@@ -83218,6 +83218,296 @@ components:
8321883218 description: A session identifier used for logging and tracing the assumed role session.
8321983219 type: string
8322083220 type: object
83221+ ObservabilityPipelineAzureDataExplorerDestination:
83222+ description: |-
83223+ The `azure_data_explorer` destination sends log events to an Azure Data Explorer table.
83224+
83225+ **Supported pipeline types:** logs
83226+ properties:
83227+ auth:
83228+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuth"
83229+ batch:
83230+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationBatch"
83231+ buffer:
83232+ $ref: "#/components/schemas/ObservabilityPipelineBufferOptions"
83233+ compression:
83234+ $ref: "#/components/schemas/ObservabilityPipelineAzureStorageDestinationCompressionGzip"
83235+ database:
83236+ description: The name of the Azure Data Explorer database to ingest into. Supports template syntax.
83237+ example: logs_db
83238+ type: string
83239+ id:
83240+ description: The unique identifier for this component.
83241+ example: azure-data-explorer-destination
83242+ type: string
83243+ ingestion_endpoint_key:
83244+ description: |-
83245+ Name of the environment variable or secret that holds the Azure Data Explorer ingestion endpoint URL.
83246+ Defaults to `DESTINATION_AZURE_DATA_EXPLORER_INGESTION_ENDPOINT` (prefixed with `DD_OP_` at runtime).
83247+ example: AZURE_DATA_EXPLORER_INGESTION_ENDPOINT
83248+ type: string
83249+ inputs:
83250+ description: A list of component IDs whose output is used as the `input` for this component.
83251+ example: ["filter-processor"]
83252+ items:
83253+ description: The ID of a component whose output is used as input for this destination.
83254+ type: string
83255+ type: array
83256+ mapping_reference:
83257+ description: The name of a pre-created ingestion mapping on the table used to map incoming events to columns. Supports template syntax.
83258+ example: application_logs_mapping
83259+ nullable: true
83260+ type: string
83261+ table:
83262+ description: The name of the Azure Data Explorer table to ingest into. Supports template syntax.
83263+ example: application_logs
83264+ type: string
83265+ token_scope:
83266+ description: |-
83267+ The OAuth scope requested when acquiring an access token for Azure Data Explorer.
83268+ Defaults to `https://kusto.kusto.windows.net/.default`.
83269+ example: https://kusto.kusto.windows.net/.default
83270+ type: string
83271+ type:
83272+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationType"
83273+ required:
83274+ - id
83275+ - type
83276+ - inputs
83277+ - database
83278+ - table
83279+ - auth
83280+ type: object
83281+ x-pipeline-types: [logs]
83282+ ObservabilityPipelineAzureDataExplorerDestinationAuth:
83283+ description: Authentication configuration for Azure Data Explorer. The `azure_credential_kind` field selects the credential type.
83284+ oneOf:
83285+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthAzureCli"
83286+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthClientSecret"
83287+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthClientCertificate"
83288+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentity"
83289+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityClientAssertion"
83290+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthWorkloadIdentity"
83291+ ObservabilityPipelineAzureDataExplorerDestinationAuthAzureCli:
83292+ description: Authenticate using the Azure CLI credentials available in the environment.
83293+ properties:
83294+ azure_credential_kind:
83295+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthAzureCliKind"
83296+ required:
83297+ - azure_credential_kind
83298+ type: object
83299+ ObservabilityPipelineAzureDataExplorerDestinationAuthAzureCliKind:
83300+ default: azure_cli
83301+ description: The Azure credential kind. The value should always be `azure_cli`.
83302+ enum:
83303+ - azure_cli
83304+ example: azure_cli
83305+ type: string
83306+ x-enum-varnames:
83307+ - AZURE_CLI
83308+ ObservabilityPipelineAzureDataExplorerDestinationAuthClientCertificate:
83309+ description: Authenticate using a Microsoft Entra application client certificate.
83310+ properties:
83311+ azure_client_id:
83312+ description: The Microsoft Entra application (client) ID.
83313+ example: 22222222-2222-2222-2222-222222222222
83314+ type: string
83315+ azure_credential_kind:
83316+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthClientCertificateKind"
83317+ azure_tenant_id:
83318+ description: The Microsoft Entra tenant ID.
83319+ example: 11111111-1111-1111-1111-111111111111
83320+ type: string
83321+ certificate_password_key:
83322+ description: Name of the environment variable or secret that holds the password for the client certificate.
