Meta tags:
description= Rate limit logs passing through a topology;
keywords= throttle,component,transform;
Headings (most frequently used words):
graph, exclude, vrl, rate, edge_attributes, types, examples, shorthand, internal_metrics, logs, limiting, node_attributes, deprecated, throttle, configuration, input, outputs, output, telemetry, how, it, works, vector, site, footer, example, configurations, available, syntaxes, for, condition, config, inputs, key_field, measure_cpu_usage, threshold, window_secs, component_id, metrics, state, about, components, setup, community, download, source, type, standard, datadog, search, emit_events_discarded_per_key, warning, component_discarded_events_total, component_errors_total, component_latency_mean_seconds, component_latency_seconds, component_received_event_bytes_total, component_received_events_count, component_received_events_total, component_sent_event_bytes_total, component_sent_events_total, events_discarded_total, transform_buffer_max_byte_size, transform_buffer_max_event_size, transform_buffer_max_size_bytes, transform_buffer_max_size_events, transform_buffer_utilization, transform_buffer_utilization_level, transform_buffer_utilization_mean, utilization, buckets, quotas, limited, events,
Text of the page (most frequently used words):
the (271), vector (95), #component (69), optional (67), type (36), transform (32), this (30), from (26), host (25), #events (23), hostname (22), data (22), event (21), which (21), for (20), source (20), logs (20), rate (19), metrics (19), process (18), instance (18), pid (18), system (18), running (18), originated (18), number (17), that (17), component_id (17), and (16), throttle (16), component_type (16), component_kind (16), log (15), kind (15), transforms (14), graph (13), exclude (13), inputs (12), condition (12), aws (12), threshold (11), file (11), configuration (10), message (10), counter (10), status (10), vrl (10), metric (9), window_secs (9), into (9), my_transform_id (9), examples (9), buffer (9), time (9), datadog (8), will (8), value (8), input (8), gauge (8), output (8), uri (8), internal (8), with (7), example (7), each (7), feeds (7), name (7), mode (7), string (7), bucket (6), discarded (6), available (6), single (6), key_field (6), json (6), toml (6), yaml (6), can (6), false (6), required (6), node (6), edge (6), 500 (6), gcp (6), github (5), limit (5), you (5), not (5), limiter (5), through (5), key (5), limited (5), maximum (5), seconds (5), level (5), types (5), are (5), syntax (5), object (5), language (5), prometheus (5), model (5), chat (4), components (4), tag (4), state (4), when (4), capacity (4), tagged (4), cell (4), provided (4), utilization (4), histogram (4), hold (4), bytes (4), has (4), deprecated (4), error (4), total (4), used (4), origins (4), spent (4), true (4), whether (4), stack (4), datadog_search (4), 200 (4), docs (4), architecture (4), rss (3), releases (3), download (3), sinks (3), trace (3), cardinality (3), updates (3), based (3), across (3), events_discarded_total (3), cells (3), every (3), use (3), buckets (3), load (3), configured (3), per (3), stream (3), 2020 (3), 07t12 (3), 223543z (3), timestamp (3), com (3), using (3), emitted (3), sanitized (3), pod (3), pod_name (3), pathname (3), peer_path (3), peer_addr (3), connection (3), container (3), container_name (3), like (3), note (3), includes (3), both (3), below (3), see (3), more (3), default (3), supported (3), cpu (3), set (3), template (3), literal (3), width (3), red (3), color (3), graphviz (3), dot (3), attributes (3), edge_attributes (3), search (3), incoming (3), remap (3), reference (3), websocket (3), splunk (3), hec (3), http (3), azure (3), kinesis (3), all (2), going (2), administration (2), deployment (2), installation (2), setup (2), sources (2), previous (2), new (2), stateful (2), its (2), behavior (2), restarts (2), any (2), passed (2), limiters (2), there (2), passing (2), quotas (2), separately (2), limiting (2), first (2), given (2), would (2), indicate (2), idle (2), mean (2), smoothed (2), over (2), exponentially (2), weighted (2), moving (2), average (2), ewma (2), transform_buffer_max_size_events (2), transform_buffer_max_size_bytes (2), been (2), favor (2), specific (2), accepted (2), either (2), cumulatively (2), other (2), separate (2), issues (2), due (2), topology (2), queued (2), executing (2), itself (2), elapsed (2), fractional (2), spends (2), stage (2), errors (2), filter (2), component_discarded_events_total (2), telemetry (2), namespacing (2), downstream (2), table (2), configurations (2), window (2), unique (2), defaults (2), enable (2), only (2), poll (2), usage (2), bool (2), parameter (2), internal_metrics (2), info (2), list (2), attribute (2), node_attributes (2), they (2), added (2), add (2), resulting (2), label (2), shorthand (2), config (2), syntaxes (2), streams (2), open (2), home (2), api (2), pipeline (2), server (2), statsd (2), socket (2), sematext (2), redis (2), pulsar (2), remote (2), write (2), opentelemetry (2), nats (2), mqtt (2), formerly (2), kafka (2), influxdb (2), humio (2), greptimedb (2), pubsub (2), stackdriver (2), cloud (2), storage (2), monitoring (2), sqs (2), firehose (2), cloudwatch (2), amqp (2), route (2), windows (2), kubernetes (2), docker (2), agent (2), end (2), concurrency (2), linux (2), observability (2), pipelines (2), support (2), blog (2), guides (2), sidebar, 