Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖 🔔 ੆Help button for documentation
    • Getting Data In

      • Basic Concepts
      • Assess Your Data Before Ingestion
      • What are Data Sources?
      • What Data Can LogScale Ingest?
      • Methods for Data Ingest
        • Falcon LogScale Collector
        • CrowdStream
        • HTTP / HTTPS API
        • Syslog
        • Amazon S3 Bucket
        • Azure Event Hubs
        • Google Cloud Logging
        • Kafka
        • SNMP Traps
        • Docker Collector
        • Windows Event Collector
        • Database Logs (JDBC)
        • Filebeat
        • Logstash
        • Fluentd
      • What is Data Parsing?
      • How is Data Impacted?
        • Types of Event Fields
          • Metadata Fields
          • Tag Fields
          • User Fields
        • Parsing Log Data Example
        • Important System Fields
          • Field @rawstring
          • Field @timestamp
          • Field @ingesttimestamp
          • Field #repo
          • Field #type
      • Example GDI Data Flows
    • How to Get Data in

      • Getting Data In Process
      • Popular Ingest Methods
        • Amazon S3 Bucket
          • Set up Amazon S3 as an ingest method
        • Azure Event Hubs
          • Set up Azure Event Hubs as an ingest method
        • Database Source
          • Set up a database as an ingest method
        • Falcon LogScale Collector
          • Install Falcon LogScale Collector
        • Filebeat
          • Set up Filebeat as an ingest method
        • Fluentd
          • Set up Fluentd as an ingest method
        • Google Cloud Logging
          • Set up Google Cloud Logging as an ingest method
        • HTTP / HTTPS API
          • Set up HTTP / HTTPS API as an ingest method
        • Kafka
          • Set up Kafka as an ingest method
        • Logstash
          • Set up Logstash as an ingest method
        • SNMP Traps
          • Set up SNMP Traps as an ingest method
        • Syslog
          • Set up Syslog as an ingest method
        • Windows Event Collector
          • Set up Windows Event Collector as an ingest method
    • Manage Data Ingest
      • Log Shippers
      • Backfilling Data
      • Disabling Ingestion
      • Event Forwarding
        • Event Forwarders
        • Event Forwarding Rules
      • Ingesting FDR Data
        • Cluster Configuration
        • Adjust Polling Nodes Per Feed
        • Ingest FDR Data
          • Troubleshooting FDR Ingest
        • Error Handling
      • Ingest Listeners
      • Ingest Tokens
      • Ingest Feeds
        • Ingest Data from AWS S3
          • Set up a New AWS Ingest Feed
          • Edit Ingest Feed Configuration
          • Delete an Ingest Feed
          • Enable and Disable Ingest Feeds
        • Ingest Data from Azure Event Hubs
          • Set up a New Azure Ingest Feed
          • Edit Azure Ingest Feed Configuration
          • Delete an Azure Ingest Feed
          • Enable and Disable Azure Ingest Feeds

 

    • Falcon LogScale Collector
      • Key Concepts
      • Prerequisities and Sizing
              • Memory Usage Log Messages
      • Installation
        • Full Installation
        • Custom Installation
          • Custom Installation Linux
          • Custom Installation macOS
          • Custom Installation Windows
            • Run the Falcon LogScale Collector Manually with Options
          • Download Installers from the Command-line
          • Update your Custom Log Collector Installation
      • Configuration
        • Create a Configuration - Remote
        • Create a Configuration - Local
        • Validate a Configuration
        • Minimal Configuration Example
        • Configuration Reference and Examples
          • Configuration Reference
            • Sources (sources)
              • Database Source
              • File Source
              • Windows Event Log Source
              • Syslog Source
              • Syslog via TLS Source
              • Unified Logs Source
              • Journal Source
              • Internal (loopback) Source
              • Command (Exec) Source
            • Sinks (sinks)
              • TLS
              • Queue (queue)
                • Queue Memory
                • Queue Disk
            • Settings (settings)
            • Optional Flags(flags)
            • Fleet Management (fleetManagement)
                • Full (full)
                • Local(localConfig)
                • Legacy (legacy)
            • Data Directory (dataDirectory)
          • Configuration Examples
              • Database Source
              • Exec (cmd) Source
              • File (Linux) Source
              • File (Linux) Source (NG-SIEM)
              • File Source
              • File Source with Transforms
              • File Source with Windows file paths
              • Journal Source
              • Syslog Source
              • Syslog Source (NG-SIEM)
              • Syslog Source Multi-Destination
              • Syslog-tls Source
              • Unified Log Source
              • Windows Event Log Source
              • Windows Multi-Source
              • Windows Multi-Source (NG-SIEM)
              • Windows Source (NG-SIEM)
          • Configuration Use Cases
            • All Sources: How to Use Transforms
            • All Sources: Use a Parser
            • All Sources: Set a Proxy Server
            • Syslog Source: Multi-Destinations Sinks
            • File Source: Read Compressed Files
            • File Source: File Rotation Support
            • Windows Source: Filters and Customizations
      • Fleet and Group Management
        • Fleet Overview
        • Security Advisories
        • Fleet Insights
          • View Metrics and Errors
          • Aggregate Data
          • Filter Data
        • Manage Groups
        • Manage Remote Configurations
        • Enroll Instances
        • Internal Logging
      • Troubleshooting
        • Debug Commands
        • Query Commands - Reference
          • Query Internal Logs
          • Query Metrics
      • Metrics
      • Metadata
      • Deployment Architectures
        • Collect Kubernetes Pod Logs
          • Configure a Falcon LogScale Collector Helm Chart
          • Falcon LogScale Collector Helm Chart
          • Helm Chart Adding Additional Metadata
          • Helm Chart with Falcon CWP (Cloud Workload Protection)
      • Related KB Articles
      • Falcon LogScale Collector Releases
        • Falcon LogScale Collector 1.11.5 GA (2026-06-17)
        • Falcon LogScale Collector 1.11.4 GA (2026-05-20)
        • Falcon LogScale Collector 1.11.2 GA (2026-04-21)
        • Falcon LogScale Collector 1.11.1 GA (2026-02-25)
        • Falcon LogScale Collector 1.11.0 GA (2026-01-27)
        • Falcon LogScale Collector 1.10.3 GA (2025-11-25)
        • Falcon LogScale Collector 1.10.2 GA (2025-10-20)
        • Falcon LogScale Collector 1.10.1 GA (2025-08-20)
        • Falcon LogScale Collector 1.10.0 GA (2025-08-15)
        • Falcon LogScale Collector 1.9.1 GA (2025-05-20)
        • Falcon LogScale Collector 1.9.0 GA (2025-04-14)
        • Falcon LogScale Collector 1.8.3 GA (2025-03-25)
        • Falcon LogScale Collector 1.8.2 GA (2025-03-12)
        • Falcon LogScale Collector 1.8.1 GA (2024-11-20)
        • Falcon LogScale Collector 1.7.4 GA (2024-10-03)
        • Falcon LogScale Collector 1.7.3 GA (2024-08-13)
        • Falcon LogScale Collector 1.7.2 GA (2024-07-09)
        • Falcon LogScale Collector 1.7.1 GA (2024-06-27)
        • Falcon LogScale Collector 1.7.0 GA (2024-06-03)
        • Falcon LogScale Collector 1.6.6 GA (2024-06-13)
        • Falcon LogScale Collector 1.6.5 GA (2024-04-29)
        • Falcon LogScale Collector 1.6.2 GA (2024-02-26)
        • Falcon LogScale Collector 1.6.1 GA (2023-12-12)
        • Falcon LogScale Collector 1.5.3 GA (2023-10-16)
        • Falcon LogScale Collector 1.5.2 GA (2023-10-03)
        • Falcon LogScale Collector 1.5.1 GA (2023-8-28)
        • Falcon LogScale Collector 1.5.0 GA (2023-8-23)
        • Falcon LogScale Collector 1.4.1 GA (2023-6-13)
        • Falcon LogScale Collector 1.4.0 GA (2023-5-08)
        • Falcon LogScale Collector 1.3.4 GA (2023-3-30)
        • Falcon LogScale Collector 1.3.3 Withdrawn (2023-3-21)
        • Falcon LogScale Collector 1.3.2 GA (2023-3-16)
        • Falcon LogScale Collector 1.3.1 GA (2023-3-9)
        • Falcon LogScale Collector 1.3.0 GA (2023-2-7)
        • Falcon LogScale Collector 1.2.3 GA (2023-1-23)
        • Falcon LogScale Collector 1.2.2 GA (2023-1-16)
        • Falcon LogScale Collector 1.2.1 GA (2022-11-10)
        • Falcon LogScale Collector 1.2.0 GA (2022-10-27)
        • Humio Log Collector 1.1.4 GA (2022-10-12)
        • Humio Log Collector 1.1.3 GA (2022-10-03)
        • Humio Log Collector 1.1.2 Not Released (2022-09-29)
        • Humio Log Collector 1.1.1 GA (2022-09-19)
        • Humio Log Collector 1.1.0 GA (2022-06-25)
        • Humio Log Collector 1.0.2 LTS (2022-05-05)
        • Humio Log Collector 1.0.1 LTS (2022-04-25)
        • Humio Log Collector 1.0.0 LTS (2022-04-23)
        • Full Falcon LogScale Collector Release Notes Index

