
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
httpDiscoveryUrl:
type: string
title: Discovery URL
description: URL to fetch target groups from (must be http or https)
pattern: ^https?://
httpDiscoveryHeaders:
type: array
title: HTTP headers
description: Extra headers to send with the discovery request
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
httpDiscoveryRejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject TLS certificates that cannot be verified for the discovery
endpoint. Falls back to the source-level setting if not specified.
maxResponseBodySize:
type: string
title: Max response body size
description: Maximum size of the HTTP SD response body. Responses exceeding this
limit will be rejected. Defaults to 20 MB.
username:
type: string
title: Username
description: Username for Prometheus Basic authentication
password:
type: string
title: Password
description: Password for Prometheus Basic authentication
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_dimensionList:
type: string
description: Binds 'dimensionList' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'dimensionList' at runtime.
__template_discoveryType:
type: string
description: Binds 'discoveryType' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'discoveryType' at runtime.
__template_logLevel:
type: string
description: Binds 'logLevel' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logLevel' at runtime.
__template_targetList:
type: string
description: Binds 'targetList' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'targetList' at runtime.
__template_nameList:
type: string
description: Binds 'nameList' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'nameList' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_password:
type: string
description: Binds 'password' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'password' at runtime.
title: InputPrometheus
InputEdgePrometheus:
type: object
required:
- type
- interval
- discoveryType
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- edge_prometheus
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
dimensionList:
type: array
title: Extra Dimensions
minItems: 0
description: Other dimensions to include in events
items:
type: string
title: dimension
fieldPerMetric:
type: boolean
title: Use field per metric
description: "When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format."
discoveryType:
title: Discovery type
type: string
enum:
- static
- dns
- ec2
- k8s-node
- k8s-pods
- k8s-service-monitor
- http_sd
x-speakeasy-enum-descriptions:
- Static
- DNS
- AWS EC2
- Kubernetes Node
- Kubernetes Pods
- Kubernetes Service Monitor (v4.18+)
- HTTP SD
description: Target discovery mechanism. Use static to manually enter a list of
targets.
x-speakeasy-unknown-values: allow
interval:
type: number
title: Poll Interval
description: How often in seconds to scrape targets for metrics.
minimum: 2
timeout:
type: number
title: HTTP Connection Timeout
description: Timeout, in milliseconds, before aborting HTTP connection attempts;
1-60000 or 0 to disable
maximum: 60000
minimum: 0
persistence:
$ref: "#/components/schemas/DiskSpoolingType"
description: Disk Spooling
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
authType:
title: Authentication method
type: string
enum:
- manual
- secret
- kubernetes
description: Enter credentials directly, or select a stored secret
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
targets:
type: array
title: Targets
minItems: 1
items:
type: object
required:
- host
properties:
protocol:
$ref: "#/components/schemas/ProtocolOptionsTargetsItems"
description: Protocol to use when collecting metrics
host:
type: string
title: Host
description: Name of host from which to pull metrics.
port:
type: number
title: Port
description: The port number in the metrics URL for discovered targets.
minimum: 1
maximum: 65535
path:
type: string
title: Path
description: Path to use when collecting metrics from discovered targets
pattern: ^/.*
description: Targets
recordType:
$ref: "#/components/schemas/RecordTypeOptions"
description: DNS record type to resolve
scrapePort:
type: number
title: Port
description: The port number in the metrics URL for discovered targets.
minimum: 1
maximum: 65535
nameList:
type: array
title: DNS names
minItems: 1
description: List of DNS names to resolve
items:
type: string
title: DNS names
scrapeProtocol:
$ref: "#/components/schemas/ProtocolOptionsTargetsItems"
description: Protocol to use when collecting metrics
scrapePath:
type: string
title: Path
description: Path to use when collecting metrics from discovered targets
pattern: ^/.*
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
usePublicIp:
type: boolean
title: Use public IP
description: Use public IP address for discovered targets. Disable to use the
private IP address.
searchFilter:
title: Search filter
description: Filter to apply when searching for EC2 instances
type: array
items:
$ref: "#/components/schemas/SearchFilterConfInputPrometheus"
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the EC2 is located
endpoint:
type: string
title: Endpoint
description: EC2 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to EC2-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for EC2
description: Use Assume Role credentials to access EC2
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
serviceMonitorNamespace:
type: string
title: ServiceMonitor Namespace
description: "Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure."
scrapeProtocolExpr:
type: string
title: Protocol
description: Protocol to use when collecting metrics
scrapePortExpr:
type: string
title: Port
description: The port number in the metrics URL for discovered targets.
scrapePathExpr:
type: string
title: Path
description: Path to use when collecting metrics from discovered targets
podFilter:
type: array
title: Filter Rules
description: |
Add rules to decide which pods to discover for metrics.
Pods are searched if no rules are given or of all the rules'
expressions evaluate to true.
items:
type: object
required:
- filter
properties:
filter:
type: string
title: Filter Expression
description: JavaScript expression applied to pods objects. Return 'true' to
include it.
description:
type: string
title: Description
description: Optional description of this rule's purpose
httpDiscoveryUrl:
type: string
title: Discovery URL
description: URL to fetch target groups from (must be http or https)
pattern: ^https?://
httpDiscoveryHeaders:
type: array
title: HTTP headers
description: Extra headers to send with the discovery request
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
httpDiscoveryRejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject TLS certificates that cannot be verified for the discovery
endpoint. Falls back to the source-level setting if not specified.
maxResponseBodySize:
type: string
title: Max response body size
description: Maximum size of the HTTP SD response body. Responses exceeding this
limit will be rejected. Defaults to 20 MB.
username:
type: string
title: Username
description: Username for Prometheus Basic authentication
password:
type: string
title: Password
description: Password for Prometheus Basic authentication
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_dimensionList:
type: string
description: Binds 'dimensionList' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'dimensionList' at runtime.
__template_nameList:
type: string
description: Binds 'nameList' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'nameList' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
title: InputEdgePrometheus
InputOffice365Mgmt:
type: object
required:
- type
- tenantId
- appId
- planType
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- office365_mgmt
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
planType:
$ref: "#/components/schemas/SubscriptionPlanOptions"
description: Microsoft 365 subscription plan for your organization, typically
Microsoft 365 Enterprise
tenantId:
type: string
title: Tenant ID
description: Microsoft 365 Azure Tenant ID
appId:
type: string
title: App ID
description: Microsoft 365 Azure Application ID
timeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout, use 0 to disable
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
publisherIdentifier:
type: string
title: Publisher Identifier
description: Optional Publisher Identifier to use in API requests, defaults to
tenant id if not defined. For more information see
[here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)
contentConfig:
type: array
title: Content Types
items:
type: object
properties:
contentType:
type: string
title: Content Type
description: Microsoft 365 Management Activity API Content Type
description:
type: string
title: Interval Description
description: If interval type is minutes the value entered must evenly divisible
by 60 or save will fail
interval:
type: number
title: Interval
minimum: 1
maximum: 60
description: Interval
logLevel:
$ref: "#/components/schemas/LogLevelOptionsContentConfigItems"
description: Collector runtime Log Level
enabled:
type: boolean
title: Enabled
description: Enabled
description: "Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule."
ingestionLag:
type: number
title: Ingestion lag (minutes)
description: Use this setting to account for ingestion lag. This is necessary
because there can be a lag of 60 - 90 minutes (or longer) before
Microsoft 365 events are available for retrieval.
minimum: 0
maximum: 7200
retryRules:
$ref: "#/components/schemas/RetryRulesTypeCodesEnableHeader"
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsManualSecret"
description: Enter client secret directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
clientSecret:
type: string
title: Client secret
description: Microsoft 365 Azure client secret
textSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_planType:
type: string
description: Binds 'planType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'planType' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_appId:
type: string
description: Binds 'appId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'appId' at runtime.
__template_publisherIdentifier:
type: string
description: Binds 'publisherIdentifier' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'publisherIdentifier' at runtime.
__template_clientSecret:
type: string
description: Binds 'clientSecret' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientSecret' at runtime.
title: InputOffice365Mgmt
InputOffice365Service:
type: object
required:
- type
- tenantId
- appId
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- office365_service
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
planType:
$ref: "#/components/schemas/SubscriptionPlanOptions"
description: Microsoft 365 subscription plan for your organization, typically
Microsoft 365 Enterprise
tenantId:
type: string
title: Tenant ID
description: Microsoft 365 Azure Tenant ID
appId:
type: string
title: App ID
description: Microsoft 365 Azure Application ID
timeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout, use 0 to disable
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
contentConfig:
type: array
title: Content Types
items:
type: object
properties:
contentType:
type: string
title: Content Type
description: Microsoft 365 Services API Content Type
description:
type: string
title: Interval Description
description: If interval type is minutes the value entered must evenly divisible
by 60 or save will fail
interval:
type: number
title: Interval
minimum: 0
maximum: 60
description: Interval
logLevel:
$ref: "#/components/schemas/LogLevelOptionsContentConfigItems"
description: Collector runtime Log Level
enabled:
type: boolean
title: Enabled
description: Enabled
description: "Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule."
retryRules:
$ref: "#/components/schemas/RetryRulesTypeCodesEnableHeader"
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsManualSecret"
description: Enter client secret directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
clientSecret:
type: string
title: Client secret
description: Microsoft 365 Azure client secret
textSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_planType:
type: string
description: Binds 'planType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'planType' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_appId:
type: string
description: Binds 'appId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'appId' at runtime.
__template_clientSecret:
type: string
description: Binds 'clientSecret' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientSecret' at runtime.
title: InputOffice365Service
InputOffice365MsgTrace:
type: object
required:
- type
- url
- interval
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- office365_msg_trace
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
url:
title: Report URL
type: string
description: URL to use when retrieving report data.
interval:
type: integer
title: Poll interval
description: How often (in minutes) to run the report. Must divide evenly into
60 minutes to create a predictable schedule, or Save will fail.
minimum: 1
maximum: 60
startDate:
title: Date range start
type: string
description: "Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps."
endDate:
title: Date range end
type: string
description: "Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps."
timeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Maximum is 2400 (40 minutes);
enter 0 to wait indefinitely.
minimum: 0
maximum: 2400
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disables time filtering of events when a date range is specified.
authType:
title: Authentication method
type: string
enum:
- manual
- secret
- oauth
- oauthSecret
- oauthCert
description: Select authentication method.
x-speakeasy-unknown-values: allow
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: \d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
rescheduleDroppedTasks:
type: boolean
title: Reschedule tasks
description: Reschedule tasks that failed with non-fatal errors
maxTaskReschedule:
type: number
title: Task reschedule limit
description: Maximum number of times a task can be rescheduled
minimum: 1
logLevel:
$ref: "#/components/schemas/LogLevelOptionsDebugError"
description: Log Level (verbosity) for collection runtime behavior.
retryRules:
$ref: "#/components/schemas/RetryRulesTypeCodesEnableHeader"
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username to run Message Trace API call.
password:
type: string
title: Password
description: Password to run Message Trace API call.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials.
clientSecret:
type: string
title: Client secret
description: client_secret to pass in the OAuth request parameter.
tenantId:
type: string
title: Tenant identifier
description: Directory ID (tenant identifier) in Azure Active Directory.
clientId:
type: string
title: Client ID
description: client_id to pass in the OAuth request parameter.
resource:
type: string
title: Resource
description: Resource to pass in the OAuth request parameter.
planType:
$ref: "#/components/schemas/SubscriptionPlanOptions"
description: Microsoft 365 subscription plan for your organization, typically
Microsoft 365 Enterprise
textSecret:
type: string
title: Client secret
description: Select or create a secret that references your client_secret to
pass in the OAuth request parameter.
certOptions:
$ref: "#/components/schemas/CertOptionsType"
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_resource:
type: string
description: Binds 'resource' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'resource' at runtime.
__template_planType:
type: string
description: Binds 'planType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'planType' at runtime.
title: InputOffice365MsgTrace
InputMicrosoftGraph:
type: object
required:
- type
- url
- interval
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- microsoft_graph
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
url:
title: Endpoint
type: string
description: Microsoft Graph API endpoint URL. (ex.
https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)
interval:
type: integer
title: Poll interval
description: How often (in minutes) to run the report. Must divide evenly into
60 minutes to create a predictable schedule, or Save will fail.
minimum: 1
maximum: 60
startDate:
title: Date range start
type: string
description: "Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps."
endDate:
title: Date range end
type: string
description: "Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps."
timeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Maximum is 2400 (40 minutes);
enter 0 to wait indefinitely.
minimum: 0
maximum: 2400
disableTimeFilter:
type: boolean
title: Disable time filter
description: Disables time filtering of events when a date range is specified.
maxPages:
type: integer
title: Page limit
description: Maximum number of pages to retrieve per collection task. Set to 0
to retrieve all pages.
minimum: 0
authType:
title: Authentication method
type: string
enum:
- oauth
- oauthSecret
- oauthCert
description: Select authentication method.
x-speakeasy-unknown-values: allow
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: \d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
rescheduleDroppedTasks:
type: boolean
title: Reschedule tasks
description: Reschedule tasks that failed with non-fatal errors
maxTaskReschedule:
type: number
title: Task reschedule limit
description: Maximum number of times a task can be rescheduled
minimum: 1
logLevel:
$ref: "#/components/schemas/LogLevelOptionsDebugError"
description: Log Level (verbosity) for collection runtime behavior.
retryRules:
$ref: "#/components/schemas/RetryRulesTypeCodesEnableHeader"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
description:
type: string
title: Description
description: Optional description for this configuration.
clientSecret:
type: string
title: Client secret
description: client_secret to pass in the OAuth request parameter.
tenantId:
type: string
title: Tenant identifier
description: Directory ID (tenant identifier) in Azure Active Directory.
clientId:
type: string
title: Client ID
description: client_id to pass in the OAuth request parameter.
resource:
type: string
title: Resource
description: Resource to pass in the OAuth request parameter.
planType:
type: string
title: Subscription plan
description: Microsoft 365 subscription plan for your organization, typically
Microsoft 365 Enterprise
enum:
- enterprise_gcc
- gcc
- gcc_high
- dod
- china
x-speakeasy-enum-descriptions:
- Microsoft 365 Enterprise
- Microsoft 365 GCC
- Microsoft 365 GCC High
- Microsoft 365 DoD
- Microsoft 365 China (21Vianet)
x-speakeasy-unknown-values: allow
textSecret:
type: string
title: Client secret
description: Select or create a secret that references your client_secret to
pass in the OAuth request parameter.
certOptions:
$ref: "#/components/schemas/CertOptionsType"
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_resource:
type: string
description: Binds 'resource' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'resource' at runtime.
__template_planType:
type: string
description: Binds 'planType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'planType' at runtime.
title: InputMicrosoftGraph
InputEventhub:
type: object
required:
- type
- brokers
- topics
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- eventhub
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
brokers:
type: array
title: Brokers
description: "List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies."
minItems: 1
items:
type: string
minLength: 1
topics:
type: array
title: Event Hub name
description: "The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic."
minItems: 1
items:
type: string
minLength: 1
groupId:
type: string
title: Group ID
description: The consumer group this instance belongs to. Default is 'Cribl'.
fromBeginning:
type: boolean
title: From beginning
description: Start reading from earliest available data; relevant only during
initial subscription
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationTypeUse"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideType"
description: TLS settings (client side)
sessionTimeout:
type: number
title: Session timeout (ms)
description: |-
Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md).
minimum: 6000
maximum: 300000
rebalanceTimeout:
type: number
title: Rebalance timeout (ms)
description: |-
Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md).
minimum: 1000
maximum: 3600000
heartbeatInterval:
type: number
title: Heartbeat interval (ms)
description: |-
Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md).
minimum: 1000
maximum: 3600000
autoCommitInterval:
type: number
title: Offset commit interval (ms)
description: How often to commit offsets. If both this and Offset commit
threshold are set, @{product} commits offsets when either condition
is met. If both are empty, @{product} commits offsets after each
batch.
minimum: 1000
maximum: 3600000
autoCommitThreshold:
type: number
title: Offset commit threshold
description: How many events are needed to trigger an offset commit. If both
this and Offset commit interval are set, @{product} commits offsets
when either condition is met. If both are empty, @{product} commits
offsets after each batch.
minimum: 1
maximum: 10000
maxBytesPerPartition:
type: number
title: Byte limit, per partition
description: Maximum amount of data that Kafka will return per partition, per
fetch request. Must equal or exceed the maximum message size
(maxBytesPerPartition) that Kafka is configured to allow. Otherwise,
@{product} can get stuck trying to retrieve messages. Defaults to
1048576 (1 MB).
minimum: 1
maximum: 10000000
maxBytes:
type: number
title: Byte limit
description: Maximum number of bytes that Kafka will return per fetch request.
Defaults to 10485760 (10 MB).
minimum: 1
maximum: 1000000000
maxSocketErrors:
type: number
title: Error limit, per socket
description: Maximum number of network errors before the consumer re-creates a
socket
minimum: 0
maximum: 100
minimizeDuplicates:
type: boolean
title: Minimize duplicates
description: Minimize duplicate events by starting only one consumer for each
topic partition
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topics:
type: string
description: Binds 'topics' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topics' at runtime.
__template_groupId:
type: string
description: Binds 'groupId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'groupId' at runtime.
title: InputEventhub
InputEventhubAmqp:
type: object
required:
- type
- consumerGroup
- checkpointing
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- eventhub_amqp
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
eventHubName:
type: string
title: Event Hub name
description: The name of the Event Hub to consume from
minLength: 1
consumerGroup:
type: string
title: Consumer group
description: The consumer group this instance belongs to. Default is '$Default'.
minLength: 1
auth:
type: object
required:
- mechanism
properties:
mechanism:
type: string
enum:
- connection-string
- oauth-bearer
x-speakeasy-enum-descriptions:
- Connection String
- OAuth Bearer
title: Authentication mechanism
description: Authentication mechanism
x-speakeasy-unknown-values: allow
textSecret:
type: string
title: Connection string (text secret)
description: Select or create a stored text secret
clientSecretAuthType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuth"
description: Authentication method
clientTextSecret:
type: string
title: Client Secret (text secret)
description: Select or create a stored text secret
certificate:
type: object
required:
- certificateName
- certPath
- privKeyPath
properties:
certificateName:
type: string
title: Certificate
description: The certificate you registered as credentials for your app in the
Azure portal
certPath:
type: string
title: Certificate path
description: Path on server containing certificates to use. PEM format. Can
reference $ENV_VARS.
privKeyPath:
type: string
title: Private key path
description: Path on server containing the private key to use. PEM format. Can
reference $ENV_VARS.
passphrase:
type: string
title: Passphrase
description: Passphrase to use to decrypt private key
oauthEndpoint:
$ref: "#/components/schemas/MicrosoftEntraIdAuthenticationEndpointOptionsSasl"
description: Endpoint used to acquire authentication tokens from Azure
clientId:
type: string
title: Client ID
description: client_id to pass in the OAuth request parameter
tenantId:
type: string
title: Tenant identifier
description: Directory ID (tenant identifier) in Azure Active Directory
fullyQualifiedNamespace:
type: string
title: Fully qualified namespace
description: The fully qualified Event Hubs namespace that the consumer is
associated with. This is likely to be similar to
{yournamespace}.servicebus.windows.net.
__template_oauthEndpoint:
type: string
description: Binds 'oauthEndpoint' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'oauthEndpoint' at
runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_fullyQualifiedNamespace:
type: string
description: Binds 'fullyQualifiedNamespace' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'fullyQualifiedNamespace' at runtime.
checkpointing:
type: object
required:
- blobStore
properties:
blobStore:
type: object
title: Azure Blob Storage
required:
- containerName
properties:
containerName:
type: string
title: Container name
description: Azure Blob Storage container used to store checkpoints. Must be
3–63 lowercase alphanumeric characters or hyphens.
minLength: 3
maxLength: 63
pattern: ^[a-z0-9](-?[a-z0-9])*$
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsClientAssertionClientAssertionrpc"
description: Authentication method
textSecret:
type: string
title: Connection string (text secret)
description: Select or create a stored text secret
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
endpointSuffix:
type: string
title: Endpoint suffix
description: Endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
clientTextSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
certificate:
$ref: "#/components/schemas/CertificateType"
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or
'cribl.'/'edge.' prefixed ID (group-scoped). Variable value
overrides 'storageAccountName' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at
runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at
runtime.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at
runtime.
description: Azure Blob Storage
fromBeginning:
type: boolean
title: From beginning
description: Start reading from earliest available data; relevant only during
initial subscription
maxBatchSize:
type: integer
minimum: 1
title: Max batch size
description: Maximum number of events in each batch delivered to the consumer
maxWaitTimeInSeconds:
type: integer
minimum: 1
title: Max wait time (secs)
description: Maximum time to wait for a batch of events before delivering a
partial batch
prefetchCount:
type: integer
minimum: 1
title: Prefetch count
description: Number of events to prefetch from the service for processing
maxRetries:
type: integer
minimum: 0
title: Retry limit
description: Maximum number of retries per operation
initialBackoff:
type: integer
minimum: 300
title: Initial retry interval (ms)
description: Initial delay before the first retry, in milliseconds
maxBackoff:
type: integer
minimum: 30000
title: Backoff limit (ms)
description: Maximum delay between retries, in milliseconds
timeoutInMs:
type: integer
minimum: 1000
title: Request timeout (ms)
description: Maximum time to wait for a request to complete
connectionInitialBackoff:
type: integer
minimum: 1
title: Connection initial retry interval (ms)
description: Initial delay before the first reconnection attempt, in milliseconds
connectionMaxBackoff:
type: integer
minimum: 1
title: Connection backoff limit (ms)
description: Maximum delay between reconnection attempts, in milliseconds
connectionTimeoutInMs:
type: integer
minimum: 1000
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputEventhubAmqp
InputExec:
type: object
required:
- type
- command
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
enum:
- exec
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: Disabled
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
command:
type: string
title: Command
description: Command to execute; supports Bourne shell (or CMD on Windows) syntax
script:
type: string
title: Script
description: Optional script content to pipe into the command's stdin. The stdin
stream is closed after the script is written.
retries:
type: number
title: Retry limit
description: Maximum number of retry attempts in the event that the command fails
minimum: 0
scheduleType:
title: Schedule type
type: string
enum:
- interval
- cronSchedule
description: Select a schedule type; either an interval (in seconds) or a
cron-style schedule.
x-speakeasy-unknown-values: allow
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
interval:
type: number
title: Interval
description: Interval between command executions in seconds.
minimum: 1
cronSchedule:
type: string
title: Schedule
description: Cron schedule to execute the command on.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputExec
InputFirehose:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- firehose
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
title: InputFirehose
InputGooglePubsub:
type: object
required:
- type
- subscriptionName
- topicName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsGooglepubsub"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
topicName:
type: string
title: Topic ID
description: ID of the topic to receive events from. When Monitor subscription
is enabled, any value may be entered.
subscriptionName:
type: string
title: Subscription ID
description: "ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription"
monitorSubscription:
type: boolean
title: Monitor subscription for new messages
description: Use when the subscription is not created by this Source and topic
is not known
createTopic:
type: boolean
title: Create topic
description: Create topic if it does not exist
createSubscription:
type: boolean
title: Create subscription
description: Create subscription if it does not exist
region:
type: string
title: Region
description: Region to retrieve messages from. Select 'default' to allow Google
to auto-select the nearest region. When using ordered delivery, the
selected region must be allowed by message storage policy.
googleAuthMethod:
$ref: "#/components/schemas/GoogleAuthenticationMethodOptions"
description: Choose Auto to use Google Application Default Credentials (ADC),
Manual to enter Google service account credentials directly, or
Secret to select or create a stored secret that references Google
service account credentials.
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of service account credentials (JSON keys) file downloaded
from Google Cloud. To upload a file, click the upload button at this
field's upper right.
secret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
maxBacklog:
type: number
title: Backlog limit
description: If Destination exerts backpressure, this setting limits how many
inbound events Stream will queue for processing before it stops
retrieving events
minimum: 1
concurrency:
type: number
title: Number of concurrent streams
description: How many streams to pull messages from at one time. Doubling the
value doubles the number of messages this Source pulls from the
topic (if available), while consuming more CPU and memory. Defaults
to 5.
minimum: 1
maximum: 100
requestTimeout:
type: number
title: Request timeout (ms)
description: Pull request timeout, in milliseconds
minimum: 10000
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
orderedDelivery:
type: boolean
title: Ordered delivery
description: Receive events in the order they were added to the queue. The
process sending events must have ordering enabled.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_topicName:
type: string
description: Binds 'topicName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topicName' at runtime.
__template_subscriptionName:
type: string
description: Binds 'subscriptionName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'subscriptionName' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
title: InputGooglePubsub
InputCribl:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- cribl
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
filter:
type: string
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputCribl
InputCriblTcp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsCribltcp"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: Socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: Forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports proxy
protocol v1 or v2
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
enableLoadBalancing:
type: boolean
title: Enable load balancing
description: Load balance traffic across all Worker Processes
authTokens:
type: array
title: Connected environment tokens
description: Shared secrets to be used by connected environments to authorize
connections. These tokens should be installed in Cribl TCP
destinations in connected environments.
items:
$ref: "#/components/schemas/AuthTokenConfInputCriblTcp"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputCriblTcp
InputCriblHttp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- cribl_http
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Connected environment tokens
description: Shared secrets to be used by connected environments to authorize
connections. These tokens should be installed in Cribl HTTP
destinations in connected environments.
items:
$ref: "#/components/schemas/AuthTokenConfInputCriblTcp"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputCriblHttp
InputCriblLakeHttp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- cribl_lake_http
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
criblAPI:
type: string
title: Cribl HTTP event API
description: Absolute path on which to listen for the Cribl HTTP API requests.
Only _bulk (default /cribl/_bulk) is available. Use empty string to
disable.
pattern: ^/|^$
elasticAPI:
type: string
title: Elasticsearch API endpoint (Bulk API)
description: Absolute path on which to listen for the Elasticsearch API
requests. Only _bulk (default /elastic/_bulk) is available. Use
empty string to disable.
pattern: ^/|^$
splunkHecAPI:
type: string
title: Splunk HEC endpoint
description: Absolute path on which listen for the Splunk HTTP Event Collector
API requests. Use empty string to disable.
pattern: ^/|^$
splunkHecAcks:
type: boolean
title: Enable Splunk HEC acknowledgements
description: Enable Splunk HEC acknowledgements
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
authTokensExt:
type: array
title: Auth tokens
items:
type: object
oneOf:
- $ref: "#/components/schemas/InputHttpAuthTokensExtItemsType"
- $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint"
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: Token
description:
type: string
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
splunkHecMetadata:
type: object
properties:
enabled:
type: boolean
title: Splunk HEC
description: When enabled, the token value is available on events as __hecToken
defaultDataset:
type: string
allowedIndexesAtToken:
type: array
minItems: 0
items:
type: string
minLength: 1
elasticsearchMetadata:
type: object
properties:
enabled:
title: Elasticsearch
type: boolean
description: Elasticsearch
defaultDataset:
type: string
description: Auth tokens
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
__template_criblAPI:
type: string
description: Binds 'criblAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'criblAPI' at runtime.
__template_elasticAPI:
type: string
description: Binds 'elasticAPI' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'elasticAPI' at runtime.
__template_splunkHecAPI:
type: string
description: Binds 'splunkHecAPI' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'splunkHecAPI' at runtime.
title: InputCriblLakeHttp
InputTcpjson:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsTcpjson"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to establish a
connection
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: Socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: Forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports proxy
protocol v1 or v2
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
enableLoadBalancing:
type: boolean
title: Enable load balancing
description: Load balance traffic across all Worker Processes
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
description:
type: string
title: Description
description: Optional description for this configuration.
authToken:
type: string
title: Auth token
description: Shared secret to be provided by any client (in authToken header
field). If empty, unauthorized access is permitted.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputTcpjson
InputSystemMetrics:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- system_metrics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between consecutive metric collections. Default
is 10 seconds.
host:
type: object
properties:
mode:
$ref: "#/components/schemas/ModeOptionsHost"
description: Select level of detail for host metrics
custom:
type: object
properties:
system:
type: object
properties:
mode:
type: string
description: Select the level of detail for system metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
processes:
type: boolean
title: Process metrics
description: Generate metrics for the numbers of processes in various states
cpu:
type: object
properties:
mode:
type: string
description: Select the level of detail for CPU metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
perCpu:
type: boolean
title: Per-CPU metrics
description: Generate metrics for each CPU
detail:
type: boolean
title: Detailed metrics
description: Generate metrics for all CPU states
time:
type: boolean
title: CPU time metrics
description: Generate raw, monotonic CPU time counters
memory:
type: object
properties:
mode:
type: string
description: Select the level of detail for memory metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate metrics for all memory states
network:
type: object
properties:
mode:
type: string
description: Select the level of detail for network metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate full network metrics
protocols:
type: boolean
title: Protocol metrics
description: Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and
UDPLite
devices:
type: array
title: Interface filter
description: "Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty."
items:
type: string
perInterface:
type: boolean
title: Per-interface metrics
description: Generate separate metrics for each interface
disk:
type: object
properties:
mode:
type: string
description: Select the level of detail for disk metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate full disk metrics
inodes:
type: boolean
title: Enable inode metrics
description: Generate filesystem inode metrics
devices:
type: array
title: Device filter
description: "Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty."
items:
type: string
mountpoints:
type: array
title: Mountpoint filter
description: "Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty."
items:
type: string
fstypes:
type: array
title: Filesystem type filter
description: "Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty."
items:
type: string
perDevice:
type: boolean
title: Per-device metrics
description: Generate separate metrics for each device
process:
$ref: "#/components/schemas/ProcessType"
container:
type: object
properties:
mode:
type: string
description: Select the level of detail for container metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
dockerSocket:
type: array
title: Docker socket
description: Full paths for Docker's UNIX-domain socket
items:
type: string
dockerTimeout:
type: number
minimum: 1
title: Docker timeout
description: Timeout, in seconds, for the Docker API
filters:
type: array
title: Container filters
description: Containers matching any of these will be included. All are included
if no filters are added.
items:
type: object
required:
- expr
properties:
expr:
type: string
title: Expression
description: Expression
allContainers:
type: boolean
title: All containers
description: Include stopped and paused containers
perDevice:
type: boolean
title: Per-device metrics
description: Generate separate metrics for each device
detail:
type: boolean
title: Detailed metrics
description: Generate full container metrics
gpu:
$ref: "#/components/schemas/GpuType"
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
persistence:
type: object
title: persistence
properties:
enable:
type: boolean
title: Enable disk spooling
description: Spool metrics to disk for Cribl Edge and Search
timeWindow:
type: string
title: Bucket time span
description: Time span for each file bucket
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to
$CRIBL_HOME/state/system_metrics
description: persistence
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputSystemMetrics
InputSystemState:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- system_state
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between consecutive state collections. Default is
300 seconds (5 minutes).
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
collectors:
type: object
properties:
hostsfile:
type: object
title: Hosts File
description: Creates events based on entries collected from the hosts file
properties:
enable:
type: boolean
title: Enabled
description: Enabled
interfaces:
type: object
title: Interfaces
description: Creates events for each of the host’s network interfaces
properties:
enable:
type: boolean
title: Enabled
description: Enabled
disk:
type: object
title: Disks & File Systems
description: Creates events for physical disks, partitions, and file systems
properties:
enable:
type: boolean
title: Enabled
description: Enabled
metadata:
type: object
title: Host Info
description: Creates events based on the host system’s current state
properties:
enable:
type: boolean
title: Enabled
description: Enabled
routes:
type: object
title: Routes
description: Creates events based on entries collected from the host’s network
routes
properties:
enable:
type: boolean
title: Enabled
description: Enabled
dns:
type: object
title: DNS
description: Creates events for DNS resolvers and search entries
properties:
enable:
type: boolean
title: Enabled
description: Enabled
user:
type: object
title: Users & Groups
description: Creates events for local users and groups
properties:
enable:
type: boolean
title: Enabled
description: Enabled
firewall:
type: object
title: Firewall
description: Creates events for Firewall rules entries
properties:
enable:
type: boolean
title: Enabled
description: Enabled
services:
type: object
title: Services
description: Creates events from the list of services
properties:
enable:
type: boolean
title: Enabled
description: Enabled
ports:
type: object
title: Listening Ports
description: Creates events from list of listening ports
properties:
enable:
type: boolean
title: Enabled
description: Enabled
loginUsers:
type: object
title: Logged-In Users
description: Creates events from list of logged-in users
properties:
enable:
type: boolean
title: Enabled
description: Enabled
persistence:
type: object
properties:
enable:
type: boolean
title: Enable disk spooling
description: Spool metrics to disk for Cribl Edge and Search
timeWindow:
type: string
title: Bucket time span
description: Time span for each file bucket
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to
$CRIBL_HOME/state/system_state
disableNativeModule:
type: boolean
title: Use Windows Tools
description: Enable to use built-in tools (PowerShell) to collect events instead
of native API (default) [Learn
more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)
disableNativeLastLogModule:
type: boolean
title: Use legacy collection for LastLog
description: Enable only to collect LastLog data via legacy implementation. This
option will be removed in a future release. Please contact Support
before enabling. [Learn
more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputSystemState
InputKubeMetrics:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- kube_metrics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between consecutive metrics collections. Default
is 15 secs.
scrapeKubelet:
type: boolean
title: Collect kubelet metrics
description: Enable to scrape kubelet metrics from
https://:10250/metrics. Requires Edge to run as a DaemonSet
with direct network access to the node.
scrapeCadvisor:
type: boolean
title: Collect cAdvisor metrics
description: Scrape cAdvisor container metrics from
https://:10250/metrics/cadvisor. Requires Edge to run as a
DaemonSet with direct network access to the Node.
rules:
type: array
title: Filter Rules
description: Add rules to decide which Kubernetes objects to generate metrics
for. Events are generated if no rules are given or of all the rules'
expressions evaluate to true.
items:
$ref: "#/components/schemas/RuleConfInputKubeMetrics"
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
persistence:
type: object
title: persistence
properties:
enable:
type: boolean
title: Enable disk spooling
description: Spool metrics on disk for Cribl Search
timeWindow:
type: string
title: Bucket time span
description: Time span for each file bucket
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to $CRIBL_HOME/state/
description: persistence
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputKubeMetrics
InputKubeLogs:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- kube_logs
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between checks for new containers. Default is 15
secs.
rules:
type: array
title: Filter Rules
description: Add rules to decide which Pods to collect logs from. Logs are
collected if no rules are given or if all the rules' expressions
evaluate to true.
items:
type: object
required:
- filter
properties:
filter:
type: string
title: Filter Expression
description: JavaScript expression applied to Pod objects. Return 'true' to
include it.
description:
type: string
title: Description
description: Optional description of this rule's purpose
timestamps:
type: boolean
title: Enable timestamps
description: For use when containers do not emit a timestamp, prefix each line
of output with a timestamp. If you enable this setting, you can use
the Kubernetes Logs Event Breaker and the kubernetes_logs
Pre-processing Pipeline to remove them from the events after the
timestamps are extracted.
lineBufferLimit:
type: number
minimum: 1024
title: Line buffer limit
description: Maximum bytes to buffer while reassembling a single log line. A
line that exceeds this size is flushed as-is, either whole or
partially. The default is 1048576 (1 MB).
__LBDisableAssembly:
type: boolean
description: Internal flag to disable LB worker payload reassembly.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
persistence:
$ref: "#/components/schemas/DiskSpoolingType"
description: Disk Spooling
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
enableLoadBalancing:
type: boolean
title: Enable load balancing
description: Load balance traffic across all Worker Processes
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputKubeLogs
InputKubeEvents:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- kube_events
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
rules:
type: array
title: Filter Rules
description: Filtering on event fields
items:
$ref: "#/components/schemas/RuleConfInputKubeMetrics"
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputKubeEvents
InputWindowsMetrics:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- windows_metrics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between consecutive metric collections. Default
is 10 seconds.
host:
type: object
properties:
mode:
$ref: "#/components/schemas/ModeOptionsHost"
description: Select level of detail for host metrics
custom:
type: object
properties:
system:
type: object
properties:
mode:
type: string
description: Select the level of details for system metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate metrics for all system information
cpu:
type: object
properties:
mode:
type: string
description: Select the level of details for CPU metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
perCpu:
type: boolean
title: Per-CPU metrics
description: Generate metrics for each CPU
detail:
type: boolean
title: Detailed metrics
description: Generate metrics for all CPU states
time:
type: boolean
title: CPU time metrics
description: Generate raw, monotonic CPU time counters
memory:
type: object
properties:
mode:
type: string
description: Select the level of details for memory metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate metrics for all memory states
network:
type: object
properties:
mode:
type: string
description: Select the level of details for network metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
detail:
type: boolean
title: Detailed metrics
description: Generate full network metrics
protocols:
type: boolean
title: Protocol metrics
description: Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and
UDPLite
devices:
type: array
title: Interface filter
description: Network interfaces to include/exclude. All interfaces are included
if this list is empty.
items:
type: string
perInterface:
type: boolean
title: Per interface metrics
description: Generate separate metrics for each interface
disk:
type: object
properties:
mode:
type: string
description: Select the level of details for disk metrics
enum:
- basic
- all
- custom
- disabled
x-speakeasy-enum-descriptions:
- Basic
- All
- Custom
- Disabled
x-speakeasy-unknown-values: allow
perVolume:
type: boolean
title: Per volume metrics
description: Generate separate metrics for each volume
detail:
type: boolean
title: Detailed metrics
description: Generate full disk metrics
volumes:
type: array
title: Volume filter
description: "Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty."
items:
type: string
process:
$ref: "#/components/schemas/ProcessType"
gpu:
$ref: "#/components/schemas/GpuType"
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
persistence:
type: object
title: persistence
properties:
enable:
type: boolean
title: Enable disk spooling
description: Spool metrics to disk for Cribl Edge and Search
timeWindow:
type: string
title: Bucket time span
description: Time span for each file bucket
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to
$CRIBL_HOME/state/windows_metrics
description: persistence
disableNativeModule:
type: boolean
title: Use Windows Tools
description: Enable to use built-in tools (PowerShell) to collect metrics
instead of native API (default) [Learn
more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputWindowsMetrics
InputCrowdstrike:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- crowdstrike
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the S3 bucket and SQS queue are located. Required,
unless the Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility timeout seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
socketTimeout:
type: number
title: Socket timeout
description: Socket inactivity timeout (in seconds). Increase this value if
timeouts occur due to backpressure.
minimum: 1
maximum: 43200
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
includeSqsMetadata:
type: boolean
title: Include notification metadata
description: Attach SQS notification metadata to a __sqsMetadata field on each
event
enableAssumeRole:
type: boolean
title: Enable for Amazon S3
description: Use Assume Role credentials to access Amazon S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
enableSQSAssumeRole:
type: boolean
title: Enable for Amazon SQS
description: Use Assume Role credentials when accessing Amazon SQS
sharedCredentials:
type: boolean
title: Share credentials for SQS and S3
description: Use the same credential settings for S3 and SQS
sharedAssumeRoleArn:
type: boolean
title: Share AssumeRole ARN settings
description: Use the same settings for S3 and SQS
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
checkpointing:
$ref: "#/components/schemas/CheckpointingType"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAssumeRoleArn:
type: string
title: SQS AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
SQSAssumeRoleExternalId:
type: string
title: SQS External ID
description: External ID to use when assuming role
SQSDurationSeconds:
type: number
title: SQS duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
SQSAwsAuthenticationMethod:
$ref: "#/components/schemas/SqsAuthenticationMethodOptions"
description: Choose Auto to use IAM roles
SQSAwsSecret:
type: string
title: SQS secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAwsSecretKey:
type: string
title: SQS secret key
description: SQS secret key
tagAfterProcessing:
$ref: "#/components/schemas/TagAfterProcessingOptions"
processedTagKey:
type: string
title: Tag key
description: The key for the S3 object tag applied after processing. This field
accepts an expression for dynamic generation.
processedTagValue:
type: string
title: Tag value
description: The value for the S3 object tag applied after processing. This
field accepts an expression for dynamic generation.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_SQSAssumeRoleArn:
type: string
description: Binds 'SQSAssumeRoleArn' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleArn' at runtime.
