.cloud.databricks.com`. The Worker uses this endpoint to read the table's schema.
1. In the {{< ui >}}Auth - Client ID{{< /ui >}} field, enter the application ID of the service principal, such as `abcdefgh-1234-5678-abcd-ef0123456789`.
1. In the {{< ui >}}Auth - Client Secret{{< /ui >}} field, enter the identifier for your OAuth client secret. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Buffering
diff --git a/content/en/observability_pipelines/destinations/elasticsearch.md b/content/en/observability_pipelines/destinations/elasticsearch.md
index 0c714b7e264..b346463e4dd 100644
--- a/content/en/observability_pipelines/destinations/elasticsearch.md
+++ b/content/en/observability_pipelines/destinations/elasticsearch.md
@@ -18,11 +18,9 @@ Use Observability Pipelines' Elasticsearch destination to send logs or metrics t
## Setup
-Configure the Elasticsearch destination when you [set up a pipeline][7]. You can set up a pipeline in the [UI][1], using the [API][8], or with [Terraform][9]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the Elasticsearch endpoint URL, username, and password. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the Elasticsearch destination when you [set up a pipeline][7]. You can set up a pipeline in the [UI][1], using the [API][8], or with [Terraform][9]. The steps in this section are configured in the UI.
After you select the Elasticsearch destination in the pipeline UI:
@@ -48,6 +46,8 @@ After you select the Elasticsearch destination in the pipeline UI:
- `logs-apache-production` for logs
- `metrics-apache-production` for metrics
+{{% observability_pipelines/secrets_env_var_note %}}
+
#### Optional settings
##### Enable TLS
diff --git a/content/en/observability_pipelines/destinations/google_pubsub.md b/content/en/observability_pipelines/destinations/google_pubsub.md
index c50824f64af..6f9d17c70ef 100644
--- a/content/en/observability_pipelines/destinations/google_pubsub.md
+++ b/content/en/observability_pipelines/destinations/google_pubsub.md
@@ -103,10 +103,10 @@ After you select the Google Pub/Sub destination in the pipeline UI:
For Secrets Management: Only enter the identifier for the TLS key pass. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
-
{{% observability_pipelines/tls_settings %}}
+{{% observability_pipelines/secrets_env_var_note %}}
+
#### Buffering
{{% observability_pipelines/destination_buffer %}}
diff --git a/content/en/observability_pipelines/destinations/google_secops.md b/content/en/observability_pipelines/destinations/google_secops.md
index 2cf06861d25..5ff54f97000 100644
--- a/content/en/observability_pipelines/destinations/google_secops.md
+++ b/content/en/observability_pipelines/destinations/google_secops.md
@@ -17,11 +17,9 @@ The Observability Pipelines Worker uses standard Google authentication methods.
## Setup
-Configure the Google SecOps destination when you [set up a pipeline][8]. You can set up a pipeline in the [UI][1], using the [API][9], or with [Terraform][10]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifier for the Google SecOps endpoint URL. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the Google SecOps destination when you [set up a pipeline][8]. You can set up a pipeline in the [UI][1], using the [API][9], or with [Terraform][10]. The steps in this section are configured in the UI.
After you select the Google SecOps destination in the pipeline UI:
@@ -33,6 +31,8 @@ After you select the Google SecOps destination in the pipeline UI:
1. Select {{< ui >}}JSON{{< /ui >}} or {{< ui >}}Raw{{< /ui >}} encoding in the dropdown menu.
1. Enter the log type. See [template syntax][4] if you want to route logs to different log types based on specific fields in your logs.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional buffering
{{% observability_pipelines/destination_buffer %}}
diff --git a/content/en/observability_pipelines/destinations/http_client.md b/content/en/observability_pipelines/destinations/http_client.md
index 54a432e5c20..19f2e8c78c1 100644
--- a/content/en/observability_pipelines/destinations/http_client.md
+++ b/content/en/observability_pipelines/destinations/http_client.md
@@ -18,11 +18,9 @@ Use Observability Pipelines' HTTP Client destination to send logs to an HTTP cli
## Set up destination
-Configure the HTTP Client destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the HTTP Client URI and, if applicable, username and password for basic authorization and the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the HTTP Client destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
After you select the HTTP Client destination in the pipeline UI:
@@ -35,6 +33,8 @@ After you select the HTTP Client destination in the pipeline UI:
- Enter the identifier for your HTTP Client token. If you leave it blank, the [default](#secret-defaults) is used.