83323+ example: AZURE_CERTIFICATE_PASSWORD
83324+ nullable: true
83325+ type: string
83326+ certificate_path:
83327+ description: Path to the `.pfx` client certificate file on the Worker.
83328+ example: /etc/certs/client.pfx
83329+ type: string
83330+ required:
83331+ - azure_credential_kind
83332+ - azure_tenant_id
83333+ - azure_client_id
83334+ - certificate_path
83335+ type: object
83336+ ObservabilityPipelineAzureDataExplorerDestinationAuthClientCertificateKind:
83337+ default: client_certificate_credential
83338+ description: The Azure credential kind. The value should always be `client_certificate_credential`.
83339+ enum:
83340+ - client_certificate_credential
83341+ example: client_certificate_credential
83342+ type: string
83343+ x-enum-varnames:
83344+ - CLIENT_CERTIFICATE_CREDENTIAL
83345+ ObservabilityPipelineAzureDataExplorerDestinationAuthClientSecret:
83346+ description: Authenticate using a Microsoft Entra application client secret.
83347+ properties:
83348+ azure_client_id:
83349+ description: The Microsoft Entra application (client) ID.
83350+ example: 22222222-2222-2222-2222-222222222222
83351+ type: string
83352+ azure_client_secret_key:
83353+ description: Name of the environment variable or secret that holds the Microsoft Entra application client secret.
83354+ example: AZURE_CLIENT_SECRET
83355+ type: string
83356+ azure_credential_kind:
83357+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthClientSecretKind"
83358+ azure_tenant_id:
83359+ description: The Microsoft Entra tenant ID.
83360+ example: 11111111-1111-1111-1111-111111111111
83361+ type: string
83362+ required:
83363+ - azure_credential_kind
83364+ - azure_tenant_id
83365+ - azure_client_id
83366+ - azure_client_secret_key
83367+ type: object
83368+ ObservabilityPipelineAzureDataExplorerDestinationAuthClientSecretKind:
83369+ default: client_secret_credential
83370+ description: The Azure credential kind. The value should always be `client_secret_credential`.
83371+ enum:
83372+ - client_secret_credential
83373+ example: client_secret_credential
83374+ type: string
83375+ x-enum-varnames:
83376+ - CLIENT_SECRET_CREDENTIAL
83377+ ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentity:
83378+ description: Authenticate using an Azure managed identity.
83379+ properties:
83380+ azure_credential_kind:
83381+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityKind"
83382+ user_assigned_managed_identity_id:
83383+ description: The ID of the user-assigned managed identity. If omitted, the system-assigned managed identity is used.
83384+ example: 00000000-0000-0000-0000-000000000000
83385+ nullable: true
83386+ type: string
83387+ user_assigned_managed_identity_id_type:
83388+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationManagedIdentityIdType"
83389+ required:
83390+ - azure_credential_kind
83391+ type: object
83392+ ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityClientAssertion:
83393+ description: Authenticate using a managed identity as a client assertion for a Microsoft Entra application.
83394+ properties:
83395+ azure_credential_kind:
83396+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityClientAssertionKind"
83397+ client_assertion_client_id:
83398+ description: The client ID of the Microsoft Entra application that trusts the managed identity.
83399+ example: 22222222-2222-2222-2222-222222222222
83400+ type: string
83401+ client_assertion_tenant_id:
83402+ description: The tenant ID of the Microsoft Entra application that trusts the managed identity.
83403+ example: 11111111-1111-1111-1111-111111111111
83404+ type: string
83405+ user_assigned_managed_identity_id:
83406+ description: The ID of the user-assigned managed identity. If omitted, the system-assigned managed identity is used.
83407+ example: 00000000-0000-0000-0000-000000000000
83408+ nullable: true
83409+ type: string
83410+ user_assigned_managed_identity_id_type:
83411+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationManagedIdentityIdType"
83412+ required:
83413+ - azure_credential_kind
83414+ - client_assertion_client_id
83415+ - client_assertion_tenant_id
83416+ type: object
83417+ ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityClientAssertionKind:
83418+ default: managed_identity_client_assertion
83419+ description: The Azure credential kind. The value should always be `managed_identity_client_assertion`.
