Skip to main content

OVHcloud Logs Data Platform

SIEM Platform

Synopsis

The OVHcloud target forwards events, formatted as GELF, to the OVHcloud Logs Data Platform GELF input over TLS, TCP, UDP, or HTTPS. It handles GELF wire framing for the chosen transport — the event payload is expected to already be a complete GELF JSON document when it reaches the target.

Schema

- name: <string>
description: <string>
type: ovhcloud
pipelines: <pipeline[]>
status: <boolean>
properties:
address: <string>
port: <numeric>
protocol: <string>
max_message_size: <numeric>
url: <string>
timeout: <numeric>
tls:
verify: <boolean>
server_name: <string>
ca_name: <string>
cert_name: <string>
key_name: <string>
passphrase: <string>
min_tls_version: <string>
max_tls_version: <string>
field_format: <string>
debug:
status: <boolean>
dont_send_logs: <boolean>

Configuration

The following fields are used to define the target:

FieldRequiredDefaultDescription
nameYTarget name
descriptionN-Optional description
typeYMust be ovhcloud
pipelinesN-Optional post-processor pipelines
statusNtrueEnable/disable the target

Connection

FieldRequiredDefaultDescription
addressY*-OVHcloud Logs Data Platform GELF endpoint, for example gra1.logs.ovh.com. Required for the tls, tcp, and udp transports
portN12202GELF+TLS input port
protocolNtlsTransport: tls (recommended, required by OVHcloud LDP) | tcp | udp (chunked) | https
max_message_sizeN8192UDP only: payload bytes per chunk before GELF chunking. 0 sends a single datagram. Ignored for tls/tcp/https
urlN*built as scheme://address:port/gelfhttps only: explicit endpoint override
timeoutN30Connection/write timeout in seconds. Bounds the stream dial and write deadline for tls/tcp/udp, and the HTTP client timeout for https

* = Conditionally required. address is required for tls, tcp, and udp; for https, either address (with port) or an explicit url must be supplied.

TLS

FieldRequiredDefaultDescription
tls.verifyNtrueVerify the server certificate
tls.server_nameN-SNI / expected server hostname
tls.ca_nameN-Custom CA to trust. Empty uses the OS trust store
tls.cert_nameN*-Client certificate for mutual TLS
tls.key_nameN*-Client key for mutual TLS
tls.passphraseN-Passphrase for an encrypted client key
tls.min_tls_versionNtls1.2Minimum negotiated TLS version
tls.max_tls_versionNtls1.3Maximum negotiated TLS version

* = Conditionally optional. tls.cert_name and tls.key_name must be supplied together to enable mutual TLS; supplying only one fails configuration validation. There is no tls.status field — TLS is engaged by setting protocol: tls or protocol: https.

note

TLS material fields (cert_name, key_name, ca_name, client_ca_name) accept any of the following:

  • File name — resolved relative to the service root directory. Nested paths such as certs/prod/server.pem are supported.
  • Absolute path — honored only if it resolves inside the service root. Any path that escapes the root is refused.
  • Inline PEM content — used verbatim when the value contains -----BEGIN.
  • Environment variable${ENV_VAR}.
  • Vault reference$secret{id=...} or $secret{store=...,ref=...}.

Processing

FieldRequiredDefaultDescription
field_formatN-Optional target-side normalization format applied before delivery. Typically left empty, since the payload already arrives as GELF from upstream processing. See applicable Normalization section

Scheduling

See Scheduling and Pool Behavior for interval and cron fields shared by all targets.

Debug Options

FieldRequiredDefaultDescription
debug.statusNfalseEnable debug logging
debug.dont_send_logsNfalseProcess logs but don't send to target (testing)

Details

This target is transport-only: it does not render GELF itself. It expects each event to already be a complete GELF JSON document when it reaches the target, and applies wire framing and delivery on top of that payload. There is no batching — each event is a single, complete delivery to the OVHcloud Logs Data Platform GELF input.

OVHcloud Requires TLS

Unlike the generic GELF target, this target defaults protocol to tls and port to 12202, and tls.verify defaults to true. The OVHcloud Logs Data Platform GELF input requires an encrypted connection; the tcp and udp transports remain available for non-default configurations, but tls (or https) is the expected transport.

Authentication

OVHcloud LDP authenticates ingestion per log stream using an X-OVH-TOKEN value. This token is carried as a GELF field on each event — set upstream, before the event reaches this target — rather than as a property of this target's configuration.

Transports

  • GELF-TLS (default): the document is written null-delimited over a TLS-wrapped stream.
  • GELF-TCP: the same null-delimited framing, without TLS.
  • GELF-UDP: the document is sent as one datagram, or split into GELF-chunked datagrams (2-byte magic 0x1e 0x0f, 8-byte message ID, sequence number, sequence count) when it exceeds max_message_size. A document that would need more than 128 chunks fails — use tls or tcp for events that large.
  • GELF-HTTPS: the document is POSTed as the request body to the GELF HTTPS input.

Endpoint Resolution (HTTPS)

An explicit url always wins. Otherwise the endpoint is built as https://address:port/gelf.

note

The target does not perform GELF rendering or field mapping — it only frames and delivers the payload it receives. Format the event as GELF, with the X-OVH-TOKEN field set, before it reaches this target.

Examples

Secure TLS

Sending GELF events to the OVHcloud Logs Data Platform over TLS...

targets:
- name: ovhcloud
type: ovhcloud
properties:
address: "gra1.logs.ovh.com"
port: 12202
tls:
verify: true

Custom Timeout

Widening the connection and write timeout for a slower network path...

targets:
- name: ovhcloud-timeout
type: ovhcloud
properties:
address: "gra1.logs.ovh.com"
timeout: 60