 

    • Package Marketplace
      • Akamai Technologies, Inc.
        • akamai/asec
          • Package akamai/asec Release Notes
          • Parsers and Generated Fields
      • Amazon Web Services, Inc.
        • aws/cloudtrail
          • Package aws/cloudtrail Release Notes
          • Parsers and Generated Fields
        • aws/fsx
          • Package aws/fsx Release Notes
          • Parsers and Generated Fields
        • aws/guardduty
          • Package aws/guardduty Release Notes
          • Parsers and Generated Fields
        • aws/s3-server-access
          • Package aws/s3-server-access Release Notes
          • Parsers and Generated Fields
        • aws/vpcflow
          • Package aws/vpcflow Release Notes
          • Parsers and Generated Fields
        • aws/waf
          • Package aws/waf Release Notes
          • Parsers and Generated Fields
      • AppOmni, Inc
        • appomni/appomni
          • Parsers and Generated Fields
      • Apple Inc.
        • apple/unifiedlog
          • Parsers and Generated Fields
      • Armis, Inc.
        • armis/centrix-iot
          • Parsers and Generated Fields
      • Asimily
        • asimily/iomt
          • Package asimily/iomt Release Notes
          • Parsers and Generated Fields
      • Broadcom Inc.
        • broadcom/proxysg
          • Package broadcom/proxysg Release Notes
          • Parsers and Generated Fields
      • Check Point Software Technologies Ltd.
        • checkpoint/ngfw
          • Package checkpoint/ngfw Release Notes
          • Parsers and Generated Fields
      • Cisco Systems, Inc.
        • cisco/asa
          • Package cisco/asa Release Notes
          • cisco/asa Dashboards
        • cisco/duo
          • Package cisco/duo Release Notes
          • Parsers and Generated Fields
        • cisco/firepower
          • Package cisco/firepower Release Notes
          • Parsers and Generated Fields
        • cisco/ios
          • Package cisco/ios Release Notes
          • Parsers and Generated Fields
        • cisco/ise
          • Package cisco/ise Release Notes
          • Parsers and Generated Fields
        • cisco/meraki
          • Package cisco/meraki Release Notes
          • Parsers and Generated Fields
        • cisco/umbrella
          • Package cisco/umbrella Release Notes
          • Parsers and Generated Fields
      • Citrix Systems, Inc.
        • citrix/netscaler
          • Package citrix/netscaler Release Notes
          • Parsers and Generated Fields
      • Claroty Ltd.
        • claroty/ctd
          • Package claroty/ctd Release Notes
          • Parsers and Generated Fields
      • CloudFlare, Inc.
        • cloudflare/area1emailsecurity
          • Installing the Package
          • Configuring Ingest for Cloudflare Area 1 Logs
          • Verify Data is Arriving in LogScale
          • cloudflare/area1emailsecurity Dashboards
        • cloudflare/zerotrust
          • Package cloudflare/zerotrust Release Notes
          • Parsers and Generated Fields
      • Corelight, Inc.
        • corelight/threathuntingguide
          • Parsers and Generated Fields
          • Using Corelight Packages
          • Sample Queries
          • Zeek (Bro) Network Security Monitor
      • CrowdStrike Holdings, Inc.
        • crowdstrike/falcon-devices
          • crowdstrike/falcon-devices Dashboards
        • crowdstrike/fdr
          • Parsers and Generated Fields
          • crowdstrike/fdr Dashboards
        • crowdstrike/fltr-core
          • Package crowdstrike/fltr-core Release Notes
          • crowdstrike/fltr-core Dashboards
        • crowdstrike/fltr-firewall-adversaries
          • crowdstrike/fltr-firewall-adversaries Dashboards
        • crowdstrike/fltr-identityprotection
          • Package crowdstrike/fltr-identityprotection Release Notes
          • crowdstrike/fltr-identityprotection Dashboards
        • crowdstrike/fltr-lolbins
          • Package crowdstrike/fltr-lolbins Release Notes
        • crowdstrike/fltr-tutorial
          • Package crowdstrike/fltr-tutorial Release Notes
          • crowdstrike/fltr-tutorial Dashboards
        • crowdstrike/intel-indicators
          • crowdstrike/intel-indicators Dashboards
        • crowdstrike/ioc
          • Package crowdstrike/ioc Release Notes
          • crowdstrike/ioc Dashboards
        • crowdstrike/logscale-opsgenie
        • crowdstrike/logscale-pagerduty
        • crowdstrike/logscale-slack
        • crowdstrike/logscale-splunk-on-call
        • crowdstrike/siem-connector
          • crowdstrike/siem-connector Dashboards
        • crowdstrike/spotlight
          • Package crowdstrike/spotlight Release Notes
          • crowdstrike/spotlight Dashboards
      • CyberArk Software Ltd.
        • cyberark/pam
          • cyberark/pam Dashboards
        • cyberark/vault
          • cyberark/vault Dashboards
      • Darktrace Limited
        • darktrace/detect
          • Package darktrace/detect Release Notes
          • Parsers and Generated Fields
      • Dell, Inc.
        • dell/isilon
          • Package dell/isilon Release Notes
          • Parsers and Generated Fields
      • Docker Inc.
        • docker/metrics
          • docker/metrics Dashboards
      • Dragos
      • Everpure, Inc.
        • everpure/flasharray
          • Package everpure/flasharray Release Notes
          • Parsers and Generated Fields
        • everpure/flashblade
          • Package everpure/flashblade Release Notes
          • Parsers and Generated Fields
      • ExtraHop Networks, Inc.
        • extrahop/revealx
          • extrahop/revealx Dashboards
      • F5, Inc.
        • f5networks/bigip
          • Package f5networks/bigip Release Notes
          • Parsers and Generated Fields
      • Forcepoint LLC
        • forcepoint/dlp
          • Package forcepoint/dlp Release Notes
          • Parsers and Generated Fields
      • Fortinet Inc.
        • fortinet/fortigate
          • Package fortinet/fortigate Release Notes
          • Parsers and Generated Fields
        • fortinet/fortimail
          • Package fortinet/fortimail Release Notes
          • Parsers and Generated Fields
      • Github
        • github/events
          • github/events Dashboards
      • Google LLC
        • google/chrome-enterprise-security-events
          • Package google/chrome-enterprise-security-events Release Notes
          • Parsers and Generated Fields
          • google/chrome-enterprise-security-events Dashboards
        • google/chronicle-alerts
          • google/chronicle-alerts Dashboards
        • google/chronicle-ioc
          • google/chronicle-ioc Dashboards
        • google/gcp-audit
          • google/gcp-audit Dashboards
      • HAProxy Technologies LLC
        • haproxy/haproxy
          • Package haproxy/haproxy Release Notes
          • Parsers and Generated Fields
      • HPE Aruba Networking
        • aruba/clearpass
          • Package aruba/clearpass Release Notes
          • Parsers and Generated Fields
      • Humio
        • humio/activity
          • Package humio/activity Release Notes
          • humio/activity Dashboards
        • humio/insights
          • Package humio/insights Release Notes
          • Parsers and Generated Fields
          • humio/insights Dashboards
        • humio/vector-metrics
          • humio/vector-metrics Dashboards
      • Imperva, Inc.
        • imperva/cloud-waf
          • Package imperva/cloud-waf Release Notes
          • Parsers and Generated Fields
          • imperva/cloud-waf Dashboards
      • Infoblox, Inc.
        • infoblox/nios
          • Package infoblox/nios Release Notes
          • Parsers and Generated Fields
      • Island Technology, Inc
        • island/island
          • Package island/island Release Notes
          • Parsers and Generated Fields
          • island/island Dashboards
      • Juniper Networks, Inc.
        • juniper/srx
          • Package juniper/srx Release Notes
          • Parsers and Generated Fields
      • Medigate
      • Microsoft Corporation
        • microsoft/dhcp-client
          • Package microsoft/dhcp-client Release Notes
          • Parsers and Generated Fields