__template_SQSAssumeRoleExternalId:
type: string
description: Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleExternalId' at runtime.
__template_SQSAwsSecretKey:
type: string
description: Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'SQSAwsSecretKey' at
runtime.
title: InputCrowdstrike
InputDatadogAgent:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- datadog_agent
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
extractMetrics:
type: boolean
title: Extract metrics
description: Extract each incoming metric to multiple events, one per data
point. Recommended when sending metrics to a statsd-type output. If
sending metrics to DatadogHQ or any destination that accepts
arbitrary JSON, leave disabled.
samplingRate:
type: number
title: Global sampling rate
description: The rate_by_service hint sent to connected tracers as the catch-all
sampling rate. Applies to any service/environment not explicitly
listed in Per-Service Sampling Rules. 1.0 = keep all traces
(default); 0.0 = suggest dropping all.
minimum: 0
maximum: 1
samplingRules:
type: array
title: Per-service sampling rules
description: Per-service sampling rate hints. Each row maps to a
"service:,env:" key in the rate_by_service response sent to
tracers.
minItems: 0
items:
type: object
required:
- service
- environment
- rate
properties:
service:
type: string
title: Service
description: Datadog service name
minLength: 1
environment:
type: string
title: Environment
description: "Datadog environment name (example: prod, staging)"
minLength: 1
rate:
type: number
title: Rate
description: Sampling rate for this service/environment combination (0.0–1.0)
minimum: 0
maximum: 1
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
proxyMode:
type: object
title: ""
required:
- enabled
properties:
enabled:
type: boolean
title: Forward API key validation requests
description: Forward key validation requests from the Datadog Agent to the
Datadog API. If disabled, Stream handles key validation requests
locally by always responding that the key is valid.
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Whether to reject certificates that cannot be verified against a
valid CA (such as self-signed certificates)
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputDatadogAgent
InputDatagen:
type: object
required:
- type
- samples
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- datagen
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
samples:
title: Datagens
type: array
minItems: 1
items:
type: object
required:
- sample
- eventsPerSec
properties:
sample:
type: string
title: Data Generator File Name
description: Data Generator File Name
eventsPerSec:
type: number
title: Events Per Second Per Worker Node
description: Maximum number of events to generate per second per Worker Node.
Defaults to 10.
minimum: 1
description: Datagens
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputDatagen
InputHttpRaw:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- http_raw
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedPaths:
type: array
title: Allowed URI paths
description: List of URI paths accepted by this input, wildcards are supported,
e.g /api/v*/hook. Defaults to allow all.
items:
type: string
minLength: 1
allowedMethods:
type: array
title: Allowed HTTP methods
description: List of HTTP methods accepted by this input. Wildcards are
supported (such as P*, GET). Defaults to allow all.
items:
type: string
minLength: 1
authTokensExt:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: object
oneOf:
- required:
- token
- $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint"
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: "Shared secret to be provided by any client (Authorization: )"
description:
type: string
title: Description
description: Description
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: "HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS."
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers echoed in Access-Control-Allow-Headers on preflight.
Use "*" to allow all headers.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowMethods:
title: CORS allowed methods
type: array
description: HTTP methods echoed in Access-Control-Allow-Methods on preflight.
minItems: 0
items:
type: string
minLength: 1
accessControlExposeHeaders:
title: CORS exposed headers
type: array
description: Headers the browser is allowed to access from the response
minItems: 0
items:
type: string
minLength: 1
accessControlAllowCredentials:
type: boolean
title: CORS include credentials
description: Include credentials in cross-origin requests. Cannot be used with
wildcard origins.
accessControlMaxAge:
type: number
title: CORS max age (seconds)
description: How long browsers should cache the preflight response
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
__template_allowedPaths:
type: string
description: Binds 'allowedPaths' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedPaths' at runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputHttpRaw
InputKinesis:
type: object
required:
- type
- streamName
- region
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsKinesis"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
streamName:
type: string
title: Stream name
description: Kinesis Data Stream to read data from
serviceInterval:
type: number
title: Service period
description: Time interval in minutes between consecutive service calls
minimum: 1
maximum: 5
shardExpr:
type: string
title: Shard selection expression
description: A JavaScript expression to be called with each shardId for the
stream. If the expression evaluates to a truthy value, the shard
will be processed.
shardIteratorType:
type: string
title: Shard iterator start
description: Location at which to start reading a shard for the first time
enum:
- TRIM_HORIZON
- LATEST
x-speakeasy-enum-descriptions:
- Earliest record
- Latest record
x-speakeasy-unknown-values: allow
payloadFormat:
type: string
title: Record data format
description: Format of data inside the Kinesis Stream records. Gzip compression
is automatically detected.
enum:
- cribl
- ndjson
- cloudwatch
- line
x-speakeasy-enum-descriptions:
- Cribl
- Newline JSON
- Cloudwatch Logs
- Event per line
x-speakeasy-unknown-values: allow
getRecordsLimit:
type: number
title: Records limit per call
description: Maximum number of records per getRecords call
minimum: 5000
maximum: 10000
getRecordsLimitTotal:
type: number
title: Total records limit
description: Maximum number of records, across all shards, to pull down at once
per Worker Process
minimum: 20000
loadBalancingAlgorithm:
type: string
title: Shard load balancing
description: The load-balancing algorithm to use for spreading out shards across
Workers and Worker Processes
enum:
- ConsistentHashing
- RoundRobin
x-speakeasy-enum-descriptions:
- Consistent Hashing
- Round Robin
x-speakeasy-unknown-values: allow
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the Kinesis stream is located
endpoint:
type: string
title: Endpoint
description: Kinesis stream service endpoint. If empty, defaults to the AWS
Region-specific endpoint. Otherwise, it must point to Kinesis
stream-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for Kinesis stream
description: Use Assume Role credentials to access Kinesis stream
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
verifyKPLCheckSums:
type: boolean
title: Verify KPL checksums
description: Verify Kinesis Producer Library (KPL) event checksums
avoidDuplicates:
type: boolean
title: Avoid duplicate records
description: When resuming streaming from a stored state, Stream will read the
next available record, rather than rereading the last-read record.
Enabling this setting can cause data loss after a Worker Node's
unexpected shutdown or restart.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_streamName:
type: string
description: Binds 'streamName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamName' at runtime.
__template_shardIteratorType:
type: string
description: Binds 'shardIteratorType' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'shardIteratorType' at runtime.
__template_payloadFormat:
type: string
description: Binds 'payloadFormat' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'payloadFormat' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: InputKinesis
InputCriblmetrics:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- criblmetrics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
prefix:
type: string
title: Metric name prefix
description: A prefix that is applied to the metrics provided by Cribl Stream
fullFidelity:
type: boolean
title: Full fidelity
description: "Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`."
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputCriblmetrics
InputMetrics:
type: object
required:
- type
- host
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- metrics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. For IPv4 (all addresses), use the default
'0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP
address.
udpPort:
type: number
title: UDP Port
maximum: 65535
description: Enter UDP port number to listen on. Not required if listening on TCP.
tcpPort:
type: number
title: TCP Port
maximum: 65535
description: Enter TCP port number to listen on. Not required if listening on UDP.
maxBufferSize:
type: number
title: Buffer size limit (events)
description: Maximum number of events to buffer when downstream is blocking.
Only applies to UDP.
minimum: 0
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to send data
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports Proxy
Protocol V1 or V2
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
udpSocketRxBufSize:
type: number
title: UDP socket buffer size (bytes)
description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization."
minimum: 256
maximum: 4294967295
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_udpPort:
type: string
description: Binds 'udpPort' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'udpPort' at runtime.
__template_tcpPort:
type: string
description: Binds 'tcpPort' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tcpPort' at runtime.
title: InputMetrics
InputS3:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsS3"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the S3 bucket and SQS queue are located. Required,
unless the Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility timeout seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
socketTimeout:
type: number
title: Socket timeout
description: Socket inactivity timeout (in seconds). Increase this value if
timeouts occur due to backpressure.
minimum: 1
maximum: 43200
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
includeSqsMetadata:
type: boolean
title: Include notification metadata
description: Attach SQS notification metadata to a __sqsMetadata field on each
event
enableAssumeRole:
type: boolean
title: Enable for Amazon S3
description: Use Assume Role credentials to access Amazon S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
enableSQSAssumeRole:
type: boolean
title: Enable for Amazon SQS
description: Use Assume Role credentials when accessing Amazon SQS
sharedCredentials:
type: boolean
title: Share credentials for SQS and S3
description: Use the same credential settings for S3 and SQS
sharedAssumeRoleArn:
type: boolean
title: Share AssumeRole ARN settings
description: Use the same settings for S3 and SQS
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will stop if a chunk cannot be downloaded within the time
specified.
maximum: 3600
minimum: 1
checkpointing:
$ref: "#/components/schemas/CheckpointingType"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
tagAfterProcessing:
type: boolean
title: Tag after processing
description: Add a tag to processed S3 objects. Requires s3:GetObjectTagging and
s3:PutObjectTagging AWS permissions.
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAssumeRoleArn:
type: string
title: SQS AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
SQSAssumeRoleExternalId:
type: string
title: SQS External ID
description: External ID to use when assuming role
SQSDurationSeconds:
type: number
title: SQS duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
SQSAwsAuthenticationMethod:
$ref: "#/components/schemas/SqsAuthenticationMethodOptions"
description: Choose Auto to use IAM roles
SQSAwsSecret:
type: string
title: SQS secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAwsSecretKey:
type: string
title: SQS secret key
description: SQS secret key
processedTagKey:
type: string
title: Tag key
description: The key for the S3 object tag applied after processing. This field
accepts an expression for dynamic generation.
processedTagValue:
type: string
title: Tag value
description: The value for the S3 object tag applied after processing. This
field accepts an expression for dynamic generation.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_SQSAssumeRoleArn:
type: string
description: Binds 'SQSAssumeRoleArn' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleArn' at runtime.
__template_SQSAssumeRoleExternalId:
type: string
description: Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleExternalId' at runtime.
__template_SQSAwsSecretKey:
type: string
description: Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'SQSAwsSecretKey' at
runtime.
title: InputS3
InputS3Inventory:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- s3_inventory
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the S3 bucket and SQS queue are located. Required,
unless the Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility timeout seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
socketTimeout:
type: number
title: Socket timeout
description: Socket inactivity timeout (in seconds). Increase this value if
timeouts occur due to backpressure.
minimum: 1
maximum: 43200
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
includeSqsMetadata:
type: boolean
title: Include notification metadata
description: Attach SQS notification metadata to a __sqsMetadata field on each
event
enableAssumeRole:
type: boolean
title: Enable for Amazon S3
description: Use Assume Role credentials to access Amazon S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
enableSQSAssumeRole:
type: boolean
title: Enable for Amazon SQS
description: Use Assume Role credentials when accessing Amazon SQS
sharedCredentials:
type: boolean
title: Share credentials for SQS and S3
description: Use the same credential settings for S3 and SQS
sharedAssumeRoleArn:
type: boolean
title: Share AssumeRole ARN settings
description: Use the same settings for S3 and SQS
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will stop if a chunk cannot be downloaded within the time
specified.
maximum: 3600
minimum: 1
checkpointing:
$ref: "#/components/schemas/CheckpointingType"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
checksumSuffix:
type: string
title: Checksum Suffix
description: Filename suffix of the manifest checksum file. If a filename
matching this suffix is received in the queue, the matching
manifest file will be downloaded and validated against its value.
Defaults to "checksum"
maxManifestSizeKB:
type: integer
title: Manifest size limit (KB)
description: Maximum download size (KB) of each manifest or checksum file.
Manifest files larger than this size will not be
read. Defaults to 4096.
minimum: 1
validateInventoryFiles:
type: boolean
title: Validate inventory files
description: If set to Yes, each inventory file in the manifest will be
validated against its checksum. Defaults to false
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAssumeRoleArn:
type: string
title: SQS AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
SQSAssumeRoleExternalId:
type: string
title: SQS External ID
description: External ID to use when assuming role
SQSDurationSeconds:
type: number
title: SQS duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
SQSAwsAuthenticationMethod:
$ref: "#/components/schemas/SqsAuthenticationMethodOptions"
description: Choose Auto to use IAM roles
SQSAwsSecret:
type: string
title: SQS secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAwsSecretKey:
type: string
title: SQS secret key
description: SQS secret key
tagAfterProcessing:
$ref: "#/components/schemas/TagAfterProcessingOptions"
processedTagKey:
type: string
title: Tag key
description: The key for the S3 object tag applied after processing. This field
accepts an expression for dynamic generation.
processedTagValue:
type: string
title: Tag value
description: The value for the S3 object tag applied after processing. This
field accepts an expression for dynamic generation.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_SQSAssumeRoleArn:
type: string
description: Binds 'SQSAssumeRoleArn' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleArn' at runtime.
__template_SQSAssumeRoleExternalId:
type: string
description: Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleExternalId' at runtime.
__template_SQSAwsSecretKey:
type: string
description: Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'SQSAwsSecretKey' at
runtime.
title: InputS3Inventory
InputSnmp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsSnmp"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. For IPv4 (all addresses), use the default
'0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP
address.
port:
type: number
title: UDP port
maximum: 65535
description: UDP port to receive SNMP traps on. Defaults to 162.
snmpV3Auth:
type: object
title: SNMPv3 authentication
description: Authentication parameters for SNMPv3 trap. Set the log level to
debug if you are experiencing authentication or decryption issues.
required:
- v3AuthEnabled
properties:
v3AuthEnabled:
type: boolean
title: Enabled
description: Enabled
allowUnmatchedTrap:
type: boolean
title: Allow unmatched traps
description: Pass through traps that don't match any of the configured users.
@{product} will not attempt to decrypt these traps.
v3Users:
type: array
title: SNMP v3 users
description: User credentials for receiving v3 traps
minItems: 1
items:
type: object
required:
- name
properties:
name:
title: V3 name
type: string
minLength: 1
description: V3 name
authProtocol:
type: string
enum:
- none
- md5
- sha
- sha224
- sha256
- sha384
- sha512
x-speakeasy-enum-descriptions:
- None
- MD5
- SHA1
- SHA224
- SHA256
- SHA384
- SHA512
title: Authentication protocol
description: Authentication protocol
x-speakeasy-unknown-values: allow
authKeyType:
enum:
- manual
- secret
type: string
x-speakeasy-enum-descriptions:
- Manual
- Secret
title: V3 authentication key type
description: Select Manual to enter the key directly, or Secret to use a stored
text secret
x-speakeasy-unknown-values: allow
authKey:
type: string
title: V3 authentication key
description: V3 authentication key
authKeySecret:
type: string
title: V3 authentication key (text secret)
description: Select or create a stored text secret
privProtocol:
enum:
- none
- des
- aes
- aes256b
- aes256r
type: string
x-speakeasy-enum-descriptions:
- None
- DES
- AES128
- AES256b (Blumenthal)
- AES256r (Reeder)
title: Privacy protocol
description: Privacy protocol
x-speakeasy-unknown-values: allow
privKeyType:
enum:
- manual
- secret
type: string
x-speakeasy-enum-descriptions:
- Manual
- Secret
title: V3 privacy key type
description: Select Manual to enter the key directly, or Secret to use a stored
text secret
x-speakeasy-unknown-values: allow
privKey:
type: string
title: V3 privacy key
description: V3 privacy key
privKeySecret:
type: string
title: V3 privacy key (text secret)
description: Select or create a stored text secret
maxBufferSize:
type: number
title: Buffer size limit (events)
description: Maximum number of events to buffer when downstream is blocking.
minimum: 0
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to send data
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
udpSocketRxBufSize:
type: number
title: UDP socket buffer size (bytes)
description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization."
minimum: 256
maximum: 4294967295
varbindsWithTypes:
type: boolean
title: Include varbind types
description: If enabled, parses varbinds as an array of objects that include
OID, value, and type
bestEffortParsing:
type: boolean
title: Best effort parsing
description: If enabled, the parser will attempt to parse varbind octet strings
as UTF-8, first, otherwise will fallback to other methods
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputSnmp
InputOpenTelemetry:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- open_telemetry
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
captureHeadersWarning:
type: string
readOnly: true
const: ""
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
sec.; maximum 600 sec. (10 min.).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Enable to expose the /cribl_health endpoint, which returns 200 OK
when this Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist.
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
protocol:
type: string
title: Protocol
description: Select whether to leverage gRPC or HTTP for OpenTelemetry
enum:
- grpc
- http
x-speakeasy-enum-descriptions:
- gRPC
- HTTP
x-speakeasy-unknown-values: allow
extractSpans:
type: boolean
title: Extract spans
description: Enable to extract each incoming span to a separate event
extractMetrics:
type: boolean
title: Extract metrics
description: Enable to extract each incoming Gauge or IntGauge metric to
multiple events, one per data point
otlpVersion:
type: string
title: OTLP version
description: The version of OTLP Protobuf definitions to use when interpreting
received data
enum:
- 0.10.0
- 1.3.1
x-speakeasy-enum-descriptions:
- 0.10.0
- 1.3.1
x-speakeasy-unknown-values: allow
authType:
type: string
title: Authentication type
description: OpenTelemetry authentication type
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
x-speakeasy-unknown-values: allow
authMethodsExt:
type: array
title: Auth methods
description: Shared secrets to authenticate clients. Supports Bearer tokens,
Basic auth, and OAuth (JWKS-backed JWT) methods. If empty,
unauthenticated access is permitted.
minItems: 0
items:
type: object
required:
- authType
properties:
authType:
type: string
title: Authentication type
enum:
- token
- tokenSecret
- basic
- basicSecret
- oauth
x-speakeasy-enum-descriptions:
- Token
- Token (secret)
- Basic
- Basic (credentials secret)
- OAuth
description: Authentication type
x-speakeasy-unknown-values: allow
token:
type: string
minLength: 1
pattern: .*\S.*
title: Token
description: Bearer token for Authorization header
description:
type: string
title: Description
description: Description
metadata:
type: array
title: Fields
description: Fields to add to events referencing this auth method
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
enabled:
type: boolean
title: Enable
description: Enable
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
minLength: 1
username:
type: string
minLength: 1
pattern: .*\S.*
title: Username
description: Username
password:
type: string
minLength: 1
pattern: .*\S.*
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
minLength: 1
issuer:
type: string
minLength: 1
pattern: .*\S.*
title: Issuer
description: Expected token issuer (iss claim)
jwksUri:
type: string
minLength: 1
pattern: .*\S.*
title: JWKS URI
description: URL of the JWKS endpoint used to fetch signing keys
audience:
type: string
minLength: 1
pattern: .*\S.*
title: Audience
description: Expected token audience (aud claim)
scopes:
type: array
items:
type: string
title: Required scopes
description: Scopes the token must grant (optional)
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited. This does not limit concurrent HTTP/2 streams
on a connection; use Maximum concurrent streams and Maximum message
size for that bound.
minimum: 0
maxMessageSizeKB:
type: number
title: Maximum message size (KB)
description: Maximum size, in KB, of a single received gRPC message (OTLP export
request). Requests exceeding this limit are rejected before
processing. Compressed requests are checked against their
decompressed size.
minimum: 1
maximum: 65536
maxConcurrentStreams:
type: number
title: Maximum concurrent streams
description: Maximum number of concurrent HTTP/2 streams allowed on a single
gRPC connection. Combined with Maximum message size, this bounds
per-connection receive and decompress state. Active connection limit
only bounds connections.
minimum: 1
maximum: 10000
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
extractLogs:
type: boolean
title: Extract logs
description: Enable to extract each incoming log record to a separate event
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_protocol:
type: string
description: Binds 'protocol' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'protocol' at runtime.
__template_otlpVersion:
type: string
description: Binds 'otlpVersion' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'otlpVersion' at runtime.
title: InputOpenTelemetry
InputModelDrivenTelemetry:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- model_driven_telemetry
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
maxMessageSizeKB:
type: number
title: Maximum message size (KB)
description: Maximum size, in KB, of a single received gRPC message. Messages
exceeding this limit are rejected before processing. Compressed
messages are checked against their decompressed size.
minimum: 1
maximum: 65536
maxConcurrentStreams:
type: number
title: Maximum concurrent streams
description: Maximum number of concurrent HTTP/2 streams allowed on a single
gRPC connection. Combined with Maximum message size, this bounds
per-connection receive and decompress state. Active connection limit
only bounds the number of connections, not the streams multiplexed
on each.
minimum: 1
maximum: 10000
shutdownTimeoutMs:
type: number
title: Shutdown timeout
description: Time in milliseconds to allow the server to shutdown gracefully
before forcing shutdown. Defaults to 5000.
minimum: 1
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputModelDrivenTelemetry
InputSqs:
type: object
required:
- type
- queueName
- queueType
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsSqs"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
queueType:
title: Queue type
type: string
description: The queue type used (or created)
enum:
- standard
- fifo
x-speakeasy-enum-descriptions:
- Standard
- FIFO
x-speakeasy-unknown-values: allow
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
createQueue:
type: boolean
title: Create queue
description: Create queue if it does not exist
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the SQS queue is located. Required, unless the
Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: SQS service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to SQS-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for SQS
description: Use Assume Role credentials to access SQS
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility Timeout Seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_queueType:
type: string
description: Binds 'queueType' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueType' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: InputSqs
InputSyslog:
type: object
required:
- type
- host
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsSyslog"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. For IPv4 (all addresses), use the default
'0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP
address.
udpPort:
type: number
title: UDP port
maximum: 65535
description: Enter UDP port number to listen on. Not required if listening on TCP.
tcpPort:
type: number
title: TCP port
maximum: 65535
description: Enter TCP port number to listen on. Not required if listening on UDP.
maxBufferSize:
type: number
title: Buffer size limit (events)
description: Maximum number of events to buffer when downstream is blocking.
Only applies to UDP.
minimum: 0
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to send data
timestampTimezone:
type: string
title: Default timezone
description: Timezone to assign to timestamps without timezone info
singleMsgUdpPackets:
type: boolean
title: Single msg per UDP
description: Treat UDP packet data received as full syslog message
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports Proxy
Protocol V1 or V2
keepFieldsList:
type: array
title: Fields to keep
description: Wildcard list of fields to keep from source data; * = ALL (default)
minItems: 0
items:
type: string
octetCounting:
type: boolean
title: Octet count framing
description: Enable if incoming messages use octet counting per RFC 6587.
inferFraming:
type: boolean
title: Infer Syslog framing
description: Enable if we should infer the syslog framing of the incoming
messages.
strictlyInferOctetCounting:
type: boolean
title: Strictly infer octet count framing
description: Enable if we should infer octet counting only if the messages
comply with RFC 5424.
allowNonStandardAppName:
type: boolean
title: Allow non-standard app name
description: Enable if RFC 3164-formatted messages have hyphens in the app name
portion of the TAG section. If disabled, only alphanumeric
characters and underscores are allowed. Ignored for RFC
5424-formatted messages.
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process for
TCP connections. Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: TCP socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: TCP forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: TCP Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
udpSocketRxBufSize:
type: number
title: UDP socket buffer size (bytes)
description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization."
minimum: 256
maximum: 4294967295
enableLoadBalancing:
type: boolean
title: Enable TCP load balancing
description: Load balance traffic across all Worker Processes
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
enableEnhancedProxyHeaderParsing:
type: boolean
title: Enable enhanced TLS handshake for proxy protocol
description: When enabled, parses PROXY protocol headers during the TLS
handshake. Disable if compatibility issues arise.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_udpPort:
type: string
description: Binds 'udpPort' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'udpPort' at runtime.
__template_tcpPort:
type: string
description: Binds 'tcpPort' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tcpPort' at runtime.
__template_timestampTimezone:
type: string
description: Binds 'timestampTimezone' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'timestampTimezone' at runtime.
anyOf:
- required:
- host
- udpPort
- required:
- host
- tcpPort
title: InputSyslog
InputFile:
type: object
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
enum:
- file
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
mode:
type: string
enum:
- manual
- auto
x-speakeasy-enum-descriptions:
- Manual
- Auto
description: Choose how to discover files to monitor
x-speakeasy-unknown-values: allow
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between scanning for files
filenames:
type: array
title: Filename allowlist
description: The full path of discovered files are matched against this wildcard
list
items:
type: string
filterArchivedFiles:
type: boolean
title: Apply filename allowlist internal to archive files
description: Apply filename allowlist to file entries in archive file types,
like tar or zip.
tailOnly:
type: boolean
title: Collect from end
description: Read only new entries at the end of all files discovered at next
startup. @{product} will then read newly discovered files from the
head. Disable this to resume reading all files from head.
idleTimeout:
type: number
minimum: 1
title: Idle timeout
description: Time, in seconds, before an idle file is closed
minAgeDur:
type: string
title: Minimum age duration
description: "The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters."
maxAgeDur:
type: string
title: Maximum age duration
description: 'The maximum age of event timestamps to collect. Format examples:
60s, 4h, 3d, 1w. Can be used in conjuction with "Check file
modification times". Leave empty to apply no age filters.'
checkFileModTime:
type: boolean
title: Check file modification times
description: Skip files with modification times earlier than the maximum age
duration
forceText:
type: boolean
title: Force text format
description: Forces files containing binary data to be streamed as text
hashLen:
type: number
minimum: 1
title: Hash length
description: Length of file header bytes to use in hash for unique file
identification. Values above 16384 may cause issues with
re-ingesting files.
enableLoadBalancing:
type: boolean
title: Enable load balancing
description: Load balance traffic across all Worker Processes
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
disableStaleChannelFlush:
type: boolean
title: Disable Event Breaker buffer timeout
description: When enabled, no Event Breaker channel flush timeout applies and
the timeout below is ignored. Prefer this option when using
header-based breakers for file types such as CSV or IIS.
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
path:
type: string
title: Search path
description: "Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/)."
depth:
type: number
minimum: 0
title: Max depth
description: Set how many subdirectories deep to search. Use 0 to search only
files in the given path, 1 to also look in its immediate
subdirectories, etc. Leave it empty for unlimited depth.
suppressMissingPathErrors:
type: boolean
title: Suppress errors when search path does not exist
description: Suppress errors when search path does not exist
deleteFiles:
type: boolean
title: Delete files
description: Delete files after they have been collected
saltHash:
type: boolean
title: Salt file hash
description: Salt the file hash with the Source file path. Ensures that all
files with the same header hash, such as CSV files, are ingested.
Moving or renaming the file, or toggling this after starting the
Source will cause re-ingestion.
optimizeLeafDirectories:
type: boolean
title: Optimize for leaf directories
description: Skip rescans of unchanged directories based on directory
modification time. Uses an exponential backoff strategy, reducing
load on the filesystems, but possibly delaying detection of new
data. This option is optimized for search paths where files exist in
the leaf directories.
enableDiscoveryThrottle:
type: boolean
title: Enable discovery Throttling
description: When enabled, discovery will throttle CPU usage to the configured
target percentage.
discoveryThrottleCpuPercent:
type: number
minimum: 1
maximum: 99
title: Discovery throttle CPU target (%)
description: Target CPU utilization percentage during file discovery. Discovery
alternates between work and yield periods within a 200ms cycle. For
example, 25% processes entries for 50ms then yields for 150ms. Lower
values reduce CPU usage at the cost of longer discovery times.
includeUnidentifiableBinary:
type: boolean
title: Enable binary files
description: Stream binary files as Base64-encoded chunks
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: InputFile
InputTcp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- tcp
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to establish a
connection
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: Socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: Forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports proxy
protocol v1 or v2
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
enableHeader:
type: boolean
title: Enable header
description: 'Client will pass the header record with every new connection. The
header can contain an authToken, and an object with a list of fields
and values to add to every event. These fields can be used to
simplify Event Breaker selection, routing, etc. Header has this
format, and must be followed by a newline: { "authToken" :
"myToken", "fields": { "field1": "value1", "field2": "value2" } }'
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
description:
type: string
title: Description
description: Optional description for this configuration.
authToken:
type: string
title: Auth token
description: Shared secret to be provided by any client (in authToken header
field). If empty, unauthorized access is permitted.
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputTcp
InputAppscope:
type: object
required:
- type
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- appscope
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to establish a
connection
maxActiveCxn:
type: number
title: Active connection limit
description: Maximum number of active connections allowed per Worker Process.
Use 0 for unlimited.
minimum: 0
socketIdleTimeout:
type: number
title: Socket idle timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. After this time, the connection will be
closed. Leave at 0 for no inactive socket monitoring.
minimum: 0
socketEndingMaxWait:
type: number
title: Forced socket termination timeout (seconds)
description: How long the server will wait after initiating a closure for a
client to close its end of the connection. If the client doesn't
close the connection within this time, the server will forcefully
terminate the socket to prevent resource leaks and ensure efficient
connection cleanup and system stability. Leave at 0 for no inactive
socket monitoring.
minimum: 0
socketMaxLifespan:
type: number
title: Socket max lifespan (seconds)
description: The maximum duration a socket can remain open, even if active. This
helps manage resources and mitigate issues caused by TCP pinning.
Set to 0 to disable.
minimum: 0
enableProxyHeader:
type: boolean
title: Enable proxy protocol
description: Enable if the connection is proxied by a device that supports proxy
protocol v1 or v2
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
enableUnixPath:
type: boolean
title: UNIX domain socket
description: Toggle to Yes to specify a file-backed UNIX domain socket
connection, instead of a network host and port.
filter:
type: object
properties:
allow:
type: array
title: Rules
description: Specify processes that AppScope should be loaded into, and the
config to use.
items:
type: object
properties:
procname:
type: string
title: Process name
description: Specify the name of a process or family of processes.
arg:
type: string
title: Process argument
description: Specify a string to substring-match against process command-line.
config:
type: string
title: AppScope config
description: Choose a config to apply to processes that match the process name
and/or argument.
required:
- procname
- config
transportURL:
type: string
title: Transport override
description: To override the UNIX domain socket or address/port specified in
General Settings (while leaving Authentication settings as is),
enter a URL.
persistence:
type: object
title: Persistence
properties:
enable:
type: boolean
title: Enable disk spooling
description: Spool events and metrics on disk for Cribl Edge and Search
timeWindow:
type: string
title: Bucket time span
description: Time span for each file bucket
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to
$CRIBL_HOME/state/appscope
description: Persistence
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
description:
type: string
title: Description
description: Optional description for this configuration.
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
unixSocketPath:
type: string
title: UNIX socket path
description: Path to the UNIX domain socket to listen on.
unixSocketPerms:
type:
- string
- number
title: UNIX socket permissions
description: Permissions to set for socket e.g., 777. If empty, falls back to
the runtime user's default permissions.
authToken:
type: string
title: Auth token
description: Shared secret to be provided by any client (in authToken header
field). If empty, unauthorized access is permitted.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputAppscope
InputWef:
type: object
required:
- type
- host
- port
- subscriptions
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- wef
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authMethod:
type: string
title: Authentication method
description: How to authenticate incoming client connections
enum:
- clientCert
- kerberos
- negotiate
x-speakeasy-enum-descriptions:
- Client certificate
- Kerberos
- Negotiate (SPNEGO)
x-speakeasy-unknown-values: allow
tls:
type: object
title: mTLS settings
required:
- privKeyPath
- certPath
- caPath
properties:
disabled:
type: boolean
title: Disabled
description: Enable TLS
rejectUnauthorized:
type: boolean
title: Validate client certs
description: Required for WEF certificate authentication
requestCert:
type: boolean
title: Authenticate client
description: Required for WEF certificate authentication
certificateName:
type: string
title: Certificate
description: Name of the predefined certificate
privKeyPath:
type: string
title: Private key path
description: Path on server containing the private key to use. PEM format. Can
reference $ENV_VARS.
passphrase:
type: string
title: Passphrase
description: Passphrase to use to decrypt private key
certPath:
type: string
title: Certificate path
description: Path on server containing certificates to use. PEM format. Can
reference $ENV_VARS.
caPath:
type: string
title: CA certificate path
description: Server path containing CA certificates (in PEM format) to use. Can
reference $ENV_VARS. If multiple certificates are present in a
.pem, each must directly certify the one preceding it.
commonNameRegex:
type: string
title: Common name
description: Regex matching allowable common names in peer certificates' subject
attribute
minVersion:
$ref: "#/components/schemas/MinimumTlsVersionOptionsTls"
description: Minimum TLS version
maxVersion:
$ref: "#/components/schemas/MaximumTlsVersionOptionsTls"
description: Maximum TLS version
ocspCheck:
type: boolean
title: Verify certificate via OCSP
description: Enable OCSP check of certificate
ocspCheckFailClose:
type: boolean
title: Strict validation
description: If enabled, checks will fail on any OCSP error. Otherwise, checks
will fail only when a certificate is revoked, ignoring other
errors.
description: mTLS settings
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Preserve the client’s original IP address in the __srcIpPort field
when connecting through an HTTP proxy that supports the
X-Forwarded-For header. This does not apply to TCP-layer Proxy
Protocol v1/v2.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
caFingerprint:
type: string
title: CA fingerprint override
description: SHA1 fingerprint expected by the client, if it does not match the
first certificate in the configured CA chain
keytab:
type: string
title: Keytab location
description: Path to the keytab file containing the service principal
credentials. @{product} will use `/etc/krb5.keytab` if not provided.
principal:
type: string
title: Service principal name
description: Kerberos principal used for authentication, typically in the form
HTTP/@
allowMachineIdMismatch:
type: boolean
title: Allow MachineID mismatch
description: Allow events to be ingested even if their MachineID does not match
the client certificate CN
subscriptions:
title: Subscriptions
description: Subscriptions to events on forwarding endpoints
type: array
items:
type: object
required:
- subscriptionName
- contentFormat
- heartbeatInterval
- batchTimeout
- targets
properties:
subscriptionName:
title: Subscription name
type: string
description: Subscription name
version:
title: Version
type: string
description: Version UUID for this subscription. If any subscription parameters
are modified, this value will change.
contentFormat:
title: Format
type: string
enum:
- Raw
- RenderedText
description: Content format in which the endpoint should deliver events
x-speakeasy-unknown-values: allow
heartbeatInterval:
title: Heartbeat
type: number
description: Maximum time (in seconds) between endpoint checkins before
considering it unavailable
minimum: 1
batchTimeout:
title: Batch timeout
type: number
description: Interval (in seconds) over which the endpoint should collect events
before sending them to Stream
minimum: 0
readExistingEvents:
title: Read existing events
type: boolean
description: Newly subscribed endpoints will send previously existing events.
Disable to receive new events only.
sendBookmarks:
title: Use bookmarks
type: boolean
description: Keep track of which events have been received, resuming from that
point after a re-subscription. This setting takes precedence
over 'Read existing events'. See [Cribl
Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions)
for more details.
compress:
title: Compression
type: boolean
description: Receive compressed events from the source
targets:
type: array
title: Targets
description: The DNS names of the endpoints that should forward these events.
You may use wildcards, such as *.mydomain.com
items:
type: string
minLength: 1
locale:
title: Locale
type: string
description: The RFC-3066 locale the Windows clients should use when sending
events. Defaults to "en-US".
querySelector:
type: string
title: Query builder mode
enum:
- simple
- xml
description: Query builder mode
x-speakeasy-unknown-values: allow
metadata:
type: array
title: Fields
description: Fields to add to events ingested under this subscription
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
queries:
type: array
title: Queries
items:
type: object
required:
- path
- queryExpression
properties:
path:
type: string
title: Path
description: The Path attribute from the relevant XML Select element
queryExpression:
type: string
title: Query expression
description: The XPath query inside the relevant XML Select element
description: Queries
xmlQuery:
type: string
title: XML query
description: The XPath query to use for selecting events
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
logFingerprintMismatch:
type: boolean
title: Log CA fingerprint mismatch warning
description: Log a warning if the client certificate authority (CA) fingerprint
does not match the expected value. A mismatch prevents Cribl from
receiving events from the Windows Event Forwarder.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_keytab:
type: string
description: Binds 'keytab' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'keytab' at runtime.
