If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: vector.dev/docs/reference/configuration/template-syntax - Template syntax | Vector docum.

site address: vector.dev/docs/reference/configuration/template-syntax/ redirected to: vector.dev/docs/reference/configuration/template-syntax

site title: Template syntax Vector documentation

Our opinion (on Monday 20 July 2026 6:31:29 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:


Hashtags existing on this website:




Meta tags:

Headings (most frequently used words):

fields, syntax, template, example, how, it, works, vector, site, footer, event, strftime, specifiers, escaping, accessing, fallback, values, missing, about, components, setup, community, download,

Text of the page (most frequently used words):
metrics (32), logs (30), aws (25), the (21), #vector (19), log (13), gcp (12), option (12), datadog (11), #syntax (10), prometheus (10), model (10), event (9), this (9), data (8), architecture (8), configuration (7), and (7), metric (7), remap (7), can (7), application_id (7), for (6), template (6), websocket (6), splunk (6), hec (6), http (6), file (6), events (6), azure (6), kinesis (6), reference (6), from (6), source (6), docs (6), fields (6), toml (6), yaml (6), sinks (5), transforms (5), components (5), you (5), with (5), internal (5), field (5), chat (4), github (4), releases (4), api (4), pipeline (4), server (4), statsd (4), socket (4), sematext (4), redis (4), pulsar (4), remote (4), write (4), opentelemetry (4), nats (4), mqtt (4), formerly (4), kafka (4), influxdb (4), humio (4), greptimedb (4), pubsub (4), stackdriver (4), cloud (4), storage (4), monitoring (4), sqs (4), firehose (4), cloudwatch (4), amqp (4), route (4), windows (4), kubernetes (4), docker (4), agent (4), end (4), concurrency (4), linux (4), my_field (4), type (4), values (4), value (4), year (4), month (4), day (4), strftime (4), aws_s3 (4), date (4), key_prefix (4), rss (3), download (3), going (3), administration (3), deployment (3), installation (3), setup (3), sources (3), secrets (3), schema (3), updates (3), new (3), global (3), options (3), tag (3), vrl (3), examples (3), home (3), default (3), support (3), accessing (3), would (3), specifiers (3), versioning (2), security (2), meta (2), glossary (2), environment (2), variables (2), cli (2), unit (2), tests (2), tls (2), webhdfs (2), exporter (2), postgres (2), papertrail (2), relic (2), mezmo (2), logdna (2), loki (2), keep (2), honeycomb (2), chronicle (2), unstructured (2), elasticsearch (2), doris (2), traces (2), databricks (2), zerobus (2), databend (2), console (2), clickhouse (2), blackhole (2), monitor (2), ingestion (2), blob (2), axiom (2), sns (2), streams (2), appsignal (2), window (2), trace (2), throttle (2), cardinality (2), limit (2), sample (2), reduce (2), lua (2), incremental (2), absolute (2), filter (2), exclusive (2), delay (2), dedupe (2), ec2 (2), metadata (2), aggregate (2), syslog (2), stdin (2), static (2), scrape (2), pushgateway (2), postgresql (2), okta (2), nginx (2), mongodb (2), logstash (2), journald (2), client (2), host (2), heroku (2), logplex (2), fluent (2), descriptor (2), exec (2), eventstoredb (2), dnstap (2), demo (2), ecs (2), apache (2), expressions (2), errors (2), functions (2), language (2), pgo (2), optimization (2), validating (2), management (2), acknowledgements (2), guarantees (2), adaptive (2), buffering (2), runtime (2), sizing (2), capacity (2), planning (2), rollout (2), high (2), availability (2), hardening (2), architecting (2), unified (2), aggregator (2), architectures (2), production (2), topologies (2), roles (2), installer (2), archives (2), manual (2), ubuntu (2), rhel (2), raspbian (2), nixos (2), macos (2), debian (2), centos (2), arch (2), amazon (2), operating (2), systems (2), platforms (2), yum (2), rpm (2), pacman (2), nix (2), msi (2), homebrew (2), helm (2), dpkg (2), apt (2), package (2), managers (2), quickstart (2), concepts (2), introduction (2), missing (2), exists (2), inputs (2), set_defaults (2), fallback (2), open (2), documentation (2), path (2), expression (2), each (2), above (2), like (2), field_name (2), escape (2), example (2), derived (2), timestamp (2), parent (2), child (2), sink (2), dynamic (2), 2020 (2), that (2), allows (2), all_application_logs (2), bucket (2), backup (2), supports (2), observability (2), pipelines (2), blog (2), guides (2), sidebar, 2026, inc, all, rights, reserved, community, prod, cookies, privacy, team, contact, about, site, footer, next, previous, thank, joining, our, newsletter, sign, receive, emails, latest, content, close, slideover, panel, page, error, logged, drops, incremented, template_failed, error_type, component_errors_total, doesn, currently, add, functionality, interim, use, set, transform, issue, 1692, find, additional, how, works, treated, literally, specified, prefixing, character, escaping, name, changed, via, timestamp_key, addition, directly, offers, shortcut, injecting, individual, accessed, using, wrap, because, batches, grouped, its, produced, effectively, enables, partitioning, something, fundamental, storing, filesystems, equal, hello, world, message, 14t01, 223z, notice, direct, references, well, were, run, following, through, let, partition, accomplish, some, any, will, clearly, documented, such, description, navbar, dropdown, menu, search, toggle, dark, mode,