        • microsoft/dhcp-server
          • Package microsoft/dhcp-server Release Notes
          • Parsers and Generated Fields
        • microsoft/iis
          • Parsers and Generated Fields
          • Microsoft IIS Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Microsoft IIS Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • microsoft/iis Dashboards
        • microsoft/microsoft365
          • Package microsoft/microsoft365 Release Notes
          • Parsers and Generated Fields
          • microsoft/microsoft365 Dashboards
        • microsoft/sysmon
          • Package microsoft/sysmon Release Notes
          • Parsers and Generated Fields
        • microsoft/windows-dns-debug
          • Package microsoft/windows-dns-debug Release Notes
          • Parsers and Generated Fields
      • Mimecast Services Ltd.
        • mimecast/email-security
          • Package mimecast/email-security Release Notes
          • Parsers and Generated Fields
          • mimecast/email-security Dashboards
      • Netskope, Inc.
        • netskope/casb
          • Package netskope/casb Release Notes
          • netskope/casb Dashboards
      • Nginx
        • nginx/nginx
          • Package nginx/nginx Release Notes
          • Parsers and Generated Fields
          • NGINX Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Nginx Server logs
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Access Logs
          • nginx/nginx Dashboards
      • Nozomi Networks Inc
        • nozomi/ids
          • Package nozomi/ids Release Notes
          • Parsers and Generated Fields
      • Obsidian Security, Inc.
        • obsidiansecurity/actionnotification
          • Parsers and Generated Fields
          • obsidiansecurity/actionnotification Dashboards
      • Okta, Inc.
        • okta/sso
          • Package okta/sso Release Notes
          • Parsers and Generated Fields
      • One Identity LLC
        • oneidentity/onelogin
          • Parsers and Generated Fields
      • Ordr, Inc.
        • ordr/ordr
          • Parsers and Generated Fields
          • ordr/ordr Dashboards
      • Palo Alto Networks, Inc.
        • palo-alto/prisma-sd-wan
          • Package palo-alto/prisma-sd-wan Release Notes
          • Parsers and Generated Fields
        • paloalto/firewall
          • Package paloalto/firewall Release Notes
          • Parsers and Generated Fields
      • Ping Identity Corporation
        • pingidentity/pingone
          • Package pingidentity/pingone Release Notes
          • Parsers and Generated Fields
          • Install the Package in LogScale
          • Configure Ingest for PingOne Service
          • Verify Data is Arriving in LogScale
          • pingidentity/pingone Dashboards
      • Proofpoint, Inc.
        • proofpoint/tap-siem-api
          • Package proofpoint/tap-siem-api Release Notes
          • Parsers and Generated Fields
      • Radware, Inc.
        • radware/alteon
          • Package radware/alteon Release Notes
          • Parsers and Generated Fields
      • Red Hat, Inc.
        • redhat/ansible
          • Package redhat/ansible Release Notes
          • Parsers and Generated Fields
          • redhat/ansible Dashboards
      • Robust Intelligence
      • Rubicon Communications LLC (Netgate)
        • netgate/pfsense
          • Package netgate/pfsense Release Notes
          • Parsers and Generated Fields
      • Rubrik, Inc.
        • rubrik/security-cloud
          • Package rubrik/security-cloud Release Notes
          • Parsers and Generated Fields
          • rubrik/security-cloud Dashboards
      • Ruby
        • ruby/logger
          • Parsers and Generated Fields
          • ruby/logger Dashboards
      • ServiceNow Inc.
        • servicenow/servicenow
          • Installing the Package in LogScale
          • servicenow/servicenow Dashboards
      • Talon
        • talon/talon-cyber-security
          • Parsers and Generated Fields
          • Configure the integration from the Talon Management Console
          • Verify Data is Arriving in LogScale
          • talon/talon-cyber-security Dashboards
      • Tausight Inc.
        • tausight/ephi-risk-posture
          • Package tausight/ephi-risk-posture Release Notes
          • Parsers and Generated Fields
      • The Apache Software Foundation (ASF)
        • apache/http-server
          • Package apache/http-server Release Notes
          • Parsers and Generated Fields
          • Apache HTTP Server Configuration
          • Installing the Package in LogScale
          • Configure Ingest for Apache HTTP Server
          • Verify Data is Arriving in LogScale
          • Extending Parsers for Custom Logs
          • apache/http-server Dashboards
        • apache/kafka-metricbeat
          • apache/kafka-metricbeat Dashboards
      • The Linux Foundation
        • linux/system-logs
          • Package linux/system-logs Release Notes
          • linux/system-logs Dashboards
      • Trellix
        • trellix/fireeye-nx
          • Package trellix/fireeye-nx Release Notes
          • Parsers and Generated Fields
      • Vectra AI, Inc.
        • vectra/detections
          • vectra/detections Dashboards
      • Veeam Software
        • veeam/veeamdataplatform
          • Package veeam/veeamdataplatform Release Notes
          • Parsers and Generated Fields
          • veeam/veeamdataplatform Dashboards
      • Zoom Video Communications, Inc.
        • zoom/qss
          • Package zoom/qss Release Notes
          • Parsers and Generated Fields
      • Zscaler, Inc.
        • zscaler/deception
          • Package zscaler/deception Release Notes
          • Parsers and Generated Fields
        • zscaler/internet-access
          • Package zscaler/internet-access Release Notes
          • Parsers and Generated Fields
          • Example Queries
          • zscaler/internet-access Dashboards
        • zscaler/private-access
          • Package zscaler/private-access Release Notes
          • Parsers and Generated Fields
    • Package Reference
    • Dashboard Reference
    • Package Management
      • Install & Update Packages
      • Package Marketplace
      • Create a Package
      • Package File Formats
      • Referencing Package Assets
      • Developer Guidelines
        • Improve an Existing Package or Create a New Package
        • Data Ingest Guidelines
        • Asset Guidelines
          • Parsers Best Practices
          • LogScale Query Language Best Practices
          • Dashboard Best Practices
          • Dashboard Widgets
          • Alerts and Saved Searches Best Practices
          • Naming and Informational Notes
        • Package Content Guidelines
        • Guidelines for Submitting a Package to LogScale Marketplace
      • Insights Package
        • Insights Overview Dashboard
        • Insights Ingest Dashboard
        • Insights Hosts Dashboard
        • Bucket Storage Dashboard
        • Kafka Dashboard
        • Insights Search Dashboard
        • Request-Response
        • Insights Segments & Datasources Dashboard
        • Insights Errors Dashboard
    • Other Integrations
      • Tines Alerts
      • XSOAR Security Management
      • Prometheus
      • Kubernetes Log Format
      • Grafana
      • Cribl CrowdStream
        • Simple or Complex Routing?
        • Navigate Between User Interfaces
        • Configure a Source
        • Configure a Destination
        • Connect: Passthru, Pipeline, or Pack
        • Commit/Deploy Config Changes
        • Moving Ahead with CrowdStream
    • Log Formats
      • NetFlow Log Format
      • Heroku Log Format
      • Linux
        • Linux System Logs
      • Azure Service Fabric Log Format
      • Docker Log Format
      • Kafka Connect Log Format
      • Amazon CloudWatch Log Format
Falcon LogScale Documentation
/ LogScale Getting Data In
/ How to Get Data in
/ Popular Ingest Methods
/ Fluentd

Set up Fluentd as an ingest method

Step 1 - Create a Fluentd ingest token

Why? Ingest tokens authenticate and authorize Fluentd instances to send data to your repository. They control which parsers can be used and what fields can be populated by Fluentd.