__template_principal:
type: string
description: Binds 'principal' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'principal' at runtime.
title: InputWef
InputWinEventLogs:
type: object
required:
- type
- logNames
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- win_event_logs
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
logNames:
type: array
title: Event logs
description: Enter the event logs to collect. Run "Get-WinEvent -ListLog *" in
PowerShell to see the available logs.
items:
minLength: 1
type: string
minItems: 1
uniqueItems: true
suppressMissingLogErrors:
type: boolean
title: Suppress missing event log errors
description: When enabled, missing event log channels will not cause the Source
to report errors. Use in Fleets where some hosts may not have all
configured event logs.
readMode:
type: string
enum:
- oldest
- newest
title: Read mode
x-speakeasy-enum-descriptions:
- Entire log
- From last entry
description: Read all stored and future event logs, or only future events
x-speakeasy-unknown-values: allow
eventFormat:
type: string
enum:
- json
- xml
title: Event format
x-speakeasy-enum-descriptions:
- JSON
- XML
description: Format of individual events
x-speakeasy-unknown-values: allow
disableNativeModule:
type: boolean
title: Use Windows Tools
description: Enable to use built-in tools (PowerShell for JSON, wevtutil for
XML) to collect event logs instead of native API (default) [Learn
more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)
interval:
type: number
minimum: 1
title: Polling interval
description: Time, in seconds, between checking for new entries (Applicable for
pre-4.8.0 nodes that use Windows Tools)
batchSize:
type: number
minimum: 1
title: Batch size
description: The maximum number of events to read in one polling interval. A
batch size higher than 500 can cause delays when pulling from
multiple event logs. (Applicable for pre-4.8.0 nodes that use
Windows Tools)
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
maxEventBytes:
type: integer
title: Event byte limit
description: The maximum number of bytes in an event before it is flushed to the
pipelines
minimum: 1
maximum: 134217728
description:
type: string
title: Description
description: Optional description for this configuration.
disableJsonRendering:
type: boolean
title: Render event message strings
description: Enable/disable the rendering of localized event message strings
(Applicable for 4.8.0 nodes and newer that use the Native API)
includeEmptyJsonFields:
type: boolean
title: Include empty JSON fields
description: Preserve fields with empty values (such as '-') in the JSON output
instead of omitting them
disableXmlRendering:
type: boolean
title: Render event message strings
description: Enable/disable the rendering of localized event message strings
(Applicable for 4.8.0 nodes and newer that use the Native API)
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputWinEventLogs
InputAppleUnifiedLogs:
type: object
required:
- type
- predicate
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- apple_unified_logs
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
predicate:
type: string
title: Predicate
description: String to filter log entries, in NSPredicate format (e.g.,
subsystem == "com.apple.security" or process == "kernel"). See
[Common Log Types and
Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples)
for more information.
minLength: 1
readMode:
type: string
enum:
- oldest
- newest
title: Read mode
x-speakeasy-enum-descriptions:
- Entire log
- From last entry
description: Read all log entries (historical and upcoming), or only upcoming,
from the last entry
x-speakeasy-unknown-values: allow
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputAppleUnifiedLogs
InputRawUdp:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- raw_udp
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. For IPv4 (all addresses), use the default
'0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP
address.
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
maxBufferSize:
type: number
title: Buffer size limit (events)
description: Maximum number of events to buffer when downstream is blocking.
minimum: 0
ipWhitelistRegex:
type: string
title: IP allowlist regex
description: Regex matching IP addresses that are allowed to send data
singleMsgUdpPackets:
type: boolean
title: Single msg per UDP
description: If true, each UDP packet is assumed to contain a single message. If
false, each UDP packet is assumed to contain multiple messages,
separated by newlines.
ingestRawBytes:
type: boolean
title: Ingest raw bytes
description: If true, a __rawBytes field will be added to each event containing
the raw bytes of the datagram.
udpSocketRxBufSize:
type: number
title: UDP socket buffer size (bytes)
description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization."
minimum: 256
maximum: 4294967295
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputRawUdp
InputJournalFiles:
type: object
required:
- type
- path
- journals
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
enum:
- journal_files
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
path:
type: string
title: Search path
description: Directory path to search for journals. Environment variables will
be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.
interval:
type: number
minimum: 1
title: Polling interval
description: "Time, in seconds, between scanning for journals. "
journals:
type: array
title: Journal allowlist
description: The full path of discovered journals are matched against this
wildcard list.
items:
type: string
rules:
type: array
title: Filter Rules
description: Add rules to decide which journal objects to allow. Events are
generated if no rules are given or if all the rules' expressions
evaluate to true.
items:
type: object
required:
- filter
properties:
filter:
type: string
title: Filter Expression
description: JavaScript expression applied to Journal objects. Return 'true' to
include it.
description:
type: string
title: Description
description: Optional description of this rule's purpose
currentBoot:
type: boolean
title: Current boot only
description: Skip log messages that are not part of the current boot session
maxAgeDur:
type: string
title: Age duration limit
description: "The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters."
suppressMissingPathErrors:
type: boolean
title: Suppress errors when search path does not exist
description: Suppress errors when search path does not exist
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
autoParse:
type: boolean
title: Auto parse
description: Detect the datatype of each event and extract its top-level fields
before the data reaches any of the processing pipelines
(pre-processing, main processing, post-processing).
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputJournalFiles
InputWiz:
type: object
required:
- type
- endpoint
- authUrl
- clientId
- contentConfig
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- wiz
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
endpoint:
type: string
title: GraphQL endpoint
description: "The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql"
pattern: ^https:\/\/
authUrl:
type: string
title: Authentication URL
description: The authentication URL to generate an OAuth token
authAudienceOverride:
type: string
title: Authentication audience
description: The audience to use when requesting an OAuth token for a custom
auth URL. When not specified, `wiz-api` will be used.
clientId:
type: string
title: Client ID
description: The client ID of the Wiz application
contentConfig:
type: array
title: Content types
items:
type: object
required:
- contentType
- contentQuery
- cronSchedule
- earliest
- latest
properties:
contentType:
type: string
title: Content name
description: The name of the Wiz query
pattern: ^[a-zA-Z0-9_\-\s]+$
contentDescription:
type: string
title: Description
description: Description
enabled:
type: boolean
title: Enable content
description: Enable content
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute
the new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to
the state to keep.
manageState:
type: object
contentQuery:
type: string
title: Content query
description: "Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`."
cronSchedule:
type: string
title: Cron schedule
description: A cron schedule on which to run this job
earliest:
type: string
title: Earliest time
description: "Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)"
latest:
type: string
title: Latest time
description: "Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)"
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
logLevel:
$ref: "#/components/schemas/LogLevelOptionsContentConfigItemsDebugError"
description: Collector runtime log level
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Defaults
to 0. Set to 0 to retrieve all pages.
minimum: 0
description: Content types
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
retryRules:
$ref: "#/components/schemas/RetryRulesType"
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsManualSecret"
description: Enter client secret directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
clientSecret:
type: string
title: Client secret
description: The client secret of the Wiz application
textSecret:
type: string
title: Client Secret (text secret)
description: Select or create a stored text secret
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_authUrl:
type: string
description: Binds 'authUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authUrl' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
title: InputWiz
InputOpenai:
type: object
required:
- type
- contentConfig
- textSecret
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- openai
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
openaiOrganization:
type: string
title: OpenAI Organization
description: Optional `OpenAI-Organization` request header value, typically
`org-xxxxxxxxxxxxxxxxxxxxxxxx`
openaiProject:
type: string
title: OpenAI Project
description: Optional `OpenAI-Project` request header value, typically
`proj_xxxxxxxxxxxxxxxxxxxxxxxx`
contentConfig:
type: array
title: Content Types
items:
type: object
required:
- contentType
- collectPath
- requestParams
- paginationType
- cronSchedule
- earliest
- latest
properties:
contentType:
type: string
title: Content type
readOnly: true
description: Content type
contentDescription:
type: string
title: Description
readOnly: true
description: Description
collectPath:
type: string
title: Endpoint
description: OpenAI Organization API path
readOnly: true
docsUrl:
type: string
title: Docs URL
readOnly: true
description: Docs URL
disabled:
type: boolean
title: Enabled
description: Enabled
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions.
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute
the new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to
the state to keep.
manageState:
type: object
requestParams:
type: array
title: Query parameters
description: Query-string parameters to send with this endpoint
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
paginationType:
type: string
title: Pagination type
enum:
- none
- response_body
- response_header
- response_header_link
x-speakeasy-enum-descriptions:
- None
- Response Body Attribute
- Response Header Attribute
- RFC 5988 Link Header
description: Pagination type
x-speakeasy-unknown-values: allow
paginationAttribute:
type: array
title: Pagination attributes
items:
type: string
description: Pagination attributes
paginationLastPageExpr:
type: string
title: Last page expression
description: Last page expression
maxPages:
type: number
title: Page limit
description: Maximum number of pages to retrieve per collection task. Set to 0
only when unlimited pagination is required.
minimum: 0
paginationNextRelationAttribute:
type: string
title: Next relation attribute
description: Used only for RFC 5988 link-header pagination
paginationCurRelationAttribute:
type: string
title: Current relation attribute
description: Optional relation that represents the current page
cronSchedule:
type: string
title: Cron schedule
description: A cron schedule on which to run this job
earliest:
type: string
title: Earliest time
description: Relative to the current time
latest:
type: string
title: Latest time
description: Relative to the current time
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
logLevel:
type: string
title: Log level
enum:
- error
- warn
- info
- debug
- silly
description: Collector runtime log level.
x-speakeasy-unknown-values: allow
endpointMetadata:
type: array
title: Hardcoded fields
description: Fields automatically added to events from this Content Type
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description: Content Types
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
apiKey:
type: string
title: API key
description: API key
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored API key. Visit [OpenAI's organization
admin keys
page](https://platform.openai.com/settings/organization/admin-keys)
to create an organization admin key.
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_openaiOrganization:
type: string
description: Binds 'openaiOrganization' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'openaiOrganization' at runtime.
__template_openaiProject:
type: string
description: Binds 'openaiProject' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'openaiProject' at runtime.
title: InputOpenai
InputWizWebhook:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- wiz_webhook
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
enableHealthCheck:
type: boolean
title: Health check endpoint
description: Expose the /cribl_health endpoint, which returns 200 OK when this
Source is healthy
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedPaths:
type: array
title: Allowed URI paths
description: List of URI paths accepted by this input. Wildcards are supported
(such as /api/v*/hook). Defaults to allow all.
items:
type: string
minLength: 1
allowedMethods:
type: array
title: Allowed HTTP methods
description: List of HTTP methods accepted by this input. Wildcards are
supported (such as P*, GET). Defaults to allow all.
items:
type: string
minLength: 1
authTokensExt:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: object
oneOf:
- required:
- token
- required:
- authType
- tokenSecret
properties:
authType:
$ref: "#/components/schemas/AuthTypeOptionsAuthTokensExtItems"
description: Discriminator value.
tokenSecret:
type: string
description: Select or create a stored text secret
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: "Shared secret to be provided by any client (Authorization: )"
description:
type: string
title: Description
description: Description
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_authTokens:
type: string
description: Binds 'authTokens' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'authTokens' at runtime.
__template_allowedPaths:
type: string
description: Binds 'allowedPaths' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedPaths' at runtime.
title: InputWizWebhook
InputNetflow:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsNetflow"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. For IPv4 (all addresses), use the default
'0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP
address.
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
enablePassThrough:
type: boolean
title: Enable pass-through
description: Allow forwarding of events to a NetFlow destination. Enabling this
feature will generate an extra event containing __netflowRaw which
can be routed to a NetFlow destination. Note that these events will
not count against ingest quota.
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist.
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
udpSocketRxBufSize:
type: number
title: UDP socket buffer size (bytes)
description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization."
minimum: 256
maximum: 4294967295
templateCacheMinutes:
type: number
title: Template cache minutes
description: Specifies how many minutes NetFlow v9 templates are cached before
being discarded if not refreshed. Adjust based on your network's
template update frequency to optimize performance and memory usage.
minimum: 1
maximum: 3600
v5Enabled:
type: boolean
title: V5
description: Accept messages in Netflow V5 format.
v9Enabled:
type: boolean
title: V9
description: Accept messages in Netflow V9 format.
ipfixEnabled:
type: boolean
title: IPFIX
description: Accept messages in IPFIX format.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
title: InputNetflow
InputSecurityLake:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
$ref: "#/components/schemas/TypeOptionsSecuritylake"
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the S3 bucket and SQS queue are located. Required,
unless the Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility timeout seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
socketTimeout:
type: number
title: Socket timeout
description: Socket inactivity timeout (in seconds). Increase this value if
timeouts occur due to backpressure.
minimum: 1
maximum: 43200
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
includeSqsMetadata:
type: boolean
title: Include notification metadata
description: Attach SQS notification metadata to a __sqsMetadata field on each
event
enableAssumeRole:
type: boolean
title: Enable for Amazon S3
description: Use Assume Role credentials to access Amazon S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
enableSQSAssumeRole:
type: boolean
title: Enable for Amazon SQS
description: Use Assume Role credentials when accessing Amazon SQS
sharedCredentials:
type: boolean
title: Share credentials for SQS and S3
description: Use the same credential settings for S3 and SQS
sharedAssumeRoleArn:
type: boolean
title: Share AssumeRole ARN settings
description: Use the same settings for S3 and SQS
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will stop if a chunk cannot be downloaded within the time
specified.
maximum: 3600
minimum: 1
checkpointing:
$ref: "#/components/schemas/CheckpointingType"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAssumeRoleArn:
type: string
title: SQS AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
SQSAssumeRoleExternalId:
type: string
title: SQS External ID
description: External ID to use when assuming role
SQSDurationSeconds:
type: number
title: SQS duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
SQSAwsAuthenticationMethod:
$ref: "#/components/schemas/SqsAuthenticationMethodOptions"
description: Choose Auto to use IAM roles
SQSAwsSecret:
type: string
title: SQS secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAwsSecretKey:
type: string
title: SQS secret key
description: SQS secret key
tagAfterProcessing:
$ref: "#/components/schemas/TagAfterProcessingOptions"
processedTagKey:
type: string
title: Tag key
description: The key for the S3 object tag applied after processing. This field
accepts an expression for dynamic generation.
processedTagValue:
type: string
title: Tag value
description: The value for the S3 object tag applied after processing. This
field accepts an expression for dynamic generation.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_SQSAssumeRoleArn:
type: string
description: Binds 'SQSAssumeRoleArn' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleArn' at runtime.
__template_SQSAssumeRoleExternalId:
type: string
description: Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleExternalId' at runtime.
__template_SQSAwsSecretKey:
type: string
description: Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'SQSAwsSecretKey' at
runtime.
title: InputSecurityLake
InputBedrockS3:
type: object
required:
- type
- queueName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- bedrock_s3
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
queueName:
type: string
title: Queue
description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
fileFilter:
type: string
title: Filename filter
description: "Regex matching file names to download and process. Defaults to: .*"
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the S3 bucket and SQS queue are located. Required,
unless the Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
maxMessages:
type: number
title: Message limit
description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10."
minimum: 1
maximum: 10
visibilityTimeout:
type: number
title: Visibility timeout seconds
description: After messages are retrieved by a ReceiveMessage request,
@{product} will hide them from subsequent retrieve requests for at
least this duration. You can set this as high as 43200 sec. (12
hours).
minimum: 0
maximum: 43200
numReceivers:
type: number
title: Number of receivers
description: How many receiver processes to run. The higher the number, the
better the throughput - at the expense of CPU overhead.
minimum: 1
maximum: 100
socketTimeout:
type: number
title: Socket timeout
description: Socket inactivity timeout (in seconds). Increase this value if
timeouts occur due to backpressure.
minimum: 1
maximum: 43200
skipOnError:
type: boolean
title: Skip file on error
description: Skip files that trigger a processing error. Disabled by default,
which allows retries after processing errors.
includeSqsMetadata:
type: boolean
title: Include notification metadata
description: Attach SQS notification metadata to a __sqsMetadata field on each
event
enableAssumeRole:
type: boolean
title: Enable for Amazon S3
description: Use Assume Role credentials to access Amazon S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
enableSQSAssumeRole:
type: boolean
title: Enable for Amazon SQS
description: Use Assume Role credentials when accessing Amazon SQS
sharedCredentials:
type: boolean
title: Share credentials for SQS and S3
description: Use the same credential settings for S3 and SQS
sharedAssumeRoleArn:
type: boolean
title: Share AssumeRole ARN settings
description: Use the same settings for S3 and SQS
preprocess:
$ref: "#/components/schemas/PreprocessType"
description: Optional preprocessing step that pipes collected data through an
external command before ingestion.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
parquetChunkSizeMB:
type: number
title: Parquet chunk size limit (MB)
description: Maximum file size for each Parquet chunk
maximum: 100
minimum: 1
parquetChunkDownloadTimeout:
type: number
title: Parquet chunk download timeout (seconds)
description: The maximum time allowed for downloading a Parquet chunk.
Processing will stop if a chunk cannot be downloaded within the time
specified.
maximum: 3600
minimum: 1
checkpointing:
$ref: "#/components/schemas/CheckpointingType"
pollTimeout:
type: number
title: Poll timeout (secs)
description: How long to wait for events before trying polling again. The lower
the number the higher the AWS bill. The higher the number the longer
it will take for the source to react to configuration changes and
system restarts.
minimum: 1
maximum: 20
encoding:
type: string
title: Encoding
description: Character encoding to use when parsing ingested data. When not set,
@{product} will default to UTF-8 but may incorrectly interpret
multi-byte characters.
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAssumeRoleArn:
type: string
title: SQS AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
SQSAssumeRoleExternalId:
type: string
title: SQS External ID
description: External ID to use when assuming role
SQSDurationSeconds:
type: number
title: SQS duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
SQSAwsAuthenticationMethod:
$ref: "#/components/schemas/SqsAuthenticationMethodOptions"
description: Choose Auto to use IAM roles
SQSAwsSecret:
type: string
title: SQS secret key pair
description: Select or create a stored secret that references your access key
and secret key
SQSAwsSecretKey:
type: string
title: SQS secret key
description: SQS secret key
tagAfterProcessing:
$ref: "#/components/schemas/TagAfterProcessingOptions"
processedTagKey:
type: string
title: Tag key
description: The key for the S3 object tag applied after processing. This field
accepts an expression for dynamic generation.
processedTagValue:
type: string
title: Tag value
description: The value for the S3 object tag applied after processing. This
field accepts an expression for dynamic generation.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_SQSAssumeRoleArn:
type: string
description: Binds 'SQSAssumeRoleArn' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleArn' at runtime.
__template_SQSAssumeRoleExternalId:
type: string
description: Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'SQSAssumeRoleExternalId' at runtime.
__template_SQSAwsSecretKey:
type: string
description: Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'SQSAwsSecretKey' at
runtime.
title: InputBedrockS3
InputServicenowTable:
type: object
required:
- type
- instance
- cronSchedule
- earliest
- latest
- tableName
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- servicenow_table
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
instance:
type: string
pattern: .*\S.*
title: Instance URL
description: ServiceNow instance base URL for Table API requests. Enter a
literal URL (http or https and the instance host, for example a
hostname ending in .service-now.com) or a Cribl expression that
resolves to a URL.
tableName:
type: string
pattern: .*\S.*
title: Table name
description: ServiceNow table name to collect from.
fields:
type: array
title: Fields
description: Field names to return from the Table API (sysparm_fields). Leave
empty to return all fields.
items:
type: string
pattern: ^[^*?\[\]]+$
orderByField:
type: string
title: Sort by field
description: Optional. Sort results by this field (for example sys_created_on or
parent.name). Leave empty to use the server default order.
orderByDirection:
type: string
title: Sort direction
description: Used only when Sort by field is set.
enum:
- asc
- desc
x-speakeasy-enum-descriptions:
- Ascending
- Descending
x-speakeasy-unknown-values: allow
query:
type: string
title: Filter query (advanced)
description: Optional ServiceNow encoded query for sysparm_query (for example
active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal
or a Cribl expression. When combined with Sort by field, the filter
and sort are joined with ^. See ServiceNow Table API documentation
for encoded query syntax.
pageSize:
type: integer
title: Page size
description: Maximum records per Table API page request (sysparm_limit). Setting
a higher value may increase the risk of timeouts.
minimum: 1
maxPages:
type: integer
title: Page limit
description: Maximum number of pages to retrieve per collection task. Set to 0
to retrieve all pages.
minimum: 0
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA
(such as self-signed certificates)
authType:
type: string
title: Authentication type
description: ServiceNow Table API authentication method
enum:
- none
- basicSecret
- oauthSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- OAuth
x-speakeasy-unknown-values: allow
cronSchedule:
type: string
pattern: .*\S.*
title: Cron schedule
description: Cron schedule on which to run this job
earliest:
type: string
pattern: .*\S.*
title: Earliest time
description: "Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)"
latest:
type: string
pattern: .*\S.*
title: Latest time
description: "Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)"
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
logLevel:
$ref: "#/components/schemas/LogLevelOptions"
description: Collector runtime log level
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: When a DNS server returns multiple addresses, @{product} cycles
through them in the order returned
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
oauthGrantType:
enum:
- client_credentials
- password
type: string
title: Grant type
description: ServiceNow OAuth grant type used for token requests
x-speakeasy-enum-descriptions:
- Password
- Client credentials
x-speakeasy-unknown-values: allow
username:
type: string
title: Username
description: ServiceNow username for the password grant type
pattern: .*\S.*
textSecret:
type: string
title: Password
description: Select or create a stored text secret for the ServiceNow password
value
useCustomOAuthParamsOrHeaders:
type: boolean
title: Use custom parameters and/or headers
description: Enable custom OAuth request parameters or headers for advanced
ServiceNow configurations. Leave disabled for standard ServiceNow
OAuth flows.
oauthParams:
type: array
title: OAuth parameters
description: Additional parameters to send in the OAuth login request.
@{product} will combine the secret with these parameters, and will
send the URL-encoded result in a POST request to the endpoint
specified in the 'Login URL'. We'll automatically add the
content-type header 'application/x-www-form-urlencoded' when sending
this request.
items:
$ref: "#/components/schemas/OauthParamConfInputServicenowTable"
oauthHeaders:
type: array
title: OAuth headers
description: Additional headers to send in the OAuth login request. @{product}
will automatically add the content-type header
'application/x-www-form-urlencoded' when sending this request.
items:
$ref: "#/components/schemas/OauthHeaderConfInputServicenowTable"
clientId:
type: string
title: ServiceNow OAuth client ID
pattern: .*\S.*
description: ServiceNow OAuth client ID
clientTextSecret:
type: string
title: Client secret
description: Select or create a stored text secret for the OAuth client secret
value
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. This source defaults to checking that `_time` is a finite
number (not only `__timestampExtracted`), so state still advances
when the event breaker assigns a fallback time. See [Understanding
State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state. Evaluates
`prevState` and `newState` variables, resolving to the state to
keep.
manageState:
type: object
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_instance:
type: string
description: Binds 'instance' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'instance' at runtime.
__template_orderByField:
type: string
description: Binds 'orderByField' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'orderByField' at runtime.
__template_query:
type: string
description: Binds 'query' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'query' at runtime.
__template_username:
type: string
description: Binds 'username' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'username' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
title: InputServicenowTable
InputProofpointPod:
type: object
required:
- type
- clusterId
- feedType
- textSecret
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- proofpoint_pod
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
clusterId:
type: string
title: Cluster ID
description: Proofpoint on Demand cluster ID.
feedType:
type: string
title: Feed type
description: Proofpoint on Demand feed to ingest.
enum:
- message
- maillog
- audit
x-speakeasy-enum-descriptions:
- Message
- Mail log
- Audit
x-speakeasy-unknown-values: allow
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
compress:
type: boolean
title: Compress
description: Compress the feed connection.
handshakeTimeout:
type: number
title: Handshake timeout (ms)
description: Maximum time to wait for the connection handshake to complete.
minimum: 1000
maximum: 60000
keepAliveIntervalSec:
type: number
title: Keepalive ping interval (seconds)
description: How often to send a keepalive ping while the feed is idle. Use 0 to
disable keepalive pings.
minimum: 0
maximum: 3600
maxMissedKeepAlives:
type: number
title: Max missed keepalives
description: Maximum number of consecutive keepalive pings that can go
unanswered before reconnecting.
minimum: 1
maximum: 100
maxMessageSize:
type: string
title: Maximum message size
description: The maximum size of a single feed message. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
readBufferSize:
type: string
title: Read buffer size
description: The maximum size to hold in memory before applying backpressure.
Enter a numeral with units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_clusterId:
type: string
description: Binds 'clusterId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clusterId' at runtime.
title: InputProofpointPod
InputZscalerHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- zscaler_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
type: object
required:
- token
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
tokenSecret:
type: string
title: Token secret (text secret)
description: Select or create a stored text secret
token:
type: string
title: Token
description: "Shared secret to be provided by any client (Authorization: )"
enabled:
type: boolean
title: Enable token
description: Enable token
description:
type: string
title: Description
description: Description
allowedIndexesAtToken:
type: array
title: Allowed indexes
description: Enter the values you want to allow in the HEC event index field at
the token level. Supports wildcards. To skip validation, leave
blank.
minItems: 0
items:
type: string
minLength: 1
metadata:
type: array
title: Fields
description: Fields to add to events referencing this token
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Zscaler HTTP Event
Collector API requests. This input supports the /event endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
hecAcks:
type: boolean
title: Zscaler HEC Acks
description: Whether to enable Zscaler HEC acknowledgements
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputZscalerHec
InputCloudflareHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- cloudflare_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
type: object
title: TLS settings (server side)
properties:
disabled:
type: boolean
title: Disabled
description: Enable or disable TLS. Defaults to enabled for Cloudflare sources.
requestCert:
type: boolean
title: Authenticate client (mutual auth)
description: Require clients to present their certificates. Used to perform
client authentication using SSL certs.
caPath:
type: string
title: CA certificate path
description: Path on server containing CA certificates to use. PEM format. Can
reference $ENV_VARS.
rejectUnauthorized:
type: boolean
title: Validate client certificates
description: Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's)
commonNameRegex:
type: string
title: Common name
description: Regex matching allowable common names in peer certificates' subject
attribute
certificateName:
type: string
title: Certificate
description: The name of the predefined certificate
privKeyPath:
type: string
title: Private key path
description: Path on server containing the private key to use. PEM format. Can
reference $ENV_VARS. Defaults to the built-in Cribl private key
when TLS is enabled.
passphrase:
type: string
title: Passphrase
description: Passphrase to use to decrypt private key
certPath:
type: string
title: Certificate path
description: Path on server containing certificates to use. PEM format. Can
reference $ENV_VARS. Defaults to the built-in Cribl certificate
when TLS is enabled.
minVersion:
$ref: "#/components/schemas/MinimumTlsVersionOptionsTls"
description: Minimum TLS version
maxVersion:
$ref: "#/components/schemas/MaximumTlsVersionOptionsTls"
description: Maximum TLS version
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Cloudflare HTTP Event
Collector API requests. This input supports the /event endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputCloudflareHec
InputSysdigHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- sysdig_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Sysdig HTTP Event
Collector API requests. This input supports the /event and /raw
endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputSysdigHec
InputUpwindHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- upwind_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Upwind HTTP Event
Collector API requests. This input supports the /event endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputUpwindHec
InputTrellixHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- trellix_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Trellix HTTP Event
Collector API requests. This input supports the /event endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputTrellixHec
InputSailpointHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- sailpoint_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for SailPoint Virtual Appliance
HTTP Event Collector requests. This source uses the
/services/collector endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
title: InputSailpointHec
InputExtrahopRevealx360:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- extrahop_revealx_360
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for ExtraHop RevealX 360 Splunk
HTTP Event Collector requests. This input supports the /event
endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputExtrahopRevealx360
InputAquaSecurityHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- aqua_security_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Aqua Security HTTP Event
Collector API requests. This input supports event, raw, and
acknowledgement endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
hecAcks:
type: boolean
title: HEC Acks
description: Whether to enable HEC indexer acknowledgements
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputAquaSecurityHec
InputOpenaiComplianceLogs:
type: object
required:
- type
- textSecret
- accountType
- cronSchedule
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- openai_compliance_logs
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
apiKey:
type: string
title: API key
description: API key
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
accountType:
type: string
title: Account type
enum:
- workspace
- organization
x-speakeasy-enum-descriptions:
- Workspace
- Organization
description: Account type
x-speakeasy-unknown-values: allow
cronSchedule:
type: string
title: Cron schedule
description: Cron schedule
earliest:
type: string
title: Earliest time
description: "Relative to the current time. Format: [+|-]"
latest:
type: string
title: Latest time
description: "Relative to the current time. Format: [+|-]"
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
logLevel:
$ref: "#/components/schemas/LogLevelOptionsContentConfigItemsDebugError"
description: Collector runtime log level
maxPages:
type: number
title: Page limit
description: Maximum number of log file listing pages to retrieve per run. Set
to 0 to retrieve all pages.
minimum: 0
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
workspaceId:
type: string
title: Workspace ID
description: The ID of the ChatGPT workspace to collect logs from (UUID format)
workspaceEventTypes:
type: array
title: Event types
description: One or more compliance log categories to collect
items:
type: string
uniqueItems: true
organizationId:
type: string
title: Organization ID
description: "The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)"
organizationEventTypes:
type: array
title: Event types
description: One or more compliance log categories to collect
items:
type: string
uniqueItems: true
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the new
state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state. Evaluates
`prevState` and `newState` variables, resolving to the state to
keep.
manageState:
type: object
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_workspaceId:
type: string
description: Binds 'workspaceId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'workspaceId' at runtime.
__template_organizationId:
type: string
description: Binds 'organizationId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'organizationId' at
runtime.
title: InputOpenaiComplianceLogs
InputAnthropicCompliance:
type: object
required:
- type
- textSecret
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- anthropic_compliance
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
apiKey:
type: string
title: API key
description: API key
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored Anthropic API key
activities:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the
new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to the
state to keep.
manageState:
type: object
title: Activities
description: Activities
chats:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the
new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to the
state to keep.
manageState:
type: object
title: Chats
description: Chats
projects:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the
new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to the
state to keep.
manageState:
type: object
title: Projects
description: Projects
chat_messages:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the
new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to the
state to keep.
manageState:
type: object
title: Chat Messages
description: Chat Messages
project_details:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between consecutive scheduled executions
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression that defines how to update the state from an
event. Use the event's data and the current state to compute the
new state. See [Understanding State Expression
Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields)
for more information.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression that defines which state to keep when merging
a task's newly reported state with previously saved state.
Evaluates `prevState` and `newState` variables, resolving to the
state to keep.
manageState:
type: object
title: Project Details
description: Project Details
groups:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
title: Groups
description: Groups
organizations:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
title: Organizations
description: Organizations
org_users:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
title: Organization Users
description: Organization Users
org_roles:
type: object
properties:
enabled:
type: boolean
title: Enabled
description: Enabled
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
title: Organization Roles
description: Organization Roles
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputAnthropicCompliance
InputAnthropicEnterpriseAnalytics:
type: object
required:
- type
- contentConfig
- textSecret
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- anthropic_enterprise_analytics
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
apiKey:
type: string
title: API key
description: API key
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored API key with read:analytics scope
contentConfig:
type: array
title: Content types
description: Analytics endpoints to collect from. Each content type runs on its
own schedule as a separate collection job.
items:
type: object
required:
- contentType
- cronSchedule
properties:
contentType:
type: string
title: Content type
enum:
- Usage Report
- Cost Report
description: Content type
x-speakeasy-unknown-values: allow
disabled:
type: boolean
title: Enabled
description: Enabled
stateTracking:
type: boolean
title: State tracking
description: Track collection progress between runs. When enabled, each run
resumes from where the last one left off, preventing duplicate
data. The API refreshes approximately every 4 hours; runs
between refreshes produce zero events until new finalized data
becomes available. This is expected behavior.
stateUpdateExpression:
type: string
title: State update expression
description: JavaScript expression evaluated per event to compute new state. The
default tracks the data_refreshed_at watermark reported by the
API.
stateMergeExpression:
type: string
title: State merge expression
description: JavaScript expression to merge state across distributed Workers.
The default keeps the most recent watermark.
manageState:
type: boolean
title: Manage state
description: Manage state
groupBy:
type: array
title: Group by
description: Dimensions for breaking down usage. Leave empty to collect a single
summed row per time bucket.
uniqueItems: true
items:
type: string
enum:
- model
- product
- context_window
- inference_geo
- speed
- rbac_group_id
- slack_channel_id
- teams_channel_id
- cost_type
- token_type
x-speakeasy-unknown-values: allow
bucketWidth:
type: string
title: Bucket width
description: Time bucket size for aggregated results. Smaller buckets yield more
events per collection run.
enum:
- 1d
- 1h
- 1m
x-speakeasy-enum-descriptions:
- Daily (1d)
- Hourly (1h)
- Per-minute (1m)
x-speakeasy-unknown-values: allow
cronSchedule:
type: string
title: Cron schedule
description: Cron schedule for collection runs. The API refreshes data
approximately every 4 hours, so polling more frequently will
not yield new results.
earliest:
type: string
title: Earliest
description: "Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d."
jobTimeout:
type: string
title: Job timeout
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: InputAnthropicEnterpriseAnalytics
InputMicrosoftCopilot:
type: object
required:
- type
- tenantId
- clientId
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- microsoft_copilot
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
tenantId:
type: string
title: Tenant ID
description: Directory (tenant) ID from Azure Active Directory
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
clientId:
type: string
title: Client ID
description: Application (client) ID from the app registration
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
resource:
type: string
title: Resource
description: Microsoft Graph resource URI used in the OAuth token request scope
parameter. Derived automatically from the selected plan type.
authType:
title: Authentication method
type: string
enum:
- oauthSecret
- oauthCert
description: Select authentication method.
x-speakeasy-unknown-values: allow
planType:
title: Subscription plan
type: string
enum:
- enterprise_gcc
- gcc
- gcc_high
- dod
description: Microsoft 365 subscription plan for your organization, typically
Microsoft 365 Enterprise.
x-speakeasy-unknown-values: allow
cronSchedule:
type: string
title: Schedule
description: Cron schedule for collection runs
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now. Used as the
initial lower bound on first run.
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
pageSize:
type: integer
title: Page size
description: Number of interactions to request per page ($top). Maximum 1000.
minimum: 1
maximum: 1000
appClassFilter:
type: array
title: App class filter
description: Limit collection to specific Copilot app classes. Leave empty to
collect all.
items:
type: string
uniqueItems: true
filterByLicense:
type: boolean
title: User discovery filtering by product license
description: Add a $filter to the /users call for assigned Copilot SKUs. This
reduces unnecessary API calls by excluding unlicensed users during
discovery rather than skipping them at collection time.
skuIds:
type: array
title: Copilot SKU IDs
description: Microsoft 365 SKU GUIDs that grant access to the Copilot
Interaction Export API. During discovery, users are filtered to
those with at least one of these SKUs in their assignedLicenses.
Pre-populated with known Copilot SKUs; add custom entries for
tenant-specific or new plans.
items:
type: string
pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$
uniqueItems: true
manageState:
type: object
timeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout, in seconds. Enter 0 to wait
indefinitely.
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: ^\d+[sm]?$
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
type: object
required:
- type
properties:
type:
$ref: "#/components/schemas/RetryTypeOptionsHealthCheckCollectorConfRetryRules"
description: The algorithm to use when performing HTTP retries
interval:
type: number
title: Initial retry interval (ms)
description: Time interval between failed request and first retry (kickoff).
Maximum allowed value is 20,000 ms (1/3 minute).
minimum: 0
maximum: 20000
limit:
type: number
title: Retry limit
description: The maximum number of times to retry a failed HTTP request
minimum: 0
maximum: 20
multiplier:
type: number
title: Backoff multiplier
description: Base for exponential backoff, e.g., base 2 means that retries will
occur after 2, then 4, then 8 seconds, and so on
minimum: 1
maximum: 20
codes:
type: array
title: Retry HTTP codes
description: List of HTTP codes that trigger a retry. Leave empty to use the
default list of 429, 500, and 503.
minItems: 1
items:
type: number
minimum: 100
maximum: 599
enableHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) or
a timestamp after which to retry the request. The delay is
limited to 20 seconds, even if the Retry-After header specifies
a longer delay. When disabled, all Retry-After headers are
ignored.
retryConnectTimeout:
type: boolean
title: Retry connection timeout
description: Make a single retry attempt when a connection timeout (ETIMEDOUT)
error occurs
retryConnectReset:
type: boolean
title: Retry connection reset
description: Retry request when a connection reset (ECONNRESET) error occurs
breakerRulesets:
type: array
title: Event Breaker rulesets
description: A list of event-breaking rulesets that will be applied, in order,
to the input data stream
items:
type: string
staleChannelFlushMs:
type: number
title: Event Breaker buffer timeout (ms)
description: How long (in milliseconds) the Event Breaker will wait for new data
to be sent to a specific channel before flushing the data stream
out, as is, to the Pipelines
minimum: 10
maximum: 43200000
description:
type: string
title: Description
description: Optional description for this configuration.
textSecret:
type: string
title: Client secret
description: Select or create a secret that references the client secret from
your app registration
certOptions:
type: object
required:
- privKeyPath
- certPath
properties:
certificateName:
type: string
title: Certificate
description: The name of a predefined certificate
privKeyPath:
type: string
title: Private key path
description: Path to the private key (PEM format). Can reference $ENV_VARS.
passphrase:
type: string
title: Passphrase
description: Passphrase to decrypt the private key
certPath:
type: string
title: Certificate path
description: Path to the certificate (PEM format). Can reference $ENV_VARS.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_planType:
type: string
description: Binds 'planType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'planType' at runtime.
title: InputMicrosoftCopilot
InputOkta:
type: object
required:
- type
- textSecret
- oktaDomain
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
enum:
- okta
description: Connector type identifier.
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
oktaDomain:
type: string
title: Okta domain
description: "Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes."
oktaToken:
type: string
title: Okta API token
description: Your Okta API token for authentication
textSecret:
type: string
title: Okta API token (text secret)
description: Select or create a stored text secret
cronSchedule:
type: string
title: Cron schedule
description: Schedule on which to run this collection job
earliest:
type: string
title: Earliest
description: Earliest time for data collection, relative to now
latest:
type: string
title: Latest
description: Latest time for data collection, relative to now
manageState:
type: object
jobTimeout:
type: string
title: Job timeout
description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m).