2026, inc, rights, reserved, community, prod, cookies, privacy, team, contact, about, site, footer, next, thank, joining, our, newsletter, sign, receive, emails, latest, content, page, meaning, changes, preserved, therefore, dependent, reset, between, depend, received, since, most, recent, restart, allow, drop, further, particular, tracked, created, equal, replenish, divided, replenishes, allows, burst, determine, sufficient, successfully, pass, consumes, spread, ensuring, throughput, averages, out, utilizes, generic, algorithm, how, works, produced, second, ratio, completely, simply, waiting, never, updated, transform_buffer_utilization_mean, current, transform_buffer_utilization_level, transform_buffer_utilization, transform_buffer_max_event_size, transform_buffer_max_byte_size, reason, component_sent_events_total, component_sent_event_bytes_total, component_received_events_total, than, sink, batching, mostly, useful, low, debugging, performance, small, batches, batch, component_received_events_count, component_received_event_bytes_total, component_latency_seconds, component_latency_mean_seconds, within, occurred, error_type, encountered, component_errors_total, were, intentionally, intentional, dropped, link, modified, fields, shown, different, enabled, details, warning, outputs, following, lists, possible, aware, may, differ, specified, codec, applied, float, own, allowed, uint, where, attribution, needed, adds, call, future, clock_gettime, task, timed, thread, clock, accumulated, nanoseconds, reported, component_cpu_usage_ns_total, measure_cpu_usage, supports, enables, dynamic, values, left, unspecified, doesn, have, then, group, independently, because, potentially, unbounded, know, keys, bounded, incremented, including, associated, instead, seen, emit, emit_events_discarded_per_key, prefix, array, wildcards, upstream, ids, example_input, collection, related, edges, linked, configure, generated, command, extra, standard, format, opt, via, without, needing, specify, shows, some, is_trace, is_metric, is_log, query, status_code, debug, severity, boolean, expression, description, supply, text, depends, logical, sampling, advanced, minimal, limits, one, services, enforce, users, view, egress, stable, versioning, security, meta, glossary, environment, variables, cli, secrets, schema, unit, tests, tls, global, options, webhdfs, exporter, postgres, papertrail, relic, mezmo, logdna, loki, keep, honeycomb, chronicle, unstructured, elasticsearch, doris, traces, databricks, zerobus, databend, console, clickhouse, blackhole, monitor, ingestion, blob, axiom, sns, appsignal, sample, reduce, lua, incremental, absolute, exclusive, delay, dedupe, ec2, metadata, aggregate, syslog, stdin, static, scrape, pushgateway, postgresql, okta, nginx, mongodb, logstash, journald, client, heroku, logplex, fluent, descriptor, exec, eventstoredb, dnstap, demo, ecs, apache, expressions, functions, pgo, optimization, validating, management, acknowledgements, guarantees, adaptive, buffering, runtime, sizing, planning, rollout, high, availability, hardening, architecting, unified, aggregator, architectures, production, topologies, roles, installer, archives, manual, ubuntu, rhel, raspbian, nixos, macos, debian, centos, arch, amazon, operating, systems, platforms, yum, rpm, pacman, nix, msi, homebrew, helm, dpkg, apt, package, managers, quickstart, concepts, introduction, navbar, dropdown, menu, toggle, dark, documentation,
Text of the page (random words):
ether the incoming event is a trace shorthand for vrl if you opt for the vrl syntax for this condition you can set the condition as a string via the condition parameter without needing to specify both a source and a type the table below shows some examples config format example yaml condition status 200 toml condition status 200 json condition status 200 condition config examples standard vrl yaml toml json exclude type vrl source status 500 exclude type vrl source status 500 exclude type vrl source status 500 datadog search yaml toml json exclude type datadog_search source stack exclude type datadog_search source stack exclude type datadog_search source stack vrl shorthand yaml toml json exclude status 500 exclude status 500 exclude status 500 graph optional object extra graph configuration configure output for component when generated with graph command graph edge_attributes optional object edge attributes to add to the edges linked to this component s node in resulting graph they are added to the edge as provided graph edge_attributes required object a collection of graph edge attributes in graphviz dot language related to a single input component graph edge_attributes required string literal a single graph edge attribute in graphviz dot language examples color red label example edge width 5 0 examples example_input color red label example edge width 5 0 graph node_attributes optional object node attributes to add to this component s node in resulting graph they are added to the node as provided graph node_attributes required string literal a single graph node attribute in graphviz dot language examples color red name example node width 5 0 inputs required string a list of upstream source or transform ids wildcards are supported see configuration for more info array string literal examples my source or transform id prefix internal_metrics optional object configuration of internal metrics for the throttle transform internal_metrics emit_events_discarded_per_key optional bool whether or not to emit the events_discarded_total internal metric with the key tag if true the counter will be incremented for each discarded event including the key value associated with the discarded event if false the counter