Connect

otlp_http

Send OpenTelemetry traces, logs, and metrics via OTLP/HTTP protocol.

Introduced in version 4.78.0.

Sends OpenTelemetry telemetry data to a remote collector via OTLP/HTTP protocol.

Accepts batches of Redpanda OTEL v1 protobuf messages (spans, log records, or metrics) and converts them to OTLP format for transmission to OpenTelemetry collectors.

  • Common

  • Advanced

output:
  label: ""
  otlp_http:
    endpoint: "" # No default (required)
    max_in_flight: 64
output:
  label: ""
  otlp_http:
    endpoint: "" # No default (required)
    content_type: protobuf
    headers: {}
    timeout: 30s
    proxy_url: ""
    follow_redirects: false
    disable_http2: false
    tls:
      enabled: false
      skip_cert_verify: false
      cert_file: ""
      key_file: ""
    tcp:
      connect_timeout: 0s
      keep_alive:
        idle: 15s
        interval: 15s
        count: 9
      tcp_user_timeout: 0s
    oauth:
      enabled: false
      consumer_key: ""
      consumer_secret: ""
      access_token: ""
      access_token_secret: ""
    basic_auth:
      enabled: false
      username: ""
      password: ""
    jwt:
      enabled: false
      private_key_file: ""
      signing_method: ""
      claims: {}
      headers: {}
    oauth2:
      enabled: false
      client_key: ""
      client_secret: ""
      token_url: ""
      scopes: []
      endpoint_params: {}
    max_in_flight: 64

Input format

Expects messages in Redpanda OTEL v1 protobuf format with metadata:

  • signal_type: "trace", "log", or "metric"

Each batch must contain messages of the same signal type. The entire batch is converted to a single OTLP export request and sent via HTTP POST.

Endpoints

The output automatically appends the signal type path to the base endpoint:

  • Traces: {endpoint}/v1/traces

  • Logs: {endpoint}/v1/logs

  • Metrics: {endpoint}/v1/metrics

Content types

Supports two content types:

  • protobuf (default): application/x-protobuf

  • json: application/json

Authentication

Supports multiple authentication methods:

  • Basic authentication

  • OAuth v1

  • OAuth v2

  • JWT

Fields

basic_auth

Configure basic authentication for requests from this component.

Type: object

basic_auth.enabled

Whether to use basic authentication in requests.

Type: bool

Default: false

basic_auth.password

The password to use for authentication. Used together with username for basic authentication.

This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets.

Type: string

Default: ""

basic_auth.username

The username of the account credentials to authenticate as. Used together with password for basic authentication.

Type: string

Default: ""

content_type

Content type for HTTP requests. Options: 'protobuf' or 'json'.

Type: string

Default: protobuf

Options: protobuf, json

disable_http2

Whether or not to disable HTTP/2.

Type: bool

Default: false

endpoint

The HTTP endpoint of the remote OTLP collector (without the signal path).

Type: string

follow_redirects

Transparently follow redirects, i.e. responses with 300-399 status codes. If disabled, the response message will contain the body, status, and headers from the redirect response and the processor will not make a request to the URL set in the Location header of the response.

Type: bool

Default: false

headers

A map of headers to add to the request.

This field supports interpolation functions.

Type: object<string>

Default: {}

# Examples:
headers:
  X-Custom-Header: value
  traceparent: ${! tracing_span().traceparent }

jwt

Beta

Configure JSON Web Token (JWT) authentication. This feature is in beta and may change in future releases. JWTs provide secure, stateless authentication between services.

Type: object

jwt.claims

A map of claims to include in the JWT. Claims pass the identity of the authenticated entity to the service provider.

Type: object

Default: {}

jwt.enabled

Whether to use JWT authentication in requests.

Type: bool

Default: false

jwt.headers

Additional key-value pairs to include in the JWT header (optional). These headers provide extra metadata for JWT processing.

Type: object

Default: {}

jwt.private_key_file

Path to a file containing the PEM-encoded private key using PKCS#1 or PKCS#8 format. The private key must be compatible with the algorithm specified in the signing_method field.