Units are seconds, if not specified. Enter 0 for unlimited time.
pattern: ^\d+[sm]?$
requestTimeout:
type: number
title: Request timeout (seconds)
description: HTTP request inactivity timeout. Use 0 to disable.
minimum: 0
maximum: 2400
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often workers should check in with the scheduler to keep job
subscription alive
minimum: 10
maxMissedKeepAlives:
type: number
title: Worker timeout (periods)
description: The number of Keep Alive Time periods before an inactive worker
will have its job subscription revoked.
minimum: 2
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
retryRules:
$ref: "#/components/schemas/RetryRulesType"
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_oktaDomain:
type: string
description: Binds 'oktaDomain' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'oktaDomain' at runtime.
title: InputOkta
InputAkamaiHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- akamai_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Akamai DataStream 2 HTTP Event
Collector API requests. Akamai delivers to the /raw endpoint beneath
this path.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
hecAcks:
type: boolean
title: HEC Acks
description: Whether to enable HEC indexer acknowledgements
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
title: InputAkamaiHec
InputPingIdentityPingone:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- ping_identity_pingone
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Ping Identity PingOne HTTP
Event Collector API requests. PingOne posts structured JSON webhooks
to the /event endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputPingIdentityPingone
InputGigamonHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- gigamon_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Gigamon HTTP Event Collector
API requests. This input supports the /event and /raw endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputGigamonHec
InputVectraAiHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- vectra_ai_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Vectra AI HTTP Event Collector
API requests. This input supports the /event and /raw endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputVectraAiHec
InputF5BigIp:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- f5_big_ip
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for F5 BIG-IP HTTP Event Collector
API requests. This input supports the /event and /raw endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
hecAcks:
type: boolean
title: HEC Acks
description: Whether to enable HEC indexer acknowledgements
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputF5BigIp
InputBeyondtrustHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- beyondtrust_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for BeyondTrust HTTP Event
Collector API requests. BeyondTrust sends event payloads to the
standard HEC endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputBeyondtrustHec
InputHashicorpHcpVaultDedicated:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- hashicorp_hcp_vault_dedicated
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for HashiCorp HCP Vault Dedicated
HTTP Event Collector API requests
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputHashicorpHcpVaultDedicated
InputMimecastHec:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- mimecast_hec
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for Mimecast HTTP Event Collector
API requests. This input supports the /event and /raw endpoints.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputMimecastHec
InputTrendMicroVisionOne:
type: object
required:
- type
- host
- port
- hecAPI
properties:
id:
type: string
title: Input ID
description: Unique ID for this input
type:
type: string
description: Source type identifier.
enum:
- trend_micro_vision_one
disabled:
type: boolean
title: Disabled
description: If true, the Source is disabled and will not collect data.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data from this Source before sending it through
the Routes
sendToRoutes:
type: boolean
description: Select whether to send data to Routes, or directly to Destinations.
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
pqEnabled:
type: boolean
title: Enable persistent queue
description: Use a disk queue to minimize data loss when connected services
block. See [Cribl
Docs](https://docs.cribl.io/stream/persistent-queues) for PQ
defaults (Cribl-managed Cloud Workers) and configuration options
(on-prem and hybrid Workers).
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
criblSourceProvenance:
$ref: "#/components/schemas/InputProvenanceTypeOptional"
description: Read-only metadata that records how the Source was created.
Preserved on update when omitted from the request body. Cannot be
set on create.
connections:
type: array
title: Use QuickConnect
description: Direct connections to Destinations, and optionally via a Pipeline
or a Pack
items:
$ref: "#/components/schemas/ConnectionConfInputCollection"
pq:
$ref: "#/components/schemas/PqType"
host:
type: string
title: Address
description: Address to bind on. Defaults to 0.0.0.0 (all addresses).
port:
type: number
title: Port
maximum: 65535
description: Port to listen on
authTokens:
type: array
title: Auth tokens
description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted."
items:
$ref: "#/components/schemas/AuthTokenConfInputCloudflareHec"
tls:
$ref: "#/components/schemas/TlsSettingsServerSideType"
description: TLS settings (server side)
maxActiveReq:
type: number
title: Active request limit
description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput."
minimum: 0
maxRequestsPerSocket:
type: integer
title: Requests-per-socket limit
description: Maximum number of requests per socket before @{product} instructs
the client to close the connection. Default is 0 (unlimited).
minimum: 0
enableProxyHeader:
type: boolean
title: Show originating IP
description: Extract the client IP and port from PROXY protocol v1/v2. When
enabled, the X-Forwarded-For header is ignored. Disable to use the
X-Forwarded-For header for client IP extraction.
captureHeaders:
type: boolean
title: Capture request headers
description: Add request headers to events, in the __headers field
captureHeadersWarning:
type: string
readOnly: true
const: ""
activityLogSampleRate:
type: number
title: Activity log sample rate
description: How often request activity is logged at the `info` level. A value
of 1 would log every request, 10 every 10th request, etc.
minimum: 1
requestTimeout:
type: number
title: Request timeout (seconds)
description: How long to wait for an incoming request to complete before
aborting it. Use 0 to disable.
minimum: 0
socketTimeout:
type: number
title: Socket timeout (seconds)
description: How long @{product} should wait before assuming that an inactive
socket has timed out. To wait forever, set to 0.
minimum: 0
keepAliveTimeout:
type: number
title: Keep-alive timeout (seconds)
description: After the last response is sent, @{product} will wait this long for
additional data before closing the socket connection. Minimum 1
second, maximum 600 seconds (10 minutes).
minimum: 1
maximum: 600
ipAllowlistRegex:
type: string
title: IP allowlist regex
description: Messages from matched IP addresses will be processed, unless also
matched by the denylist
ipDenylistRegex:
type: string
title: IP denylist regex
description: Messages from matched IP addresses will be ignored. This takes
precedence over the allowlist.
hecAPI:
type: string
title: HEC endpoint
description: Absolute path on which to listen for the Trend Micro Vision One
HTTP Event Collector API requests. This input supports the /event
endpoint.
pattern: ^/
metadata:
type: array
title: Fields
description: Fields to add to every event. May be overridden by fields added at
the token or request level.
items:
$ref: "#/components/schemas/MetadataConfInputCollection"
allowedIndexes:
type: array
title: Allowed indexes
description: List values allowed in HEC event index field. Leave blank to skip
validation. Supports wildcards. The values here can expand index
validation at the token level.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowOrigin:
title: CORS allowed origins
type: array
description: HTTP origins to which @{product} should send CORS (cross-origin
resource sharing) Access-Control-Allow-* headers. Supports
wildcards.
minItems: 0
items:
type: string
minLength: 1
accessControlAllowHeaders:
title: CORS allowed headers
type: array
description: HTTP headers that @{product} will send to allowed origins as
"Access-Control-Allow-Headers" in a CORS preflight response. Use "*"
to allow all headers.
minItems: 0
items:
type: string
minLength: 1
emitTokenMetrics:
type: boolean
title: Emit per-token request metrics
description: Emit per-token (.http.perToken) and summary
(.http.summary) request metrics
description:
type: string
title: Description
description: Optional description for this configuration.
__template_environment:
type: string
description: Binds 'environment' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'environment' at runtime.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_hecAPI:
type: string
description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'hecAPI' at runtime.
__template_allowedIndexes:
type: string
description: Binds 'allowedIndexes' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'allowedIndexes' at
runtime.
__template_accessControlAllowOrigin:
type: string
description: Binds 'accessControlAllowOrigin' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowOrigin' at runtime.
__template_accessControlAllowHeaders:
type: string
description: Binds 'accessControlAllowHeaders' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'accessControlAllowHeaders' at runtime.
title: InputTrendMicroVisionOne
Input:
oneOf:
- $ref: "#/components/schemas/InputCollection"
- $ref: "#/components/schemas/InputKafka"
- $ref: "#/components/schemas/InputMsk"
- $ref: "#/components/schemas/InputHttp"
- $ref: "#/components/schemas/InputSplunk"
- $ref: "#/components/schemas/InputSplunkSearch"
- $ref: "#/components/schemas/InputSplunkHec"
- $ref: "#/components/schemas/InputAzureBlob"
- $ref: "#/components/schemas/InputAzureVnetFlowLog"
- $ref: "#/components/schemas/InputElastic"
- $ref: "#/components/schemas/InputConfluentCloud"
- $ref: "#/components/schemas/InputGrafana"
- $ref: "#/components/schemas/InputLoki"
- $ref: "#/components/schemas/InputPrometheusRw"
- $ref: "#/components/schemas/InputPrometheus"
- $ref: "#/components/schemas/InputEdgePrometheus"
- $ref: "#/components/schemas/InputOffice365Mgmt"
- $ref: "#/components/schemas/InputOffice365Service"
- $ref: "#/components/schemas/InputOffice365MsgTrace"
- $ref: "#/components/schemas/InputMicrosoftGraph"
- $ref: "#/components/schemas/InputEventhub"
- $ref: "#/components/schemas/InputEventhubAmqp"
- $ref: "#/components/schemas/InputExec"
- $ref: "#/components/schemas/InputFirehose"
- $ref: "#/components/schemas/InputGooglePubsub"
- $ref: "#/components/schemas/InputCribl"
- $ref: "#/components/schemas/InputCriblTcp"
- $ref: "#/components/schemas/InputCriblHttp"
- $ref: "#/components/schemas/InputCriblLakeHttp"
- $ref: "#/components/schemas/InputTcpjson"
- $ref: "#/components/schemas/InputSystemMetrics"
- $ref: "#/components/schemas/InputSystemState"
- $ref: "#/components/schemas/InputKubeMetrics"
- $ref: "#/components/schemas/InputKubeLogs"
- $ref: "#/components/schemas/InputKubeEvents"
- $ref: "#/components/schemas/InputWindowsMetrics"
- $ref: "#/components/schemas/InputCrowdstrike"
- $ref: "#/components/schemas/InputDatadogAgent"
- $ref: "#/components/schemas/InputDatagen"
- $ref: "#/components/schemas/InputHttpRaw"
- $ref: "#/components/schemas/InputKinesis"
- $ref: "#/components/schemas/InputCriblmetrics"
- $ref: "#/components/schemas/InputMetrics"
- $ref: "#/components/schemas/InputS3"
- $ref: "#/components/schemas/InputS3Inventory"
- $ref: "#/components/schemas/InputSnmp"
- $ref: "#/components/schemas/InputOpenTelemetry"
- $ref: "#/components/schemas/InputModelDrivenTelemetry"
- $ref: "#/components/schemas/InputSqs"
- $ref: "#/components/schemas/InputSyslog"
- $ref: "#/components/schemas/InputFile"
- $ref: "#/components/schemas/InputTcp"
- $ref: "#/components/schemas/InputAppscope"
- $ref: "#/components/schemas/InputWef"
- $ref: "#/components/schemas/InputWinEventLogs"
- $ref: "#/components/schemas/InputAppleUnifiedLogs"
- $ref: "#/components/schemas/InputRawUdp"
- $ref: "#/components/schemas/InputJournalFiles"
- $ref: "#/components/schemas/InputWiz"
- $ref: "#/components/schemas/InputOpenai"
- $ref: "#/components/schemas/InputWizWebhook"
- $ref: "#/components/schemas/InputNetflow"
- $ref: "#/components/schemas/InputSecurityLake"
- $ref: "#/components/schemas/InputBedrockS3"
- $ref: "#/components/schemas/InputServicenowTable"
- $ref: "#/components/schemas/InputProofpointPod"
- $ref: "#/components/schemas/InputZscalerHec"
- $ref: "#/components/schemas/InputCloudflareHec"
- $ref: "#/components/schemas/InputSysdigHec"
- $ref: "#/components/schemas/InputUpwindHec"
- $ref: "#/components/schemas/InputTrellixHec"
- $ref: "#/components/schemas/InputSailpointHec"
- $ref: "#/components/schemas/InputExtrahopRevealx360"
- $ref: "#/components/schemas/InputAquaSecurityHec"
- $ref: "#/components/schemas/InputOpenaiComplianceLogs"
- $ref: "#/components/schemas/InputAnthropicCompliance"
- $ref: "#/components/schemas/InputAnthropicEnterpriseAnalytics"
- $ref: "#/components/schemas/InputMicrosoftCopilot"
- $ref: "#/components/schemas/InputOkta"
- $ref: "#/components/schemas/InputAkamaiHec"
- $ref: "#/components/schemas/InputPingIdentityPingone"
- $ref: "#/components/schemas/InputGigamonHec"
- $ref: "#/components/schemas/InputVectraAiHec"
- $ref: "#/components/schemas/InputF5BigIp"
- $ref: "#/components/schemas/InputBeyondtrustHec"
- $ref: "#/components/schemas/InputHashicorpHcpVaultDedicated"
- $ref: "#/components/schemas/InputMimecastHec"
- $ref: "#/components/schemas/InputTrendMicroVisionOne"
discriminator:
propertyName: type
mapping:
collection: "#/components/schemas/InputCollection"
kafka: "#/components/schemas/InputKafka"
msk: "#/components/schemas/InputMsk"
http: "#/components/schemas/InputHttp"
splunk: "#/components/schemas/InputSplunk"
splunk_search: "#/components/schemas/InputSplunkSearch"
splunk_hec: "#/components/schemas/InputSplunkHec"
azure_blob: "#/components/schemas/InputAzureBlob"
azure_vnet_flow_log: "#/components/schemas/InputAzureVnetFlowLog"
elastic: "#/components/schemas/InputElastic"
confluent_cloud: "#/components/schemas/InputConfluentCloud"
grafana: "#/components/schemas/InputGrafana"
loki: "#/components/schemas/InputLoki"
prometheus_rw: "#/components/schemas/InputPrometheusRw"
prometheus: "#/components/schemas/InputPrometheus"
edge_prometheus: "#/components/schemas/InputEdgePrometheus"
office365_mgmt: "#/components/schemas/InputOffice365Mgmt"
office365_service: "#/components/schemas/InputOffice365Service"
office365_msg_trace: "#/components/schemas/InputOffice365MsgTrace"
microsoft_graph: "#/components/schemas/InputMicrosoftGraph"
eventhub: "#/components/schemas/InputEventhub"
eventhub_amqp: "#/components/schemas/InputEventhubAmqp"
exec: "#/components/schemas/InputExec"
firehose: "#/components/schemas/InputFirehose"
google_pubsub: "#/components/schemas/InputGooglePubsub"
cribl: "#/components/schemas/InputCribl"
cribl_tcp: "#/components/schemas/InputCriblTcp"
cribl_http: "#/components/schemas/InputCriblHttp"
cribl_lake_http: "#/components/schemas/InputCriblLakeHttp"
tcpjson: "#/components/schemas/InputTcpjson"
system_metrics: "#/components/schemas/InputSystemMetrics"
system_state: "#/components/schemas/InputSystemState"
kube_metrics: "#/components/schemas/InputKubeMetrics"
kube_logs: "#/components/schemas/InputKubeLogs"
kube_events: "#/components/schemas/InputKubeEvents"
windows_metrics: "#/components/schemas/InputWindowsMetrics"
crowdstrike: "#/components/schemas/InputCrowdstrike"
datadog_agent: "#/components/schemas/InputDatadogAgent"
datagen: "#/components/schemas/InputDatagen"
http_raw: "#/components/schemas/InputHttpRaw"
kinesis: "#/components/schemas/InputKinesis"
criblmetrics: "#/components/schemas/InputCriblmetrics"
metrics: "#/components/schemas/InputMetrics"
s3: "#/components/schemas/InputS3"
s3_inventory: "#/components/schemas/InputS3Inventory"
snmp: "#/components/schemas/InputSnmp"
open_telemetry: "#/components/schemas/InputOpenTelemetry"
model_driven_telemetry: "#/components/schemas/InputModelDrivenTelemetry"
sqs: "#/components/schemas/InputSqs"
syslog: "#/components/schemas/InputSyslog"
file: "#/components/schemas/InputFile"
tcp: "#/components/schemas/InputTcp"
appscope: "#/components/schemas/InputAppscope"
wef: "#/components/schemas/InputWef"
win_event_logs: "#/components/schemas/InputWinEventLogs"
apple_unified_logs: "#/components/schemas/InputAppleUnifiedLogs"
raw_udp: "#/components/schemas/InputRawUdp"
journal_files: "#/components/schemas/InputJournalFiles"
wiz: "#/components/schemas/InputWiz"
openai: "#/components/schemas/InputOpenai"
wiz_webhook: "#/components/schemas/InputWizWebhook"
netflow: "#/components/schemas/InputNetflow"
security_lake: "#/components/schemas/InputSecurityLake"
bedrock_s3: "#/components/schemas/InputBedrockS3"
servicenow_table: "#/components/schemas/InputServicenowTable"
proofpoint_pod: "#/components/schemas/InputProofpointPod"
zscaler_hec: "#/components/schemas/InputZscalerHec"
cloudflare_hec: "#/components/schemas/InputCloudflareHec"
sysdig_hec: "#/components/schemas/InputSysdigHec"
upwind_hec: "#/components/schemas/InputUpwindHec"
trellix_hec: "#/components/schemas/InputTrellixHec"
sailpoint_hec: "#/components/schemas/InputSailpointHec"
extrahop_revealx_360: "#/components/schemas/InputExtrahopRevealx360"
aqua_security_hec: "#/components/schemas/InputAquaSecurityHec"
openai_compliance_logs: "#/components/schemas/InputOpenaiComplianceLogs"
anthropic_compliance: "#/components/schemas/InputAnthropicCompliance"
anthropic_enterprise_analytics: "#/components/schemas/InputAnthropicEnterpriseAnalytics"
microsoft_copilot: "#/components/schemas/InputMicrosoftCopilot"
okta: "#/components/schemas/InputOkta"
akamai_hec: "#/components/schemas/InputAkamaiHec"
ping_identity_pingone: "#/components/schemas/InputPingIdentityPingone"
gigamon_hec: "#/components/schemas/InputGigamonHec"
vectra_ai_hec: "#/components/schemas/InputVectraAiHec"
f5_big_ip: "#/components/schemas/InputF5BigIp"
beyondtrust_hec: "#/components/schemas/InputBeyondtrustHec"
hashicorp_hcp_vault_dedicated: "#/components/schemas/InputHashicorpHcpVaultDedicated"
mimecast_hec: "#/components/schemas/InputMimecastHec"
trend_micro_vision_one: "#/components/schemas/InputTrendMicroVisionOne"
title: Input
CountedInputSplunkHec:
type: object
required:
- items
- count
properties:
count:
type: integer
description: Number of items returned in the items array.
items:
type: array
description: The list of items returned in this response.
items:
$ref: "#/components/schemas/InputSplunkHec"
AddHecTokenRequest:
type: object
properties:
allowedIndexesAtToken:
type: array
items:
type: string
description: List of index names that the HEC token is allowed to write to.
description:
type: string
description: Brief description for the HEC token.
enabled:
type: boolean
description: If true, the HEC token is enabled. Otherwise,
false.
metadata:
type: array
items:
$ref: "#/components/schemas/MetadataConfAddHecTokenRequest"
description: Array of key-value pairs to associate with the HEC token for
tagging, categorization, or providing additional context. Each item
in the array is an object with a name and a
value.
token:
type: string
description: The HEC token value to add to the Splunk HEC Source.
required:
- token
title: AddHecTokenRequest
CountedString:
type: object
required:
- items
- count
properties:
count:
type: integer
description: Number of items returned in the items array.
items:
type: array
description: The list of items returned in this response.
items:
type: string
CountedJobInfo:
type: object
required:
- items
- count
properties:
count:
type: integer
description: Number of items returned in the items array.
items:
type: array
description: The list of items returned in this response.
items:
$ref: "#/components/schemas/JobInfo"
RunnableJobCollection:
required:
- collector
- run
properties:
id:
type: string
title: Job ID
pattern: ^[a-zA-Z0-9_-]+$
description: Unique ID for this Job
description:
type: string
title: Description
description: Description
type:
$ref: "#/components/schemas/JobTypeOptionsRunnableJobCollection"
description: Job type
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
removeFields:
type: array
title: Remove Discover fields
description: List of fields to remove from Discover results. Wildcards (for
example, aws*) are allowed. This is useful when discovery returns
sensitive fields that should not be exposed in the Jobs user
interface.
minItems: 0
items:
type: string
title: Items
description: List of fields to remove from Discover results
resumeOnBoot:
type: boolean
title: Resume job on boot
description: Resume the ad hoc job if a failure condition causes Stream to
restart during job execution
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
schedule:
$ref: "#/components/schemas/ScheduleTypeRunnableJobCollection"
description: Configuration for a scheduled job
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
workerAffinity:
type: boolean
title: Worker affinity
description: If enabled, tasks are created and run by the same Worker Node
collector:
$ref: "#/components/schemas/Collector"
input:
$ref: "#/components/schemas/InputTypeRunnableJobCollection"
description: Input settings for a collection job, including event breaking,
routing, and preprocessing options.
run:
type: object
description: Run settings that control how and when the Collection job runs.
required:
- mode
properties:
rescheduleDroppedTasks:
type: boolean
title: Reschedule tasks
description: Reschedule tasks that failed with non-fatal errors
maxTaskReschedule:
type: number
title: Task reschedule limit
description: Maximum number of times a task can be rescheduled
minimum: 1
logLevel:
$ref: "#/components/schemas/LogLevelOptionsRunnableJobCollectionScheduleRun"
description: Level at which to set task logging
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: \d+[sm]?$
mode:
type: string
title: Mode
description: Job run mode. Preview will either return up to N matching results,
or will run until capture time T is reached. Discovery will
gather the list of files to turn into streaming tasks, without
running the data collection job. Full Run will run the
collection job.
enum:
- list
- preview
- run
x-speakeasy-unknown-values: allow
timeRangeType:
type: string
title: Time range
enum:
- absolute
- relative
description: Time range
x-speakeasy-unknown-values: allow
earliest:
type:
- number
- string
title: Earliest
description: Earliest time to collect data for the selected timezone
latest:
type:
- number
- string
title: Latest
description: Latest time to collect data for the selected timezone
timestampTimezone:
type: string
description: Timezone to use for Earliest and Latest times
title: Range timezone
expression:
type: string
title: Filter
description: A filter for tokens in the provided collect path and/or the events
being collected
minTaskSize:
type: string
title: Lower task bundle size
description: >-
Limits the bundle size for small tasks. For example,
if your lower bundle size is 1MB, you can bundle up to five 200KB files into one task.
pattern: ^((\d*\.?\d+)((KB|MB|GB|TB|PB|EB|ZB|YB|kb|mb|gb|tb|pb|eb|zb|yb){1}))$
maxTaskSize:
type: string
title: Upper task bundle size
description: >-
Limits the bundle size for files above the lower task bundle
size. For example, if your upper bundle size is 10MB,
you can bundle up to five 2MB files into one task. Files greater than this size will be assigned to individual tasks.
pattern: ^((\d*\.?\d+)((KB|MB|GB|TB|PB|EB|ZB|YB|kb|mb|gb|tb|pb|eb|zb|yb){1}))$
discoverToRoutes:
type: boolean
title: Send to Routes
description: Send discover results to Routes
capture:
type: object
title: Capture Settings
properties:
duration:
type: number
title: Capture time (sec)
description: Amount of time to keep capture open, in seconds
minimum: 1
maxEvents:
type: number
title: Capture up to N events
description: Maximum number of events to capture
minimum: 1
maximum: 10000
level:
type: integer
title: Where to capture
enum:
- 0
- 1
- 2
- 3
x-speakeasy-enum-descriptions:
- 1. Before pre-processing Pipeline
- 2. Before the Routes
- 3. Before post-processing Pipeline
- 4. Before the Destination
description: Where to capture
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- BeforePreProcessingPipeline
- BeforeTheRoutes
- BeforePostProcessingPipeline
- BeforeTheDestination
description: Capture Settings
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
type: object
description: Configuration for a saved collection job, including Collector,
input, and optional run settings.
title: RunnableJobCollection
RunnableJobExecutor:
required:
- executor
- run
properties:
id:
type: string
title: Job ID
pattern: ^[a-zA-Z0-9_-]+$
description: Unique ID for this Job
description:
type: string
title: Description
description: Description
type:
$ref: "#/components/schemas/JobTypeOptionsRunnableJobCollection"
description: Job type
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
removeFields:
type: array
title: Remove Discover fields
description: List of fields to remove from Discover results. Wildcards (for
example, aws*) are allowed. This is useful when discovery returns
sensitive fields that should not be exposed in the Jobs user
interface.
minItems: 0
items:
type: string
title: Items
description: List of fields to remove from Discover results
resumeOnBoot:
type: boolean
title: Resume job on boot
description: Resume the ad hoc job if a failure condition causes Stream to
restart during job execution
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
schedule:
$ref: "#/components/schemas/ScheduleTypeRunnableJobCollection"
description: Configuration for a scheduled job
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
executor:
$ref: "#/components/schemas/ExecutorTypeRunnableJobExecutor"
description: Executor configuration, including the executor type and its settings.
run:
type: object
description: Run settings that control how and when the Executor job runs.
properties:
rescheduleDroppedTasks:
type: boolean
title: Reschedule tasks
description: Reschedule tasks that failed with non-fatal errors
maxTaskReschedule:
type: number
title: Task reschedule limit
description: Maximum number of times a task can be rescheduled
minimum: 1
logLevel:
$ref: "#/components/schemas/LogLevelOptionsRunnableJobCollectionScheduleRun"
description: Level at which to set task logging
jobTimeout:
title: Job timeout
type: string
description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time."
pattern: \d+[sm]?$
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
type: object
description: Configuration for a saved executor job, including executor type and
run settings.
title: RunnableJobExecutor
RunnableJobScheduledSearch:
required:
- savedQueryId
- type
properties:
id:
type: string
title: Job ID
pattern: ^[a-zA-Z0-9_-]+$
description: Unique ID for this Job
description:
type: string
title: Description
description: Description
type:
$ref: "#/components/schemas/JobTypeOptionsRunnableJobCollection"
description: Job type
ttl:
type: string
title: Time to live
description: Time to keep the job's artifacts on disk after job completion. This
also affects how long a job is listed in the Job Inspector.
pattern: \d+[smh]$
ignoreGroupJobsLimit:
type: boolean
title: Ignore Worker Group job limits
description: When enabled, this job's artifacts are not counted toward the
Worker Group's finished job artifacts limit. Artifacts will be
removed only after the Collector's configured time to live.
removeFields:
type: array
title: Remove Discover fields
description: List of fields to remove from Discover results. Wildcards (for
example, aws*) are allowed. This is useful when discovery returns
sensitive fields that should not be exposed in the Jobs user
interface.
minItems: 0
items:
type: string
title: Items
description: List of fields to remove from Discover results
resumeOnBoot:
type: boolean
title: Resume job on boot
description: Resume the ad hoc job if a failure condition causes Stream to
restart during job execution
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
schedule:
$ref: "#/components/schemas/ScheduleTypeRunnableJobCollection"
description: Configuration for a scheduled job
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
savedQueryId:
type: string
title: ID of the SavedQuery
description: Identifies which search query to run
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
type: object
description: Configuration for a saved scheduled search job, including the
search query to run.
title: RunnableJobScheduledSearch
RunnableJob:
oneOf:
- $ref: "#/components/schemas/RunnableJobCollection"
- $ref: "#/components/schemas/RunnableJobExecutor"
- $ref: "#/components/schemas/RunnableJobScheduledSearch"
title: RunnableJob
TaskErrorInfo:
type: object
additionalProperties: true
properties:
message:
type: string
description: Human-readable error message.
name:
type: string
description: Error name, if available.
stack:
type: string
description: Truncated stack trace of the error.
required:
- message
description: Serialized error object that describes why a job entered its
current state. Includes message and may
include a nested reason for wrapped errors.
title: TaskErrorInfo
TaskErrorDetail:
type: object
properties:
message:
type: string
description: Human-readable error message.
name:
type: string
description: Error name, if available.
reason:
$ref: "#/components/schemas/TaskErrorInfo"
description: Nested cause of the error, if any.
stack:
type: string
description: Truncated stack trace of the error.
required:
- message
description: Task error details. May include a nested reason for
wrapped errors and additional properties from the original error.
title: TaskErrorDetail
JobStatus:
type: object
properties:
reason:
$ref: "#/components/schemas/TaskErrorDetail"
description: Reason the job entered its current state, typically
populated upon failure. May include a nested reason for
wrapped errors.
state:
type: integer
description: State of the Job
enum:
- 0
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
x-speakeasy-enums:
- Initializing
- Pending
- Running
- Paused
- Cancelled
- Finished
- Failed
- Orphaned
- Unknown
- Length
x-speakeasy-unknown-values: allow
required:
- state
description: Status of a job, including its current state and failure reason.
title: JobStatus
JobInfo:
type: object
properties:
args:
$ref: "#/components/schemas/RunnableJob"
description: Configuration and run settings used to launch the job.
id:
type: string
description: Unique identifier for the job.
keep:
type: boolean
description: If true, retain the job and its artifacts instead of
deleting according to the time-to-live or retention policy. The job
persists until it is manually deleted.
stats:
type: object
additionalProperties:
$ref: "#/components/schemas/AdditionalPropertiesTypeJobInfoStats"
description: Counters and metrics collected during job execution.
status:
$ref: "#/components/schemas/JobStatus"
description: Status of the job.
workerOwner:
type: string
description: The GUID of the worker node that owns this artifact, set when the
job ran on a Captain while the leader was offline. When present, the
leader proxies read access to the artifact; mutating actions
(replay, delete, stop) are not supported.
required:
- args
- id
- stats
- status
description: Detailed information about a job, including its configuration,
status, and statistics.
title: JobInfo
CountedInputResponse:
type: object
required:
- items
- count
properties:
count:
type: integer
description: Number of items returned in the items array.
items:
type: array
description: The list of items returned in this response.
items:
$ref: "#/components/schemas/InputResponse"
MetadataItem:
type: object
properties:
name:
type: string
description: Name of the metadata field.
value:
type: string
description: JavaScript expression to compute the metadata field's value,
enclosed in quotes or backticks. Can evaluate to a constant.
required:
- name
- value
title: MetadataItem
NotificationMode:
type: string
enum:
- direct
- policy
title: NotificationMode
x-speakeasy-unknown-values: allow
EmailRecipient:
type: object
properties:
bcc:
type: string
description: "Bcc: Recipients' email addresses."
cc:
type: string
description: "Cc: Recipients' email addresses."
to:
type: string
description: Recipients' email addresses.
required:
- to
title: EmailRecipient
NotificationSmtpTargetConfig:
type: object
properties:
body:
type: string
description: Email body.
emailRecipient:
$ref: "#/components/schemas/EmailRecipient"
description: Email recipient settings for the Notification target.
subject:
type: string
description: Email subject.
required:
- emailRecipient
title: NotificationSmtpTargetConfig
NotificationTargetConfig:
type: object
properties:
conf:
$ref: "#/components/schemas/NotificationSmtpTargetConfig"
description: Simple Mail Transfer Protocol (SMTP) configuration for the
Notification target.
id:
type: string
description: The id of the Notification target.
required:
- id
title: NotificationTargetConfig
NotificationTargetDetails:
type: object
properties:
id:
type: string
description: The id of the Notification target.
type:
type: string
description: The type of the Notification target.
required:
- id
- type
title: NotificationTargetDetails
Notification:
type: object
properties:
__srcGroup:
type: string
description: Fleet or group id this entity was inherited from when served by a
Config Helper for a child fleet. Present when inherited from parent,
including when the child has a local overlay. Omitted when the
entity is local and not inherited. Display-only; never persisted.
__srcOverridden:
type: boolean
description: If true, the child fleet has a local overlay on an inherited
entity. Omitted when inherited and unmodified, or when local and not
inherited. Display-only; never persisted.
condition:
type: string
description: The condition that triggers the Notification. Use GET
/conditions for a list of supported condition
values.
conf:
type: object
additionalProperties: true
description: Configuration for the condition that triggers the
Notification. Supported fields vary depending on the
condition. Use GET /conditions/{id} to
review the configuration for a specific condition.
disabled:
type: boolean
description: If true, the Notification is disabled and the
specified condition will not trigger it.
group:
type: string
description: The id of the Worker Group or Edge Fleet that the
Notification applies to.
id:
type: string
description: Unique identifier.
metadata:
type: array
items:
$ref: "#/components/schemas/MetadataItem"
description: Metadata tags for the Notification.
mode:
$ref: "#/components/schemas/NotificationMode"
description: "Delivery mode for Notifications.
direct: Notification is sent directly to Notification targets that are defined in templateTargetPairs.
policy: Notification is routed through Notification Policies, which match alerts by labels and route them to Notification targets without relying on templateTargetPairs."
pack:
type: string
description: The id of the Pack the Notification belongs to.
Automatically populated and returned in responses.
targetConfigs:
type: array
items:
$ref: "#/components/schemas/NotificationTargetConfig"
description: Override settings to apply for each referenced Notification target.
targetDetails:
type: array
items:
$ref: "#/components/schemas/NotificationTargetDetails"
description: Additional details about referenced Notification targets.
Optionally populated on request.
targets:
type: array
items:
type: string
description: List of the id values for the Notification targets to
send the Notification to.
templateTargetPairs:
type: array
items:
type: object
properties:
targetId:
type: string
description: The id of the Notification target to send the
Notification to.
templateId:
type: string
description: The id of the Notification template to use.
required:
- targetId
- templateId
description: If mode is direct, the key-value pairs
that define the Notification templates and targets to use for
sending Notifications.
required:
- condition
- conf
- id
- targets
title: Notification
StatusError:
type: object
properties:
details:
type: object
additionalProperties: true
description: Additional error details.
message:
type: string
description: Human-readable message that describes the error.
required:
- message
title: StatusError
WorkerPQStatus:
type: object
properties:
error:
$ref: "#/components/schemas/StatusError"
description: Error information for the persistent queue, if applicable.
health:
type: integer
description: Persistent queue health status for the Worker Process, as a numeric
code.
0 == Healthy (green; normal
operation)
1 == Degraded (yellow; potential
issues)
2 == Critical (red; problem or error
that affects operation).
metrics:
type: object
additionalProperties: true
description: Persistent-queue metrics reported for the Worker Process.
timestamp:
type: integer
description: Timestamp (in Unix time) when the persistent queue status was last
reported for the Worker Process, in milliseconds.
required:
- health
- metrics
- timestamp
title: WorkerPQStatus
InputResponse:
allOf:
- $ref: "#/components/schemas/Input"
- type: object
properties:
notifications:
type: array
items:
$ref: "#/components/schemas/Notification"
description: Notifications attached to the Source.
status:
$ref: "#/components/schemas/StatusType"
description: "Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable."
description: Source configuration with optional Notifications and runtime status.
title: InputResponse
SourceType:
type: array
items:
type: string
title: SourceType
PaginatedInputResponse:
type: object
required:
- items
- count
properties:
items:
type: array
description: The items returned in this response, after any offset/limit
pagination has been applied.
items:
$ref: "#/components/schemas/InputResponse"
count:
type: integer
description: Number of items returned in the items array.
offset:
type: integer
description: Pagination offset. Returned when offset/limit query parameters are
provided.
limit:
type: integer
description: Pagination limit. Returned when offset/limit query parameters are
provided.
totalCount:
type: integer
description: Total number of items available. Returned when offset/limit query
parameters are provided.
UpdateHecTokenRequest:
type: object
properties:
allowedIndexesAtToken:
type: array
items:
type: string
description: List of index names that the HEC token is allowed to write to.
description:
type: string
description: Brief description for the HEC token.
enabled:
type: boolean
description: If true, the HEC token is enabled. Otherwise,
false.
metadata:
type: array
items:
$ref: "#/components/schemas/MetadataConfAddHecTokenRequest"
description: Array of key-value pairs to associate with the HEC token for
tagging, categorization, or providing additional context. Each item
in the array is an object with a name and a
value.
title: UpdateHecTokenRequest
OutputDefault:
type: object
required:
- type
- defaultId
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- default
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
defaultId:
type:
- string
- "null"
title: Default Output ID
description: ID of the default output. This will be used whenever a
nonexistent/deleted output is referenced.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: OutputDefault
OutputWebhook:
type: object
required:
- type
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- webhook
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
method:
$ref: "#/components/schemas/MethodOptions"
description: The method to use when sending events
format:
type: string
title: Format
description: How to format events before sending out
enum:
- ndjson
- json_array
- custom
- advanced
x-speakeasy-enum-descriptions:
- NDJSON (Newline Delimited JSON)
- JSON Array
- Custom
- Advanced
x-speakeasy-unknown-values: allow
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 512000
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events. You can also add headers dynamically
on a per-event basis in the __headers field, as explained in [Cribl
Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
type: string
title: Authentication type
description: Authentication method to use for the HTTP request
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
- oauth
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
- OAuth
x-speakeasy-unknown-values: allow
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
loadBalanced:
type: boolean
title: Load balancing
description: Enable for optimal performance. Even if you have one hostname, it
can expand to multiple IPs. If disabled, consider enabling
round-robin DNS.
description:
type: string
title: Description
description: Optional description for this configuration.
customSourceExpression:
type: string
title: Source expression
description: "Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON."
customDropWhenNull:
type: boolean
title: Drop when null
description: Whether to drop events when the source expression evaluates to null
customEventDelimiter:
type: string
title: Event delimiter
description: Delimiter string to insert between individual events. Defaults to
newline character.
customContentType:
type: string
title: Content type
description: Content type to use for request. Defaults to application/x-ndjson.
Any content types set in Advanced Settings > Extra HTTP headers will
override this entry.
customPayloadExpression:
type: string
title: Batch expression
description: 'Expression specifying how to format the payload for each batch. To
reference the events to send, use the `${events}` variable. Example
expression: `{ "items" : [${events}] }` would send the batch inside
a JSON object.'
advancedContentType:
type: string
title: Content type
description: HTTP content-type header value
formatEventCode:
type: string
title: Format inbound event
description: "Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code."
formatPayloadCode:
type: string
title: Format outbound payload
description: "Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code."
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
loginUrl:
type: string
title: Login URL
description: URL for OAuth
pattern: ^https?://.*
secretParamName:
type: string
title: OAuth Secret parameter name
description: Secret parameter name to pass in request body
secret:
type: string
title: OAuth secret
description: Secret parameter value to pass in request body
tokenAttributeName:
type: string
title: Token attribute name
description: Name of the auth token attribute in the OAuth response. Can be
top-level (e.g., 'token'); or nested, using a period (e.g.,
'data.token').
authHeaderExpr:
type: string
title: Authorize expression
description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`."
tokenTimeoutSecs:
type: number
title: Refresh interval (secs.)
description: How often the OAuth token should be refreshed.
minimum: 1
maximum: 300000
oauthParams:
type: array
title: OAuth parameters
description: Additional parameters to send in the OAuth login request.
@{product} will combine the secret with these parameters, and will
send the URL-encoded result in a POST request to the endpoint
specified in the 'Login URL'. We'll automatically add the
content-type header 'application/x-www-form-urlencoded' when sending
this request.
items:
$ref: "#/components/schemas/OauthParamConfInputServicenowTable"
oauthHeaders:
type: array
title: OAuth headers
description: Additional headers to send in the OAuth login request. @{product}
will automatically add the content-type header
'application/x-www-form-urlencoded' when sending this request.
items:
$ref: "#/components/schemas/OauthHeaderConfInputServicenowTable"
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: "@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use."