will not be emitted instead the number of discarded events can be seen through the component_discarded_events_total internal metric note that this defaults to false because the key tag has potentially unbounded cardinality only set this to true if you know that the number of unique keys is bounded default false key_field optional string template the value to group events into separate buckets to be rate limited independently if left unspecified or if the event doesn t have key_field then the event is not rate limited separately note this parameter supports vector s template syntax which enables you to use dynamic per event values examples message hostname measure_cpu_usage optional bool enable cpu usage metrics for this transform when set to true each poll of the transform task is timed using the os thread cpu clock and the accumulated nanoseconds are reported as the component_cpu_usage_ns_total counter tagged with component_id component_kind and component_type defaults to false enable only for transforms where cpu attribution is needed as it adds a clock_gettime call on every future poll default false threshold required uint the number of events allowed for a given bucket per configured window_secs each unique key has its own threshold window_secs required float the time window in which the configured threshold is applied in seconds input types the following table lists all telemetry data types supported by the component across possible configurations be aware that the available data types may differ based on the specified codec configuration logs log events are supported outputs component_id default output stream of the component use this component s id as an input to downstream transforms and sinks output types logs warning the fields shown below will be different if log namespacing is enabled see log namespacing for more details the modified input log event telemetry metrics link component_discarded_events_total counter the number of events dropped by this component component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on intentional true if the events were discarded intentionally like a filter transform or false if due to an error pid optional the process id of the vector instance component_errors_total counter the total number of errors encountered by this component component_id the vector component id component_kind the vector component kind component_type the vector component type error_type the type of the error host optional the hostname of the system vector is running on pid optional the process id of the vector instance stage the stage within the component at which the error occurred component_latency_mean_seconds gauge the mean elapsed time in fractional seconds that an event spends in a single transform this includes both the time spent queued in the transform s input buffer and the time spent executing the transform itself this value is smoothed over time using an exponentially weighted moving average ewma host optional the hostname of the system vector is running on pid optional the process id of the vector instance component_latency_seconds histogram the elapsed time in fractional seconds that an event spends in a single transform this includes both the time spent queued in the transform s input buffer and the time spent executing the transform itself host optional the hostname of the system vector is running on pid optional the process id of the vector instance component_received_event_bytes_total counter the number of event bytes accepted by this component either from tagged origins like file and uri or cumulatively from other origins component_id the vector component id component_kind the vector component kind component_type the vector component type container_name optional the name of the container from which the data originated file optional the file from which the data originated host optional the hostname of the system vector is running on mode optional the connection mode used by the component peer_addr optional the ip from which the data originated peer_path optional the pathname from which the data originated pid optional the process id of the vector instance pod_name optional the name of the pod from which the data originated uri optional the sanitized uri from which the data originated component_received_events_count histogram a histogram of the number of events passed in each internal batch in vector s internal topology note that this is separate than sink level batching it is mostly useful for low level debugging performance issues in vector due to small internal batches component_id the vector component id component_kind the vector component kind component_type the vector component type container_name optional the name of the container from which the data originated file optional the file from which the data originated host optional the hostname of the system vector is running on mode optional the connection mode used by the component peer_addr optional the ip from which the data originated peer_path optional the pathname from which the data originated pid optional the process id of the vector instance pod_name optional the name of the pod from which the data originated uri optional the sanitized uri from which the data originated component_received_events_total counter the number of events accepted by this component either from tagged origins like file and uri or cumulatively from other origins component_id the vector component id component_kind the vector component kind component_type the vector component type container_name optional