Vector // Telemetry & Log Pipeline

Ultra High-Throughput Aggregation • Real-Time Normalization • Multi-Sink Dispatch

Node: x1 Master Pipeline Streaming Backpressure: 0% ← Mission Control HUD
Ingest Throughput
1,280 eps
Events per second
Bandwidth Rate
1.84 MB/s
Zero packet drop
Active Sinks
4 / 4
Splunk, Influx, Datadog, Postgres
Transform Latency
0.42 ms
Memory-safe parsing
🔀 Vector Topology: Sources ➔ Transforms ➔ Sinks
Rust Vector Engine Active
1. Ingest Sources
suricata_eve: Suricata EVE JSON (/var/log/suricata)
184 eps
k3s_audit: K3s Pod & API Server Audit Logs
460 eps
scada_telemetry: Ignition PLC Tag Change Events
340 eps
nginx_edge: AWS Hub SSL Access & TLS logs
120 eps
cluster_syslog: Systemd & Kernel dmesg streams
176 eps
2. VRL Transforms
opsec_masking: Obscure IP octets to xx.xx.xx.<last>
Enforced
geoip_enrich: ASN & country tagging for external probes
Active
json_normalize: ISO 8601 timestamps & Purdue classification
Active
metric_extractor: Convert tag strings to float meters
Active
3. Egress Sinks
splunk_hec: Splunk SIEM (Port 30830)
Healthy (0 errors)
influx_v2: InfluxDB Historian (Port 8086)
Healthy (0 errors)
datadog_agent: Datadog APM Intake (Port 30860)
Healthy (0 errors)
postgres_sink: scada_telemetry_log Table
Healthy (0 errors)