1. JSON is the only available encoder.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable compression
diff --git a/content/en/observability_pipelines/destinations/kafka.md b/content/en/observability_pipelines/destinations/kafka.md
index cb8a2c3616d..476056479b3 100644
--- a/content/en/observability_pipelines/destinations/kafka.md
+++ b/content/en/observability_pipelines/destinations/kafka.md
@@ -27,11 +27,9 @@ Common scenarios when you might use this destination:
## Setup
-Configure the Kafka destination when you [set up a pipeline][10]. You can set up a pipeline in the [UI][5], using the [API][11], or with [Terraform][12]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the Kafka bootstrap servers and, if applicable, the SASL username and password and the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the Kafka destination when you [set up a pipeline][10]. You can set up a pipeline in the [UI][5], using the [API][11], or with [Terraform][12]. The steps in this section are configured in the UI.
After you select the Kafka destination in the pipeline UI:
@@ -41,6 +39,8 @@ After you select the Kafka destination in the pipeline UI:
{{< img src="observability_pipelines/destinations/kafka_settings.png" alt="The Kafka destination with sample values" style="width:30%;" >}}
+{{% observability_pipelines/secrets_env_var_note %}}
+
#### Optional settings
##### Enable TLS
diff --git a/content/en/observability_pipelines/destinations/microsoft_sentinel.md b/content/en/observability_pipelines/destinations/microsoft_sentinel.md
index 3ef4095e0a5..91c96600b4c 100644
--- a/content/en/observability_pipelines/destinations/microsoft_sentinel.md
+++ b/content/en/observability_pipelines/destinations/microsoft_sentinel.md
@@ -156,11 +156,9 @@ The table below summarizes the Azure and Microsoft Sentinel information you need
## Setup
-Set up the Microsoft Sentinel destination when you [set up a pipeline][10]. You can set up a pipeline in the [UI][1], using the [API][11], or with [Terraform][12]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the Microsoft Sentinel client secret and Data Collection Endpoint. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up the Microsoft Sentinel destination when you [set up a pipeline][10]. You can set up a pipeline in the [UI][1], using the [API][11], or with [Terraform][12]. The steps in this section are configured in the UI.
After you select the Microsoft Sentinel destination in the pipeline UI:
@@ -171,6 +169,8 @@ After you select the Microsoft Sentinel destination in the pipeline UI:
1. Enter the full table name to which you are sending logs. An example table name: `Custom-MyOPWLogs_CL`.
1. Enter the Data Collection Rule (DCR) immutable ID, such as `dcr-000a00a000a00000a000000aa000a0aa`.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional buffering
{{% observability_pipelines/destination_buffer %}}
diff --git a/content/en/observability_pipelines/destinations/new_relic.md b/content/en/observability_pipelines/destinations/new_relic.md
index c1a6f828b10..9a6a860901a 100644
--- a/content/en/observability_pipelines/destinations/new_relic.md
+++ b/content/en/observability_pipelines/destinations/new_relic.md
@@ -15,11 +15,9 @@ Use Observability Pipelines' New Relic destination to send logs to New Relic.
## Setup
-Configure the New Relic destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the account ID and license. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the New Relic destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
After you select the New Relic destination in the pipeline UI:
@@ -27,6 +25,8 @@ After you select the New Relic destination in the pipeline UI:
1. Enter the identifier for your license. If you leave it blank, the [default](#secret-defaults) is used.
1. Select the data center region ({{< ui >}}US{{< /ui >}} or {{< ui >}}EU{{< /ui >}}) of your New Relic account.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional buffering
{{% observability_pipelines/destination_buffer %}}
diff --git a/content/en/observability_pipelines/destinations/opensearch.md b/content/en/observability_pipelines/destinations/opensearch.md
index 9ce5fe96a8b..957cf244922 100644
--- a/content/en/observability_pipelines/destinations/opensearch.md
+++ b/content/en/observability_pipelines/destinations/opensearch.md
@@ -15,11 +15,9 @@ Use Observability Pipelines' OpenSearch destination to send logs to OpenSearch.
## Setup
-Configure the OpenSearch destination when you [set up a pipeline][6]. You can set up a pipeline in the [UI][1], using the [API][7], or with [Terraform][8]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the OpenSearch endpoint URL, username, and password. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the OpenSearch destination when you [set up a pipeline][6]. You can set up a pipeline in the [UI][1], using the [API][7], or with [Terraform][8]. The steps in this section are configured in the UI.