the name of the container from which the data originated file optional the file from which the data originated host optional the hostname of the system vector is running on mode optional the connection mode used by the component peer_addr optional the ip from which the data originated peer_path optional the pathname from which the data originated pid optional the process id of the vector instance pod_name optional the name of the pod from which the data originated uri optional the sanitized uri from which the data originated component_sent_event_bytes_total counter the total number of event bytes emitted by this component component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on output optional the specific output of the component pid optional the process id of the vector instance component_sent_events_total counter the total number of events emitted by this component component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on output optional the specific output of the component pid optional the process id of the vector instance events_discarded_total counter the total number of events discarded by this component host optional the hostname of the system vector is running on pid optional the process id of the vector instance reason the type of the error transform_buffer_max_byte_size gauge the maximum number of bytes the buffer that feeds into a transform can hold deprecated this metric has been deprecated in favor of transform_buffer_max_size_bytes component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_max_event_size gauge the maximum number of events the buffer that feeds into a transform can hold deprecated this metric has been deprecated in favor of transform_buffer_max_size_events component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_max_size_bytes gauge the maximum number of bytes the buffer that feeds into a transform can hold component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_max_size_events gauge the maximum number of events the buffer that feeds into a transform can hold component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_utilization histogram the utilization level of the buffer that feeds into a transform component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_utilization_level gauge the current utilization level of the buffer that feeds into a transform component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance transform_buffer_utilization_mean gauge the mean utilization level of the buffer that feeds into a transform this value is smoothed over time using an exponentially weighted moving average ewma component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance utilization gauge a ratio from 0 to 1 of the load on a component a value of 0 would indicate a completely idle component that is simply waiting for input a value of 1 would indicate a that is never idle this value is updated every 5 seconds component_id the vector component id component_kind the vector component kind component_type the vector component type host optional the hostname of the system vector is running on pid optional the process id of the vector instance examples rate limiting given this event log host host 1 hostname com message first message timestamp 2020 10 07t12 33 21 223543z log host host 1 hostname com message second message timestamp 2020 10 07t12 33 21 223543z and this configuration yaml toml json transforms my_transform_id type throttle inputs my source or transform id threshold 1 window_secs 60 transforms my_transform_id type throttle inputs my source or transform id threshold 1 window_secs 60 transforms my_transform_id type throttle inputs my source or transform id threshold 1 window_secs 60 this vector event is produced log host host 1 hostname com message first message timestamp 2020 10 07t12 33 21 223543z how it works rate limiting the throttle transform will spread load across the configured window_secs ensuring that each bucket s throughput averages out to the threshold per window_secs it utilizes a generic cell rate algorithm to rate limit the event stream buckets the throttle transform buckets events into rate limiters based on the provided key_field or a single bucket if not provided each bucket is rate limited separately quotas rate limiters use cells to determine if there is sufficient capacity for an event to successfully pass through a rate limiter each event passing through the transform consumes an available cell if there is no available cell the event will be rate limited a rate limiter is created with a maximum number of cells equal to the threshold and cells replenish at a rate of window_secs divided by threshold for example a window_secs of 60 with a threshold of 10 replenishes a cell every 6 seconds and allows a burst of up to 10 events rate limited events the rate limiter will allow up to threshold number of events through and drop any further events for that particular bucket when the rate limiter is at capacity any event passed when the rate limiter is at capacity will be discarded and tracked by an events_discarded_total metric tagged by the bucket s key state this component is stateful meaning its behavior changes based on previous inputs events state is not preserved across restarts therefore state dependent behavior will reset between restarts and depend on the inputs events received since the most recent restart on this page sign up to receive emails on the latest vector content and new releases thank you for joining our updates newsletter previous tag cardinality limit next ...
|