Type: string

Default: ""

jwt.signing_method

The cryptographic algorithm used to sign the JWT. Supported algorithms are RS256, RS384, RS512, and EdDSA. This algorithm must be compatible with the private key specified in the private_key_file field.

Type: string

Default: ""

max_in_flight

The maximum number of messages to have in flight at a given time. For outputs that send messages in batches, this limit applies to message batches. Increase this value to improve throughput.

Type: int

Default: 64

oauth

Configure OAuth version 1.0 authentication for secure API access.

Type: object

oauth.access_token

The value used to gain access to the protected resources on behalf of the user.

Type: string

Default: ""

oauth.access_token_secret

The secret that establishes ownership of the access_token in OAuth 1.0 authentication.

This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets.

Type: string

Default: ""

oauth.consumer_key

The value used to identify this component or client to the service provider.

Type: string

Default: ""

oauth.consumer_secret

The secret that establishes ownership of the consumer key in OAuth 1.0 authentication.

This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets.

Type: string

Default: ""

oauth.enabled

Whether to enable OAuth version 1.0 authentication for requests.

Type: bool

Default: false

oauth2

Allows you to specify open authentication via OAuth version 2 using the client credentials token flow.

Type: object

oauth2.client_key

A value used to identify the client to the token provider.

Type: string

Default: ""

oauth2.client_secret

A secret used to establish ownership of the client key.

This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets.

Type: string

Default: ""

oauth2.enabled

Whether to use OAuth version 2 in requests.

Type: bool

Default: false

oauth2.endpoint_params

A list of optional endpoint parameters, values should be arrays of strings.

Type: object

Default: {}

# Examples:
endpoint_params:
  audience:
    - https://example.com
  resource:
    - https://api.example.com

oauth2.scopes[]

A list of optional requested permissions.

Type: array<string>

Default: []

oauth2.token_url

The URL of the token provider.

Type: string

Default: ""

proxy_url

An optional HTTP proxy URL.

Type: string

Default: ""

tcp

Configure TCP socket-level settings to optimize network performance and reliability. These low-level controls are useful for:

  • Unresponsive hosts: Set connect_timeout to limit how long a connection attempt can take (the default 0s sets no limit)

  • Long-lived connections: Configure keep_alive settings to detect and recover from stale connections

  • Unstable networks: Tune keep-alive probes to balance between quick failure detection and avoiding false positives

  • Linux systems with specific requirements: Use tcp_user_timeout (Linux 2.6.37+) to control data acknowledgment timeouts

Most users should keep the default values. Only modify these settings if you’re experiencing connection stability issues or have specific network requirements.

Type: object

tcp.connect_timeout

Maximum amount of time a dial will wait for a connect to complete. Zero disables.

Type: string

Default: 0s

tcp.keep_alive

TCP keep-alive probe configuration.

Type: object

tcp.keep_alive.count

Maximum unanswered keep-alive probes before dropping the connection. Zero defaults to 9.

Type: int

Default: 9

tcp.keep_alive.idle

Duration the connection must be idle before sending the first keep-alive probe. Zero defaults to 15s. Negative values disable keep-alive probes.

Type: string

Default: 15s

tcp.keep_alive.interval

Duration between keep-alive probes. Zero defaults to 15s.

Type: string

Default: 15s

tcp.tcp_user_timeout

Maximum time to wait for acknowledgment of transmitted data before killing the connection. Linux-only (kernel 2.6.37+), ignored on other platforms. When enabled, keep_alive.idle must be greater than this value per RFC 5482. Zero disables.

Type: string

Default: 0s

timeout

Timeout for HTTP requests.

Type: string

Default: 30s

tls

TLS configuration for HTTP client.

Type: object

tls.cert_file

Path to the TLS certificate file for client authentication.

Type: string

Default: ""

tls.enabled

Enable TLS connections.

Type: bool

Default: false

tls.key_file

Path to the TLS key file for client authentication.

Type: string

Default: ""

tls.skip_cert_verify

Skip certificate verification (insecure).

Type: bool

Default: false