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
pattern: ^https?://.*
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, @{product} sends only
grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
url:
type: string
title: Webhook URL
description: URL of a webhook endpoint to send events to, such as
http://localhost:10200
pattern: ^https?://.*
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: Webhook URLs
description: Webhook URLs
minItems: 1
items:
type: object
required:
- url
properties:
url:
type: string
title: Webhook LB URL
description: URL of a webhook endpoint to send events to, such as
http://localhost:10200
pattern: ^https?://.*
weight:
type: number
title: Load Weight
description: Assign a weight (>0) to each endpoint to indicate its
traffic-handling capability
minimum: 0
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_secret:
type: string
description: Binds 'secret' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'secret' at runtime.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
anyOf:
- required:
- url
- required:
- urls
title: OutputWebhook
OutputSentinel:
type: object
required:
- type
- endpointURLConfiguration
- loginUrl
- client_id
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- sentinel
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size (KB) of the request body (defaults to the API's
maximum limit of 1000 KB)
minimum: 100
maximum: 1000
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events. You can also add headers dynamically
on a per-event basis in the __headers field, as explained in [Cribl
Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
enum:
- oauth
description: Discriminator value.
x-speakeasy-unknown-values: allow
loginUrl:
type: string
title: Login URL
description: URL for OAuth
pattern: ^https?://.*
refreshTokenField:
type: string
title: Refresh token field
description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials."
rotateRefreshToken:
type: boolean
title: Rotate refresh token
description: "@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use."
refreshUrl:
type: string
title: Refresh URL
description: Override the refresh endpoint URL if it differs from the Login URL.
Defaults to Login URL.
pattern: ^https?://.*
refreshRequestParams:
type: array
title: Refresh grant parameters
description: Parameters to include in the refresh token request body. Most
servers require 'client_id' here. If not set, @{product} sends only
grant_type, refresh_token, and client_secret.
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
oauthSecretSource:
type: string
title: OAuth secret source
description: Enter the OAuth secret directly, or select a stored text secret
enum:
- inline
- secret
x-speakeasy-unknown-values: allow
client_id:
title: Client ID
type: string
description: JavaScript expression to compute the Client ID for the Azure
application. Can be a constant.
scope:
title: Scope
type: string
description: Scope to pass in the OAuth request
endpointURLConfiguration:
title: Endpoint configuration
description: Enter the data collection endpoint URL or the individual ID
type: string
enum:
- url
- ID
x-speakeasy-enum-descriptions:
- URL
- ID
x-speakeasy-unknown-values: allow
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
format:
enum:
- ndjson
- json_array
- custom
- advanced
x-speakeasy-unknown-values: allow
customSourceExpression:
type: string
title: Source expression
description: "Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON."
customDropWhenNull:
type: boolean
title: Drop when null
description: Whether to drop events when the source expression evaluates to null
customEventDelimiter:
type: string
title: Event delimiter
description: Delimiter string to insert between individual events. Defaults to
newline character.
customContentType:
type: string
title: Content type
description: Content type to use for request. Defaults to application/x-ndjson.
Any content types set in Advanced Settings > Extra HTTP headers will
override this entry.
customPayloadExpression:
type: string
title: Batch expression
description: 'Expression specifying how to format the payload for each batch. To
reference the events to send, use the `${events}` variable. Example
expression: `{ "items" : [${events}] }` would send the batch inside
a JSON object.'
advancedContentType:
type: string
title: Content type
description: HTTP content-type header value
formatEventCode:
type: string
title: Format inbound event
description: "Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code."
formatPayloadCode:
type: string
title: Format outbound payload
description: "Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code."
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
secret:
type: string
title: OAuth secret
description: Secret parameter value to pass in request body
oauthTextSecret:
type: string
title: OAuth secret (text secret)
description: Select or create a stored text secret for the OAuth secret value
url:
title: URL
type: string
description: URL to send events to. Can be overwritten by an event's __url field.
pattern: ^https?://.*
dcrID:
type: string
title: Data collection rule ID
description: Immutable ID for the Data Collection Rule (DCR)
dceEndpoint:
type: string
title: Data collection endpoint
description: "Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`"
pattern: ^https:\/\/([a-zA-Z0-9-_\.]+)\.ingest\.monitor\.azure\.com(\/?)$
streamName:
type: string
title: Stream name
description: The name of the stream (Sentinel table) in which to store the events
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
__template_refreshUrl:
type: string
description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'refreshUrl' at runtime.
__template_client_id:
type: string
description: Binds 'client_id' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'client_id' at runtime.
__template_scope:
type: string
description: Binds 'scope' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'scope' at runtime.
__template_secret:
type: string
description: Binds 'secret' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'secret' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_dcrID:
type: string
description: Binds 'dcrID' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'dcrID' at runtime.
__template_dceEndpoint:
type: string
description: Binds 'dceEndpoint' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'dceEndpoint' at runtime.
__template_streamName:
type: string
description: Binds 'streamName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamName' at runtime.
title: OutputSentinel
OutputDevnull:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- devnull
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: OutputDevnull
OutputSyslog:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsSyslog"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
type: string
title: Protocol
description: The network protocol to use for sending out syslog messages
enum:
- tcp
- udp
x-speakeasy-enum-descriptions:
- TCP
- UDP
x-speakeasy-unknown-values: allow
facility:
type: integer
title: Facility
description: Default value for message facility. Will be overwritten by value of
__facility if set. Defaults to user.
enum:
- 0
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
x-speakeasy-enum-descriptions:
- kern
- user
- mail
- daemon
- auth
- syslog
- lpr
- news
- uucp
- cron
- authpriv
- ftp
- ntp
- security
- console
- solaris-cron
- local0
- local1
- local2
- local3
- local4
- local5
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- Kern
- User
- Mail
- Daemon
- Auth
- Syslog
- Lpr
- News
- Uucp
- Cron
- Authpriv
- Ftp
- Ntp
- Security
- Console
- SolarisCron
- Local0
- Local1
- Local2
- Local3
- Local4
- Local5
severity:
type: integer
title: Severity
description: Default value for message severity. Will be overwritten by value of
__severity if set. Defaults to notice.
enum:
- 0
- 1
- 2
- 3
- 4
- 5
- 6
- 7
x-speakeasy-enum-descriptions:
- emergency
- alert
- critical
- error
- warning
- notice
- info
- debug
x-speakeasy-unknown-values: allow
x-speakeasy-enums:
- Emergency
- Alert
- Critical
- Error
- Warning
- Notice
- Info
- Debug
appName:
type: string
title: App name
description: Default name for device or application that originated the message.
Defaults to Cribl, but will be overwritten by value of __appname if
set.
messageFormat:
type: string
enum:
- rfc3164
- rfc5424
title: Message format
description: The syslog message format depending on the receiver's support
x-speakeasy-enum-descriptions:
- RFC3164
- RFC5424
x-speakeasy-unknown-values: allow
timestampFormat:
type: string
enum:
- syslog
- iso8601
title: Timestamp format
description: Timestamp format to use when serializing event's time field
x-speakeasy-enum-descriptions:
- Syslog
- ISO8601
x-speakeasy-unknown-values: allow
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
octetCountFraming:
type: boolean
title: Octet count framing
description: Prefix messages with the byte count of the message. If disabled, no
prefix will be set, and the message will be appended with a \n.
logFailedRequests:
type: boolean
title: Log failed requests to disk
description: Use to troubleshoot issues with sending data
description:
type: string
title: Description
description: Optional description for this configuration.
loadBalanced:
type: boolean
title: Load balancing
description: For optimal performance, enable load balancing even if you have one
hostname, as it can expand to multiple IPs. If this setting is
disabled, consider enabling round-robin DNS.
host:
type: string
title: Address
description: The hostname of the receiver
port:
type: number
title: Port
maximum: 65535
description: The port to connect to on the provided host
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
hosts:
type: array
title: Destinations
description: Set of hosts to load-balance data to
minItems: 1
items:
$ref: "#/components/schemas/HostConfOutputSyslog"
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
maxConcurrentSenders:
type: number
minimum: 0
title: Connection limit
description: Maximum number of concurrent connections (per Worker Process). A
random set of IPs will be picked on every DNS resolution period. Use
0 for unlimited.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
maxRecordSize:
type: number
title: Record size limit
minimum: 1
maximum: 65535
description: Maximum size of syslog messages. Make sure this value is less than
or equal to the MTU to avoid UDP packet fragmentation.
udpDnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if the destination is an IP address. A value of 0 means
every message sent will incur a DNS lookup.
enableIpSpoofing:
title: Enable Source IP spoofing
description: Send Syslog traffic using the original event's Source IP and port.
To enable this, you must install the external `udp-sender` helper
binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the
`CAP_NET_RAW` capability.
type: boolean
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
required:
- type
title: OutputSyslog
OutputSplunk:
type: object
required:
- type
- host
- port
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsSplunk"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
host:
type: string
title: Address
description: The hostname of the receiver
port:
type: number
title: Port
maximum: 65535
description: The port to connect to on the provided host
nestedFields:
$ref: "#/components/schemas/NestedFieldSerializationOptions"
description: How to serialize nested fields into index-time fields
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
enableMultiMetrics:
type: boolean
title: Output multiple metrics
description: Output metrics in multiple-metric format in a single event.
Supported in Splunk 8.0 and above.
enableACK:
type: boolean
title: Minimize in-flight data loss
description: Check if indexer is shutting down and stop sending data. This helps
minimize data loss during shutdown.
logFailedRequests:
type: boolean
title: Log failed requests to disk
description: Use to troubleshoot issues with sending data
maxS2Sversion:
$ref: "#/components/schemas/MaxS2SVersionOptions"
description: The highest S2S protocol version to advertise during handshake
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
description:
type: string
title: Description
description: Optional description for this configuration.
maxFailedHealthChecks:
type: number
title: Failed health check limit
description: Maximum number of times healthcheck can fail before we close
connection. If set to 0 (disabled), and the connection to Splunk is
forcibly closed, some data loss might occur.
minimum: 0
compress:
$ref: "#/components/schemas/CompressionOptions"
description: Controls whether the sender should send compressed data to the
server. Select 'Disabled' to reject compressed connections or
'Always' to ignore server's configuration and send compressed data.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
authToken:
type: string
title: Auth token
description: Shared secret token to use when establishing a connection to a
Splunk indexer.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
__template_nestedFields:
type: string
description: Binds 'nestedFields' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'nestedFields' at runtime.
__template_maxS2Sversion:
type: string
description: Binds 'maxS2Sversion' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'maxS2Sversion' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
title: OutputSplunk
OutputSplunkLb:
type: object
required:
- type
- hosts
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- splunk_lb
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
maxConcurrentSenders:
type: number
minimum: 0
title: Connection limit
description: Maximum number of concurrent connections (per Worker Process). A
random set of IPs will be picked on every DNS resolution period. Use
0 for unlimited.
nestedFields:
$ref: "#/components/schemas/NestedFieldSerializationOptions"
description: How to serialize nested fields into index-time fields
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
enableMultiMetrics:
type: boolean
title: Output multiple metrics
description: Output metrics in multiple-metric format in a single event.
Supported in Splunk 8.0 and above.
enableACK:
type: boolean
title: Minimize in-flight data loss
description: Check if indexer is shutting down and stop sending data. This helps
minimize data loss during shutdown.
logFailedRequests:
type: boolean
title: Log failed requests to disk
description: Use to troubleshoot issues with sending data
maxS2Sversion:
$ref: "#/components/schemas/MaxS2SVersionOptions"
description: The highest S2S protocol version to advertise during handshake
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
indexerDiscovery:
type: boolean
title: Indexer Discovery
description: Automatically discover indexers in indexer clustering environment.
senderUnhealthyTimeAllowance:
type: number
title: Endpoint health fluctuation time allowance (ms)
description: How long (in milliseconds) each LB endpoint can report blocked
before the Destination reports unhealthy, blocking the sender.
(Grace period for fluctuations.) Use 0 to disable; max 1 minute.
minimum: 0
maximum: 60000
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
description:
type: string
title: Description
description: Optional description for this configuration.
maxFailedHealthChecks:
type: number
title: Failed health check limit
description: Maximum number of times healthcheck can fail before we close
connection. If set to 0 (disabled), and the connection to Splunk is
forcibly closed, some data loss might occur.
minimum: 0
compress:
$ref: "#/components/schemas/CompressionOptions"
description: Controls whether the sender should send compressed data to the
server. Select 'Disabled' to reject compressed connections or
'Always' to ignore server's configuration and send compressed data.
indexerDiscoveryConfigs:
type: object
description: List of configurations to set up indexer discovery in Splunk
Indexer clustering environment.
required:
- masterUri
- site
- refreshIntervalSec
properties:
site:
type: string
pattern: "[0-9A-Za-z-._]+"
title: Site
description: Clustering site of the indexers from where indexers need to be
discovered. In case of single site cluster, it defaults to
'default' site.
masterUri:
type: string
pattern: ^https?://[a-zA-Z0-9-._]+:[0-9]+$
title: Cluster manager URI
description: "Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089"
refreshIntervalSec:
type: number
minimum: 60
maximum: 86400
title: Refresh period
description: Time interval, in seconds, between two consecutive indexer list
fetches from cluster manager
rejectUnauthorized:
type: boolean
title: Validate cluster manager certificates
description: During indexer discovery, reject cluster manager certificates that
are not authorized by the system's CA. Disable to allow
untrusted (for example, self-signed) certificates.
authTokens:
type: array
title: Authentication tokens
description: Tokens required to authenticate to cluster manager for indexer
discovery
items:
type: object
properties:
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
authToken:
type: string
title: Auth token
description: Shared secret to be provided by any client (in authToken header
field). If empty, unauthorized access is permitted.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
authToken:
type: string
title: Auth token
description: Shared secret to be provided by any client (in authToken header
field). If empty, unauthorized access is permitted.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
hosts:
type: array
title: Destinations
description: Set of Splunk indexers to load-balance data to.
minItems: 1
items:
$ref: "#/components/schemas/HostConfOutputSyslog"
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
authToken:
type: string
title: Auth token
description: Shared secret token to use when establishing a connection to a
Splunk indexer.
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_nestedFields:
type: string
description: Binds 'nestedFields' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'nestedFields' at runtime.
__template_maxS2Sversion:
type: string
description: Binds 'maxS2Sversion' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'maxS2Sversion' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
title: OutputSplunkLb
OutputSplunkHec:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- splunk_hec
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: Enable for optimal performance. Even if you have one hostname, it
can expand to multiple IPs. If disabled, consider enabling
round-robin DNS.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 2097152
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
enableMultiMetrics:
type: boolean
title: Output multi-metrics
description: Output metrics in multiple-metric format, supported in Splunk 8.0
and above to allow multiple metrics in a single event.
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
nextQueue:
type: string
title: Next Processing Queue
description: In the Splunk app, define which Splunk processing queue to send the
events after HEC processing.
tcpRouting:
type: string
title: Default _TCP_ROUTING
description: In the Splunk app, set the value of _TCP_ROUTING for events that do
not have _ctrl._TCP_ROUTING set.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
url:
type: string
title: Splunk HEC Endpoint
description: URL to a Splunk HEC endpoint to send events to, e.g.,
http://localhost:8088/services/collector/event
pattern: ^https?://.*
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: Splunk HEC Endpoints
description: Splunk HEC Endpoints
minItems: 1
items:
type: object
required:
- url
properties:
url:
type: string
title: HEC Endpoint
description: URL to a Splunk HEC endpoint to send events to, e.g.,
http://localhost:8088/services/collector/event
pattern: ^https?://.*
weight:
type: number
title: Load Weight
description: Assign a weight (>0) to each endpoint to indicate its
traffic-handling capability
minimum: 0
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
token:
type: string
title: HEC Auth token
description: Splunk HEC authentication token
textSecret:
type: string
title: HEC Auth token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
required:
- type
title: OutputSplunkHec
OutputWizHec:
type: object
required:
- type
- wiz_connector_id
- wiz_environment
- data_center
- wiz_sourcetype
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- wiz_hec
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 9000
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
wiz_connector_id:
type: string
title: Wiz connector ID
description: The unique identifier for the specific Cribl connector defined in
your Wiz Settings. This is used to cross-validate the bearer token
and ensure traffic is originating from the authorized integration.
wiz_environment:
type: string
title: Wiz environment
description: Your Wiz deployment environment
data_center:
type: string
title: Wiz data center
description: Your Wiz deployment data center (such as us1, us8, or eu1). From
Tenant Info → Data Center and Regions → Tenant Data Center in your
Wiz console.
wiz_sourcetype:
type: string
title: Wiz Defend Source type
description: The Wiz log source type. Select a predefined type or enter a custom
value.
enum:
- AWS_CLOUDTRAIL
- AWS_EKS_AUDIT_LOGS
- AWS_RESOLVER_QUERY_LOGS
- AZURE_ACTIVITY_LOGS
- GCP_AUDIT_LOGS
- GITHUB_AUDIT_LOGS
- OCI_AUDIT_LOGS
- AWS_VPC_FLOW_LOGS
x-speakeasy-unknown-values: allow
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: Authentication token
description: Wiz Defend Auth token
textSecret:
type: string
title: Authentication token (text secret)
description: Select or create a stored text secret
wiz_vpc_event_format:
enum:
- json
- csv_row
type: string
title: Event format
description: The format of the VPC Flow Log events
x-speakeasy-unknown-values: allow
wiz_vpc_flow_log_format:
type: string
title: Flow log format
description: The format string for VPC Flow Log fields
minLength: 1
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_wiz_environment:
type: string
description: Binds 'wiz_environment' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'wiz_environment' at
runtime.
__template_data_center:
type: string
description: Binds 'data_center' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'data_center' at runtime.
__template_wiz_sourcetype:
type: string
description: Binds 'wiz_sourcetype' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'wiz_sourcetype' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputWizHec
OutputTcpjson:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsTcpjson"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: Use load-balanced destinations
compression:
$ref: "#/components/schemas/CompressionOptionsGzipNone"
description: Codec to use to compress the data before sending
logFailedRequests:
type: boolean
title: Log failed requests to disk
description: Use to troubleshoot issues with sending data
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
tokenTTLMinutes:
type: number
title: Auth Token TTL minutes
minimum: 1
maximum: 60
description: The number of minutes before the internally generated
authentication token expires, valid values between 1 and 60
sendHeader:
type: boolean
title: Send auth token in initial record
description: Upon connection, send a header-like record containing the auth
token and other metadata.This record will not contain an actual
event – only subsequent records will.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
description:
type: string
title: Description
description: Optional description for this configuration.
host:
type: string
title: Address
description: The hostname of the receiver
port:
type: number
title: Port
maximum: 65535
description: The port to connect to on the provided host
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
hosts:
type: array
title: Destinations
description: Set of hosts to load-balance data to
minItems: 1
items:
$ref: "#/components/schemas/HostConfOutputSyslog"
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
maxConcurrentSenders:
type: number
minimum: 0
title: Connection limit
description: Maximum number of concurrent connections (per Worker Process). A
random set of IPs will be picked on every DNS resolution period. Use
0 for unlimited.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
authToken:
type: string
title: Auth token
description: Optional authentication token to include as part of the connection
header
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
required:
- type
title: OutputTcpjson
OutputWavefront:
type: object
required:
- type
- domain
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- wavefront
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
domain:
type: string
title: Domain name
description: WaveFront domain name, e.g. "longboard"
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: Auth token
description: WaveFront API authentication token (see
[here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputWavefront
OutputSignalfx:
type: object
required:
- type
- realm
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- signalfx
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
realm:
type: string
title: Realm
description: SignalFx realm name, e.g. "us0". For a complete list of available
SignalFx realm names, please check
[here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: Auth token
description: SignalFx API access token (see
[here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputSignalfx
OutputFilesystem:
type: object
required:
- type
- destPath
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- filesystem
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
destPath:
type: string
title: Output location
description: Final destination for the output files
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputFilesystem
OutputS3:
type: object
required:
- type
- bucket
- stagePath
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsS3"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
enableAssumeRole:
type: boolean
title: Enable for S3
description: Use Assume Role credentials to access S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
bucket:
type: string
title: S3 bucket name
description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
region:
type: string
title: Region
description: Region where the S3 bucket is located
destPath:
type: string
title: Key prefix
description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`"
maxConcurrentFileParts:
type: number
title: Concurrent file parts upload limit
description: Maximum number of parts to upload in parallel per file. Minimum
part size is 5MB.
minimum: 1
maximum: 10
verifyPermissions:
type: boolean
title: Verify if bucket exists
description: Disable if you can access files within the bucket but not the
bucket itself
maxClosingFilesToBackpressure:
type: number
title: Staging file limit
description: Maximum number of files that can be waiting for upload before
backpressure is applied
minimum: 10
maximum: 4200
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 86400
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 86400
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
awsSecretKey:
type: string
title: Secret key
description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)"
objectACL:
$ref: "#/components/schemas/ObjectAclOptions"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptions"
description: Storage class to select for uploaded objects
serverSideEncryption:
$ref: "#/components/schemas/ServerSideEncryptionForUploadedObjectsOptions"
description: Server-side encryption to use for uploaded objects
kmsKeyId:
type: string
title: KMS key ID
description: ID or ARN of the KMS customer-managed key to use for encryption
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: This value can be a constant or a JavaScript expression
(`${C.env.SOME_ACCESS_KEY}`)
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_serverSideEncryption:
type: string
description: Binds 'serverSideEncryption' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serverSideEncryption' at runtime.
__template_kmsKeyId:
type: string
description: Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'kmsKeyId' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputS3
OutputAzureBlob:
type: object
required:
- type
- containerName
- stagePath
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsAzureblob"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
containerName:
type: string
title: Container name
description: The Azure Blob Storage container name. Name can include only
lowercase letters, numbers, and hyphens. For dynamic container
names, enter a JavaScript expression within quotes or backticks, to
be evaluated at initialization. The expression can evaluate to a
constant value and can reference Global Variables, such as
`myContainer-${C.env["CRIBL_WORKER_ID"]}`.
createContainer:
type: boolean
title: Create container
description: Create the configured container in Azure Blob Storage if it does
not already exist
destPath:
type: string
title: Blob prefix
description: Root directory prepended to path before uploading. Value can be a
JavaScript expression enclosed in quotes or backticks, to be
evaluated at initialization. The expression can evaluate to a
constant value and can reference Global Variables, such as
`myBlobPrefix-${C.env["CRIBL_WORKER_ID"]}`.
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files before compressing and
moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
maxConcurrentFileParts:
type: number
title: Concurrent file parts limit
description: Maximum number of parts to upload in parallel per file
minimum: 1
maximum: 10
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
authType:
$ref: "#/components/schemas/AuthenticationMethodOptions"
description: Authentication method
storageClass:
type: string
title: Blob access tier
enum:
- Inferred
- Hot
- Cool
- Cold
- Archive
x-speakeasy-enum-descriptions:
- Default account access tier
- Hot tier
- Cool tier
- Cold tier
- Archive tier
description: Blob access tier
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
connectionString:
type: string
title: Connection string
description: Enter your Azure Storage account connection string. If left blank,
Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.
textSecret:
type: string
title: Connection string (text secret)
description: Select or create a stored text secret
storageAccountName:
type: string
title: Storage account name
description: The name of your Azure storage account
tenantId:
type: string
title: Tenant ID
description: The service principal's tenant ID
clientId:
type: string
title: Client ID
description: The service principal's client ID
azureCloud:
type: string
title: Azure Cloud
description: The Azure cloud to use. Defaults to Azure Public Cloud.
endpointSuffix:
type: string
title: Endpoint suffix
description: Endpoint suffix for the service URL. Takes precedence over the
Azure Cloud setting. Defaults to core.windows.net.
clientTextSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
certificate:
$ref: "#/components/schemas/CertificateType"
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_containerName:
type: string
description: Binds 'containerName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'containerName' at runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
__template_connectionString:
type: string
description: Binds 'connectionString' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'connectionString' at runtime.
__template_storageAccountName:
type: string
description: Binds 'storageAccountName' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'storageAccountName' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_azureCloud:
type: string
description: Binds 'azureCloud' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'azureCloud' at runtime.
title: OutputAzureBlob
OutputAzureDataExplorer:
type: object
required:
- type
- clusterUrl
- database
- table
- compress
- oauthEndpoint
- tenantId
- clientId
- scope
- oauthType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- azure_data_explorer
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
clusterUrl:
type: string
title: Cluster base URI
description: The base URI for your cluster. Typically,
`https://..kusto.windows.net`.
pattern: ^https://
database:
type: string
title: Database name
description: Name of the database containing the table where data will be ingested
pattern: ^[\w\s\-\.]+$
maxLength: 260
table:
type: string
title: Table name
description: Name of the table to ingest data into
pattern: ^[\w\-\.]+$
maxLength: 1024
validateDatabaseSettings:
type: boolean
title: Validate database settings
description: When saving or starting the Destination, validate the database name
and credentials; also validate table name, except when creating a
new table. Disable if your Azure app does not have both the Database
Viewer and the Table Viewer role.
ingestMode:
type: string
title: Ingestion mode
enum:
- batching
- streaming
x-speakeasy-enum-descriptions:
- Batching
- Streaming
description: Ingestion mode
x-speakeasy-unknown-values: allow
oauthEndpoint:
$ref: "#/components/schemas/MicrosoftEntraIdAuthenticationEndpointOptionsSasl"
description: Endpoint used to acquire authentication tokens from Azure
tenantId:
type: string
title: Tenant ID
description: Directory ID (tenant identifier) in Azure Active Directory
clientId:
type: string
title: Client ID
description: client_id to pass in the OAuth request parameter
scope:
type: string
title: Scope
description: Scope to pass in the OAuth request parameter
oauthType:
title: Authentication method
type: string
enum:
- clientSecret
- clientTextSecret
- certificate
x-speakeasy-enum-descriptions:
- Client secret
- Client secret (text secret)
- Certificate
description: The type of OAuth 2.0 client credentials grant flow to use
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
clientSecret:
type: string
title: Client secret
description: The client secret that you generated for your app in the Azure portal
textSecret:
type: string
title: Client secret (text secret)
description: Select or create a stored text secret
certificate:
type: object
properties:
certificateName:
type: string
title: Certificate
description: The certificate you registered as credentials for your app in the
Azure portal
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
isMappingObj:
type: boolean
title: Add mapping object
description: Send a JSON mapping object instead of specifying an existing named
data mapping
mappingObj:
type: string
title: Data mapping
description: Enter a JSON object that defines your desired data mapping
mappingRef:
type: string
title: Data mapping
description: Enter the name of a data mapping associated with your target table.
Or, if incoming event and target table fields match exactly, you can
leave the field empty.
pattern: ^[\w\-\.]+$
ingestUrl:
type: string
title: Ingestion service URI
description: The ingestion service URI for your cluster. Typically,
`https://ingest-..kusto.windows.net`.
pattern: ^https://
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files before compressing and
moving to final destination. Use performant and stable storage.
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
maxConcurrentFileParts:
type: number
title: Concurrent file parts limit
description: Maximum number of parts to upload in parallel per file
minimum: 1
maximum: 10
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
flushImmediately:
type: boolean
title: Flush immediately
description: Bypass the data management service's aggregation mechanism
retainBlobOnSuccess:
type: boolean
title: Retain blob on success
description: Prevent blob deletion after ingestion is complete
extentTags:
type: array
title: Extent tags
description: Strings or tags associated with the extent (ingested data shard)
items:
type: object
required:
- value
properties:
prefix:
type: string
title: Prefix (optional)
enum:
- dropBy
- ingestBy
x-speakeasy-enum-descriptions:
- drop-by
- ingest-by
description: Prefix (optional)
x-speakeasy-unknown-values: allow
value:
type: string
title: Value
description: Value
ingestIfNotExists:
type: array
title: Enforce uniqueness via tag values
description: Prevents duplicate ingestion by verifying whether an extent with
the specified ingest-by tag already exists
items:
type: object
required:
- value
properties:
value:
type: string
title: Value
description: Value
reportLevel:
type: string
title: Report level
description: Level of ingestion status reporting. Defaults to FailuresOnly.
enum:
- failuresOnly
- doNotReport
- failuresAndSuccesses
x-speakeasy-enum-descriptions:
- FailuresOnly
- DoNotReport
- FailuresAndSuccesses
x-speakeasy-unknown-values: allow
reportMethod:
type: string
title: Report method
description: Target of the ingestion status reporting. Defaults to Queue.
enum:
- queue
- table
- queueAndTable
x-speakeasy-enum-descriptions:
- Queue
- Table
- QueueAndTable
x-speakeasy-unknown-values: allow
additionalProperties:
type: array
title: Additional fields
description: Optionally, enter additional configuration properties to send to
the ingestion service
items:
type: object
required:
- key
- value
properties:
key:
type: string
title: Key
pattern: ^[\w\-\.]+$
description: Key
value:
type: string
title: Value
description: Value
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 4096
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_clusterUrl:
type: string
description: Binds 'clusterUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clusterUrl' at runtime.
__template_database:
type: string
description: Binds 'database' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'database' at runtime.
__template_table:
type: string
description: Binds 'table' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'table' at runtime.
__template_oauthEndpoint:
type: string
description: Binds 'oauthEndpoint' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'oauthEndpoint' at runtime.
__template_tenantId:
type: string
description: Binds 'tenantId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tenantId' at runtime.
__template_clientId:
type: string
description: Binds 'clientId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientId' at runtime.
__template_scope:
type: string
description: Binds 'scope' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'scope' at runtime.
__template_clientSecret:
type: string
description: Binds 'clientSecret' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'clientSecret' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
__template_mappingRef:
type: string
description: Binds 'mappingRef' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'mappingRef' at runtime.
__template_ingestUrl:
type: string
description: Binds 'ingestUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'ingestUrl' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
title: OutputAzureDataExplorer
OutputAzureLogs:
type: object
required:
- type
- logType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- azure_logs
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
logType:
type: string
title: Log Type
description: The Log Type of events sent to this LogAnalytics workspace.
Defaults to `Cribl`. Use only letters, numbers, and `_` characters,
and can't exceed 100 characters. Can be overwritten by event field
__logType.
maxLength: 100
resourceId:
type: string
title: Resource ID
description: Optional Resource ID of the Azure resource to associate the data
with. Can be overridden by the __resourceId event field. This ID
populates the _ResourceId property, allowing the data to be included
in resource-centric queries. If the ID is neither specified nor
overridden, resource-centric queries will omit the data.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
apiUrl:
type: string
title: DNS name of API endpoint
description: "The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=."
pattern: ^\.[^\/]+$
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
title: Authentication method
type: string
enum:
- manual
- secret
description: Enter workspace ID and workspace key directly, or select a stored
secret
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
workspaceId:
type: string
title: Workspace ID
description: Azure Log Analytics Workspace ID. See Azure Dashboard Workspace >
Advanced settings.
workspaceKey:
type: string
title: Workspace key
description: Azure Log Analytics Workspace Primary or Secondary Shared Key. See
Azure Dashboard Workspace > Advanced settings.
keypairSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_workspaceId:
type: string
description: Binds 'workspaceId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'workspaceId' at runtime.
__template_workspaceKey:
type: string
description: Binds 'workspaceKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'workspaceKey' at runtime.
title: OutputAzureLogs
OutputKinesis:
type: object
required:
- type
- streamName
- region
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsKinesis"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
streamName:
type: string
title: Stream Name
description: Kinesis stream name to send events to.
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the Kinesis stream is located
endpoint:
type: string
title: Endpoint
description: Kinesis stream service endpoint. If empty, defaults to the AWS
Region-specific endpoint. Otherwise, it must point to Kinesis
stream-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for Kinesis stream
description: Use Assume Role credentials to access Kinesis stream
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
concurrency:
type: number
title: Put request concurrency
description: Maximum number of ongoing put requests before blocking.
minimum: 1
maximum: 32
maxRecordSizeKB:
type: number
title: Record size limit (KB, uncompressed)
description: Maximum size (KB) of each individual record before compression. For
uncompressed or non-compressible data 1MB is the max recommended
size
minimum: 1
maximum: 10240
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Max record size.
compression:
type: string
enum:
- none
- gzip
title: Compression
description: Compression type to use for records
x-speakeasy-enum-descriptions:
- None
- Gzip
x-speakeasy-unknown-values: allow
useListShards:
type: boolean
title: ListShards API
description: Provides higher stream rate limits, improving delivery speed and
reliability by minimizing throttling. See the [ListShards
API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html)
documentation for details.
asNdjson:
type: boolean
title: Send batched
description: Batch events into a single record as NDJSON
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
maxEventsPerFlush:
type: number
title: Records-per-flush limit
description: Maximum number of records to send in a single request
minimum: 1
maximum: 500
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_streamName:
type: string
description: Binds 'streamName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamName' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: OutputKinesis
OutputHoneycomb:
type: object
required:
- type
- dataset
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- honeycomb
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
dataset:
type: string
title: Dataset name
description: Name of the dataset to send events to – e.g., observability
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsApi"
description: Enter API key directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
team:
type: string
title: API key
description: Team API key where the dataset belongs
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputHoneycomb
OutputAzureEventhub:
type: object
required:
- type
- brokers
- topic
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- azure_eventhub
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
brokers:
type: array
title: Brokers
description: List of Event Hubs Kafka brokers to connect to, eg.
yourdomain.servicebus.windows.net:9093. The hostname can be found in
the host portion of the primary or secondary connection string in
Shared Access Policies.
minItems: 1
items:
type: string
minLength: 1
topic:
type: string
title: Event Hub name
description: The name of the Event Hub (Kafka Topic) to publish events. Can be
overwritten using field __topicOut.
ack:
$ref: "#/components/schemas/AcknowledgmentsOptions"
description: Control the number of required acknowledgments
format:
$ref: "#/components/schemas/RecordDataFormatOptions"
description: Format to use to serialize events before writing to the Event Hubs
Kafka brokers
maxRecordSizeKB:
type: number
minimum: 1
title: Record size limit (KB, uncompressed)
description: Maximum size of each record batch before compression. Setting
should be < message.max.bytes settings in Event Hubs brokers.
flushEventCount:
type: number
minimum: 1
maximum: 10000
title: Events-per-batch limit
description: Maximum number of events in a batch before forcing a flush
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Max record size.
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationTypeUse"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideType"
description: TLS settings (client side)
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topic:
type: string
description: Binds 'topic' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topic' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputAzureEventhub
OutputGoogleBigquery:
type: object
required:
- type
- projectId
- datasetId
- tableId
- googleAuthMethod
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- google_bigquery
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
projectId:
type: string
title: Project ID
description: Google Cloud project ID that contains the BigQuery dataset
datasetId:
type: string
title: Dataset ID
description: BigQuery dataset ID
tableId:
type: string
title: Table ID
description: BigQuery table ID
timestampColumn:
type: string
title: Timestamp column
description: Column name to write event time (`_time`) as a BigQuery TIMESTAMP.
Used for time partitioning
googleAuthMethod:
type: string
title: Google authentication method
description: Choose Auto to use Google Application Default Credentials (ADC), or
Secret to select or create a stored secret that references Google
service account credentials
enum:
- auto
- secret
x-speakeasy-enum-descriptions:
- Auto
- Secret
x-speakeasy-unknown-values: allow
secret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
flushPeriod:
title: Flush period (sec)
description: Maximum time to wait before sending a batch (when batch size limit
is not reached)
type: number
minimum: 1
maxQueueSize:
type: number
title: Queue size limit
description: Maximum number of queued batches before blocking
minimum: 1
maxRecordSizeKB:
type: number
title: Batch size limit (KB)
description: Maximum size (KB) of a single append request. BigQuery limit is 10 MB
minimum: 1
maximum: 10240
maxInProgress:
type: number
title: Concurrent request limit
description: The maximum number of in-progress API requests before backpressure
is applied
minimum: 1
maximum: 100
maxSendRetries:
type: number
title: Max send retries
description: Maximum retries per batch for retryable failures (transient,
rate-limit, unknown) before dropping. 0 (default) retries
indefinitely.
minimum: 0
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_projectId:
type: string
description: Binds 'projectId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'projectId' at runtime.
__template_datasetId:
type: string
description: Binds 'datasetId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'datasetId' at runtime.
__template_tableId:
type: string
description: Binds 'tableId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tableId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputGoogleBigquery
OutputGoogleChronicle:
type: object
required:
- type
- logFormatType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- google_chronicle
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
apiVersion:
type: string
title: API version
enum:
- v1
- v2
x-speakeasy-enum-descriptions:
- V1
- V2
description: API version
x-speakeasy-unknown-values: allow
authenticationMethod:
type: string
title: Authentication method
enum:
- manual
- secret
- serviceAccount
- serviceAccountSecret
x-speakeasy-enum-descriptions:
- API key
- API key secret
- Service account credentials
- Service account credentials secret
description: Authentication method
x-speakeasy-unknown-values: allow
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
logFormatType:
type: string
title: Send events as
description: Send events as
enum:
- unstructured
- udm
x-speakeasy-enum-descriptions:
- Unstructured
- UDM
x-speakeasy-unknown-values: allow
region:
type: string
title: Region
description: Regional endpoint to send events to
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 1024
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
extraLogTypes:
type: array
title: Custom log types
description: Custom log types. If the value "Custom" is selected in the setting
"Default log type" above, the first custom log type in this table
will be automatically selected as default log type.
items:
type: object
required:
- logType
properties:
logType:
type: string
title: Log Type
pattern: ^[A-Z0-9_]+$
description: Log Type
description:
type: string
title: Description
description: Description
logType:
type: string
title: Default log type
description: Default log type value to send to SecOps. Can be overwritten by
event field __logType.
logTextField:
type: string
title: Log text field
description: Name of the event field that contains the log text to send. If not
specified, Stream sends a JSON representation of the whole event.
customerId:
type: string
title: Customer ID
description: A unique identifier (UUID) for your Google SecOps instance. This is
provided by your Google representative and is required for API V2
authentication.
namespace:
type: string
title: Namespace
description: User-configured environment namespace to identify the data domain
the logs originated from. Use namespace as a tag to identify the
appropriate data domain for indexing and enrichment functionality.
Can be overwritten by event field __namespace.
customLabels:
type: array
title: Custom labels
description: "Custom labels to be added to every batch "
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
udmType:
type: string
title: UDM type
description: Defines the specific format for UDM events sent to Google SecOps.