Text of the page (random words):
template syntax vector documentation docs guides components download blog support observability pipelines toggle dark mode search x 𝕏 github chat rss updates open navbar dropdown menu docs guides components download blog support observability pipelines x 𝕏 github chat rss updates docs home introduction concepts setup quickstart installation package managers apt dpkg helm homebrew msi nix pacman rpm yum platforms docker kubernetes operating systems amazon linux arch linux centos debian macos nixos raspbian rhel ubuntu windows manual from archives from source vector installer deployment roles topologies going to production reference architectures aggregator architecture agent architecture unified architecture architecting hardening high availability rollout sizing and capacity planning architecture data model log events metric events pipeline model runtime model buffering model concurrency model adaptive concurrency guarantees end to end acknowledgements administration management monitoring validating optimization pgo reference vector remap language functions errors examples expressions configuration sources amqp apache metrics aws ecs metrics aws kinesis firehose aws s3 aws sqs datadog agent demo logs dnstap docker logs eventstoredb metrics exec file file descriptor fluent gcp pubsub heroku logplex host metrics http client http server internal logs internal metrics journald kafka kubernetes logs logstash mongodb metrics mqtt nats nginx metrics okta opentelemetry postgresql metrics prometheus pushgateway prometheus remote write prometheus scrape pulsar redis socket splunk hec static metrics statsd stdin syslog vector websocket windows event log transforms remap with vrl aggregate aws ec2 metadata dedupe delay exclusive route filter incremental to absolute log to metric lua metric to log reduce route sample tag cardinality limit throttle trace to log window sinks amqp appsignal aws cloudwatch logs aws cloudwatch metrics aws kinesis data firehose logs aws kinesis streams logs aws s3 aws sns aws sqs axiom azure blob storage azure logs ingestion azure monitor logs blackhole clickhouse console databend databricks zerobus datadog events datadog logs datadog metrics datadog traces doris elasticsearch file gcp chronicle unstructured gcp cloud monitoring formerly stackdriver gcp cloud storage gcp stackdriver gcp pubsub greptimedb logs greptimedb metrics honeycomb http humio logs humio metrics influxdb logs influxdb metrics kafka keep loki mezmo formerly logdna mqtt nats new relic opentelemetry papertrail postgres prometheus exporter prometheus remote write pulsar redis sematext logs sematext metrics socket splunk hec logs splunk hec metrics statsd vector webhdfs websocket websocket server global options pipeline components tls configuration api unit tests schema template syntax secrets cli environment variables api glossary meta security releases versioning vector docs home reference configuration template syntax template syntax vector supports a template syntax for some configuration options this allows for dynamic values derived from event data any option that supports this syntax will be clearly documented as such in the description example let s partition data on aws s3 by application_id and date we can accomplish this with the key_prefix option in the aws_s3 sink yaml toml sinks backup type aws_s3 bucket all_application_logs key_prefix application_id application_id date f sinks backup type aws_s3 bucket all_application_logs key_prefix application_id application_id date f notice that vector allows direct field references as well as strftime specifiers if we were to run the following log event through vector timestamp 2020 02 14t01 22 23 223z application_id 1 message hello world the value of the above key_prefix option would equal application_id 1 date 2020 02 14 because the aws_s3 sink batches data each event would be grouped by its produced value this effectively enables dynamic partitioning something fundamental to storing log data in filesystems syntax event fields individual log event fields can be accessed using to wrap a vrl path expression yaml toml option parent child option parent child strftime specifiers in addition to directly accessing fields vector offers a shortcut for injecting strftime specifiers yaml toml option year