Skip to main content
Fluent Bit forwards logs to Bronto using its built-in HTTP output plugin. This page covers Fluent Bit configuration only. For installation instructions, see the Fluent Bit installation guide. For the full Fluent Bit configuration reference, see the Fluent Bit documentation.

Endpoint and authentication

Use the ingestion endpoint for your Bronto region: Every request requires these headers:

Minimal configuration

Tail a single log file and forward to Bronto.
fluent-bit.conf
For the full HTTP output configuration reference, see the Fluent Bit HTTP output documentation.

Parsing unstructured logs

Rather than building Fluent Bit parsers for unstructured text, ship raw log lines to Bronto and use the Bronto Custom Parser to extract structured fields server-side. The Custom Parser uses LLMs to generate parsers automatically and ships with built-in support for Apache, IIS, HAProxy, Syslog, key-value, and custom formats — no regex maintenance required.

Common patterns

The patterns below cover configuration concerns most Bronto customers run into.

Adding metadata to every log

Use the record_modifier filter to inject metadata — e.g. a deployment identifier, branch name, or region — from environment variables. Export the variable from your CI/CD pipeline or container runtime, then reference it in your Fluent Bit config.
fluent-bit.conf

Multi-line logs (stack traces)

Multi-line application output — like Java, Python, or Ruby stack traces — must be reassembled at the input stage so each stack trace ships as a single log record. Use the multiline.parser directive on [INPUT]. Fluent Bit ships with parsers for java, python, ruby, go, dotnet, and others.
fluent-bit.conf
multiline.parser at the [INPUT] level requires Fluent Bit 1.8 or later.

Routing multiple log sources to separate datasets

A single Fluent Bit instance can ship logs from multiple applications to different Bronto datasets. Tag each [INPUT] distinctly, then use Match on each [OUTPUT].
fluent-bit.conf
The Match field is the routing mechanism — a filter or output with Match api.logs will never apply to worker.logs, and vice versa. A filter with Match * applies to every stream.

Kubernetes

For Kubernetes deployments, install Fluent Bit as a DaemonSet via the official Helm chart and use the x-bronto-collection header to identify the cluster. Dataset names are inferred from Kubernetes metadata.
fluent-bit.conf

Verify log collection

Once you have applied your configuration and restarted Fluent Bit, you can expect to see your log data being ingested to Bronto and accessible via the Search page.

Further reading