Detailed steps:

  1. Sign in to Falcon LogScale, and browse to your repository.

  2. Click Settings, Ingest Tokens.

  3. Click Add token.

  4. Type in a descriptive name (for example, fluentd-production-cluster).

  5. Set the appropriate permissions:

    • Assign parser to allow Fluentd to specify parsers based on log source type

    • Assign fields to enable field creation from Fluentd metadata and log data

  6. Click Create token to save the token and securely store the generated string - you'll need this when configuring Fluentd output.

  7. Note your LogScale ingestion endpoint URL:

    • For cloud deployments: Typically https://cloud.humio.com or your regional endpoint

    • For on-premises deployments: Your self-hosted LogScale URL

    • The full ingestion endpoint will be: https://cloud.humio.com/api/v1/ingest/humio-structured

Step 2 - Plan your Fluentd deployment

Why? Planning your deployment strategy ensures optimal coverage, performance, and scalability. Fluentd's flexible architecture supports various deployment patterns, and choosing the right approach depends on your infrastructure, log volumes, and processing requirements.

Detailed steps:

  1. Identify your deployment pattern:

    • Agent-based deployment: Install Fluentd on each host that generates logs

      • Best for: Servers, VMs, physical hosts

      • Advantages: Direct file access, low latency, host-level processing

      • Considerations: Requires installation and management on each host

      • Typical use: td-agent (stable Fluentd distribution) on each server

    • Aggregator deployment: Deploy Fluentd as centralized log aggregation layer

      • Best for: High-volume environments, complex processing requirements

      • Advantages: Centralized processing, reduced endpoint resource usage, buffering and retry logic

      • Considerations: Network bandwidth, aggregator capacity planning

      • Typical use: Lightweight forwarders on endpoints, heavy processing on aggregators

    • Hybrid deployment: Combine agent and aggregator patterns

      • Best for: Large-scale, multi-tier environments

      • Advantages: Distributed processing, fault tolerance, scalability

      • Considerations: Increased complexity, multiple configuration layers

      • Typical use: Fluentd agents forward to Fluentd aggregators, which forward to LogScale

    • Kubernetes deployment: Deploy Fluentd as DaemonSet or sidecar

      • Best for: Kubernetes clusters, containerized applications

      • Advantages: Native Kubernetes integration, automatic pod discovery, metadata enrichment

      • Considerations: Resource allocation per node, ConfigMap management

      • Typical use: Fluent Bit for collection, Fluentd for aggregation and processing

  2. Assess existing Fluentd deployments:

    • Inventory current Fluentd/td-agent installations and versions

    • Review existing Fluentd configurations and plugins

    • Identify current output destinations (Elasticsearch, S3, Kafka, etc.)

    • Determine if you're migrating completely or implementing multi-output routing

    • Document custom plugins or filters that may need adaptation

  3. Determine log sources and input plugins:

    • File-based logs: tail plugin for log files

    • Syslog: syslog plugin for network syslog reception

    • HTTP/REST: http plugin for webhook integrations

    • TCP/UDP: forward plugin for Fluentd-to-Fluentd communication

    • Container logs: Docker, Kubernetes container logs

    • Application logs: Direct integration via Fluentd libraries

    • Cloud services: AWS CloudWatch, Azure Monitor, GCP Logging via plugins

    • Databases: SQL queries via database plugins

  4. Assess resource requirements:

    • CPU: 0.5-2 CPU cores per Fluentd instance (varies with processing complexity)

    • Memory: 512 MB - 4 GB depending on buffer sizes and plugin usage

    • Disk: 100-500 MB for installation plus buffer space (configurable, can be several GB)

    • Network: Outbound HTTPS (443) to LogScale endpoints, inbound ports for receiving logs

  5. Plan processing and transformation requirements:

    • Identify parsing needs (JSON, regex, multiline, etc.)

    • Determine filtering requirements (include/exclude patterns)

    • Plan field transformations and enrichment

    • Design routing logic for multi-destination scenarios

    • Consider performance impact of complex processing pipelines

  6. Plan network connectivity:

    • Identify LogScale ingestion endpoints (cloud or on-premises)

    • Configure firewall rules for outbound HTTPS connections

    • Configure firewall rules for inbound connections (if using aggregator pattern)

    • Determine if proxy configuration is required

    • Plan for TLS/SSL certificate validation

  7. Plan configuration management:

    • Decide on configuration distribution method (manual, Ansible, Puppet, Chef, Kubernetes ConfigMaps)

    • Plan for configuration versioning and change control

    • Determine update and upgrade strategy for Fluentd versions

    • Consider using configuration management for plugin installation

Step 3 - Install Fluentd

Why? Installing Fluentd on your target systems enables log collection, processing, and forwarding. The installation method varies by platform and deployment pattern, but all methods result in a running Fluentd instance ready for configuration.

Detailed steps:

  1. For Debian/Ubuntu Linux systems (using td-agent):

    1. Install td-agent (stable Fluentd distribution):

      curl -fsSL https://toolbelt.treasuredata.com/sh/install-ubuntu-jammy-td-agent4.sh | sh
    2. Start and enable the td-agent service:

      sudo systemctl start td-agent
      sudo systemctl enable td-agent
    3. Verify the installation:

      td-agent --version
  2. For RHEL/CentOS/Amazon Linux systems (using td-agent):

    1. Install td-agent:

      curl -fsSL https://toolbelt.treasuredata.com/sh/install-redhat-td-agent4.sh | sh
    2. Start and enable the td-agent service:

      sudo systemctl start td-agent
      sudo systemctl enable td-agent
    3. Verify the installation:

      td-agent --version
  3. For Windows systems:

    1. Download the td-agent MSI installer from the Treasure Data website

    2. Run the installer with administrative privileges:

      msiexec /i td-agent-4.x.x-x64.msi /qn
    3. Start the td-agent service:

      net start fluentdwinsvc
    4. Verify the installation:

      "C:\opt\td-agent\bin\td-agent.bat" --version
  4. For macOS systems:

    1. Install using Homebrew:

      brew install fluentd
    2. Alternatively, install using Ruby gem:

      gem install fluentd
    3. Verify the installation:

      fluentd --version
  5. For Docker containers:

    1. Pull the official Fluentd Docker image:

      docker pull fluent/fluentd:v1.16-1
    2. Run Fluentd container with configuration:

      docker run -d \
        --name fluentd \
        -p 24224:24224 \
        -p 24224:24224/udp \
        -v /path/to/fluentd.conf:/fluentd/etc/fluent.conf \
        -v /var/log:/var/log:ro \
        fluent/fluentd:v1.16-1
    3. For custom plugins, create a custom Dockerfile:

      FROM fluent/fluentd:v1.16-1
      
      USER root
      
      # Install plugins
      RUN gem install fluent-plugin-rewrite-tag-filter
      RUN gem install fluent-plugin-record-modifier
      
      USER fluent
  6. For Kubernetes (DaemonSet deployment):