This must match the type of UDM data being sent.
enum:
- entities
- logs
x-speakeasy-unknown-values: allow
apiKey:
type: string
title: API key
description: Organization's API key in Google SecOps
apiKeySecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of service account credentials (JSON keys) file downloaded
from Google Cloud. To upload a file, click the upload button at this
field's upper right.
serviceAccountCredentialsSecret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_apiVersion:
type: string
description: Binds 'apiVersion' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'apiVersion' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_customerId:
type: string
description: Binds 'customerId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'customerId' at runtime.
title: OutputGoogleChronicle
OutputGoogleCloudStorage:
type: object
required:
- type
- bucket
- endpoint
- region
- stagePath
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- google_cloud_storage
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
bucket:
type: string
title: Bucket name
description: "Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`."
region:
type: string
title: Region
description: Region where the bucket is located
endpoint:
type: string
title: Endpoint
description: Google Cloud Storage service endpoint
awsAuthenticationMethod:
type: string
title: Authentication method
enum:
- auto
- manual
- secret
x-speakeasy-enum-descriptions:
- auto
- manual
- Secret Key pair
description: Authentication method
x-speakeasy-unknown-values: allow
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
destPath:
type: string
title: Key prefix
description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`"
verifyPermissions:
type: boolean
title: Verify if bucket exists
description: Disable if you can access files within the bucket but not the
bucket itself
objectACL:
$ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcontrol"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptionsArchiveColdline"
description: Storage class to select for uploaded objects
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
awsApiKey:
type: string
title: Access key
description: HMAC access key. This value can be a constant or a JavaScript
expression, such as `${C.env.GCS_ACCESS_KEY}`.
awsSecretKey:
type: string
title: Secret
description: HMAC secret. This value can be a constant or a JavaScript
expression, such as `${C.env.GCS_SECRET}`.
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
title: OutputGoogleCloudStorage
OutputGoogleCloudLogging:
type: object
required:
- type
- logLocationType
- logLocationExpression
- logNameExpression
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- google_cloud_logging
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
logLocationType:
type: string
title: Log location type
x-speakeasy-enum-descriptions:
- Project
- Organization
- Billing Account
- Folder
enum:
- project
- organization
- billingAccount
- folder
description: Log location type
x-speakeasy-unknown-values: allow
logNameExpression:
type: string
title: Log name expression
description: JavaScript expression to compute the value of the log name. If
Validate and correct log name is enabled, invalid characters
(characters other than alphanumerics, forward-slashes, underscores,
hyphens, and periods) will be replaced with an underscore.
sanitizeLogNames:
type: boolean
title: Validate and correct log name
description: Validate and correct log name
payloadFormat:
type: string
title: Payload format
description: Format to use when sending payload. Defaults to Text.
enum:
- text
- json
x-speakeasy-enum-descriptions:
- Text
- JSON
x-speakeasy-unknown-values: allow
logLabels:
type: array
title: Log labels
description: Labels to apply to the log entry
items:
$ref: "#/components/schemas/LogLabelConfOutputGoogleCloudLogging"
resourceTypeExpression:
type: string
title: Resource type expression
description: JavaScript expression to compute the value of the managed resource
type field. Must evaluate to one of the valid values
[here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types).
Defaults to "global".
resourceTypeLabels:
type: array
title: Resource labels
description: Labels to apply to the managed resource. These must correspond to
the valid labels for the specified resource type (see
[here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)).
Otherwise, they will be dropped by Google Cloud Logging.
items:
$ref: "#/components/schemas/LogLabelConfOutputGoogleCloudLogging"
severityExpression:
type: string
title: Severity expression
description: JavaScript expression to compute the value of the severity field.
Must evaluate to one of the severity values supported by Google
Cloud Logging
[here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity)
(case insensitive). Defaults to "DEFAULT".
insertIdExpression:
type: string
title: Insert ID expression
description: JavaScript expression to compute the value of the insert ID field.
googleAuthMethod:
$ref: "#/components/schemas/GoogleAuthenticationMethodOptions"
description: Choose Auto to use Google Application Default Credentials (ADC),
Manual to enter Google service account credentials directly, or
Secret to select or create a stored secret that references Google
service account credentials.
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of service account credentials (JSON keys) file downloaded
from Google Cloud. To upload a file, click the upload button at this
field's upper right.
secret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body.
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Max number of events to include in the request body. Default is 0
(unlimited).
minimum: 0
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Max record size.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking.
minimum: 1
maximum: 32
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it.
throttleRateReqPerSec:
type: integer
title: Throttle request rate
description: Maximum number of requests to limit to per second.
maximum: 2000
requestMethodExpression:
type: string
title: Request method expression
description: A JavaScript expression that evaluates to the HTTP request method
as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
requestUrlExpression:
type: string
title: Request URL expression
description: A JavaScript expression that evaluates to the HTTP request URL as a
string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
requestSizeExpression:
type: string
title: Request size expression
description: A JavaScript expression that evaluates to the HTTP request size as
a string, in int64 format. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
statusExpression:
type: string
title: Request status expression
description: A JavaScript expression that evaluates to the HTTP request method
as a number. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
responseSizeExpression:
type: string
title: Response size expression
description: A JavaScript expression that evaluates to the HTTP response size as
a string, in int64 format. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
userAgentExpression:
type: string
title: Request user agent expression
description: A JavaScript expression that evaluates to the HTTP request user
agent as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
remoteIpExpression:
type: string
title: Remote IP expression
description: A JavaScript expression that evaluates to the HTTP request remote
IP as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
serverIpExpression:
type: string
title: Server IP expression
description: A JavaScript expression that evaluates to the HTTP request server
IP as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
refererExpression:
type: string
title: Referer expression
description: A JavaScript expression that evaluates to the HTTP request referer
as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
latencyExpression:
type: string
title: Latency expression
description: A JavaScript expression that evaluates to the HTTP request latency,
formatted as .s (for example, 1.23s). See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
cacheLookupExpression:
type: string
title: Cache lookup expression
description: A JavaScript expression that evaluates to the HTTP request cache
lookup as a boolean. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
cacheHitExpression:
type: string
title: Cache hit expression
description: A JavaScript expression that evaluates to the HTTP request cache
hit as a boolean. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
cacheValidatedExpression:
type: string
title: Cache validated with origin server expression
description: A JavaScript expression that evaluates to the HTTP request cache
validated with origin server as a boolean. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
cacheFillBytesExpression:
type: string
title: Cache fill bytes expression
description: A JavaScript expression that evaluates to the HTTP request cache
fill bytes as a string, in int64 format. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
protocolExpression:
type: string
title: Protocol expression
description: A JavaScript expression that evaluates to the HTTP request protocol
as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest)
for details.
idExpression:
type: string
title: ID expression
description: A JavaScript expression that evaluates to the log entry operation
ID as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation)
for details.
producerExpression:
type: string
title: Producer expression
description: A JavaScript expression that evaluates to the log entry operation
producer as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation)
for details.
firstExpression:
type: string
title: First expression
description: A JavaScript expression that evaluates to the log entry operation
first flag as a boolean. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation)
for details.
lastExpression:
type: string
title: Last expression
description: A JavaScript expression that evaluates to the log entry operation
last flag as a boolean. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation)
for details.
fileExpression:
type: string
title: File expression
description: A JavaScript expression that evaluates to the log entry source
location file as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation)
for details.
lineExpression:
type: string
title: Line expression
description: A JavaScript expression that evaluates to the log entry source
location line as a string, in int64 format. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation)
for details.
functionExpression:
type: string
title: Function expression
description: A JavaScript expression that evaluates to the log entry source
location function as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation)
for details.
uidExpression:
type: string
title: UID expression
description: A JavaScript expression that evaluates to the log entry log split
UID as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit)
for details.
indexExpression:
type: string
title: Index expression
description: A JavaScript expression that evaluates to the log entry log split
index as a number. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit)
for details.
totalSplitsExpression:
type: string
title: Total splits expression
description: A JavaScript expression that evaluates to the log entry log split
total splits as a number. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit)
for details.
traceExpression:
type: string
title: Trace expression
description: A JavaScript expression that evaluates to the REST resource name of
the trace being written as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry)
for details.
spanIdExpression:
type: string
title: Span ID expression
description: A JavaScript expression that evaluates to the ID of the cloud trace
span associated with the current operation in which the log is being
written as a string. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry)
for details.
traceSampledExpression:
type: string
title: Trace sampled expression
description: A JavaScript expression that evaluates to the the sampling decision
of the span associated with the log entry. See the
[documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry)
for details.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
logLocationExpression:
title: Folder ID expression
description: JavaScript expression to compute the value of the folder ID with
which log entries should be associated. If Validate and correct log
name is enabled, invalid characters (characters other than
alphanumerics, forward-slashes, underscores, hyphens, and periods)
will be replaced with an underscore.
type: string
payloadExpression:
title: Payload object expression
description: JavaScript expression to compute the value of the payload. Must
evaluate to a JavaScript object value. If an invalid value is
encountered it will result in the default value instead. Defaults to
the entire event.
type: string
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_logLocationType:
type: string
description: Binds 'logLocationType' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logLocationType' at
runtime.
__template_logNameExpression:
type: string
description: Binds 'logNameExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'logNameExpression' at runtime.
__template_payloadFormat:
type: string
description: Binds 'payloadFormat' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'payloadFormat' at runtime.
__template_resourceTypeExpression:
type: string
description: Binds 'resourceTypeExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'resourceTypeExpression' at runtime.
__template_severityExpression:
type: string
description: Binds 'severityExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'severityExpression' at runtime.
__template_insertIdExpression:
type: string
description: Binds 'insertIdExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'insertIdExpression' at runtime.
__template_traceExpression:
type: string
description: Binds 'traceExpression' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'traceExpression' at
runtime.
__template_spanIdExpression:
type: string
description: Binds 'spanIdExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'spanIdExpression' at runtime.
__template_traceSampledExpression:
type: string
description: Binds 'traceSampledExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'traceSampledExpression' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_logLocationExpression:
type: string
description: Binds 'logLocationExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'logLocationExpression' at runtime.
__template_payloadExpression:
type: string
description: Binds 'payloadExpression' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'payloadExpression' at runtime.
title: OutputGoogleCloudLogging
OutputGoogleCloudObservability:
type: object
required:
- type
- googleAuthMethod
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- google_cloud_observability
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
type: string
enum:
- grpc
description: Discriminator value.
x-speakeasy-unknown-values: allow
otlpVersion:
type: string
enum:
- 1.3.1
description: Discriminator value.
x-speakeasy-unknown-values: allow
endpoint:
type: string
title: Endpoint
description: Fixed Google Cloud Observability gRPC endpoint. All three signals
share this transport; the OTLP service path determines whether the
call lands on traces, metrics, or logs.
enum:
- telemetry.googleapis.com:443
x-speakeasy-unknown-values: allow
googleAuthMethod:
type: string
title: Google authentication method
description: Choose Auto to use Google Application Default Credentials (ADC).
Choose Secret to select or create a stored secret that references
Google service account credentials.
enum:
- auto
- secret
x-speakeasy-enum-descriptions:
- Auto
- Secret
x-speakeasy-unknown-values: allow
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."})
are serialized directly instead of being wrapped as key-value maps'
metadata:
type: array
title: Metadata
description: List of key-value pairs to send with each gRPC request. Value
supports JavaScript expressions that are evaluated just once, when
the destination gets started. To pass credentials as metadata, use
'C.Secret'.
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
dynamicHeadersEnabled:
type: boolean
title: Use dynamic metadata
description: Batch event data upon dynamic metadata (whether presented or not)
dynamicHeadersField:
type: string
title: Dynamic metadata field
description: When presented, this field which contains metadata, will be
injected into the Destination metadata and used to batch events.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body sent to Google Cloud
Observability
minimum: 1024
maximum: 10240
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often the sender should ping the peer to keep the connection open
minimum: 1
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeExtended"
description: TLS settings (client side)
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Max number of events to include in the request body. Default is 0
(unlimited). Use to keep outgoing data points within GCO request
limits. For metrics, combine with the OTLP Metrics function
batchSize.
minimum: 0
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
secret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputGoogleCloudObservability
OutputGooglePubsub:
type: object
required:
- type
- topicName
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsGooglepubsub"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
topicName:
type: string
title: Topic ID
description: ID of the topic to send events to.
createTopic:
type: boolean
title: Create topic
description: If enabled, create topic if it does not exist.
orderedDelivery:
type: boolean
title: Ordered delivery
description: If enabled, send events in the order they were added to the queue.
For this to work correctly, the process receiving events must have
ordering enabled.
region:
type: string
title: Region
description: Region to publish messages to. Select 'default' to allow Google to
auto-select the nearest region. When using ordered delivery, the
selected region must be allowed by message storage policy.
googleAuthMethod:
$ref: "#/components/schemas/GoogleAuthenticationMethodOptions"
description: Choose Auto to use Google Application Default Credentials (ADC),
Manual to enter Google service account credentials directly, or
Secret to select or create a stored secret that references Google
service account credentials.
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of service account credentials (JSON keys) file downloaded
from Google Cloud. To upload a file, click the upload button at this
field's upper right.
secret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
batchSize:
type: number
title: Batch size
minimum: 1
maximum: 10000
description: The maximum number of items the Google API should batch before it
sends them to the topic.
batchTimeout:
type: number
title: Batch timeout (ms)
minimum: 1
maximum: 100000
description: The maximum amount of time, in milliseconds, that the Google API
should wait to send a batch (if the Batch size is not reached).
maxQueueSize:
type: number
title: Queue size limit
description: Maximum number of queued batches before blocking.
minimum: 1
maxRecordSizeKB:
type: number
title: Batch size limit (KB)
description: Maximum size (KB) of batches to send.
minimum: 1
maximum: 256
flushPeriod:
title: Flush period (sec)
description: Maximum time to wait before sending a batch (when batch size limit
is not reached)
type: number
maxInProgress:
type: number
title: Concurrent request limit
description: The maximum number of in-progress API requests before backpressure
is applied.
minimum: 1
maximum: 100
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_topicName:
type: string
description: Binds 'topicName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topicName' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputGooglePubsub
OutputExabeam:
type: object
required:
- type
- bucket
- region
- endpoint
- stagePath
- collectorInstanceId
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- exabeam
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
bucket:
type: string
title: Bucket name
description: "Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`."
region:
type: string
title: Region
description: Region where the bucket is located
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
endpoint:
type: string
title: Endpoint
description: Google Cloud Storage service endpoint
objectACL:
$ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcontrol"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptionsArchiveColdline"
description: Storage class to select for uploaded objects
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
encodedConfiguration:
type: string
title: Exabeam connection string
description: Enter an encoded string containing Exabeam configurations
collectorInstanceId:
type: string
title: Collector instance ID
description: >
ID of the Exabeam Collector where data should be sent. Example:
11112222-3333-4444-5555-666677778888
awsAuthenticationMethod:
type: string
title: Authentication method
enum:
- manual
- secret
x-speakeasy-enum-descriptions:
- Manual
- Secret
description: Authentication method
x-speakeasy-unknown-values: allow
siteName:
type: string
title: Site name
description: Constant or JavaScript expression to create an Exabeam site name.
Values that aren't successfully evaluated will be treated as string
constants.
siteId:
type: string
title: Site ID
description: Exabeam site ID. If left blank, @{product} will use the value of
the Exabeam site name.
timezoneOffset:
type: string
title: Timezone offset
description: Timezone offset
hostname:
type: string
title: Hostname
description: JavaScript expression for the host from which the log was ingested
into the SIEM, evaluated per event. Static values must be quoted or
backticked (for example, 'collector-1.example.com'); unquoted text
is evaluated as JavaScript, not as a literal. To reference an event
field use an expression, such as `${host}`. Emitted as the
"hostname" metadata field; omitted when empty or not a usable
scalar.
forwarder:
type: string
title: Forwarder
description: JavaScript expression for the host that forwarded the log,
evaluated per event. Static values must be quoted or backticked (for
example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as
a literal. To reference an event field use an expression, such as
`${__forwarder}`. Emitted as the "forwarder" metadata field; omitted
when empty or not a usable scalar.
origin:
type: string
title: Origin
description: "JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object."
logtags:
type: string
title: Log tags
description: 'JavaScript expression that must resolve to an object of custom
metadata key/value pairs (searchable in Exabeam as
m_c_logtags_). Assemble the object upstream and reference it
here (example: __exabeam_logtags), or build it inline (example:
{department: dept, servertype: stype}). Evaluated per event.
Unquoted text is evaluated as JavaScript, not as a literal. Emitted
as the "logtags" metadata field; omitted when the result is not a
non-empty object.'
awsApiKey:
type: string
title: Access key
description: HMAC access key. Can be a constant or a JavaScript expression, such
as `${C.env.GCS_ACCESS_KEY}`.
awsSecretKey:
type: string
title: Secret
description: HMAC secret. Can be a constant or a JavaScript expression, such as
`${C.env.GCS_SECRET}`.
description:
type: string
title: Description
description: Optional description for this configuration.
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputExabeam
OutputKafka:
type: object
required:
- type
- brokers
- topic
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptions"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
brokers:
type: array
title: Bootstrap servers
description: Enter each Kafka bootstrap server you want to use. Specify hostname
and port, e.g., mykafkabroker:9092, or just hostname, in which case
@{product} will assign port 9092.
minItems: 1
items:
type: string
minLength: 1
topic:
type: string
title: Topic
description: The topic to publish events to. Can be overridden using the
__topicOut field.
ack:
$ref: "#/components/schemas/AcknowledgmentsOptionsAllLeader"
description: Control the number of required acknowledgments.
format:
$ref: "#/components/schemas/RecordDataFormatOptionsJsonProtobuf"
description: Format to use to serialize events before writing to Kafka.
compression:
$ref: "#/components/schemas/CompressionOptionsGzipLz4"
description: Codec to use to compress the data before sending to Kafka
maxRecordSizeKB:
type: number
minimum: 1
title: Record size limit (KB, uncompressed)
description: Maximum size of each record batch before compression. The value
must not exceed the Kafka brokers' message.max.bytes setting.
flushEventCount:
type: number
minimum: 1
maximum: 10000
title: Events-per-batch limit
description: The maximum number of events you want the Destination to allow in a
batch before forcing a flush
flushPeriodSec:
type: number
title: Flush period (sec)
description: The maximum amount of time you want the Destination to wait before
forcing a flush. Shorter intervals tend to result in smaller batches
being sent.
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationType"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
protobufLibraryId:
type: string
title: Definition set
description: Select a set of Protobuf definitions for the events you want to send
protobufEncodingId:
type: string
title: Object type
description: Select the type of object you want the Protobuf definitions to use
for event encoding
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_topic:
type: string
description: Binds 'topic' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topic' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_compression:
type: string
description: Binds 'compression' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compression' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputKafka
OutputConfluentCloud:
type: object
required:
- type
- brokers
- topic
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsConfluentcloud"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
brokers:
type: array
title: Bootstrap servers
description: List of Confluent Cloud bootstrap servers to use, such as
yourAccount.confluent.cloud:9092.
minItems: 1
items:
type: string
minLength: 1
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
topic:
type: string
title: Topic
description: The topic to publish events to. Can be overridden using the
__topicOut field.
ack:
$ref: "#/components/schemas/AcknowledgmentsOptionsAllLeader"
description: Control the number of required acknowledgments.
format:
$ref: "#/components/schemas/RecordDataFormatOptionsJsonProtobuf"
description: Format to use to serialize events before writing to Kafka.
compression:
$ref: "#/components/schemas/CompressionOptionsGzipLz4"
description: Codec to use to compress the data before sending to Kafka
maxRecordSizeKB:
type: number
minimum: 1
title: Record size limit (KB, uncompressed)
description: Maximum size of each record batch before compression. The value
must not exceed the Kafka brokers' message.max.bytes setting.
flushEventCount:
type: number
minimum: 1
maximum: 10000
title: Events-per-batch limit
description: The maximum number of events you want the Destination to allow in a
batch before forcing a flush
flushPeriodSec:
type: number
title: Flush period (sec)
description: The maximum amount of time you want the Destination to wait before
forcing a flush. Shorter intervals tend to result in smaller batches
being sent.
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
sasl:
$ref: "#/components/schemas/AuthenticationType"
description: Authentication parameters to use when connecting to brokers. Using
TLS is highly recommended.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
protobufLibraryId:
type: string
title: Definition set
description: Select a set of Protobuf definitions for the events you want to send
protobufEncodingId:
type: string
title: Object type
description: Select the type of object you want the Protobuf definitions to use
for event encoding
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_brokers:
type: string
description: Binds 'brokers' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'brokers' at runtime.
__template_topic:
type: string
description: Binds 'topic' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topic' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_compression:
type: string
description: Binds 'compression' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compression' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputConfluentCloud
OutputMsk:
type: object
required:
- type
- brokers
- topic
- region
- awsAuthenticationMethod
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsMsk"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
brokers:
type: array
title: Bootstrap servers
description: Enter each Kafka bootstrap server you want to use. Specify hostname
and port, e.g., mykafkabroker:9092, or just hostname, in which case
@{product} will assign port 9092.
minItems: 1
items:
type: string
minLength: 1
topic:
type: string
title: Topic
description: The topic to publish events to. Can be overridden using the
__topicOut field.
ack:
$ref: "#/components/schemas/AcknowledgmentsOptionsAllLeader"
description: Control the number of required acknowledgments.
format:
$ref: "#/components/schemas/RecordDataFormatOptionsJsonProtobuf"
description: Format to use to serialize events before writing to Kafka.
compression:
$ref: "#/components/schemas/CompressionOptionsGzipLz4"
description: Codec to use to compress the data before sending to Kafka
maxRecordSizeKB:
type: number
minimum: 1
title: Record size limit (KB, uncompressed)
description: Maximum size of each record batch before compression. The value
must not exceed the Kafka brokers' message.max.bytes setting.
flushEventCount:
type: number
minimum: 1
maximum: 10000
title: Events-per-batch limit
description: The maximum number of events you want the Destination to allow in a
batch before forcing a flush
flushPeriodSec:
type: number
title: Flush period (sec)
description: The maximum amount of time you want the Destination to wait before
forcing a flush. Shorter intervals tend to result in smaller batches
being sent.
kafkaSchemaRegistry:
$ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth"
description: Kafka Schema Registry Authentication
connectionTimeout:
type: number
title: Connection timeout (ms)
description: Maximum time to wait for a connection to complete successfully
minimum: 1000
maximum: 3600000
requestTimeout:
type: number
title: Request timeout (ms)
description: Maximum time to wait for Kafka to respond to a request
minimum: 1000
maximum: 3600000
maxRetries:
type: number
title: Retry limit
description: If messages are failing, you can set the maximum number of retries
as high as 100 to prevent loss of data
minimum: 0
maximum: 100
maxBackOff:
type: number
title: Backoff limit (ms)
description: The maximum wait time for a retry, in milliseconds. Default (and
minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180
seconds).
minimum: 30000
maximum: 180000
initialBackoff:
type: number
title: Initial retry interval (ms)
description: Initial value used to calculate the retry, in milliseconds. Maximum
is 600,000 ms (10 minutes).
minimum: 300
maximum: 600000
backoffRate:
type: number
title: Backoff multiplier
description: Set the backoff multiplier (2-20) to control the retry frequency
for failed messages. For faster retries, use a lower multiplier. For
slower retries with more delay between attempts, use a higher
multiplier. The multiplier is used in an exponential backoff
formula; see the Kafka
[documentation](https://kafka.js.org/docs/retry-detailed) for
details.
minimum: 2
maximum: 20
authenticationTimeout:
type: number
title: Authentication timeout (ms)
description: Maximum time to wait for Kafka to respond to an authentication
request
minimum: 1000
maximum: 3600000
reauthenticationThreshold:
type: number
title: Reauthentication threshold (ms)
description: Specifies a time window during which @{product} can reauthenticate
if needed. Creates the window measuring backward from the moment
when credentials are set to expire.
minimum: 1000
maximum: 1800000
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the MSK cluster is located
endpoint:
type: string
title: Endpoint
description: MSK cluster service endpoint. If empty, defaults to the AWS
Region-specific endpoint. Otherwise, it must point to MSK
cluster-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for MSK
description: Use Assume Role credentials to access MSK
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
protobufLibraryId:
type: string
title: Definition set
description: Select a set of Protobuf definitions for the events you want to send
protobufEncodingId:
type: string
title: Object type
description: Select the type of object you want the Protobuf definitions to use
for event encoding
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_topic:
type: string
description: Binds 'topic' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topic' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_compression:
type: string
description: Binds 'compression' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compression' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: OutputMsk
OutputElastic:
type: object
required:
- type
- index
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- elastic
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: Enable for optimal performance. Even if you have one hostname, it
can expand to multiple IPs. If disabled, consider enabling
round-robin DNS.
index:
type: string
title: Index or data stream
description: Index or data stream to send events to. Must be a JavaScript
expression (which can evaluate to a constant value), enclosed in
quotes or backticks. Can be overwritten by an event's __index field.
docType:
type: string
title: Type
description: Document type to use for events. Can be overwritten by an event's
__type field.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 102400
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
extraParams:
type: array
title: Extra parameters
items:
$ref: "#/components/schemas/SaslExtensionConfInputKafka"
description: Extra parameters
auth:
$ref: "#/components/schemas/AuthTypeTemplatemanualApiKeyAuthType"
elasticVersion:
type: string
title: Elastic version
description: Optional Elasticsearch version, used to format events. If not
specified, will auto-discover version.
enum:
- "auto"
- "6"
- "7"
x-speakeasy-enum-descriptions:
- Auto
- 6.x
- 7.x
x-speakeasy-unknown-values: allow
elasticPipeline:
type: string
title: Elastic pipeline
description: Optional Elasticsearch destination pipeline
includeDocId:
type: boolean
title: Include document _id
description: Include the `document_id` field when sending events to an Elastic
TSDS (time series data stream)
writeAction:
type: string
title: Write action
description: Action to use when writing events. Must be set to `Create` when
writing to a data stream.
enum:
- index
- create
x-speakeasy-enum-descriptions:
- Index
- Create
x-speakeasy-unknown-values: allow
retryPartialErrors:
type: boolean
title: Retry partial errors
description: Retry failed events when a bulk request to Elastic is successful,
but the response body returns an error for one or more events in the
batch
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
url:
type: string
title: Bulk API URL or Cloud ID
description: "The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: Bulk API URLs
description: Bulk API URLs
minItems: 1
items:
type: object
required:
- url
properties:
url:
type: string
title: URL
description: "The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk"
weight:
type: number
title: Load Weight
description: Assign a weight (>0) to each endpoint to indicate its
traffic-handling capability
minimum: 0
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_index:
type: string
description: Binds 'index' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'index' at runtime.
__template_docType:
type: string
description: Binds 'docType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'docType' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_elasticPipeline:
type: string
description: Binds 'elasticPipeline' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'elasticPipeline' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
title: OutputElastic
OutputElasticCloud:
type: object
required:
- type
- url
- index
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- elastic_cloud
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Cloud ID
description: Enter Cloud ID of the Elastic Cloud environment to send events to
index:
type: string
title: Data stream or index
description: Data stream or index to send events to. Must be a JavaScript
expression (which can evaluate to a constant value), enclosed in
quotes or backticks. Can be overwritten by an event's __index field.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 102400
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
extraParams:
type: array
title: Extra parameters
description: Extra parameters to use in HTTP requests
items:
$ref: "#/components/schemas/SaslExtensionConfInputKafka"
auth:
$ref: "#/components/schemas/AuthTypeTemplatemanualApiKeyAuthType"
elasticPipeline:
type: string
title: Elastic pipeline
description: Optional Elastic Cloud Destination pipeline
includeDocId:
type: boolean
title: Include document _id
description: Include the `document_id` field when sending events to an Elastic
TSDS (time series data stream)
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_index:
type: string
description: Binds 'index' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'index' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_elasticPipeline:
type: string
description: Binds 'elasticPipeline' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'elasticPipeline' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputElasticCloud
OutputNewrelic:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- newrelic
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
region:
$ref: "#/components/schemas/RegionOptions"
description: Which New Relic region endpoint to use.
logType:
type: string
title: Log type
description: "Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value."
messageField:
type: string
title: Log message field
description: Name of field to send as log message value. If not present, event
will be serialized and sent as JSON.
metadata:
type: array
title: Fields
description: Fields to add to events from this input
maxItems: 4
items:
type: object
required:
- name
- value
properties:
name:
type: string
title: Field Name
description: Name of the metadata field.
enum:
- service
- hostname
- timestamp
- auditId
x-speakeasy-unknown-values: allow
value:
type: string
title: Value
description: JavaScript expression to compute field's value, enclosed in quotes
or backticks. (Can evaluate to a constant.)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 1024
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsApi"
description: Enter API key directly, or select a stored secret
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
customUrl:
type: string
pattern: ^https?://.*
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
apiKey:
type: string
title: API key
description: New Relic API key. Can be overridden using __newRelic_apiKey field.
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_logType:
type: string
description: Binds 'logType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logType' at runtime.
__template_messageField:
type: string
description: Binds 'messageField' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'messageField' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
required:
- type
title: OutputNewrelic
OutputNewrelicEvents:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- newrelic_events
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
region:
$ref: "#/components/schemas/RegionOptions"
description: Which New Relic region endpoint to use.
accountId:
type: string
title: Account ID
description: New Relic account ID
eventType:
type: string
title: Event type
description: Default New Relic eventType to use when event type is not present.
For more information, see the [New Relic eventType
documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 1024
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsApi"
description: Enter API key directly, or select a stored secret
description:
type: string
title: Description
description: Optional description for this configuration.
customUrl:
type: string
pattern: ^https?://.*
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
apiKey:
type: string
title: API key
description: New Relic API key. Can be overridden using __newRelic_apiKey field.
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_accountId:
type: string
description: Binds 'accountId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'accountId' at runtime.
__template_eventType:
type: string
description: Binds 'eventType' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'eventType' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_customUrl:
type: string
description: Binds 'customUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'customUrl' at runtime.
required:
- type
- accountId
- eventType
title: OutputNewrelicEvents
OutputInfluxdb:
type: object
required:
- type
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- influxdb
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Write API URL
description: URL of an InfluxDB cluster to send events to, e.g.,
http://localhost:8086/write
pattern: ^https?://.*
useV2API:
type: boolean
title: Use v2 API
description: The v2 API can be enabled with InfluxDB versions 1.8 and later.
timestampPrecision:
type: string
title: Timestamp precision
description: Sets the precision for the supplied Unix time values. Defaults to
milliseconds.
enum:
- ns
- u
- ms
- s
- m
- h
x-speakeasy-enum-descriptions:
- Nanoseconds
- Microseconds
- Milliseconds
- Seconds
- Minutes
- Hours
x-speakeasy-unknown-values: allow
dynamicValueFieldName:
type: boolean
title: Dynamic value fields
description: Enabling this will pull the value field from the metric name. E,g,
'db.query.user' will use 'db.query' as the measurement and 'user' as
the value field.
valueFieldName:
type: string
title: Value field name
description: Name of the field in which to store the metric when sending to
InfluxDB. If dynamic generation is enabled and fails, this will be
used as a fallback.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 51200
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
type: string
title: Authentication type
description: InfluxDB authentication type
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
database:
type: string
title: Database
description: Database to write to.
bucket:
type: string
title: Bucket
description: Bucket to write to.
org:
type: string
title: Organization
description: Organization ID for this bucket.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_database:
type: string
description: Binds 'database' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'database' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
title: OutputInfluxdb
OutputCloudwatch:
type: object
required:
- type
- logGroupName
- logStreamName
- region
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- cloudwatch
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
logGroupName:
type: string
title: Log group name
description: CloudWatch log group to associate events with
logStreamName:
type: string
title: Log stream prefix
description: "Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId"
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the CloudWatchLogs is located
endpoint:
type: string
title: Endpoint
description: CloudWatchLogs service endpoint. If empty, defaults to the AWS
Region-specific endpoint. Otherwise, it must point to
CloudWatchLogs-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for CloudWatchLogs
description: Use Assume Role credentials to access CloudWatchLogs
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
maxQueueSize:
type: number
title: Queue size limit
description: Maximum number of queued batches before blocking
minimum: 1
maximum: 32
maxRecordSizeKB:
type: number
title: Record size limit (KB, uncompressed)
description: Maximum size (KB) of each individual record before compression. For
non compressible data 1MB is the max recommended size
minimum: 1
maximum: 10240
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Max record size.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_logGroupName:
type: string
description: Binds 'logGroupName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logGroupName' at runtime.
__template_logStreamName:
type: string
description: Binds 'logStreamName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logStreamName' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: OutputCloudwatch
OutputMinio:
type: object
required:
- type
- bucket
- stagePath
- endpoint
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- minio
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
bucket:
type: string
title: MinIO bucket name
description: "Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
region:
type: string
title: Region
description: Region where the MinIO bucket is located
destPath:
type: string
title: Key prefix
description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`"
maxConcurrentFileParts:
type: number
title: Concurrent file parts upload limit
description: Maximum number of parts to upload in parallel per file. Minimum
part size is 5MB.
minimum: 1
maximum: 10
verifyPermissions:
type: boolean
title: Verify if bucket exists
description: Disable if you can access files within the bucket but not the
bucket itself
maxClosingFilesToBackpressure:
type: number
title: Staging file limit
description: Maximum number of files that can be waiting for upload before
backpressure is applied
minimum: 10
maximum: 4200
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 86400
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 86400
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
awsSecretKey:
type: string
title: Secret key
description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)"
endpoint:
type: string
title: MinIO endpoint
description: MinIO service url (e.g. http://minioHost:9000)
pattern: ^https?://.*
objectACL:
$ref: "#/components/schemas/ObjectAclOptions"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptionsReducedredundancyStandard"
description: Storage class to select for uploaded objects
serverSideEncryption:
$ref: "#/components/schemas/ServerSideEncryptionForUploadedObjectsOptionsAes256"
description: Server-side encryption to use for uploaded objects
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: This value can be a constant or a JavaScript expression
(`${C.env.SOME_ACCESS_KEY}`)
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_serverSideEncryption:
type: string
description: Binds 'serverSideEncryption' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serverSideEncryption' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputMinio
OutputStatsd:
type: object
required:
- type
- protocol
- host
- port
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- statsd
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
$ref: "#/components/schemas/DestinationProtocolOptions"
description: Protocol to use when communicating with the destination.
host:
type: string
title: Host
description: The hostname of the destination.
port:
type: number
title: Port
minimum: 1
maximum: 65535
description: Destination port.
mtu:
type: number
minimum: 1
maximum: 65535
title: Record size limit (bytes)
description: When protocol is UDP, specifies the maximum size of packets sent to
the destination. Also known as the MTU for the network path to the
destination system.
flushPeriodSec:
type: number
title: Flush period (sec)
description: When protocol is TCP, specifies how often buffers should be
flushed, resulting in records sent to the destination.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if the destination is an IP address. A value of 0 means
every batch sent will incur a DNS lookup.
description:
type: string
title: Description
description: Optional description for this configuration.
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputStatsd
OutputStatsdExt:
type: object
required:
- type
- protocol
- host
- port
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- statsd_ext
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
$ref: "#/components/schemas/DestinationProtocolOptions"
description: Protocol to use when communicating with the destination.
host:
type: string
title: Host
description: The hostname of the destination.
port:
type: number
title: Port
minimum: 1
maximum: 65535
description: Destination port.
mtu:
type: number
minimum: 1
maximum: 65535
title: Record size limit (bytes)
description: When protocol is UDP, specifies the maximum size of packets sent to
the destination. Also known as the MTU for the network path to the
destination system.
flushPeriodSec:
type: number
title: Flush period (sec)
description: When protocol is TCP, specifies how often buffers should be
flushed, resulting in records sent to the destination.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if the destination is an IP address. A value of 0 means
every batch sent will incur a DNS lookup.
description:
type: string
title: Description
description: Optional description for this configuration.
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputStatsdExt
OutputGraphite:
type: object
required:
- type
- protocol
- host
- port
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- graphite
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
$ref: "#/components/schemas/DestinationProtocolOptions"
description: Protocol to use when communicating with the destination.
host:
type: string
title: Host
description: The hostname of the destination.
port:
type: number
title: Port
minimum: 1
maximum: 65535
description: Destination port.
mtu:
type: number
minimum: 1
maximum: 65535
title: Record size limit (bytes)
description: When protocol is UDP, specifies the maximum size of packets sent to
the destination. Also known as the MTU for the network path to the
destination system.
flushPeriodSec:
type: number
title: Flush period (sec)
description: When protocol is TCP, specifies how often buffers should be
flushed, resulting in records sent to the destination.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if the destination is an IP address. A value of 0 means
every batch sent will incur a DNS lookup.
description:
type: string
title: Description
description: Optional description for this configuration.
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputGraphite
OutputRouter:
type: object
required:
- type
- rules
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- router
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
reportBranchMetrics:
type: boolean
title: Report Branch Metrics
description: Report per-rule event counts and percentages as internal metrics
(router.out_events, router.out_events_pct, router.in_events,
router.unmatched_events, router.unmatched_events_pct). Adds metric
series per rule.
rules:
type: array
title: Rules
description: Event routing rules
minItems: 1
items:
type: object
required:
- filter
- output
properties:
filter:
type: string
title: Filter Expression
description: JavaScript expression to select events to send to output
output:
type: string
title: Output
description: Output to send matching events to
description:
type: string
title: Description
description: Description of this rule's purpose
final:
type: boolean
title: Final
description: Flag to control whether to stop the event from being checked
against other rules
description:
type: string
title: Description
description: Optional description for this configuration.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: OutputRouter
OutputSns:
type: object
required:
- type
- topicArn
- messageGroupId
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- sns
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
topicArn:
type: string
title: Topic ARN
description: "The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`"
messageGroupId:
type: string
title: Message Group ID
description: "Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
maxRetries:
type: number
title: Maximum number of retries
description: Maximum number of retries before the output returns an error. Note
that not all errors are retryable. The retries use an exponential
backoff policy.
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the SNS is located
endpoint:
type: string
title: Endpoint
description: SNS service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to SNS-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for SNS
description: Use Assume Role credentials to access SNS
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_topicArn:
type: string
description: Binds 'topicArn' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'topicArn' at runtime.
