Skip to main content
Version: v4.25

to_fluent_bit

Sends events via Fluent Bit.

Synopsis

to_fluent_bit plugin:string, [options=record, fluent_bit_options=record]

Description

The to_fluent_bit operator acts as a bridge into the Fluent Bit ecosystem, making it possible to send events to Fluent Bit output plugin.

An invocation of the fluent-bit commandline utility

fluent-bit -o plugin -p key1=value1 -p key2=value2 -p…

translates to our to_fluent_bit operator as follows:

to_fluent_bit "plugin", options={key1: value1, key2:value2, …}
Read from Fluent Bit

You can acquire events from Fluent Bit using the from_fluent_bit operator.

plugin: string

The name of the Fluent Bit plugin.

Run fluent-bit -h and look under the Outputs section of the help text for available plugin names. The web documentation often comes with an example invocation near the bottom of the page, which also provides a good idea how you could use the operator.

options = record (optional)

Sets plugin configuration properties.

The key-value pairs in this record are equivalent to -p key=value for the fluent-bit executable.

fluent_bit_options = record (optional)

Sets global properties of the Fluent Bit service. E.g., fluent_bit_options={flush:1, grace:3}.

Consult the list of available key-value pairs to configure Fluent Bit according to your needs.

We recommend factoring these options into the plugin-specific fluent-bit.yaml so that they are independent of the fluent-bit operator arguments.

URI support & integration with from

The to_fluent_bit operator can also be used from the to operator. For this, the fluentbit:// scheme can be used. The URI is then translated:

to "fluentbit://plugin"
to_fluent_bit "plugin"

Examples

ElasticSearch

Send events to ElasticSearch:

to_fluent_bit "es",
  options={
    host: 192.168.2.3,
    port: 9200,
    index: "my_index",
    type: "my_type"
  }

Slack

Send events to Slack:

let $slack_hook = "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
to_fluent_bit "slack", options={webhook: $slack_hook}

Splunk

tip

Use the dedicated to_splunk operator instead