    1. Create a namespace for Fluentd:

      kubectl create namespace logging
    2. Create a Kubernetes manifest for Fluentd DaemonSet:

      apiVersion: v1
      kind: ServiceAccount
      metadata:
        name: fluentd
        namespace: logging
      ---
      apiVersion: rbac.authorization.k8s.io/v1
      kind: ClusterRole
      metadata:
        name: fluentd
      rules:
      - apiGroups:
        - ""
        resources:
        - pods
        - namespaces
        verbs:
        - get
        - list
        - watch
      ---
      apiVersion: rbac.authorization.k8s.io/v1
      kind: ClusterRoleBinding
      metadata:
        name: fluentd
      roleRef:
        kind: ClusterRole
        name: fluentd
        apiGroup: rbac.authorization.k8s.io
      subjects:
      - kind: ServiceAccount
        name: fluentd
        namespace: logging
      ---
      apiVersion: v1
      kind: ConfigMap
      metadata:
        name: fluentd-config
        namespace: logging
      data:
        fluent.conf: |
          # Configuration will be added in Step 4
      ---
      apiVersion: apps/v1
      kind: DaemonSet
      metadata:
        name: fluentd
        namespace: logging
        labels:
          app: fluentd
      spec:
        selector:
          matchLabels:
            app: fluentd
        template:
          metadata:
            labels:
              app: fluentd
          spec:
            serviceAccount: fluentd
            serviceAccountName: fluentd
            tolerations:
            - key: node-role.kubernetes.io/master
              effect: NoSchedule
            containers:
            - name: fluentd
              image: fluent/fluentd-kubernetes-daemonset:v1.16-debian-1
              env:
              - name: FLUENT_UID
                value: "0"
              resources:
                limits:
                  memory: 512Mi
                requests:
                  cpu: 100m
                  memory: 200Mi
              volumeMounts:
              - name: config
                mountPath: /fluentd/etc
              - name: varlog
                mountPath: /var/log
              - name: varlibdockercontainers
                mountPath: /var/lib/docker/containers
                readOnly: true
            terminationGracePeriodSeconds: 30
            volumes:
            - name: config
              configMap:
                name: fluentd-config
            - name: varlog
              hostPath:
                path: /var/log
            - name: varlibdockercontainers
              hostPath:
                path: /var/lib/docker/containers
    3. Apply the manifest:

      kubectl apply -f fluentd-daemonset.yaml
    4. Verify deployment:

      kubectl get daemonset -n logging
      kubectl get pods -n logging -l app=fluentd
  7. Install required plugins for LogScale integration:

    • For td-agent installations:

      sudo td-agent-gem install fluent-plugin-rewrite-tag-filter
      sudo td-agent-gem install fluent-plugin-record-modifier
    • For native Fluentd installations:

      fluent-gem install fluent-plugin-rewrite-tag-filter
      fluent-gem install fluent-plugin-record-modifier
    • These plugins enable advanced log processing and field manipulation

  8. Verify installation across all platforms:

    • Check that Fluentd/td-agent binary is present and executable

    • Verify the service is installed but not yet fully configured

    • Confirm configuration directory exists and is writable

    • Check Fluentd version (1.14+ recommended for best compatibility)

Step 4 - Configure Fluentd to send data to LogScale

Why? Configuration defines what logs Fluentd collects, how they're processed, and where they're sent. Proper configuration ensures efficient collection, sophisticated transformation, and reliable delivery to LogScale using Fluentd's HTTP output plugin.

Detailed steps:

  1. Locate the Fluentd configuration file:

    • Linux (td-agent): /etc/td-agent/td-agent.conf

    • Windows (td-agent): C:\opt\td-agent\etc\td-agent\td-agent.conf

    • Native Fluentd: /etc/fluent/fluent.conf or custom location

    • Docker/Kubernetes: Mount configuration via volume or ConfigMap

  2. Back up the existing configuration:

    sudo cp /etc/td-agent/td-agent.conf /etc/td-agent/td-agent.conf.backup
  3. Understand Fluentd configuration structure:

    • <source>: Defines input sources (where logs come from)

    • <filter>: Defines processing and transformation rules

    • <match>: Defines output destinations (where logs go)

    • Tags: Route events through the pipeline based on patterns

    • Events flow: source → filter → match (output)

  4. Configure basic file input (tail plugin):

    <source>
      @type tail
      
      # Path to log files (supports wildcards)
      path /var/log/application/*.log
      
      # Position file to track reading progress
      pos_file /var/log/td-agent/application.log.pos
      
      # Tag for routing
      tag application.logs
      
      # Parser for log format
      <parse>
        @type json
        time_key timestamp
        time_format %Y-%m-%dT%H:%M:%S.%L%z
      </parse>
      
      # Read from end of file (don't read historical data)
      read_from_head false
      
      # Refresh interval for checking new files
      refresh_interval 60s
    </source>
    • The path setting defines which files to monitor

    • The pos_file tracks file positions to prevent duplicate ingestion

    • The tag routes events through the processing pipeline

  5. Configure multiline log parsing (for stack traces):

    <source>
      @type tail
      path /var/log/application/error.log
      pos_file /var/log/td-agent/error.log.pos
      tag application.errors
      
      <parse>
        @type multiline
        format_firstline /^\d{4}-\d{2}-\d{2}/
        format1 /^(?<timestamp>\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}) \[(?<level>\w+)\] (?<message>.*)/
      </parse>
    </source>
    • Multiline parsing combines multiple lines into single events

    • The format_firstline pattern identifies the start of new events

  6. Configure syslog input:

    <source>
      @type syslog
      
      # Listening port
      port 5140
      
      # Protocol (tcp or udp)
      protocol_type tcp
      
      # Tag
      tag syslog.messages
      
      # Parser
      <parse>
        @type syslog
        message_format rfc5424
      </parse>
    </source>
    • The syslog input receives logs from network devices and remote systems

  7. Configure HTTP input (for webhook integrations):

    <source>
      @type http
      
      # Listening port
      port 8888
      
      # Bind address
      bind 0.0.0.0
      
      # Body size limit
      body_size_limit 32m
      
      # Keep alive timeout
      keepalive_timeout 10s
      
      # Tag (can be overridden by HTTP request)
      tag http.events
    </source>
    • The HTTP input receives logs via HTTP POST requests

  8. Configure forward input (for Fluentd-to-Fluentd communication):

    <source>
      @type forward
      
      # Listening port
      port 24224
      
      # Bind address
      bind 0.0.0.0
      
      # Optional: Shared key for authentication
      <security>
        self_hostname aggregator-01
        shared_key secure_shared_key_here
      </security>
    </source>
    • The forward input receives logs from other Fluentd instances

    • This enables aggregator deployment patterns

  9. Configure Kubernetes container log collection:

    <source>
      @type tail
      path /var/log/containers/*.log
      pos_file /var/log/fluentd-containers.log.pos
      tag kubernetes.*
      read_from_head true
      
      <parse>
        @type json
        time_format %Y-%m-%dT%H:%M:%S.%NZ
      </parse>
    </source>
    
    # Enrich with Kubernetes metadata
    <filter kubernetes.**>
      @type kubernetes_metadata
      
      # Kubernetes API endpoint
      kubernetes_url https://kubernetes.default.svc
      
      # Cache settings
      cache_size 1000
      cache_ttl 3600
      
      # Watch for pod changes
      watch true
    </filter>
    • The kubernetes_metadata filter enriches events with pod, namespace, and container information

  10. Configure filters for data transformation:

    # Add custom fields
    <filter application.**>
      @type record_modifier
      
      <record>
        environment production
        datacenter us-east-1
        service_name ${tag_parts[1]}
      </record>
    </filter>
    
    # Parse JSON in message field
    <filter application.**>
      @type parser
      key_name message
      reserve_data true
      