__template_messageGroupId:
type: string
description: Binds 'messageGroupId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'messageGroupId' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: OutputSns
OutputSqs:
type: object
required:
- type
- queueName
- queueType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsSqs"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
queueName:
type: string
title: Queue Name
description: "The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`."
queueType:
title: Queue Type
type: string
description: The queue type used (or created). Defaults to Standard.
enum:
- standard
- fifo
x-speakeasy-enum-descriptions:
- Standard
- FIFO
x-speakeasy-unknown-values: allow
awsAccountId:
title: AWS account ID
description: SQS queue owner's AWS account ID. Leave empty if SQS queue is in
same AWS account.
type: string
messageGroupId:
type: string
title: Message Group ID
description: This parameter applies only to FIFO queues. The tag that specifies
that a message belongs to a specific message group. Messages that
belong to the same message group are processed in a FIFO manner. Use
event field __messageGroupId to override this value.
createQueue:
type: boolean
title: Create Queue
description: Create queue if it does not exist.
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: AWS Region where the SQS queue is located. Required, unless the
Queue entry is a URL or ARN that includes a Region.
endpoint:
type: string
title: Endpoint
description: SQS service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to SQS-compatible endpoint.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
enableAssumeRole:
type: boolean
title: Enable for SQS
description: Use Assume Role credentials to access SQS
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
maxQueueSize:
type: number
title: Queue size limit
description: Maximum number of queued batches before blocking.
minimum: 1
maxRecordSizeKB:
type: number
title: Record size limit (KB)
description: Maximum size (KB) of batches to send. Per the SQS spec, the max
allowed value is 256 KB.
minimum: 1
maximum: 256
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Max record size.
maxInProgress:
type: number
title: Concurrent request limit
description: The maximum number of in-progress API requests before backpressure
is applied.
minimum: 1
maximum: 100
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: Access key
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_queueName:
type: string
description: Binds 'queueName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueName' at runtime.
__template_queueType:
type: string
description: Binds 'queueType' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'queueType' at runtime.
__template_awsAccountId:
type: string
description: Binds 'awsAccountId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsAccountId' at runtime.
__template_messageGroupId:
type: string
description: Binds 'messageGroupId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'messageGroupId' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
title: OutputSqs
OutputSnmp:
type: object
required:
- type
- hosts
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsSnmp"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
hosts:
type: array
title: SNMP Trap Destinations
description: One or more SNMP destinations to forward traps to
minItems: 1
items:
type: object
required:
- host
- port
properties:
host:
type: string
title: Address
description: Destination host
port:
type: number
title: Port
maximum: 65535
description: Destination port, default is 162
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if all destinations are IP addresses. A value of 0 means
every trap sent will incur a DNS lookup.
enableIpSpoofing:
title: Enable Source IP spoofing
description: Send SNMP Trap traffic using the original event's Source IP and
port. To enable this, you must install the external `udp-sender`
helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant
it the `CAP_NET_RAW` capability.
type: boolean
description:
type: string
title: Description
description: Optional description for this configuration.
maxRecordSize:
type: number
title: Maximum transmission unit (MTU)
minimum: 1
description: MTU in bytes. The actual maximum SNMP Trap payload size will be MTU
minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6).
Payloads exceeding this limit will be dropped.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: OutputSnmp
OutputSumoLogic:
type: object
required:
- type
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- sumo_logic
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: API URL
description: Sumo Logic HTTP collector URL to which events should be sent
pattern: ^https?://.*
customSource:
type: string
title: Custom source name
description: Override the source name configured on the Sumo Logic HTTP
collector. This can also be overridden at the event level with the
__sourceName field.
customCategory:
type: string
title: Custom source category
description: Override the source category configured on the Sumo Logic HTTP
collector. This can also be overridden at the event level with the
__sourceCategory field.
format:
type: string
title: Data format
description: Preserve the raw event format instead of JSONifying it
enum:
- json
- raw
x-speakeasy-enum-descriptions:
- JSON
- Raw
x-speakeasy-unknown-values: allow
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 1024
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputSumoLogic
OutputDatadog:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- datadog
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
contentType:
type: string
title: Send logs as
description: The content type to use when sending logs
enum:
- text
- json
x-speakeasy-enum-descriptions:
- text/plain
- application/json
x-speakeasy-unknown-values: allow
message:
type: string
title: Message field
description: Name of the event field that contains the message to send. If not
specified, Stream sends a JSON representation of the whole event.
source:
type: string
title: Source
description: Name of the source to send with logs. When you send logs as JSON
objects, the event's 'source' field (if set) will override this
value.
host:
type: string
title: Host
description: Name of the host to send with logs. When you send logs as JSON
objects, the event's 'host' field (if set) will override this value.
service:
type: string
title: Service
description: Name of the service to send with logs. When you send logs as JSON
objects, the event's '__service' field (if set) will override this
value.
tags:
type: array
title: Datadog tags
description: List of tags to send with logs, such as 'env:prod' and
'env_staging:east'
items:
type: string
batchByTags:
type: boolean
title: Batch by tags
description: Batch events by API key and the ddtags field on the event. When
disabled, batches events only by API key. If incoming events have
high cardinality in the ddtags field, disabling this setting may
improve Destination performance.
allowApiKeyFromEvents:
type: boolean
title: Allow API key from events
description: Allow API key to be set from the event's '__agent_api_key' field
severity:
type: string
title: Severity
description: Default value for message severity. When you send logs as JSON
objects, the event's '__severity' field (if set) will override this
value.
enum:
- emergency
- alert
- critical
- error
- warning
- notice
- info
- debug
x-speakeasy-enum-descriptions:
- emergency
- alert
- critical
- error
- warning
- notice
- info
- debug
x-speakeasy-unknown-values: allow
site:
type: string
title: Datadog site
description: Datadog site to which events should be sent
enum:
- us
- us3
- us5
- eu
- fed1
- ap1
- custom
x-speakeasy-enum-descriptions:
- US
- US3
- US5
- Europe
- US1-FED
- AP1
- Custom
x-speakeasy-unknown-values: allow
sendCountersAsCount:
type: boolean
title: Send counter metrics as 'count'
description: If not enabled, Datadog will transform 'counter' metrics to
'gauge'. [Learn more about Datadog metrics
types.](https://docs.datadoghq.com/metrics/types/?tab=count)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsApi"
description: Enter API key directly, or select a stored secret
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
customUrl:
type: string
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
apiKey:
type: string
title: API key
description: Organization's API key in Datadog
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_tags:
type: string
description: Binds 'tags' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
required:
- type
title: OutputDatadog
OutputGrafanaCloud:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- grafana_cloud
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards. These fields are added as dimensions and labels to
generated metrics and logs, respectively.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
lokiUrl:
type: string
title: Loki URL
description: The endpoint to send logs to, such as
https://logs-prod-us-central1.grafana.net
pattern: ^https?://
prometheusUrl:
type: string
title: Prometheus URL
description: The remote_write endpoint to send Prometheus metrics to, such as
https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push
pattern: ^https?://
message:
type: string
title: Logs message field
description: Name of the event field that contains the message to send. If not
specified, Stream sends a JSON representation of the whole event.
messageFormat:
$ref: "#/components/schemas/MessageFormatOptions"
description: Format to use when sending logs to Loki (Protobuf or JSON)
labels:
type: array
title: Logs labels
description: "List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'"
minItems: 0
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
metricRenameExpr:
type: string
title: Metrics renaming expression
description: JavaScript expression that can be used to rename metrics. For
example, name.replace(/\./g, '_') will replace all '.' characters in
a metric's name with the supported '_' character. Use the 'name'
global variable to access the metric's name. You can access event
fields' values via __e..
prometheusAuth:
$ref: "#/components/schemas/PrometheusAuthType"
lokiAuth:
$ref: "#/components/schemas/PrometheusAuthType"
concurrency:
type: number
title: Request concurrency
description: "Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order."
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: "Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order."
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: "Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order."
minimum: 0
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: "Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order."
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
type: boolean
title: Compress
description: Compress the payload body before sending. Applies only to JSON
payloads; the Protobuf variant for both Prometheus and Loki are
snappy-compressed by default.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_lokiUrl:
type: string
description: Binds 'lokiUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'lokiUrl' at runtime.
__template_prometheusUrl:
type: string
description: Binds 'prometheusUrl' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'prometheusUrl' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
anyOf:
- required:
- lokiUrl
- required:
- prometheusUrl
required:
- type
title: OutputGrafanaCloud
OutputLoki:
type: object
required:
- type
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- loki
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards. These fields are added as labels to generated logs.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Loki URL
description: The endpoint to send logs to
pattern: ^https?://.*
message:
type: string
title: Logs message field
description: Name of the event field that contains the message to send. If not
specified, Stream sends a JSON representation of the whole event.
messageFormat:
$ref: "#/components/schemas/MessageFormatOptions"
description: Format to use when sending logs to Loki (Protobuf or JSON)
labels:
type: array
title: Logs labels
description: "List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'"
minItems: 0
items:
$ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret"
authType:
$ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret"
description: Authentication type
concurrency:
type: number
title: Request concurrency
description: "Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order."
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: "Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order."
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: "Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order."
minimum: 0
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: "Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order."
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
enableDynamicHeaders:
type: boolean
title: Enable dynamic headers
description: Add per-event HTTP headers from the __headers field to outgoing
requests. Events with different headers are batched and sent
separately.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
token:
type: string
title: Auth token
description: "Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :"
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
username:
type: string
title: Username
description: Username for authentication
password:
type: string
title: Password
description: Password (API key in Grafana Cloud domain) for authentication
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputLoki
OutputAmazonManagedPrometheus:
type: object
required:
- type
- url
- region
- awsAuthenticationMethod
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- amazon_managed_prometheus
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards. These fields are added as dimensions to generated
metrics.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Remote Write URL
description: The Amazon Managed Service for Prometheus remote_write endpoint
pattern: ^https://aps-workspaces(?:-fips)?\.([a-z0-9]+(?:-[a-z0-9]+)*)\.(?:amazonaws\.com|api\.aws)/workspaces/ws-[A-Za-z0-9-]+/api/v1/remote_write$
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsAutoSecret"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecretKey:
type: string
title: Secret key
description: Secret key
region:
type: string
title: Region
description: Region where the AMSP is located
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
enableAssumeRole:
type: boolean
title: Enable for AMSP
description: Use Assume Role credentials to access AMSP
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
metricRenameExpr:
type: string
title: Metric renaming expression
description: JavaScript expression that can be used to rename metrics. For
example, name.replace(/\./g, '_') will replace all '.' characters in
a metric's name with the supported '_' character. Use the 'name'
global variable to access the metric's name. You can access event
fields' values via __e..
sendMetadata:
type: boolean
title: Send metadata
description: Generate and send metadata (`type` and `metricFamilyName`) requests
usePrometheusHistogramBucketSuffix:
type: boolean
title: Use `_bucket` suffix for histogram buckets
description: Serialize histogram bucket series as `_bucket` to match
Prometheus histogram naming convention
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum uncompressed size, in KB, of the request body. The 1 MB cap
is intentional and protects against data that compresses poorly,
since oversized requests fail with a non-retryable 413.
minimum: 1
maximum: 1024
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events. SigV4-managed headers and the
Prometheus remote-write protocol version header are generated by
this Destination and cannot be configured here.
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
metricsFlushPeriodSec:
type: number
title: Metadata flush period (sec)
description: How frequently metrics metadata is sent out. Value cannot be
smaller than the base Flush period set above.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputAmazonManagedPrometheus
OutputPrometheus:
type: object
required:
- type
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsPrometheus"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards. These fields are added as dimensions to generated
metrics.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Remote Write URL
description: The endpoint to send metrics to
pattern: ^https?://.*
metricRenameExpr:
type: string
title: Metric renaming expression
description: JavaScript expression that can be used to rename metrics. For
example, name.replace(/\./g, '_') will replace all '.' characters in
a metric's name with the supported '_' character. Use the 'name'
global variable to access the metric's name. You can access event
fields' values via __e..
sendMetadata:
type: boolean
title: Send metadata
description: Generate and send metadata (`type` and `metricFamilyName`) requests
usePrometheusHistogramBucketSuffix:
type: boolean
title: Use `_bucket` suffix for histogram buckets
description: Serialize histogram bucket series as `_bucket` to match
Prometheus histogram naming convention
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
type: string
title: Authentication type
description: Remote Write authentication type
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
- aws_sigv4
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
- AWS Signature v4
x-speakeasy-unknown-values: allow
description:
type: string
title: Description
description: Optional description for this configuration.
metricsFlushPeriodSec:
type: number
title: Metadata flush period (sec)
description: How frequently metrics metadata is sent out. Value cannot be
smaller than the base Flush period set above.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsAutoSecret"
description: AWS authentication method. Choose Auto to use IAM roles.
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
region:
type: string
title: Region
description: AWS region used to sign Remote Write requests
awsService:
type: string
title: AWS service ID
description: ID used to sign Remote Write requests (for example, `aps` for
Amazon Managed Service for Prometheus)
pattern: ^[a-z][a-z0-9]*(-[a-z0-9]+)*$
enableAssumeRole:
type: boolean
title: Enable for Prometheus
description: Use Assume Role credentials to access Prometheus
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_awsService:
type: string
description: Binds 'awsService' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsService' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
title: OutputPrometheus
OutputRing:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- ring
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
format:
type: string
title: Data format
description: Format of the output data.
enum:
- json
- raw
x-speakeasy-unknown-values: allow
partitionExpr:
type: string
title: Partitioning expression
description: JS expression to define how files are partitioned and organized. If
left blank, Cribl Stream will fallback on event.__partition.
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted."
pattern: ^\d+\s*(?:\w{2})?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/DataCompressionFormatOptionsPersistence"
description: Data compression format
destPath:
type: string
title: Path location
description: Path to use to write metrics. Defaults to $CRIBL_HOME/state/
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
required:
- type
title: OutputRing
OutputOpenTelemetry:
type: object
required:
- type
- endpoint
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- open_telemetry
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
$ref: "#/components/schemas/ProtocolOptions"
description: Select a transport option for OpenTelemetry
endpoint:
type: string
title: Endpoint
description: The endpoint where OTel events will be sent. Enter any valid URL or
an IP address (IPv4 or IPv6; enclose IPv6 addresses in square
brackets). Unspecified ports will default to 4317, unless the
endpoint is an HTTPS-based URL or TLS is enabled, in which case 443
will be used.
otlpVersion:
type: string
title: OTLP version
description: The version of OTLP Protobuf definitions to use when structuring
data to send
enum:
- 0.10.0
- 1.3.1
x-speakeasy-enum-descriptions:
- 0.10.0
- 1.3.1
x-speakeasy-unknown-values: allow
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."})
are serialized directly instead of being wrapped as key-value maps'
compress:
$ref: "#/components/schemas/CompressionOptionsDeflateGzip"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpCompress:
$ref: "#/components/schemas/CompressionOptionsMessages"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
authType:
type: string
title: Authentication type
enum:
- none
- basic
- credentialsSecret
- token
- textSecret
- oauthSecret
x-speakeasy-enum-descriptions:
- None
- Basic
- Basic (credentials secret)
- Token
- Token (text secret)
- OAuth (text secret)
description: Authentication type
x-speakeasy-unknown-values: allow
httpTracesEndpointOverride:
type: string
title: Traces endpoint override
description: If you want to send traces to the default `{endpoint}/v1/traces`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpMetricsEndpointOverride:
type: string
title: Metrics endpoint override
description: If you want to send metrics to the default `{endpoint}/v1/metrics`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpLogsEndpointOverride:
type: string
title: Logs endpoint override
description: If you want to send logs to the default `{endpoint}/v1/logs`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
metadata:
type: array
title: Metadata
description: List of key-value pairs to send with each gRPC request. Value
supports JavaScript expressions that are evaluated just once, when
the destination gets started. To pass credentials as metadata, use
'C.Secret'.
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
dynamicHeadersEnabled:
type: boolean
title: Use dynamic metadata
description: Batch event data upon dynamic metadata (whether presented or not)
dynamicHeadersField:
type: string
title: Dynamic metadata field
description: When presented, this field which contains metadata, will be
injected into the Destination metadata and used to batch events.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often the sender should ping the peer to keep the connection open
minimum: 1
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
token:
type: string
title: Token
description: Bearer token to include in the authorization header
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
loginUrl:
type: string
title: Login URL
description: URL for OAuth
pattern: ^https?://.*
secretParamName:
type: string
title: OAuth Secret parameter name
description: Secret parameter name to pass in request body
oauthTextSecret:
type: string
title: OAuth secret (text secret)
description: Select or create a stored text secret for the OAuth secret
parameter value to pass in request body
tokenAttributeName:
type: string
title: Token attribute name
description: Name of the auth token attribute in the OAuth response. Can be
top-level (e.g., 'token'); or nested, using a period (e.g.,
'data.token').
authHeaderExpr:
type: string
title: Authorize expression
description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`."
tokenTimeoutSecs:
type: number
title: Refresh interval (secs.)
description: How often the OAuth token should be refreshed.
minimum: 1
maximum: 300000
oauthParams:
type: array
title: OAuth parameters
description: Additional parameters to send in the OAuth login request.
@{product} will combine the secret with these parameters, and will
send the URL-encoded result in a POST request to the endpoint
specified in the 'Login URL'. We'll automatically add the
content-type header 'application/x-www-form-urlencoded' when sending
this request.
items:
$ref: "#/components/schemas/OauthParamConfInputServicenowTable"
oauthHeaders:
type: array
title: OAuth headers
description: Additional headers to send in the OAuth login request. @{product}
will automatically add the content-type header
'application/x-www-form-urlencoded' when sending this request.
items:
$ref: "#/components/schemas/OauthHeaderConfInputServicenowTable"
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeExtended"
description: TLS settings (client side)
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
title: OutputOpenTelemetry
OutputServiceNow:
type: object
required:
- type
- endpoint
- protocol
- otlpVersion
- tokenSecret
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- service_now
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
endpoint:
type: string
title: Endpoint
description: The endpoint where ServiceNow events will be sent. Enter any valid
URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square
brackets)
tokenSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
authTokenName:
type: string
title: Auth token name
description: Auth token name
otlpVersion:
$ref: "#/components/schemas/OtlpVersionOptions"
description: The version of OTLP Protobuf definitions to use when structuring
data to send
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
protocol:
$ref: "#/components/schemas/ProtocolOptions"
description: Select a transport option for OpenTelemetry
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."})
are serialized directly instead of being wrapped as key-value maps'
compress:
$ref: "#/components/schemas/CompressionOptionsDeflateGzip"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpCompress:
$ref: "#/components/schemas/CompressionOptionsMessages"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpTracesEndpointOverride:
type: string
title: Traces endpoint override
description: If you want to send traces to the default `{endpoint}/v1/traces`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpMetricsEndpointOverride:
type: string
title: Metrics endpoint override
description: If you want to send metrics to the default `{endpoint}/v1/metrics`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpLogsEndpointOverride:
type: string
title: Logs endpoint override
description: If you want to send logs to the default `{endpoint}/v1/logs`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
metadata:
type: array
title: Metadata
description: List of key-value pairs to send with each gRPC request. Value
supports JavaScript expressions that are evaluated just once, when
the destination gets started. To pass credentials as metadata, use
'C.Secret'.
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
dynamicHeadersEnabled:
type: boolean
title: Use dynamic metadata
description: Batch event data upon dynamic metadata (whether presented or not)
dynamicHeadersField:
type: string
title: Dynamic metadata field
description: When presented, this field which contains metadata, will be
injected into the Destination metadata and used to batch events.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often the sender should ping the peer to keep the connection open
minimum: 1
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeExtended"
description: TLS settings (client side)
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputServiceNow
OutputDataset:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- dataset
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
messageField:
type: string
title: Message field
description: Name of the event field that contains the message or attributes to
send. If not specified, all of the event's non-internal fields will
be sent as attributes.
excludeFields:
type: array
title: Exclude fields
description: Fields to exclude from the event if the Message field is either
unspecified or refers to an object. Ignored if the Message field is
a string. If empty, we send all non-internal fields.
items:
type: string
serverHostField:
type: string
title: Server/host field
description: Name of the event field that contains the `serverHost` identifier.
If not specified, defaults to `cribl_`.
timestampField:
type: string
title: Timestamp field
description: Name of the event field that contains the timestamp. If not
specified, defaults to `ts`, `_time`, or `Date.now()`, in that
order.
defaultSeverity:
type: string
title: Severity
description: Default value for event severity. If the `sev` or `__severity`
fields are set on an event, the first one matching will override
this value.
enum:
- finest
- finer
- fine
- info
- warning
- error
- fatal
x-speakeasy-enum-descriptions:
- 0 - finest
- 1 - finer
- 2 - fine
- 3 - info
- 4 - warning
- 5 - error
- 6 - fatal
x-speakeasy-unknown-values: allow
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
site:
type: string
title: DataSet site
description: DataSet site to which events should be sent
enum:
- us
- eu
- custom
x-speakeasy-enum-descriptions:
- US
- Europe
- Custom
x-speakeasy-unknown-values: allow
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 6144
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsApi"
description: Enter API key directly, or select a stored secret
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
customUrl:
type: string
pattern: ^https?://.*
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
apiKey:
type: string
title: API key
description: A 'Log Write Access' API key for the DataSet account
textSecret:
type: string
title: API key (text secret)
description: Select or create a stored text secret
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_customUrl:
type: string
description: Binds 'customUrl' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'customUrl' at runtime.
required:
- type
title: OutputDataset
OutputCriblTcp:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsCribltcp"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: Use load-balanced destinations
compression:
$ref: "#/components/schemas/CompressionOptionsGzipNone"
description: Codec to use to compress the data before sending
logFailedRequests:
type: boolean
title: Log failed requests to disk
description: Use to troubleshoot issues with sending data
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
writeTimeout:
type: number
title: Write timeout
description: Amount of time (milliseconds) to wait for a write to complete
before assuming connection is dead
tokenTTLMinutes:
type: number
title: Auth Token TTL minutes
minimum: 1
maximum: 60
description: The number of minutes before the internally generated
authentication token expires, valid values between 1 and 60
authTokens:
type: array
title: Connected environment tokens
description: Shared secrets to be used by connected environments to authorize
connections. These tokens should also be installed in Cribl TCP
Source in Cribl.Cloud.
items:
$ref: "#/components/schemas/AuthTokenConfInputCriblTcp"
excludeFields:
type: array
title: Exclude fields
description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported."
items:
type: string
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
host:
type: string
title: Address
description: The hostname of the receiver
port:
type: number
title: Port
maximum: 65535
description: The port to connect to on the provided host
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
hosts:
type: array
title: Destinations
description: Set of hosts to load-balance data to
minItems: 1
items:
$ref: "#/components/schemas/HostConfOutputSyslog"
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
maxConcurrentSenders:
type: number
minimum: 0
title: Connection limit
description: Maximum number of concurrent connections (per Worker Process). A
random set of IPs will be picked on every DNS resolution period. Use
0 for unlimited.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
required:
- type
title: OutputCriblTcp
OutputCriblHttp:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- cribl_http
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: For optimal performance, enable load balancing even if you have one
hostname, as it can expand to multiple IPs. If this setting is
disabled, consider enabling round-robin DNS.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
tokenTTLMinutes:
type: number
title: Auth Token TTL minutes
minimum: 1
maximum: 60
description: The number of minutes before the internally generated
authentication token expires. Valid values are between 1 and 60.
excludeFields:
type: array
title: Exclude fields
description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported."
items:
type: string
compression:
$ref: "#/components/schemas/CompressionOptionsGzipNone"
description: Codec to use to compress the data before sending
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
authTokens:
type: array
title: Connected environment tokens
description: Shared secrets to be used by connected environments to authorize
connections. These tokens should also be installed in Cribl HTTP
Source in Cribl.Cloud.
items:
$ref: "#/components/schemas/AuthTokenConfOutputCriblHttp"
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
url:
type: string
title: Cribl endpoint
description: URL of a Cribl Worker to send events to, such as
http://localhost:10200
pattern: ^https?://.*
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: Cribl Worker endpoints
description: Cribl Worker endpoints
minItems: 1
items:
$ref: "#/components/schemas/UrlConfOutputCriblHttp"
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
required:
- type
title: OutputCriblHttp
OutputCriblSearchEngine:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- cribl_search_engine
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: For optimal performance, enable load balancing even if you have one
hostname, as it can expand to multiple IPs. If this setting is
disabled, consider enabling round-robin DNS.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath"
description: TLS settings (client side)
tokenTTLMinutes:
type: number
title: Auth Token TTL minutes
minimum: 1
maximum: 60
description: The number of minutes before the internally generated
authentication token expires. Valid values are between 1 and 60.
excludeFields:
type: array
title: Exclude fields
description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported."
items:
type: string
compression:
$ref: "#/components/schemas/CompressionOptionsGzipNone"
description: Codec to use to compress the data before sending
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
throttleRatePerSec:
type: string
title: Throttling
description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling."
pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
authTokens:
type: array
title: Connected environment tokens
description: Shared secrets to be used by connected environments to authorize
connections. These tokens should also be installed in Cribl Search
Source in Cribl.Cloud.
items:
$ref: "#/components/schemas/AuthTokenConfOutputCriblHttp"
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
sendAs:
type: string
title: Send as
enum:
- logs
- metrics
- both
x-speakeasy-enum-descriptions:
- Logs
- Metrics
- Logs and Metrics
description: Which signals this Destination carries. Logs sends everything to
log search, including metric events. Metrics routes metric events to
the metric store and drops everything else. Logs and Metrics routes
metric events to the metric store and sends the rest to log search.
Metric routing requires the receiving Cribl Search Source to be
enabled for metrics storage; if it is not, metric events are
discarded rather than stored as logs.
x-speakeasy-unknown-values: allow
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
description:
type: string
title: Description
description: Optional description for this configuration.
url:
type: string
title: Cribl endpoint
description: URL of a Cribl Worker to send events to, such as
http://localhost:10200
pattern: ^https?://.*
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: Cribl Worker endpoints
description: Cribl Worker endpoints
minItems: 1
items:
$ref: "#/components/schemas/UrlConfOutputCriblHttp"
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
required:
- type
title: OutputCriblSearchEngine
OutputHumioHec:
type: object
required:
- type
- format
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- humio_hec
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: LogScale endpoint
description: "URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw"
pattern: ^https?://.*
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 32768
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
format:
$ref: "#/components/schemas/RequestFormatOptions"
description: When set to JSON, the event is automatically formatted with
required fields before sending. When set to Raw, only the event's
`_raw` value is sent.
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: LogScale auth token
description: CrowdStrike Falcon LogScale authentication token
textSecret:
type: string
title: LogScale auth token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputHumioHec
OutputCrowdstrikeNextGenSiem:
type: object
required:
- type
- format
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- crowdstrike_next_gen_siem
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: Next-Gen SIEM endpoint
description: |-
URL provided from a CrowdStrike data connector.
Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector
pattern: ^https?://.*
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 32768
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
format:
$ref: "#/components/schemas/RequestFormatOptions"
description: When set to JSON, the event is automatically formatted with
required fields before sending. When set to Raw, only the event's
`_raw` value is sent.
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: Next-Gen SIEM authentication token
description: Next-Gen SIEM authentication token
textSecret:
type: string
title: Next-Gen SIEM authentication token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputCrowdstrikeNextGenSiem
OutputDlS3:
type: object
required:
- type
- bucket
- stagePath
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- dl_s3
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
endpoint:
type: string
title: Endpoint
description: S3 service endpoint. If empty, defaults to the AWS Region-specific
endpoint. Otherwise, it must point to S3-compatible endpoint.
enableAssumeRole:
type: boolean
title: Enable for S3
description: Use Assume Role credentials to access S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
bucket:
type: string
title: S3 bucket name
description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
region:
type: string
title: Region
description: Region where the S3 bucket is located
destPath:
type: string
title: Key prefix
description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`"
maxConcurrentFileParts:
type: number
title: Concurrent file parts upload limit
description: Maximum number of parts to upload in parallel per file. Minimum
part size is 5MB.
minimum: 1
maximum: 10
verifyPermissions:
type: boolean
title: Verify if bucket exists
description: Disable if you can access files within the bucket but not the
bucket itself
maxClosingFilesToBackpressure:
type: number
title: Staging file limit
description: Maximum number of files that can be waiting for upload before
backpressure is applied
minimum: 10
maximum: 4200
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 86400
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 86400
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
awsSecretKey:
type: string
title: Secret key
description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)"
objectACL:
$ref: "#/components/schemas/ObjectAclOptions"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptions"
description: Storage class to select for uploaded objects
serverSideEncryption:
$ref: "#/components/schemas/ServerSideEncryptionForUploadedObjectsOptions"
description: Server-side encryption to use for uploaded objects
kmsKeyId:
type: string
title: KMS key ID
description: ID or ARN of the KMS customer-managed key to use for encryption
partitioningFields:
type: array
title: Partition by fields
description: List of fields to partition the path by, in addition to time, which
is included automatically. The effective partition will be
YYYY/MM/DD/HH/.
items:
type: string
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: This value can be a constant or a JavaScript expression
(`${C.env.SOME_ACCESS_KEY}`)
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_serverSideEncryption:
type: string
description: Binds 'serverSideEncryption' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serverSideEncryption' at runtime.
__template_kmsKeyId:
type: string
description: Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'kmsKeyId' at runtime.
__template_partitioningFields:
type: string
description: Binds 'partitioningFields' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'partitioningFields' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputDlS3
OutputSecurityLake:
type: object
required:
- type
- bucket
- stagePath
- region
- accountId
- customSource
- assumeRoleArn
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsSecuritylake"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards. These fields are added as dimensions and labels to
generated metrics and logs, respectively.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
endpoint:
type: string
title: Endpoint
description: Amazon Security Lake service endpoint. If empty, defaults to the
AWS Region-specific endpoint. Otherwise, it must point to Amazon
Security Lake-compatible endpoint.
enableAssumeRole:
type: boolean
title: Enable for S3
description: Use Assume Role credentials to access S3
assumeRoleArn:
type: string
title: AssumeRole ARN
description: Amazon Resource Name (ARN) of the role to assume
pattern: "^arn:"
minLength: 20
assumeRoleExternalId:
type: string
title: External ID
description: External ID to use when assuming role
durationSeconds:
type: number
title: Duration (seconds)
description: Duration of the assumed role's session, in seconds. Minimum is 900
(15 minutes), default is 3600 (1 hour), and maximum is 43200 (12
hours).
minimum: 900
maximum: 43200
awsAuthenticationMethod:
$ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf"
description: AWS authentication method. Choose Auto to use IAM roles.
reuseConnections:
type: boolean
title: Reuse connections
description: Reuse connections between requests, which can improve performance
rejectUnauthorized:
type: boolean
title: Reject unauthorized certificates
description: Reject certificates that cannot be verified against a valid CA,
such as self-signed certificates
bucket:
type: string
title: S3 bucket name
description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`"
region:
type: string
title: Region
description: Region where the Amazon Security Lake is located.
maxConcurrentFileParts:
type: number
title: Concurrent file parts upload limit
description: Maximum number of parts to upload in parallel per file. Minimum
part size is 5MB.
minimum: 1
maximum: 10
verifyPermissions:
type: boolean
title: Verify if bucket exists
description: Disable if you can access files within the bucket but not the
bucket itself
maxClosingFilesToBackpressure:
type: number
title: Staging file limit
description: Maximum number of files that can be waiting for upload before
backpressure is applied
minimum: 10
maximum: 4200
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 86400
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 86400
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
awsSecretKey:
type: string
title: Secret key
description: Secret key
objectACL:
$ref: "#/components/schemas/ObjectAclOptions"
description: Object ACL to assign to uploaded objects
storageClass:
$ref: "#/components/schemas/StorageClassOptions"
description: Storage class to select for uploaded objects
serverSideEncryption:
$ref: "#/components/schemas/ServerSideEncryptionForUploadedObjectsOptions"
description: Server-side encryption to use for uploaded objects
kmsKeyId:
type: string
title: KMS key ID
description: ID or ARN of the KMS customer-managed key to use for encryption
accountId:
type: string
title: Account ID
description: ID of the AWS account whose data the Destination will write to
Security Lake. This should have been configured when creating the
Amazon Security Lake custom source.
customSource:
type: string
title: Custom source name
description: Name of the custom source configured in Amazon Security Lake
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
description:
type: string
title: Description
description: Optional description for this configuration.
awsApiKey:
type: string
title: Access key
description: This value can be a constant or a JavaScript expression
(`${C.env.SOME_ACCESS_KEY}`)
awsSecret:
type: string
title: Secret key pair
description: Select or create a stored secret that references your access key
and secret key
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
__template_assumeRoleArn:
type: string
description: Binds 'assumeRoleArn' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'assumeRoleArn' at runtime.
__template_assumeRoleExternalId:
type: string
description: Binds 'assumeRoleExternalId' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'assumeRoleExternalId' at runtime.
__template_bucket:
type: string
description: Binds 'bucket' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'bucket' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_awsSecretKey:
type: string
description: Binds 'awsSecretKey' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsSecretKey' at runtime.
__template_objectACL:
type: string
description: Binds 'objectACL' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'objectACL' at runtime.
__template_storageClass:
type: string
description: Binds 'storageClass' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'storageClass' at runtime.
__template_serverSideEncryption:
type: string
description: Binds 'serverSideEncryption' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'serverSideEncryption' at runtime.
__template_kmsKeyId:
type: string
description: Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'kmsKeyId' at runtime.
__template_accountId:
type: string
description: Binds 'accountId' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'accountId' at runtime.
__template_customSource:
type: string
description: Binds 'customSource' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'customSource' at runtime.
__template_awsApiKey:
type: string
description: Binds 'awsApiKey' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'awsApiKey' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputSecurityLake
OutputCriblLake:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- cribl_lake
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files, before compressing
and moving to final destination. Use performant and stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 86400
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 86400
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
storageLocationId:
type: string
title: Storage location
description: Storage location that contains the target Lake dataset.
destPath:
type: string
title: Lake Dataset
description: Lake dataset to send the data to.
format:
type: string
enum:
- json
- parquet
- raw
x-speakeasy-unknown-values: allow
dynamicDataset:
type: boolean
maxClosingFilesToBackpressure:
type: number
minimum: 10
maximum: 1000
maxConcurrentFileParts:
type: number
minimum: 1
maximum: 10
freshnessGracePeriodSec:
type: number
minimum: 5
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_destPath:
type: string
description: Binds 'destPath' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'destPath' at runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
required:
- type
title: OutputCriblLake
OutputDiskSpool:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- disk_spool
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
timeWindow:
type: string
title: Bucket time span
description: Time period for grouping spooled events. Default is 10m.
maxDataSize:
type: string
title: Data size limit
description: "Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB."
pattern: ^\d+(\.\d+)?\s*(?:[kmgKMG](b|B))?$
maxDataTime:
title: Data age limit
type: string
description: "Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h."
pattern: \d+[smhd]$
compress:
$ref: "#/components/schemas/CompressionOptionsPersistence"
description: Data compression format. Default is gzip.
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized within the time-buckets. If blank, the event's __partition
property is used and otherwise, events go directly into the
time-bucket directory.
description:
type: string
title: Description
description: Optional description for this configuration.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
required:
- type
title: OutputDiskSpool
OutputClickHouse:
type: object
required:
- type
- database
- tableName
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- click_house
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: URL
description: "URL of the ClickHouse instance. Example: http://localhost:8123/"
authType:
$ref: "#/components/schemas/AuthenticationTypeOptions"
description: Authentication type
database:
type: string
title: ClickHouse database
description: ClickHouse database
tableName:
type: string
title: ClickHouse table
description: Name of the ClickHouse table where data will be inserted. Name can
contain letters (A-Z, a-z), numbers (0-9), and the character "_",
and must start with either a letter or the character "_".
pattern: ^[a-zA-Z_][0-9a-zA-Z_]*$
format:
$ref: "#/components/schemas/FormatOptions"
description: Data format to use when sending data to ClickHouse. Defaults to
JSON Compact.
mappingType:
$ref: "#/components/schemas/MappingTypeOptions"
description: How event fields are mapped to ClickHouse columns
asyncInserts:
type: boolean
title: Async inserts
description: Collect data into batches for later processing on the ClickHouse
server. Disable to write to a ClickHouse table immediately. Cribl
sends the configured value with every insert
(async_insert=1 or async_insert=0) so
behavior is consistent across ClickHouse versions, including 26.3
LTS and later, where async inserts are enabled by default on the
server.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 25600
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
workload:
type: string
title: Workload
description: Optional ClickHouse workload name to append as a SETTINGS clause on
INSERT queries. Used for workload scheduling classification.
dumpFormatErrorsToDisk:
type: boolean
title: Log last schema mismatch
description: Log the most recent event that fails to match the table schema
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
sqlUsername:
type: string
title: Username
description: Username for certificate authentication
waitForAsyncInserts:
type: boolean
title: Wait for async inserts
description: Cribl will wait for confirmation that data has been fully inserted
into the ClickHouse database before proceeding. Disabling this
option can increase throughput, but Cribl won't be able to verify
data has been completely inserted.
excludeMappingFields:
type: array
title: Exclude fields
description: Fields to exclude from sending to ClickHouse
minItems: 0
items:
type: string
minLength: 0
describeTable:
type: string
title: Retrieve table columns
description: Retrieves the table schema from ClickHouse and populates the Column
Mapping table
columnMappings:
type: array
title: Column Mapping
description: Column Mapping
items:
$ref: "#/components/schemas/ColumnMappingConfOutputClickHouse"
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_database:
type: string
description: Binds 'database' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'database' at runtime.