83420+ enum:
83421+ - managed_identity_client_assertion
83422+ example: managed_identity_client_assertion
83423+ type: string
83424+ x-enum-varnames:
83425+ - MANAGED_IDENTITY_CLIENT_ASSERTION
83426+ ObservabilityPipelineAzureDataExplorerDestinationAuthManagedIdentityKind:
83427+ default: managed_identity
83428+ description: The Azure credential kind. The value should always be `managed_identity`.
83429+ enum:
83430+ - managed_identity
83431+ example: managed_identity
83432+ type: string
83433+ x-enum-varnames:
83434+ - MANAGED_IDENTITY
83435+ ObservabilityPipelineAzureDataExplorerDestinationAuthWorkloadIdentity:
83436+ description: Authenticate using Azure Workload Identity (for example, on Kubernetes).
83437+ properties:
83438+ azure_credential_kind:
83439+ $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestinationAuthWorkloadIdentityKind"
83440+ client_id:
83441+ description: The client ID of the Microsoft Entra application. If omitted, it is read from the environment.
83442+ example: 22222222-2222-2222-2222-222222222222
83443+ nullable: true
83444+ type: string
83445+ tenant_id:
83446+ description: The Microsoft Entra tenant ID. If omitted, it is read from the environment.
83447+ example: 11111111-1111-1111-1111-111111111111
83448+ nullable: true
83449+ type: string
83450+ token_file_path:
83451+ description: Path to the federated token file. If omitted, it is read from the environment.
83452+ example: /var/run/secrets/azure/tokens/azure-identity-token
83453+ nullable: true
83454+ type: string
83455+ required:
83456+ - azure_credential_kind
83457+ type: object
83458+ ObservabilityPipelineAzureDataExplorerDestinationAuthWorkloadIdentityKind:
83459+ default: workload_identity
83460+ description: The Azure credential kind. The value should always be `workload_identity`.
83461+ enum:
83462+ - workload_identity
83463+ example: workload_identity
83464+ type: string
83465+ x-enum-varnames:
83466+ - WORKLOAD_IDENTITY
83467+ ObservabilityPipelineAzureDataExplorerDestinationBatch:
83468+ description: Event batching settings for Azure Data Explorer ingestion.
83469+ properties:
83470+ max_bytes:
83471+ description: Maximum batch size in bytes.
83472+ example: 2000000
83473+ format: int64
83474+ maximum: 4000000
83475+ minimum: 1
83476+ type: integer
83477+ max_events:
83478+ description: Maximum number of events per batch before it is flushed.
83479+ example: 1000
83480+ format: int64
83481+ minimum: 1
83482+ type: integer
83483+ timeout_secs:
83484+ description: Maximum number of seconds to wait before flushing a partial batch.
83485+ example: 1
83486+ format: int64
83487+ minimum: 1
83488+ type: integer
83489+ type: object
83490+ ObservabilityPipelineAzureDataExplorerDestinationManagedIdentityIdType:
83491+ description: The type of the user-assigned managed identity ID.
83492+ enum:
83493+ - client_id
83494+ - object_id
83495+ - resource_id
83496+ example: client_id
83497+ type: string
83498+ x-enum-varnames:
83499+ - CLIENT_ID
83500+ - OBJECT_ID
83501+ - RESOURCE_ID
83502+ ObservabilityPipelineAzureDataExplorerDestinationType:
83503+ default: azure_data_explorer
83504+ description: The destination type. The value should always be `azure_data_explorer`.
83505+ enum:
83506+ - azure_data_explorer
83507+ example: azure_data_explorer
83508+ type: string
83509+ x-enum-varnames:
83510+ - AZURE_DATA_EXPLORER
8322183511 ObservabilityPipelineAzureStorageDestinationCompression:
8322283512 description: |-
8322383513 Compression configuration for archived logs. When omitted, logs are compressed with gzip
@@ -83630,6 +83920,7 @@ components:
8363083920 - $ref: "#/components/schemas/ObservabilityPipelineAmazonS3GenericDestination"
8363183921 - $ref: "#/components/schemas/ObservabilityPipelineAmazonSecurityLakeDestination"
8363283922 - $ref: "#/components/schemas/AzureStorageDestination"
83923+ - $ref: "#/components/schemas/ObservabilityPipelineAzureDataExplorerDestination"
8363383924 - $ref: "#/components/schemas/ObservabilityPipelineClickhouseDestination"
8363483925 - $ref: "#/components/schemas/ObservabilityPipelineCloudPremDestination"
8363583926 - $ref: "#/components/schemas/ObservabilityPipelineCrowdStrikeNextGenSiemDestination"
0 commit comments