      <parse>
        @type json
      </parse>
    </filter>
    
    # Rename fields
    <filter application.**>
      @type record_transformer
      enable_ruby true
      
      <record>
        log_level ${record["level"]}
        log_message ${record["msg"]}
      </record>
      
      remove_keys level,msg
    </filter>
    
    # Filter out debug logs
    <filter application.**>
      @type grep
      
      <exclude>
        key log_level
        pattern /^DEBUG$/
      </exclude>
    </filter>
    • Filters transform events before sending to LogScale

    • Multiple filters can be chained for complex transformations

  11. Configure the HTTP output for LogScale:

    <match **>
      @type http
      
      # LogScale ingestion endpoint
      endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
      
      # HTTP method
      http_method post
      
      # Headers including authentication
      <headers>
        Authorization Bearer YOUR_INGEST_TOKEN_HERE
        Content-Type application/json
      </headers>
      
      # JSON formatting
      json_array true
      
      # Buffering configuration
      <buffer>
        @type file
        path /var/log/td-agent/buffer/logscale
        
        # Flush settings
        flush_mode interval
        flush_interval 5s
        flush_at_shutdown true
        
        # Chunk settings
        chunk_limit_size 5M
        chunk_limit_records 1000
        
        # Queue settings
        total_limit_size 1GB
        overflow_action drop_oldest_chunk
        
        # Retry settings
        retry_type exponential_backoff
        retry_wait 1s
        retry_max_interval 60s
        retry_timeout 1h
        retry_max_times 10
      </buffer>
      
      # Format for each record
      <format>
        @type json
      </format>
      
      # Error handling
      error_response_as_unrecoverable false
      retryable_response_codes [503, 429]
    </match>
    • The endpoint specifies the LogScale ingestion URL

    • The Authorization header contains your ingest token

    • Buffer settings ensure reliable delivery with retry logic

    • File-based buffering persists events to disk for durability

  12. Configure routing to multiple destinations (optional):

    # Copy events to multiple outputs
    <match application.**>
      @type copy
      
      # Send to LogScale
      <store>
        @type http
        endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
        <headers>
          Authorization Bearer YOUR_LOGSCALE_TOKEN
        </headers>
        <buffer>
          @type file
          path /var/log/td-agent/buffer/logscale
        </buffer>
      </store>
      
      # Also send to another destination
      <store>
        @type elasticsearch
        host elasticsearch.example.com
        port 9200
      </store>
    </match>
    • The copy output sends events to multiple destinations simultaneously

    • This enables gradual migration or hybrid architectures

  13. Example complete configuration for LogScale:

    # System configuration
    <system>
      log_level info
      suppress_repeated_stacktrace true
    </system>
    
    # Input: Tail application logs
    <source>
      @type tail
      path /var/log/application/*.log
      pos_file /var/log/td-agent/application.log.pos
      tag application.logs
      
      <parse>
        @type json
        time_key timestamp
      </parse>
    </source>
    
    # Input: Syslog
    <source>
      @type syslog
      port 5140
      protocol_type tcp
      tag syslog.messages
      
      <parse>
        @type syslog
      </parse>
    </source>
    
    # Filter: Add metadata
    <filter **>
      @type record_modifier
      
      <record>
        hostname ${hostname}
        environment production
      </record>
    </filter>
    
    # Filter: Exclude debug logs
    <filter application.**>
      @type grep
      
      <exclude>
        key level
        pattern /^DEBUG$/
      </exclude>
    </filter>
    
    # Output: Send to LogScale
    <match **>
      @type http
      endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
      
      <headers>
        Authorization Bearer YOUR_INGEST_TOKEN_HERE
        Content-Type application/json
      </headers>
      
      json_array true
      
      <buffer>
        @type file
        path /var/log/td-agent/buffer/logscale
        flush_interval 5s
        chunk_limit_size 5M
        total_limit_size 1GB
        retry_type exponential_backoff
      </buffer>
      
      <format>
        @type json
      </format>
    </match>
  14. Validate the configuration:

    # For td-agent
    sudo td-agent --dry-run -c /etc/td-agent/td-agent.conf
    
    # For native Fluentd
    fluentd --dry-run -c /etc/fluent/fluent.conf
    • This command checks for syntax errors and configuration issues

  15. Restart Fluentd to apply the configuration:

    # For td-agent
    sudo systemctl restart td-agent
    
    # For native Fluentd
    sudo systemctl restart fluentd

Step 5 - Advanced settings configuration

Why? Advanced settings optimize Fluentd's performance, reliability, and resource usage based on your specific log volumes, processing complexity, and operational requirements.

Detailed steps:

  • System-wide Configuration:

    1. Configure system parameters:

      <system>
        # Log level (trace, debug, info, warn, error, fatal)
        log_level info
        
        # Suppress repeated stacktraces
        suppress_repeated_stacktrace true
        
        # Emit error log interval
        emit_error_log_interval 30s
        
        # Process name
        process_name fluentd-production
        
        # Worker configuration
        workers 2
        
        # Root directory
        root_dir /var/log/td-agent
        
        # File permission
        file_permission 0644
        dir_permission 0755
      </system>
      • System settings control Fluentd's global behavior

      • Worker configuration enables multi-process parallelism

  • Advanced Buffer Configuration:

    1. Configure sophisticated buffering strategies:

      <match **>
        @type http
        endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
        
        <buffer tag>
          # Buffer type (file or memory)
          @type file
          path /var/log/td-agent/buffer/logscale
          
          # Flush mode (interval, immediate, lazy)
          flush_mode interval
          flush_interval 5s
          flush_at_shutdown true
          
          # Flush thread count
          flush_thread_count 2
          
          # Chunk settings
          chunk_limit_size 5M
          chunk_limit_records 1000
          chunk_full_threshold 0.9
          
          # Queue settings
          queued_chunks_limit_size 256
          total_limit_size 1GB
          overflow_action drop_oldest_chunk
          
          # Retry settings
          retry_type exponential_backoff
          retry_wait 1s
          retry_exponential_backoff_base 2
          retry_max_interval 60s
          retry_timeout 1h
          retry_max_times 10
          retry_forever false
          
          # Retry randomization
          retry_randomize true
          
          # Disable chunk backup
          disable_chunk_backup false
          
          # Timekey for time-sliced output
          timekey 60
          timekey_wait 10s
          timekey_use_utc true
        </buffer>
      </match>
      • Buffer configuration balances reliability, performance, and resource usage

      • File-based buffers provide durability across restarts

      • Retry settings ensure reliable delivery during transient failures

  • Performance Optimization:

    1. Configure tail input performance settings:

      <source>
        @type tail
        path /var/log/application/*.log
        pos_file /var/log/td-agent/application.log.pos
        tag application.logs
        
        # Read performance
        read_from_head false
        read_lines_limit 1000
        read_bytes_limit_per_second 8388608  # 8MB/s
        
        # File watching
        refresh_interval 60s
        limit_recently_modified 3600
        skip_refresh_on_startup false
        
        # Position file
        pos_file_compaction_interval 72h
        
        # Follow inodes
        follow_inodes true
        
        # Rotation handling
        rotate_wait 5s
        enable_watch_timer true
        enable_stat_watcher true
        
        # Open on every read
        open_on_every_update false
        
        # Emit unmatched lines
        emit_unmatched_lines false
        
        <parse>
          @type json
        </parse>
      </source>
      • Performance settings optimize file reading and rotation handling

      • Rate limiting prevents overwhelming downstream systems

  • Advanced Parsing and Transformation:

    1. Configure complex parsing with regex:

      <source>
        @type tail
        path /var/log/nginx/access.log
        pos_file /var/log/td-agent/nginx.log.pos
        tag nginx.access
        
        <parse>
          @type regexp
          expression /^(?<remote_addr>[^ ]*) - (?<remote_user>[^ ]*) \[(?<time>[^\]]*)\] "(?<method>\S+)(?: +(?<path>[^ ]*) +\S*)?" (?<status>[^ ]*) (?<body_bytes_sent>[^ ]*)(?: "(?<http_referer>[^\"]*)" "(?<http_user_agent>[^\"]*)")?$/
          time_format %d/%b/%Y:%H:%M:%S %z
        </parse>
      </source>
    2. Configure advanced record transformation:

      <filter application.**>
        @type record_transformer
        enable_ruby true
        auto_typecast true
        renew_record false
        renew_time_key false
        keep_keys level,message
        
        <record>
          # Add hostname
          hostname "#{Socket.gethostname}"
          
          # Add timestamp
          ingestion_time ${Time.now.iso8601}
          
          # Transform fields
          severity ${record["level"].upcase}
          
          # Conditional field
          is_error ${record["level"] == "ERROR" ? true : false}
          
          # Extract from nested JSON
          user_id ${record.dig("user", "id")}
          
          # String manipulation
          service ${tag_parts[0]}.${tag_parts[1]}
        </record>
        
        # Remove original fields
        remove_keys level
      </filter>
      • Ruby expressions enable sophisticated field transformations

    3. Configure tag-based routing:

      # Rewrite tags based on content
      <match application.**>
        @type rewrite_tag_filter
        
        <rule>
          key level
          pattern /^ERROR$/
          tag error.${tag}
        </rule>
        
        <rule>
          key level
          pattern /^WARN$/
          tag warning.${tag}
        </rule>
        
        <rule>
          key level
          pattern /.*/
          tag info.${tag}
        </rule>
      </match>
      
      # Route errors to high-priority output
      <match error.**>
        @type http
        endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
        
        <buffer>
          flush_interval 1s  # Faster flush for errors
        </buffer>
      </match>
      
      # Route other logs to normal output
      <match {warning,info}.**>
        @type http
        endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
        
        <buffer>
          flush_interval 5s
        </buffer>
      </match>
      • Tag rewriting enables content-based routing

  • Security Configuration:

    1. Configure TLS for HTTP output:

      <match **>
        @type http
        endpoint https://cloud.humio.com/api/v1/ingest/humio-structured
        
        # TLS settings
        tls_verify_mode peer
        tls_version TLSv1_2
        tls_ciphers HIGH:!aNULL:!MD5
        
        # Client certificate (for mutual TLS)
        # tls_client_cert_path /path/to/client.crt
        # tls_client_private_key_path /path/to/client.key
        # tls_client_private_key_passphrase secret
        
        # CA certificate
        # tls_ca_cert_path /path/to/ca.crt
      </match>
    2. Configure secure forward input:

      <source>
        @type forward
        port 24224
        bind 0.0.0.0
        
        # Security settings
        <security>
          self_hostname aggregator-01
          shared_key secure_shared_key_here
          
          # User authentication
          <user>
            username fluentd-agent
            password secure_password_here
          </user>
        </security>
        
        # TLS settings
        <transport tls>
          cert_path /path/to/server.crt
          private_key_path /path/to/server.key
          private_key_passphrase secret
          
          # Client verification
          client_cert_auth true
          ca_cert_path /path/to/ca.crt
        </transport>
      </source>
      • Security settings protect Fluentd-to-Fluentd communication

  • Monitoring and Metrics:

    1. Enable monitoring endpoints:

      # Monitor agent plugin
      <source>
        @type monitor_agent
        bind 0.0.0.0
        port 24220
        
        # Include configuration
        include_config true
        
        # Include retry information
        include_retry true
      </source>
      
      # Prometheus metrics
      <source>
        @type prometheus
        bind 0.0.0.0
        port 24231
        metrics_path /metrics
      </source>
      
      # Prometheus output monitor
      <source>
        @type prometheus_output_monitor
        interval 10
        
        <labels>
          hostname ${hostname}
          environment production
        </labels>
      </source>
      • Monitor agent exposes Fluentd internal metrics

      • Prometheus integration enables metrics collection

  • High Availability Configuration:

    1. Configure forward output with failover:

      <match **>
        @type forward
        
        # Primary server
        <server>
          host aggregator-01.example.com
          port 24224
          weight 100
        </server>
        
        # Secondary server
        <server>
          host aggregator-02.example.com
          port 24224
          weight 100
          standby
        </server>
        
        # Heartbeat
        heartbeat_type tcp
        heartbeat_interval 1s
        
        # Phi accrual failure detector
        phi_failure_detector true
        phi_threshold 16
        
        # Hard timeout
        hard_timeout 60s
        
        # Buffer
        <buffer>
          @type file
          path /var/log/td-agent/buffer/forward
          flush_interval 5s
        </buffer>
        
        # Security
        <security>
          self_hostname agent-01
          shared_key secure_shared_key_here
        </security>
      </match>
      • Failover configuration ensures high availability

      • Standby servers activate when primary fails

  • Resource Management:

    1. Configure resource limits in systemd service file:

      # Edit /etc/systemd/system/td-agent.service.d/override.conf
      [Service]
      # CPU limit
      CPUQuota=200%
      
      # Memory limit
      MemoryLimit=2G
      
      # File descriptor limit
      LimitNOFILE=65536
      
      # Process limit
      LimitNPROC=16384
    2. Apply the changes:

      sudo systemctl daemon-reload
      sudo systemctl restart td-agent

Step 6 - Start Fluentd and verify operation

Why? Starting Fluentd activates log collection, processing, and forwarding. Verification ensures Fluentd is functioning correctly and data is flowing to LogScale as expected.

Detailed steps:

  1. Start the Fluentd service:

    • For Linux (td-agent):

      sudo systemctl start td-agent
      sudo systemctl enable td-agent  # Enable auto-start on boot
    • For Windows (td-agent):

      net start fluentdwinsvc
    • For Docker:

      docker start fluentd
    • For Kubernetes:

      # DaemonSet starts automatically after deployment
      kubectl rollout status daemonset/fluentd -n logging
  2. Verify Fluentd is running:

    • For Linux:

      sudo systemctl status td-agent
      # Check for "active (running)" status
    • For Windows:

      sc query fluentdwinsvc
      # Check for "RUNNING" state
    • For Docker:

      docker ps | grep fluentd
      docker logs fluentd
    • For Kubernetes:

      kubectl get pods -n logging -l app=fluentd
      kubectl logs -n logging -l app=fluentd
  3. Check Fluentd logs for startup messages:

    • Log location: /var/log/td-agent/td-agent.log

    • Look for successful configuration loading

    • Verify plugins are loaded correctly

    • Confirm input sources are initialized

    • Check for any error or warning messages

    • Example log entries to look for:

      [info]: starting fluentd-1.16.2
      [info]: reading config file path="/etc/td-agent/td-agent.conf"
      [info]: using configuration file: <ROOT>
      [info]: adding match pattern="**" type="http"
      [info]: adding source type="tail"
      [info]: #0 starting fluentd worker pid=12345
      [info]: #0 fluentd worker is now running worker=0
  4. Verify input sources are active:

    • Check logs for file discovery messages (tail plugin)

    • Verify listening ports are open (syslog, forward, http plugins):

      sudo netstat -tlnp | grep td-agent
      # or
      sudo ss -tlnp | grep td-agent
    • Confirm position files are being created and updated

  5. Generate test log entries:

    • Write test entries to monitored log files:

      echo '{"timestamp":"'$(date -Iseconds)'","level":"INFO","message":"Test log from Fluentd"}' >> /var/log/application/test.log
    • Send test syslog message:

      logger -n localhost -P 5140 -T "Test syslog message"
    • Send test HTTP message:

      curl -X POST -d 'json={"event":"test","timestamp":"'$(date -Iseconds)'"}' http://localhost:8888/application.test
  6. Verify data in LogScale:

    • Navigate to your repository in LogScale

    • Run a query to find recently ingested events from Fluentd:

      @source=fluentd OR hostname=*
    • Verify events have correct timestamps

    • Confirm fields are extracted correctly

    • Check that custom fields and tags are present

    • Verify host metadata is included

    • For Kubernetes deployments, verify pod and container metadata

  7. Check Fluentd metrics (if monitoring enabled):

    • Access the monitor agent endpoint:

      curl http://localhost:24220/api/plugins.json | jq
    • Access Prometheus metrics:

      curl http://localhost:24231/metrics
    • Review key metrics:

      • buffer_queue_length: Events in buffer

      • buffer_total_queued_size: Buffer size in bytes

      • retry_count: Number of retries

      • emit_count: Events emitted

      • emit_records: Records emitted

  8. Verify continuous operation:

    • Monitor for several minutes to ensure stable operation

    • Check that events continue to flow to LogScale

    • Verify no error accumulation in Fluentd logs

    • Confirm resource usage (CPU, memory) is within acceptable limits

  9. Test error handling and recovery:

    • Temporarily block network access to LogScale endpoint

    • Verify Fluentd buffers events to disk

    • Monitor buffer growth in logs and metrics

    • Restore network access and confirm buffered events are sent

    • Verify no data loss occurred during the outage

  10. Test Fluentd restart behavior:

    • Restart the Fluentd service

    • Verify it resumes from the last processed position (no duplicate events)

    • Confirm position files are being used correctly

    • Check that buffered events are preserved and sent after restart

  11. Test log rotation handling:

    • Rotate a monitored log file (using logrotate or manual rename)

    • Verify Fluentd continues reading from the rotated file

    • Confirm Fluentd picks up the new file after rotation

    • Check that no events are lost during rotation

Step 7 - Monitoring and maintenance

Why? Ongoing monitoring ensures the reliability, performance, and efficiency of your Fluentd infrastructure, enabling proactive issue detection and continuous optimization of log processing pipelines.

What you should do:

  • Set up alerts for Fluentd health:

    • Fluentd process/service down or not running

    • Connection failures to LogScale endpoint

    • Buffer queue length exceeding thresholds

    • Buffer disk usage approaching limits

    • Retry count increasing continuously

    • Plugin errors or crashes

    • Position file corruption or access errors

    • Resource usage exceeding limits (CPU, memory, file descriptors)

    • Fluentd version outdated or unsupported

  • Monitor Fluentd performance metrics:

    • Events read per second from each input

    • Events emitted per second to outputs

    • Event processing latency (input to output)

    • Buffer queue length and total size

    • Retry counts and failure rates

    • Network throughput and bandwidth usage

    • CPU and memory consumption per Fluentd instance

    • File descriptor usage

    • Plugin-specific metrics (tail, forward, http, etc.)

  • Monitor data quality and completeness:

    • Compare events read vs. events emitted (should be equal after filtering)

    • Check for gaps in log timestamps indicating missed data

    • Verify parsing success rates for each input

    • Monitor for duplicate events (may indicate position file issues)

    • Validate field transformation accuracy through sampling

  • Create operational dashboards:

    • Fluentd fleet health overview (all instances)

    • Per-host Fluentd status and metrics

    • Ingestion throughput trends by input type

    • Buffer utilization and flush patterns

    • Error and warning summaries with drill-down capabilities

    • Resource utilization across the Fluentd fleet

    • Version distribution and update compliance

    • Plugin performance and error rates

  • Regularly review and optimize:

    • Input configurations based on actual log patterns and volumes

    • Filter and transformation logic for efficiency

    • Buffer sizes based on network reliability and log burst patterns

    • Flush intervals to balance latency with throughput

    • Retry settings based on observed failure patterns

    • Tag routing and matching patterns

    • Parser configurations as log formats evolve

    • Worker count based on CPU availability and workload

  • Maintain Fluentd fleet consistency:

    • Use configuration management tools (Ansible, Puppet, Chef) for standardization

    • Version control Fluentd configurations

    • Implement configuration validation before deployment

    • Document configuration standards and best practices

    • Maintain an inventory of all Fluentd deployments

    • Track plugin versions and dependencies

  • Implement update and upgrade procedures:

    • Monitor Fluentd release notes for new versions and security updates

    • Test new versions in non-production environments first

    • Plan phased rollouts to minimize risk

    • Verify plugin compatibility with new Fluentd versions

    • Test configuration compatibility across versions

    • Maintain rollback procedures for failed upgrades

    • Document upgrade procedures and lessons learned

  • Implement security best practices:

    • Rotate ingest tokens regularly (every 90 days recommended)

    • Run Fluentd with minimal required permissions

    • Ensure TLS/SSL certificates are valid and up to date

    • Protect position files with appropriate permissions (0600)

    • Secure Fluentd-to-Fluentd communication with shared keys and TLS

    • Audit Fluentd access to log files and systems

    • Monitor for unauthorized configuration changes

    • Implement network segmentation for Fluentd traffic

    • Regularly update plugins to address security vulnerabilities

  • Handle log source changes:

    • Establish notification processes for application log format changes

    • Update parsers when log formats change

    • Adjust file path patterns when log locations change

    • Review and update filters when field names change

    • Document all log source changes and configuration updates

  • Manage buffer and position files:

    • Monitor buffer directory disk usage

    • Clean up old buffer chunks periodically

    • Back up position files before major changes

    • Implement position file compaction schedules

    • Monitor position file growth and corruption

  • Plan for scaling and growth:

    • Monitor log volume trends as infrastructure grows

    • Plan Fluentd capacity for new hosts and applications

    • Evaluate aggregator deployment patterns for high-volume scenarios

    • Consider horizontal scaling with multiple aggregators

    • Implement load balancing for aggregator clusters

    • Test disaster recovery procedures and failover scenarios

    • Document Fluentd architecture and dependencies

  • Troubleshoot common issues:

    • No data appearing in LogScale:

      • Verify Fluentd is running and connected

      • Check ingest token is valid and has correct permissions

      • Verify network connectivity to LogScale endpoint

      • Check Fluentd logs for errors

      • Verify file paths are correct and files exist

      • Check tag matching patterns in match directives

    • Duplicate events:

      • Verify position files are being saved correctly

      • Check for multiple Fluentd instances monitoring the same files

      • Review buffer and retry settings

      • Ensure position file path is persistent (not in /tmp)

    • High resource usage:

      • Review number of monitored files and inputs

      • Optimize filter and transformation logic

      • Adjust buffer sizes and flush intervals

      • Consider using aggregator pattern to offload processing

      • Review Ruby code in record_transformer for efficiency

    • Buffer overflow:

      • Increase buffer size limits

      • Reduce flush interval for faster draining

      • Increase flush thread count

      • Check network connectivity to output destination

      • Review overflow_action setting (block vs. drop)

    • Parsing errors:

      • Verify parser type matches log format

      • Check regex patterns for accuracy

      • Review sample events causing parsing failures

      • Test parsers with sample data before deployment

      • Enable emit_invalid_record_to_error for debugging

    • Plugin errors:

      • Verify plugin is installed correctly

      • Check plugin version compatibility with Fluentd version

      • Review plugin-specific configuration requirements

      • Check for plugin dependency issues

  • Maintain operational documentation:

    • Document all Fluentd deployments and their purposes

    • Maintain runbooks for common troubleshooting scenarios

    • Document configuration standards and templates

    • Keep inventory of monitored log sources and their owners

    • Document dependencies between Fluentd and applications

    • Maintain change logs for configuration modifications

    • Document custom plugins and their purposes

  • Conduct regular reviews:

    • Quarterly reviews of all Fluentd deployments and their value

    • Monthly performance reviews to identify optimization opportunities

    • Weekly operational reviews of errors and warnings

    • Annual disaster recovery and business continuity testing

  • Leverage community and support resources:

    • Participate in Fluentd community forums and Slack channels

    • Review Fluentd documentation for new features and plugins

    • Explore community-contributed plugins and configurations

    • Attend Fluentd meetups and conferences

    • Share lessons learned and contribute back to the community

  • Consider migration strategies:

    • If migrating from other platforms to LogScale, plan phased approach

    • Test multi-output configurations for gradual migration

    • Validate data completeness during migration period

    • Document differences in field naming and parsing between platforms

    • Plan for eventual removal of legacy outputs after migration

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

Enter search term