otlp_http
Send OpenTelemetry traces, logs, and metrics via OTLP/HTTP protocol.
Introduced in version 4.78.0.
Sends OpenTelemetry telemetry data to a remote collector via OTLP/HTTP protocol.
Accepts batches of Redpanda OTEL v1 protobuf messages (spans, log records, or metrics) and converts them to OTLP format for transmission to OpenTelemetry collectors.
-
Common
-
Advanced
output:
label: ""
otlp_http:
endpoint: "" # No default (required)
max_in_flight: 64
output:
label: ""
otlp_http:
endpoint: "" # No default (required)
content_type: protobuf
headers: {}
timeout: 30s
proxy_url: ""
follow_redirects: false
disable_http2: false
tls:
enabled: false
skip_cert_verify: false
cert_file: ""
key_file: ""
tcp:
connect_timeout: 0s
keep_alive:
idle: 15s
interval: 15s
count: 9
tcp_user_timeout: 0s
oauth:
enabled: false
consumer_key: ""
consumer_secret: ""
access_token: ""
access_token_secret: ""
basic_auth:
enabled: false
username: ""
password: ""
jwt:
enabled: false
private_key_file: ""
signing_method: ""
claims: {}
headers: {}
oauth2:
enabled: false
client_key: ""
client_secret: ""
token_url: ""
scopes: []
endpoint_params: {}
max_in_flight: 64
Input format
Expects messages in Redpanda OTEL v1 protobuf format with metadata:
-
signal_type: "trace", "log", or "metric"
Each batch must contain messages of the same signal type. The entire batch is converted to a single OTLP export request and sent via HTTP POST.
Endpoints
The output automatically appends the signal type path to the base endpoint:
-
Traces:
{endpoint}/v1/traces -
Logs:
{endpoint}/v1/logs -
Metrics:
{endpoint}/v1/metrics
Content types
Supports two content types:
-
protobuf(default):application/x-protobuf -
json:application/json
Fields
basic_auth.password
The password to use for authentication. Used together with username for basic authentication.
|
This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets. |
Type: string
Default: ""
basic_auth.username
The username of the account credentials to authenticate as. Used together with password for basic authentication.
Type: string
Default: ""
content_type
Content type for HTTP requests. Options: 'protobuf' or 'json'.
Type: string
Default: protobuf
Options: protobuf, json
follow_redirects
Transparently follow redirects, i.e. responses with 300-399 status codes. If disabled, the response message will contain the body, status, and headers from the redirect response and the processor will not make a request to the URL set in the Location header of the response.
Type: bool
Default: false
headers
A map of headers to add to the request.
This field supports interpolation functions.
Type: object<string>
Default: {}
# Examples:
headers:
X-Custom-Header: value
traceparent: ${! tracing_span().traceparent }
jwt
Beta
Configure JSON Web Token (JWT) authentication. This feature is in beta and may change in future releases. JWTs provide secure, stateless authentication between services.
Type: object
jwt.claims
A map of claims to include in the JWT. Claims pass the identity of the authenticated entity to the service provider.
Type: object
Default: {}
jwt.headers
Additional key-value pairs to include in the JWT header (optional). These headers provide extra metadata for JWT processing.
Type: object
Default: {}
jwt.private_key_file
Path to a file containing the PEM-encoded private key using PKCS#1 or PKCS#8 format. The private key must be compatible with the algorithm specified in the signing_method field.
Type: string
Default: ""
jwt.signing_method
The cryptographic algorithm used to sign the JWT. Supported algorithms are RS256, RS384, RS512, and EdDSA. This algorithm must be compatible with the private key specified in the private_key_file field.
Type: string
Default: ""
max_in_flight
The maximum number of messages to have in flight at a given time. For outputs that send messages in batches, this limit applies to message batches. Increase this value to improve throughput.
Type: int
Default: 64
oauth.access_token
The value used to gain access to the protected resources on behalf of the user.
Type: string
Default: ""
oauth.access_token_secret
The secret that establishes ownership of the access_token in OAuth 1.0 authentication.
|
This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets. |
Type: string
Default: ""
oauth.consumer_key
The value used to identify this component or client to the service provider.
Type: string
Default: ""
oauth.consumer_secret
The secret that establishes ownership of the consumer key in OAuth 1.0 authentication.
|
This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets. |
Type: string
Default: ""
oauth.enabled
Whether to enable OAuth version 1.0 authentication for requests.
Type: bool
Default: false
oauth2
Allows you to specify open authentication via OAuth version 2 using the client credentials token flow.
Type: object
oauth2.client_key
A value used to identify the client to the token provider.
Type: string
Default: ""
oauth2.client_secret
A secret used to establish ownership of the client key.
|
This field contains sensitive information that usually shouldn’t be added to a configuration directly. For more information, see Secrets. |
Type: string
Default: ""
oauth2.endpoint_params
A list of optional endpoint parameters, values should be arrays of strings.
Type: object
Default: {}
# Examples:
endpoint_params:
audience:
- https://example.com
resource:
- https://api.example.com
tcp
Configure TCP socket-level settings to optimize network performance and reliability. These low-level controls are useful for:
-
Unresponsive hosts: Set
connect_timeoutto limit how long a connection attempt can take (the default0ssets no limit) -
Long-lived connections: Configure
keep_alivesettings to detect and recover from stale connections -
Unstable networks: Tune keep-alive probes to balance between quick failure detection and avoiding false positives
-
Linux systems with specific requirements: Use
tcp_user_timeout(Linux 2.6.37+) to control data acknowledgment timeouts
Most users should keep the default values. Only modify these settings if you’re experiencing connection stability issues or have specific network requirements.
Type: object
tcp.connect_timeout
Maximum amount of time a dial will wait for a connect to complete. Zero disables.
Type: string
Default: 0s
tcp.keep_alive.count
Maximum unanswered keep-alive probes before dropping the connection. Zero defaults to 9.
Type: int
Default: 9
tcp.keep_alive.idle
Duration the connection must be idle before sending the first keep-alive probe. Zero defaults to 15s. Negative values disable keep-alive probes.
Type: string
Default: 15s
tcp.keep_alive.interval
Duration between keep-alive probes. Zero defaults to 15s.
Type: string
Default: 15s