y month m day d option year y month m day d the value is derived from the timestamp field and the name of this field can be changed via the global timestamp_key option escaping you can escape this syntax by prefixing the character with a for example you can escape the event field syntax like this yaml toml option field_name option field_name and strftime specified like so yaml toml option year y month m day d option year y month m day d each of the values above would be treated literally how it works accessing fields you can find additional examples for accessing fields in the path expression reference documentation fallback values vector doesn t currently support fallback values issue 1692 is open to add this functionality in the interim you can use the remap transform to set a default value yaml toml transforms set_defaults type remap inputs my source id source if exists my_field my_field default transforms set_defaults type remap inputs my source id source if exists my_field my_field default missing fields if a field is missing an error is logged and vector drops the event the component_errors_total internal metric is incremented with an error_type tag of template_failed on this page close docs slideover panel docs home introduction concepts setup quickstart installation package managers apt dpkg helm homebrew msi nix pacman rpm yum platforms docker kubernetes operating systems amazon linux arch linux centos debian macos nixos raspbian rhel ubuntu windows manual from archives from source vector installer deployment roles topologies going to production reference architectures aggregator architecture agent architecture unified architecture architecting hardening high availability rollout sizing and capacity planning architecture data model log events metric events pipeline model runtime model buffering model concurrency model adaptive concurrency guarantees end to end acknowledgements administration management monitoring validating optimization pgo reference vector remap language functions errors examples expressions configuration sources amqp apache metrics aws ecs metrics aws kinesis firehose aws s3 aws sqs datadog agent demo logs dnstap docker logs eventstoredb metrics exec file file descriptor fluent gcp pubsub heroku logplex host metrics http client http server internal logs internal metrics journald kafka kubernetes logs logstash mongodb metrics mqtt nats nginx metrics okta opentelemetry postgresql metrics prometheus pushgateway prometheus remote write prometheus scrape pulsar redis socket splunk hec static metrics statsd stdin syslog vector websocket windows event log transforms remap with vrl aggregate aws ec2 metadata dedupe delay exclusive route filter incremental to absolute log to metric lua metric to log reduce route sample tag cardinality limit throttle trace to log window sinks amqp appsignal aws cloudwatch logs aws cloudwatch metrics aws kinesis data firehose logs aws kinesis streams logs aws s3 aws sns aws sqs axiom azure blob storage azure logs ingestion azure monitor logs blackhole clickhouse console databend databricks zerobus datadog events datadog logs datadog metrics datadog traces doris elasticsearch file gcp chronicle unstructured gcp cloud monitoring formerly stackdriver gcp cloud storage gcp stackdriver gcp pubsub greptimedb logs greptimedb metrics honeycomb http humio logs humio metrics influxdb logs influxdb metrics kafka keep loki mezmo formerly logdna mqtt nats new relic opentelemetry papertrail postgres prometheus exporter prometheus remote write pulsar redis sematext logs sematext metrics socket splunk hec logs splunk hec metrics statsd vector webhdfs websocket websocket server global options pipeline components tls configuration api unit tests schema template syntax secrets cli environment variables api glossary meta security releases versioning sign up to receive emails on the latest vector content and new releases thank you for joining our updates newsletter previous schema next secrets vector site footer about vector contact us the team privacy cookies components sources transforms sinks setup installation deployment configuration administration going to prod community github x chat download releases x 𝕏 github chat rss 2026 datadog inc all rights reserved sidebar
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)

