Skip to content

Pipelines

A pipeline defines which events are relevant and how they are normalized before routing. Logstrm compiles pipeline matches during configuration load and applies transformations in a deterministic order.

pipelines:
  - name: azure_frontdoor
    match: 'category == "FrontDoorAccessLog" OR category == "FrontDoorWebApplicationFirewallLog"'
    transform:
      - action: KEEP
        fields: [timestamp, clientIP, requestUri, httpStatusCode, action, category]
      - action: RENAME
        mapping:
          clientIP: source_ip
          httpStatusCode: http_status_code
          requestUri: request_uri

Transformation actions

Action Purpose Guidance
KEEP Allowlist fields Prefer it for controlled SIEM schemas.
DROP Remove fields Use it for raw payloads, debug data and internal metadata.
RENAME Normalize names Keep destination schemas stable across sources.
MASK Redact values Use RE2-safe patterns and scope rules to fields.
ENRICH Add local context Keep lookups bounded and measure cache behavior.

Keep and drop operations should be designed together: allowlisting is usually safer for external destinations, while dropping is useful for preserving a broad internal schema.

Design checklist

  • Give each pipeline a descriptive stable name.
  • Match on source-specific fields before generic fallbacks.
  • Remove raw messages after extracting required fields.
  • Mask before an event leaves the Data Plane.
  • Test representative events, including malformed and unusually large input.