__template_tableName:
type: string
description: Binds 'tableName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tableName' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputClickHouse
OutputCustomerMetricsStorage:
type: object
required:
- type
- database
- tableName
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- customer_metrics_storage
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: URL
description: "URL of the ClickHouse instance. Example: http://localhost:8123/"
authType:
$ref: "#/components/schemas/AuthenticationTypeOptions"
description: Authentication type
database:
type: string
title: ClickHouse database
description: ClickHouse database
tableName:
type: string
title: ClickHouse table
description: Name of the ClickHouse table where data will be inserted. Name can
contain letters (A-Z, a-z), numbers (0-9), and the character "_",
and must start with either a letter or the character "_".
pattern: ^[a-zA-Z_][0-9a-zA-Z_]*$
format:
$ref: "#/components/schemas/FormatOptions"
description: Data format to use when sending data to ClickHouse. Defaults to
JSON Compact.
mappingType:
$ref: "#/components/schemas/MappingTypeOptions"
description: How event fields are mapped to ClickHouse columns
asyncInserts:
type: boolean
title: Async inserts
description: Collect data into batches for later processing on the ClickHouse
server. Disable to write to a ClickHouse table immediately. Cribl
sends the configured value with every insert
(async_insert=1 or async_insert=0) so
behavior is consistent across ClickHouse versions, including 26.3
LTS and later, where async inserts are enabled by default on the
server.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 25600
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
workload:
type: string
title: Workload
description: Optional ClickHouse workload name to append as a SETTINGS clause on
INSERT queries. Used for workload scheduling classification.
dumpFormatErrorsToDisk:
type: boolean
title: Log last schema mismatch
description: Log the most recent event that fails to match the table schema
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
sqlUsername:
type: string
title: Username
description: Username for certificate authentication
waitForAsyncInserts:
type: boolean
title: Wait for async inserts
description: Cribl will wait for confirmation that data has been fully inserted
into the ClickHouse database before proceeding. Disabling this
option can increase throughput, but Cribl won't be able to verify
data has been completely inserted.
excludeMappingFields:
type: array
title: Exclude fields
description: Fields to exclude from sending to ClickHouse
minItems: 0
items:
type: string
minLength: 0
describeTable:
type: string
title: Retrieve table columns
description: Retrieves the table schema from ClickHouse and populates the Column
Mapping table
columnMappings:
type: array
title: Column Mapping
description: Column Mapping
items:
$ref: "#/components/schemas/ColumnMappingConfOutputClickHouse"
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_database:
type: string
description: Binds 'database' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'database' at runtime.
__template_tableName:
type: string
description: Binds 'tableName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tableName' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputCustomerMetricsStorage
OutputLocalSearchStorage:
type: object
required:
- type
- database
- tableName
- url
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- local_search_storage
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
url:
type: string
title: URL
description: "URL of the database instance. Example: http://localhost:8123/"
authType:
$ref: "#/components/schemas/AuthenticationTypeOptions"
description: Authentication type
database:
type: string
title: Database
description: Database
tableName:
type: string
title: Table
description: Name of the table where data will be inserted. Name can contain
letters (A-Z, a-z), numbers (0-9), and the character "_", and must
start with either a letter or the character "_".
pattern: ^[a-zA-Z_][0-9a-zA-Z_]*$
format:
type: string
title: Format
description: Data format to use when sending data. Defaults to JSON Compact.
enum:
- json-compact-each-row-with-names
- json-each-row
x-speakeasy-enum-descriptions:
- JSONCompactEachRowWithNames
- JSONEachRow
x-speakeasy-unknown-values: allow
mappingType:
type: string
title: Mapping type
description: How event fields are mapped to columns.
enum:
- automatic
- custom
x-speakeasy-enum-descriptions:
- Automatic
- Custom
x-speakeasy-unknown-values: allow
asyncInserts:
type: boolean
title: Async inserts
description: Collect data into batches for later processing. Disable to write to
a table immediately.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPathExtended"
description: TLS settings (client side)
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 25600
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
workload:
type: string
title: Workload
description: Optional ClickHouse workload name to append as a SETTINGS clause on
INSERT queries. Used for workload scheduling classification.
dumpFormatErrorsToDisk:
type: boolean
title: Log last schema mismatch
description: Log the most recent event that fails to match the table schema
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
statsDestination:
type: object
properties:
url:
type: string
database:
type: string
tableName:
type: string
authType:
type: string
username:
type: string
sqlUsername:
type: string
password:
type: string
waitForAsyncInserts:
type: boolean
concurrency:
type: number
description:
type: string
title: Description
description: Optional description for this configuration.
username:
type: string
title: Username
description: Username
password:
type: string
title: Password
description: Password
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
sqlUsername:
type: string
title: Username
description: Username for certificate authentication
waitForAsyncInserts:
type: boolean
title: Wait for async inserts
description: Cribl will wait for confirmation that data has been fully inserted
into the database before proceeding. Disabling this option can
increase throughput, but Cribl won't be able to verify data has been
completely inserted.
excludeMappingFields:
type: array
title: Exclude fields
description: Fields to exclude from sending
minItems: 0
items:
type: string
minLength: 0
describeTable:
type: string
title: Retrieve table columns
description: Retrieves the table schema and populates the Column Mapping table
columnMappings:
type: array
title: Column Mapping
description: Column Mapping
items:
type: object
required:
- columnName
- columnValueExpression
properties:
columnName:
type: string
title: Column name
description: Name of the column that will store field value
columnType:
type: string
title: Column type
description: Type of the column in the database
columnValueExpression:
type: string
title: Column value
description: JavaScript expression to compute value to be inserted into the
table
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
__template_database:
type: string
description: Binds 'database' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'database' at runtime.
__template_tableName:
type: string
description: Binds 'tableName' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'tableName' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputLocalSearchStorage
OutputXsiam:
type: object
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- xsiam
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
loadBalanced:
type: boolean
title: Load balancing
description: Enable for optimal performance. Even if you have one hostname, it
can expand to multiple IPs. If disabled, consider enabling
round-robin DNS.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 100
maximum: 10000
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
authType:
title: Authentication method
type: string
enum:
- token
- secret
description: Enter a token directly, or provide a secret referencing a token
x-speakeasy-unknown-values: allow
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
throttleRateReqPerSec:
type: integer
title: Throttle request rate limit
description: Maximum number of requests to limit to per second
maximum: 2000
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
url:
type: string
title: XSIAM endpoint
description: XSIAM endpoint URL to send events to, such as https://api-{tenant
external URL}/logs/v1/event
pattern: ^https?://.*
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
excludeSelf:
type: boolean
title: Exclude current host IPs
description: Exclude all IPs of the current host from the list of any resolved
hostnames
urls:
type: array
title: XSIAM Endpoints
description: XSIAM Endpoints
minItems: 1
items:
type: object
properties:
weight:
type: number
title: Load Weight
description: Assign a weight (>0) to each endpoint to indicate its
traffic-handling capability
minimum: 0
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (seconds)
description: The interval in which to re-resolve any hostnames and pick up
destinations from A records
loadBalanceStatsPeriodSec:
type: number
minimum: 10
title: Load balance stats period (seconds)
description: How far back in time to keep traffic stats for load balancing
purposes
token:
type: string
title: Auth token
description: XSIAM authentication token
textSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
required:
- type
title: OutputXsiam
OutputNetflow:
type: object
required:
- type
- hosts
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
$ref: "#/components/schemas/TypeOptionsNetflow"
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
hosts:
type: array
title: NetFlow Destinations
description: One or more NetFlow Destinations to forward events to
minItems: 1
items:
type: object
required:
- host
- port
properties:
host:
type: string
title: Address
description: Destination host
port:
type: number
title: Port
maximum: 65535
description: Destination port, default is 2055
__template_host:
type: string
description: Binds 'host' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'host' at runtime.
__template_port:
type: string
description: Binds 'port' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'port' at runtime.
dnsResolvePeriodSec:
type: number
minimum: 0
maximum: 86400
title: DNS resolution period (sec)
description: How often to resolve the destination hostname to an IP address.
Ignored if all destinations are IP addresses. A value of 0 means
every datagram sent will incur a DNS lookup.
enableIpSpoofing:
title: Enable Source IP spoofing
description: Send NetFlow traffic using the original event's Source IP and port.
To enable this, you must install the external `udp-sender` helper
binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the
`CAP_NET_RAW` capability.
type: boolean
description:
type: string
title: Description
description: Optional description for this configuration.
maxRecordSize:
type: number
title: Maximum transmission unit (MTU)
minimum: 1
description: MTU in bytes. The actual maximum NetFlow payload size will be MTU
minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For
example, with the default MTU of 1500, the max payload is 1472 bytes
for IPv4. Payloads exceeding this limit will be dropped.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
title: OutputNetflow
OutputDynatraceHttp:
type: object
required:
- type
- format
- endpoint
- telemetryType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- dynatrace_http
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
method:
$ref: "#/components/schemas/MethodOptions"
description: The method to use when sending events
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 5000
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
maximum: 50000
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events. You can also add headers dynamically
on a per-event basis in the __headers field, as explained in [Cribl
Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
authType:
type: string
title: Authentication type
enum:
- token
- textSecret
x-speakeasy-enum-descriptions:
- Auth token
- Token (text secret)
description: Authentication type
x-speakeasy-unknown-values: allow
format:
type: string
title: Format
description: How to format events before sending. Defaults to JSON. Plaintext is
not currently supported.
enum:
- json_array
- plaintext
x-speakeasy-enum-descriptions:
- JSON
- Plaintext
x-speakeasy-unknown-values: allow
endpoint:
type: string
title: Endpoint
enum:
- cloud
- activeGate
- manual
x-speakeasy-enum-descriptions:
- Cloud
- ActiveGate
- Manual
description: Endpoint
x-speakeasy-unknown-values: allow
telemetryType:
type: string
title: Telemetry type
enum:
- logs
- metrics
x-speakeasy-enum-descriptions:
- Logs
- Metrics
description: Telemetry type
x-speakeasy-unknown-values: allow
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
token:
type: string
title: Token
description: Bearer token to include in the authorization header
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
environmentId:
type: string
title: Environment ID
description: ID of the environment to send to
activeGateDomain:
type: string
description: ActiveGate domain with Log analytics collector module enabled. For
example
https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.
title: ActiveGate domain
url:
title: URL
type: string
description: URL to send events to. Can be overwritten by an event's __url field.
pattern: ^https?://.*
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_url:
type: string
description: Binds 'url' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'url' at runtime.
title: OutputDynatraceHttp
OutputDynatraceOtlp:
type: object
required:
- type
- endpoint
- endpointType
- protocol
- otlpVersion
- tokenSecret
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- dynatrace_otlp
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
protocol:
type: string
title: Protocol
description: Select a transport option for Dynatrace
enum:
- http
x-speakeasy-enum-descriptions:
- HTTP
x-speakeasy-unknown-values: allow
endpoint:
type: string
title: Endpoint
description: The endpoint where Dynatrace events will be sent. Enter any valid
URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square
brackets)
otlpVersion:
$ref: "#/components/schemas/OtlpVersionOptions"
description: The version of OTLP Protobuf definitions to use when structuring
data to send
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."})
are serialized directly instead of being wrapped as key-value maps'
compress:
$ref: "#/components/schemas/CompressionOptionsDeflateGzip"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpCompress:
$ref: "#/components/schemas/CompressionOptionsMessages"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpTracesEndpointOverride:
type: string
title: Traces endpoint override
description: If you want to send traces to the default `{endpoint}/v1/traces`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpMetricsEndpointOverride:
type: string
title: Metrics endpoint override
description: If you want to send metrics to the default `{endpoint}/v1/metrics`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
httpLogsEndpointOverride:
type: string
title: Logs endpoint override
description: If you want to send logs to the default `{endpoint}/v1/logs`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
metadata:
type: array
title: Metadata
description: List of key-value pairs to send with each gRPC request. Value
supports JavaScript expressions that are evaluated just once, when
the destination gets started. To pass credentials as metadata, use
'C.Secret'.
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
dynamicHeadersEnabled:
type: boolean
title: Use dynamic metadata
description: Batch event data upon dynamic metadata (whether presented or not)
dynamicHeadersField:
type: string
title: Dynamic metadata field
description: When presented, this field which contains metadata, will be
injected into the Destination metadata and used to batch events.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit
description: Maximum size (in KB) of the request body. The maximum payload size
is 4 MB. If this limit is exceeded, the entire OTLP message is
dropped
minimum: 1024
maximum: 4096
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often the sender should ping the peer to keep the connection open
minimum: 1
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
endpointType:
type: string
title: Endpoint type
description: Select the type of Dynatrace endpoint configured
enum:
- saas
- ag
x-speakeasy-enum-descriptions:
- SaaS
- ActiveGate
x-speakeasy-unknown-values: allow
tokenSecret:
type: string
title: Auth token (text secret)
description: Select or create a stored text secret
authTokenName:
type: string
title: Api-Token name
description: Api-Token name
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputDynatraceOtlp
OutputTraversalOtlp:
type: object
required:
- type
- endpoint
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- traversal_otlp
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
authType:
type: string
title: Authentication type
enum:
- none
- credentialsSecret
- textSecret
- oauthSecret
x-speakeasy-enum-descriptions:
- None
- Basic (credentials secret)
- Token (text secret)
- OAuth (text secret)
description: Authentication type
x-speakeasy-unknown-values: allow
endpoint:
type: string
title: Endpoint
description: The endpoint where OTel log events will be sent. Enter any valid
URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square
brackets).
protocol:
$ref: "#/components/schemas/ProtocolOptions"
description: Select a transport option for OpenTelemetry
preserveNativeAnyValue:
type: boolean
title: Preserve native AnyValue wrappers
description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."})
are serialized directly instead of being wrapped as key-value maps'
compress:
$ref: "#/components/schemas/CompressionOptionsDeflateGzip"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpCompress:
$ref: "#/components/schemas/CompressionOptionsMessages"
description: Type of compression to apply to messages sent to the OpenTelemetry
endpoint
httpLogsEndpointOverride:
type: string
title: Logs endpoint override
description: If you want to send logs to the default `{endpoint}/v1/logs`
endpoint, leave this field empty; otherwise, specify the desired
endpoint
metadata:
type: array
title: Metadata
description: List of key-value pairs to send with each gRPC request. Value
supports JavaScript expressions that are evaluated just once, when
the destination gets started. To pass credentials as metadata, use
'C.Secret'.
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
dynamicHeadersEnabled:
type: boolean
title: Use dynamic metadata
description: Batch event data upon dynamic metadata (whether presented or not)
dynamicHeadersField:
type: string
title: Dynamic metadata field
description: When presented, this field which contains metadata, will be
injected into the Destination metadata and used to batch events.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 10240
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
connectionTimeout:
type: number
title: Connection timeout
description: Amount of time (milliseconds) to wait for the connection to
establish before retrying
keepAliveTime:
type: number
title: Keep alive time (seconds)
description: How often the sender should ping the peer to keep the connection open
minimum: 1
keepAlive:
type: boolean
title: Keep alive
description: Disable to close the connection immediately after sending the
outgoing request
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
credentialsSecret:
type: string
title: Credentials secret
description: Select or create a secret that references your credentials
textSecret:
type: string
title: Token (text secret)
description: Select or create a stored text secret
loginUrl:
type: string
title: Login URL
description: URL for OAuth
pattern: ^https?://.*
secretParamName:
type: string
title: OAuth Secret parameter name
description: Secret parameter name to pass in request body
oauthTextSecret:
type: string
title: OAuth secret (text secret)
description: Select or create a stored text secret for the OAuth secret
parameter value to pass in request body
tokenAttributeName:
type: string
title: Token attribute name
description: Name of the auth token attribute in the OAuth response. Can be
top-level (e.g., 'token'); or nested, using a period (e.g.,
'data.token').
authHeaderExpr:
type: string
title: Authorize expression
description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`."
tokenTimeoutSecs:
type: number
title: Refresh interval (secs.)
description: How often the OAuth token should be refreshed.
minimum: 1
maximum: 300000
oauthParams:
type: array
title: OAuth parameters
description: Additional parameters to send in the OAuth login request.
@{product} will combine the secret with these parameters, and will
send the URL-encoded result in a POST request to the endpoint
specified in the 'Login URL'. We'll automatically add the
content-type header 'application/x-www-form-urlencoded' when sending
this request.
items:
$ref: "#/components/schemas/OauthParamConfInputServicenowTable"
oauthHeaders:
type: array
title: OAuth headers
description: Additional headers to send in the OAuth login request. @{product}
will automatically add the content-type header
'application/x-www-form-urlencoded' when sending this request.
items:
$ref: "#/components/schemas/OauthHeaderConfInputServicenowTable"
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
For optimal performance, consider enabling this setting for non-load
balanced destinations.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
tls:
$ref: "#/components/schemas/TlsSettingsClientSideTypeExtended"
description: TLS settings (client side)
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_loginUrl:
type: string
description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'loginUrl' at runtime.
title: OutputTraversalOtlp
OutputSentinelOneAiSiem:
type: object
required:
- type
- region
- endpoint
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- sentinel_one_ai_siem
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1024
maximum: 2097152
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
authType:
$ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems"
description: Select Manual to enter an auth token directly, or select Secret to
use a text secret to authenticate
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
region:
type: string
title: Region
description: The SentinelOne region to send events to. In most cases you can
find the region by either looking at your SentinelOne URL or knowing
what geographic region your SentinelOne instance is contained in.
enum:
- US
- CA
- EMEA
- AP
- APS
- AU
- Custom
x-speakeasy-unknown-values: allow
endpoint:
title: AI SIEM endpoint path
type: string
enum:
- /services/collector/event
- /services/collector/raw
description: Endpoint to send events to. Use /services/collector/event for
structured JSON payloads with standard HEC top-level fields. Use
/services/collector/raw for unstructured log lines (plain text).
x-speakeasy-unknown-values: allow
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
token:
type: string
title: AI SIEM API Key
description: In the SentinelOne Console select Policy & Settings then select the
Singularity AI SIEM section, API Keys will be at the bottom. Under
Log Access Keys select a Write token and copy it here
textSecret:
type: string
title: AI SIEM API Key (text secret)
description: Select or create a stored text secret
baseUrl:
title: Base AI SIEM endpoint URL
type: string
pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$
description: "Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$."
hostExpression:
type: string
title: serverHost expression
description: Define serverHost for events using a JavaScript expression. You
must enclose text constants in quotes (such as, 'myServer').
sourceExpression:
type: string
title: logFile expression
description: Define logFile for events using a JavaScript expression. You must
enclose text constants in quotes (such as, 'myLogFile.txt').
sourceTypeExpression:
type: string
title: parser expression
description: Define the parser for events using a JavaScript expression. This
value helps parse data into AI SIEM. You must enclose text constants
in quotes (such as, 'dottedJson'). For custom parsers, substitute
'dottedJson' with your parser's name.
dataSourceCategoryExpression:
type: string
title: dataSource.category expression
description: Define the dataSource.category for events using a JavaScript
expression. This value helps categorize data and helps enable extra
features in SentinelOne AI SIEM. You must enclose text constants in
quotes. The default value is 'security'.
dataSourceNameExpression:
type: string
title: dataSource.name expression
description: Define the dataSource.name for events using a JavaScript
expression. This value should reflect the type of data being
inserted into AI SIEM. You must enclose text constants in quotes
(such as, 'networkActivity' or 'authLogs').
dataSourceVendorExpression:
type: string
title: dataSource.vendor expression
description: Define the dataSource.vendor for events using a JavaScript
expression. This value should reflect the vendor of the data being
inserted into AI SIEM. You must enclose text constants in quotes
(such as, 'Cisco' or 'Microsoft').
eventTypeExpression:
type: string
title: event.type expression
description: Optionally, define the event.type for events using a JavaScript
expression. This value acts as a label, grouping events into
meaningful categories. You must enclose text constants in quotes
(such as, 'Process Creation' or 'Network Connection').
host:
type: string
title: serverHost expression
description: Define the serverHost for events using a JavaScript expression.
This value will be passed to AI SIEM. You must enclose text
constants in quotes (such as, 'myServerName').
source:
type: string
title: logFile
description: Specify the logFile value to pass as a parameter to SentinelOne AI
SIEM. Don't quote this value. The default is cribl.
sourceType:
type: string
title: parser
description: Specify the sourcetype parameter for SentinelOne AI SIEM, which
determines the parser. Don't quote this value. For custom parsers,
substitute hecRawParser with your parser's name. The default is
hecRawParser.
dataSourceCategory:
type: string
title: dataSource.category
description: Specify the dataSource.category value to pass as a parameter to
SentinelOne AI SIEM. This value helps categorize data and enables
additional features. Don't quote this value. The default is
security.
dataSourceName:
type: string
title: dataSource.name
description: Specify the dataSource.name value to pass as a parameter to AI
SIEM. This value should reflect the type of data being inserted.
Don't quote this value. The default is cribl.
dataSourceVendor:
type: string
title: dataSource.vendor
description: Specify the dataSource.vendorvalue to pass as a parameter to AI
SIEM. This value should reflect the vendor of the data being
inserted. Don't quote this value. The default is cribl.
eventType:
type: string
title: event.type
description: Specify the event.type value to pass as an optional parameter to AI
SIEM. This value acts as a label, grouping events into meaningful
categories like Process Creation, File Modification, or Network
Connection. Don't quote this value. By default, this field is empty.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
title: OutputSentinelOneAiSiem
OutputChronicle:
type: object
required:
- type
- gcpProjectId
- gcpInstance
- region
- logType
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- chronicle
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
apiVersion:
type: string
title: API version
description: API version
authenticationMethod:
type: string
title: Authentication method
enum:
- serviceAccount
- serviceAccountSecret
description: Authentication method
x-speakeasy-unknown-values: allow
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
region:
type: string
title: Region
description: Regional endpoint to send events to
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum size, in KB, of the request body
minimum: 1
maximum: 4096
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events to include in the request body. Default is
0 (unlimited).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body before sending
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
useRoundRobinDns:
type: boolean
title: Round-robin DNS
description: Enable round-robin DNS lookup. When a DNS server returns multiple
addresses, @{product} will cycle through them in the order returned.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
totalMemoryLimitKB:
type: number
title: Buffer memory limit (KB)
description: Maximum total size of the batches waiting to be sent. If left
blank, defaults to 5 times the max body size (if set). If 0, no
limit is enforced.
minimum: 0
ingestionMethod:
type: string
title: Chronicle API ingestion method
description: Chronicle API ingestion method
namespace:
type: string
title: Namespace
description: User-configured environment namespace to identify the data domain
the logs originated from. This namespace is used as a tag to
identify the appropriate data domain for indexing and enrichment
functionality. Can be overwritten by event field __namespace.
logType:
type: string
title: Default log type
description: Default log type value to send to SecOps. Can be overwritten by
event field __logType.
logTextField:
type: string
title: Log text field
description: Name of the event field that contains the log text to send. If not
specified, Stream sends a JSON representation of the whole event.
gcpProjectId:
type: string
title: GCP project ID
description: The Google Cloud Platform (GCP) project ID to send events to
gcpInstance:
type: string
title: GCP instance
description: The Google Cloud Platform (GCP) instance to send events to. This is
the Chronicle customer uuid.
customLabels:
type: array
title: Custom labels
description: Custom labels to be added to every event
items:
type: object
required:
- key
- value
properties:
key:
type: string
title: Key
description: Key
value:
type: string
title: Value
description: Value
rbacEnabled:
type: boolean
title: Enable RBAC
description: Designate this label for role-based access control and filtering
endpoint:
type: string
title: Endpoint
description: "Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)"
pattern: ^https?://.*
description:
type: string
title: Description
description: Optional description for this configuration.
serviceAccountCredentials:
type: string
title: Service account credentials
description: Contents of service account credentials (JSON keys) file downloaded
from Google Cloud. To upload a file, click the upload button at this
field's upper right.
serviceAccountCredentialsSecret:
type: string
title: Service account credentials (text secret)
description: Select or create a stored text secret
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: //."
pqCompress:
$ref: "#/components/schemas/CompressionOptionsPq"
description: Codec to use to compress the persisted data
pqOnBackpressure:
$ref: "#/components/schemas/QueueFullBehaviorOptions"
description: How to handle events when the queue is exerting backpressure (full
capacity or low disk). 'Block' is the same behavior as non-PQ
blocking. 'Drop new data' throws away incoming data, while leaving
the contents of the PQ unchanged.
pqMaxBufferSizeBytes:
type: string
title: Buffer size limit (bytes)
description: The maximum size to hold in memory before writing events to disk.
Enter a numeral with units of KB, MB, etc. The minimum value is 64KB
and the maximum value is 10MB.
pattern: ^\d+\s*(?:\w{2})?$
pqControls:
type: object
title: ""
description: Persistent queue controls.
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_region:
type: string
description: Binds 'region' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'region' at runtime.
__template_failedRequestLoggingMode:
type: string
description: Binds 'failedRequestLoggingMode' to a variable for dynamic value
resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.'
prefixed ID (group-scoped). Variable value overrides
'failedRequestLoggingMode' at runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_namespace:
type: string
description: Binds 'namespace' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'namespace' at runtime.
__template_logType:
type: string
description: Binds 'logType' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logType' at runtime.
__template_logTextField:
type: string
description: Binds 'logTextField' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'logTextField' at runtime.
__template_gcpProjectId:
type: string
description: Binds 'gcpProjectId' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'gcpProjectId' at runtime.
__template_gcpInstance:
type: string
description: Binds 'gcpInstance' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'gcpInstance' at runtime.
__template_endpoint:
type: string
description: Binds 'endpoint' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'endpoint' at runtime.
title: OutputChronicle
OutputDatabricks:
type: object
required:
- type
- workspaceId
- scope
- clientId
- clientTextSecret
- catalog
- schema
- eventsVolumeName
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- databricks
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
destPath:
type: string
title: Upload path
description: Optional path to prepend to files before uploading.
stagePath:
type: string
title: Staging location
description: Filesystem location in which to buffer files before compressing and
moving to final destination. Use performant, stable storage.
addIdToStagePath:
type: boolean
title: Add output ID
description: Add the Output ID value to staging location
removeEmptyDirs:
type: boolean
title: Remove empty staging directories
description: Remove empty staging directories after moving files
partitionExpr:
type: string
title: Partitioning expression
description: JavaScript expression defining how files are partitioned and
organized. Default is date-based. If blank, Stream will fall back to
the event's __partition field value – if present – otherwise to each
location's root directory.
format:
$ref: "#/components/schemas/DataFormatOptions"
description: Format of the output data
baseFileName:
type: string
title: File name prefix expression
description: JavaScript expression to define the output filename prefix (can be
constant)
fileNameSuffix:
type: string
title: File name suffix expression
description: JavaScript expression to define the output filename suffix (can be
constant). The `__format` variable refers to the value of the `Data
format` field (`json` or `raw`). The `__compression` field refers
to the kind of compression being used (`none` or `gzip`).
maxFileSizeMB:
type: number
title: File size limit (MB)
description: Maximum uncompressed output file size. Files of this size will be
closed and moved to final output location.
maximum: 1024
minimum: 5
maxFileOpenTimeSec:
type: number
title: File open time limit (sec)
description: Maximum amount of time to write to a file. Files open for longer
than this will be closed and moved to final output location.
minimum: 10
maximum: 1800
maxFileIdleTimeSec:
type: number
title: Idle time limit (sec)
description: Maximum amount of time to keep inactive files open. Files open for
longer than this will be closed and moved to final output location.
minimum: 5
maximum: 1800
maxOpenFiles:
type: number
title: Open file limit
description: Maximum number of files to keep open concurrently. When exceeded,
@{product} will close the oldest open files and move them to the
final output location.
minimum: 10
maximum: 2000
headerLine:
type: string
title: Header line
description: If set, this line will be written to the beginning of each output
file
writeHighWaterMark:
type: number
title: Writing high watermark (KB)
description: Buffer size used to write to a file
maximum: 4096
minimum: 16
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptionsBlockDrop"
description: How to handle events when all receivers are exerting backpressure
deadletterEnabled:
type: boolean
title: Enable dead-lettering
description: If a file fails to move to its final destination after the maximum
number of retries, move it to a designated directory to prevent
further errors
onDiskFullBackpressure:
$ref: "#/components/schemas/DiskSpaceProtectionOptions"
description: How to handle events when disk space is below the global 'Min free
disk space' limit
forceCloseOnShutdown:
type: boolean
title: Force close on shutdown
description: Force all staged files to close during an orderly Node shutdown.
This triggers immediate upload of in-progress data — regardless of
idle time, file age, or size thresholds — to minimize data loss.
retrySettings:
$ref: "#/components/schemas/RetrySettingsType"
orphans:
$ref: "#/components/schemas/OrphanFileRecoveryType"
description: Orphan file recovery
workspaceId:
type: string
title: Workspace ID
description: Unique identifier for the Databricks workspace. Used to construct
the OAuth login URL and API base URL.
workspaceHost:
type: string
title: Workspace host
description: Hostname for the Databricks workspace. Override this to connect to
government or secure cloud environments (e.g. cloud.databricks.us,
cloud.databricks.mil, azuredatabricks.net).
scope:
type: string
title: OAuth scope
description: OAuth scope for Unity Catalog authentication
clientId:
type: string
title: Client ID
description: OAuth client ID for Unity Catalog authentication
catalog:
type: string
title: Catalog
description: Name of the Unity Catalog catalog to use for the Destination.
schema:
type: string
title: Schema
description: Name of the Unity Catalog schema to use for the Destination.
eventsVolumeName:
type: string
title: Events volume name
description: Name of the Unity Catalog volume where event data is written.
clientTextSecret:
type: string
title: Client Secret
description: OAuth client secret for Unity Catalog authentication
timeoutSec:
type: integer
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it.
minimum: 30
description:
type: string
title: Description
description: Optional description for this configuration.
compress:
$ref: "#/components/schemas/CompressionOptionsHttp"
description: Data compression format to apply to HTTP content before it is
delivered
compressionLevel:
$ref: "#/components/schemas/CompressionLevelOptions"
description: Compression level to apply before moving files to final destination
automaticSchema:
type: boolean
title: Automatic schema
description: Automatically calculate the schema based on the events of each
Parquet file generated
parquetSchema:
type: string
title: Parquet schema
description: To add a new schema, navigate to Processing > Knowledge > Parquet
Schemas
minLength: 1
parquetVersion:
$ref: "#/components/schemas/ParquetVersionOptions"
description: Determines which data types are supported and how they are
represented
parquetDataPageVersion:
$ref: "#/components/schemas/DataPageVersionOptions"
description: Serialization format of data pages. Note that some reader
implementations use Data page V2's attributes to work more
efficiently, while others ignore it.
parquetRowGroupLength:
type: number
title: Group row limit
description: The number of rows that every group will contain. The final group
can contain a smaller number of rows.
minimum: 1
maximum: 67108864
parquetPageSize:
type: string
title: Page size
description: Target memory size for page segments, such as 1MB or 128MB.
Generally, lower values improve reading speed, while higher values
improve compression.
pattern: ^\d+\s*(?:[kK][bB]|[mM][bB]|[gG][bB]|[tT][bB])?$
shouldLogInvalidRows:
type: boolean
title: Log invalid rows
description: Log up to 3 rows that @{product} skips due to data mismatch
keyValueMetadata:
type: array
title: Metadata (optional)
description: 'The metadata of files the Destination writes will include the
properties you add here as key-value pairs. Useful for tagging.
Examples: "key":"OCSF Event Class", "value":"9001"'
minItems: 0
items:
$ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem"
enableStatistics:
type: boolean
title: Write statistics
description: Statistics profile an entire file in terms of minimum/maximum
values within data, numbers of nulls, etc. You can use Parquet tools
to view statistics.
enableWritePageIndex:
type: boolean
title: Write page indexes
description: One page index contains statistics for one data page. Parquet
readers use statistics to enable page skipping.
enablePageChecksum:
type: boolean
title: Write page checksum
description: Parquet tools can use the checksum of a Parquet page to verify data
integrity
emptyDirCleanupSec:
type: number
title: Staging cleanup period
description: How frequently, in seconds, to clean up empty directories
minimum: 10
maximum: 86400
directoryBatchSize:
type: number
title: Directory batch size
description: Number of directories to process in each batch during cleanup of
empty directories. Minimum is 10, maximum is 10000. Higher values
may require more memory.
deadletterPath:
type: string
title: Dead-letter location
description: Storage location for files that fail to reach their final
destination after maximum retries are exceeded
maxRetryNum:
type: number
title: Retry limit
description: The maximum number of times a file will attempt to move to its
final destination before being dead-lettered
minimum: 1
__template_streamtags:
type: string
description: Binds 'streamtags' to a variable for dynamic value resolution. Set
to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'streamtags' at runtime.
__template_partitionExpr:
type: string
description: Binds 'partitionExpr' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'partitionExpr' at runtime.
__template_format:
type: string
description: Binds 'format' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'format' at runtime.
__template_baseFileName:
type: string
description: Binds 'baseFileName' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'baseFileName' at runtime.
__template_fileNameSuffix:
type: string
description: Binds 'fileNameSuffix' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'fileNameSuffix' at
runtime.
__template_onBackpressure:
type: string
description: Binds 'onBackpressure' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'onBackpressure' at
runtime.
__template_compress:
type: string
description: Binds 'compress' to a variable for dynamic value resolution. Set to
variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'compress' at runtime.
__template_parquetSchema:
type: string
description: Binds 'parquetSchema' to a variable for dynamic value resolution.
Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID
(group-scoped). Variable value overrides 'parquetSchema' at runtime.
title: OutputDatabricks
OutputSnowflakeStreaming:
type: object
required:
- type
- accountIdentifier
- user
- pem
- database
- schema
- table
properties:
id:
type: string
title: Output ID
description: Unique ID for this output
type:
type: string
enum:
- snowflake_streaming
description: Connector type identifier.
pipeline:
type: string
title: Pipeline
description: Pipeline to process data before sending out to this output
systemFields:
type: array
title: System fields
description: Fields to automatically add to events, such as cribl_pipe. Supports
wildcards.
items:
type: string
environment:
type: string
title: Environment
description: Optionally, enable this config only on a specified Git branch. If
empty, will be enabled everywhere.
streamtags:
type: array
title: Tags
description: Metadata tags used for categorization and filtering.
items:
type: string
accountIdentifier:
type: string
title: Account identifier
description: "Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)"
user:
type: string
title: User
description: Snowflake user with key-pair authentication configured
pem:
type: object
title: Private key
required:
- keyName
properties:
keyName:
type: string
title: Private key
description: Select the stored secret containing the RSA private key (PEM
format) for Snowflake key-pair authentication
description: Private key
database:
type: string
title: Target database
description: Target database
schema:
type: string
title: Target schema
description: Target schema
table:
type: string
title: Target table
description: Target table
url:
type: string
title: URL
description: Override endpoint URL (for PrivateLink or custom deployments).
Defaults to https://.snowflakecomputing.com:443
role:
type: string
title: Role
description: Snowflake role to assume for this connection
keepAlive:
type: boolean
title: Keep alive
description: Keep connections open between requests. Disable only if
experiencing connection pooling issues.
concurrency:
type: number
title: Request concurrency
description: Maximum number of ongoing requests before blocking
minimum: 1
maximum: 32
maxPayloadSizeKB:
type: number
title: Body size limit (KB)
description: Maximum uncompressed size of each batch. With compression enabled
(default), batches are zstd-compressed before sending. Snowflake has
observed a ~4 MB limit on the compressed wire size.
minimum: 64
maximum: 10240
maxPayloadEvents:
type: number
title: Events-per-request limit
description: Maximum number of events per request. Default is 0 (unlimited,
size-gated only).
minimum: 0
compress:
type: boolean
title: Compress
description: Compress the payload body using zstd compression before sending.
rejectUnauthorized:
type: boolean
title: Validate server certs
description: >-
Reject certificates not authorized by a CA in the CA certificate
path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence.
timeoutSec:
type: number
minimum: 1
maximum: 9007199254740991
title: Request timeout
description: Amount of time, in seconds, to wait for a request to complete
before canceling it
maxConnectionReuseSec:
type: number
minimum: 0
title: Max connection reuse (seconds)
description: How long, in seconds, to reuse a keep-alive connection after its
first use before forcing it closed. Set to 0 to disable the
time-based close and reuse connections for as long as the
destination server permits.
flushPeriodSec:
type: number
title: Flush period (sec)
description: Maximum time between requests. Small values could cause the payload
size to be smaller than the configured Body size limit.
extraHttpHeaders:
type: array
title: Extra HTTP headers
description: Headers to add to all events
items:
$ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic"
failedRequestLoggingMode:
$ref: "#/components/schemas/FailedRequestLoggingModeOptions"
description: Data to log when a request fails. All headers are redacted by
default, unless listed as safe headers below.
safeHeaders:
type: array
title: Safe headers
description: List of headers that are safe to log in plain text
items:
type: string
controlRequestTimeoutSec:
type: number
title: Snowflake channel open timeout
description: Timeout in seconds for token exchange, channel open/close, and
hostname discovery. Defaults to 30 seconds.
minimum: 1
maximum: 300
responseRetrySettings:
type: array
title: Settings for failed HTTP requests
description: Automatically retry after unsuccessful response status codes, such
as 429 (Too Many Requests) or 503 (Service Unavailable)
minItems: 0
items:
$ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook"
timeoutRetrySettings:
$ref: "#/components/schemas/TimeoutRetrySettingsType"
responseHonorRetryAfterHeader:
type: boolean
title: Honor Retry-After header
description: Honor any Retry-After header that specifies a delay (in seconds) no
longer than 180 seconds after the retry request. @{product} limits
the delay to 180 seconds, even if the Retry-After header specifies a
longer delay. When enabled, takes precedence over user-configured
retry options. When disabled, all Retry-After headers are ignored.
onBackpressure:
$ref: "#/components/schemas/BackpressureBehaviorOptions"
description: How to handle events when all receivers are exerting backpressure
description:
type: string
title: Description
description: Optional description for this configuration.
pqStrictOrdering:
title: Strict ordering
description: Use FIFO (first in, first out) processing. Disable to forward new
events to receivers before queue is flushed.
type: boolean
pqRatePerSec:
type: number
title: Drain rate limit (EPS)
description: Throttling rate (in events per second) to impose while writing to
Destinations from PQ. Defaults to 0, which disables throttling.
minimum: 0
pqMode:
$ref: "#/components/schemas/ModeOptions"
description: In Error mode, PQ writes events to the filesystem if the
Destination is unavailable. In Backpressure mode, PQ writes events
to the filesystem when it detects backpressure from the Destination.
In Always On mode, PQ always writes events to the filesystem.
pqMaxBufferSize:
type: number
title: Buffer size limit (events - deprecated)
description: Maximum number of events to hold in memory before writing the
events to disk. Deprecated and only supported in workers < v4.17.0.
Use pqMaxBufferSizeBytes instead.
minimum: 42
maximum: 1000
pqMaxBackpressureSec:
type: number
title: Backpressure duration limit
description: How long (in seconds) to wait for backpressure to resolve before
engaging the queue
minimum: 0
pqMaxFileSize:
type: string
title: File size limit
description: The maximum size to store in each queue file before closing and
optionally compressing (KB, MB, etc.)
pattern: ^\d+\s*(?:\w{2})?$
pqMaxSize:
type: string
title: Queue size limit
description: The maximum disk space that the queue can consume (as an average
per Worker Process) before queueing stops. Enter a numeral with
units of KB, MB, etc.
pattern: ^\d+\s*(?:\w{2})?$
pqPath:
type: string
title: Queue file path
description: "The location for the persistent queue files. To this field's value, the system will append: /