    No Images


    Verified site has: 233 subpage(s). Do you want to verify them? Verify pages:

    1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
    51-55 56-60 61-65 66-70 71-75 76-80 81-85 86-90 91-95 96-100
    101-105 106-110 111-115 116-120 121-125 126-130 131-135 136-140 141-145 146-150
    151-155 156-160 161-165 166-170 171-175 176-180 181-185 186-190 191-195 196-200
    201-205 206-210 211-215 216-220 221-225 226-230 231-233


    The site also has references to the 1 subdomain(s)

      chat.vector.dev  Verify


    The site also has 3 references to external domain(s).

     datadoghq.com  Verify  x.com  Verify  github.com  Verify


    The site also has 1 references to other resources (not html/xhtml )

     vector.dev/blog/index.xml  Verify


    Top 50 hastags from of all verified websites.

    Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

    Header

    HTTP/1.1 301 Moved Permanently
    Server CloudFront
    Date Mon, 20 Jul 2026 06:31:28 GMT
    Content-Type text/html
    Content-Length 167
    Connection close
    Location htt????/vector.dev/docs/reference/configuration/template-syntax/
    X-Cache Redirect from cloudfront
    Via 1.1 42501186135af3199ef312857c031b5a.cloudfront.net (CloudFront)
    X-Amz-Cf-Pop CDG50-P6
    Alt-Svc h3= :443 ; ma=86400
    X-Amz-Cf-Id XgEMZLKpisy7400eCXdp8brzP4xdvahz8LfzW-iUHXUe-BvskiZi-Q==
    HTTP/2 200
    content-type text/html
    date Thu, 16 Jul 2026 10:43:59 GMT
    content-encoding gzip
    etag W/ 38a3293e768ceef87186486b390d3dae
    server AmazonS3
    cache-control public, max-age=0, s-maxage=31536000
    last-modified Thu, 16 Jul 2026 02:12:37 GMT
    vary Accept-Encoding
    x-cache Hit from cloudfront
    via 1.1 b4b67c4894b9140bc1cdb48058ca5f04.cloudfront.net (CloudFront)
    x-amz-cf-pop CDG50-P6
    alt-svc h3= :443 ; ma=86400
    x-amz-cf-id 3Nq94aPFVi2ShaOYvdvD7hhleqn76tTsVzA8c9B0TassNfJTj_GRTg==
    age 330449

    Meta Tags

    title="Template syntax | Vector documentation"
    charset="utf-8"
    name="viewport" content="width=device-width,initial-scale=1,shrink-to-fit=no"
    http-equiv="x-ua-compatible" content="id=edge"
    name="generator" content="Hugo 0.154.5"
    name="twitter:card" content="summary"
    name="twitter:image" content="htt????/vector.dev/img/vector-open-graph.png"
    name="twitter:image:alt" content="Logo for Vector"
    name="twitter:site" content="@vectordotdev"
    name="twitter:creator" content="@vectordotdev"
    property="og:title" content="Template syntax"
    property="og:image" content="htt????/vector.dev/img/vector-open-graph.png"
    property="og:url" content="htt????/vector.dev/docs/reference/configuration/template-syntax/"
    name="algolia:title" content="Template syntax"

    Load Info

    page size18049
    load time (s)0.103367
    redirect count1
    speed download175233
    server IP 13.249.228.67
    * all occurrences of the string "http://" have been changed to "htt???/"