After you select the OpenSearch destination in the pipeline UI:
@@ -41,6 +39,8 @@ After you select the OpenSearch destination in the pipeline UI:
- In the {{< ui >}}Namespace{{< /ui >}} field, enter the grouping for organizing your data streams, for example `production`.
- In the UI, there is a preview of the data stream name you configured. With the above example inputs, the data stream name that the Worker writes to is `logs-apache-production`.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### OpenSearch index
diff --git a/content/en/observability_pipelines/destinations/sentinelone.md b/content/en/observability_pipelines/destinations/sentinelone.md
index 6091da4e1c3..58fdec589eb 100644
--- a/content/en/observability_pipelines/destinations/sentinelone.md
+++ b/content/en/observability_pipelines/destinations/sentinelone.md
@@ -19,17 +19,17 @@ Use Observability Pipelines' SentinelOne destination to send logs to SentinelOne
## Setup
+For Secrets Management: Only enter the identifier for the token. Do not enter the actual value.
+
Configure the SentinelOne destination when you [set up a pipeline][4]. You can set up a pipeline in the [UI][1], using the [API][5], or with [Terraform][6]. The steps in this section are configured in the UI.
After you select the SentinelOne destination in the pipeline UI:
-For Secrets Management: Only enter the identifier for the token. Do not enter the actual value.
-
-{{% observability_pipelines/secrets_env_var_note %}}
-
1. Enter the identifier for your token. If you leave it blank, the [default](#secret-defaults) is used.
1. Select your SentinelOne logs environment in the dropdown menu.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional buffering
{{% observability_pipelines/destination_buffer %}}
diff --git a/content/en/observability_pipelines/destinations/socket.md b/content/en/observability_pipelines/destinations/socket.md
index 95ef1c41b75..fcb1e83604a 100644
--- a/content/en/observability_pipelines/destinations/socket.md
+++ b/content/en/observability_pipelines/destinations/socket.md
@@ -15,18 +15,18 @@ Use Observability Pipelines' Socket destination to send logs to a socket endpoin
## Setup
+For Secrets Management: Only enter the identifier for the socket address and, if applicable, the key pass. Do not enter the actual values.
+
Configure the Socket destination when you [set up a pipeline][2]. You can set up a pipeline in the [UI][1], using the [API][3], or with [Terraform][4]. The steps in this section are configured in the UI.
After you select the Socket destination in the pipeline UI:
-For Secrets Management: Only enter the identifier for the socket address and, if applicable, the key pass. Do not enter the actual values.
-
-{{% observability_pipelines/secrets_env_var_note %}}
-
1. Enter the identifier for your address. If you leave it blank, the [default](#secret-defaults) is used.
1. In the {{< ui >}}Mode{{< /ui >}} dropdown menu, select the socket type to use.
1. In the {{< ui >}}Encoding{{< /ui >}} dropdown menu, select either {{< ui >}}JSON{{< /ui >}} or {{< ui >}}Raw message{{< /ui >}} as the output format.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable TLS
diff --git a/content/en/observability_pipelines/destinations/splunk_hec/logs.md b/content/en/observability_pipelines/destinations/splunk_hec/logs.md
index a3e18e09cd5..c1e12269453 100644
--- a/content/en/observability_pipelines/destinations/splunk_hec/logs.md
+++ b/content/en/observability_pipelines/destinations/splunk_hec/logs.md
@@ -17,11 +17,9 @@ Use Observability Pipelines' Splunk HTTP Event Collector (HEC) destination to se
## Setup
-Configure the Splunk HEC destination when you [set up a pipeline][5]. You can set up a pipeline in the [UI][1], using the [API][6], or with [Terraform][7]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifiers for the Splunk HEC token and endpoint. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the Splunk HEC destination when you [set up a pipeline][5]. You can set up a pipeline in the [UI][1], using the [API][6], or with [Terraform][7]. The steps in this section are configured in the UI.
After you select the Splunk HEC destination in the pipeline UI:
@@ -32,6 +30,8 @@ After you select the Splunk HEC destination in the pipeline UI:
1. Enter the identifier for your token. If you leave it blank, the [default](#secret-defaults) is used.
1. Enter the identifier for your endpoint URL. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Splunk index
diff --git a/content/en/observability_pipelines/destinations/splunk_hec/metrics.md b/content/en/observability_pipelines/destinations/splunk_hec/metrics.md
index 5c749589ab5..0ec39eb8909 100644
--- a/content/en/observability_pipelines/destinations/splunk_hec/metrics.md
+++ b/content/en/observability_pipelines/destinations/splunk_hec/metrics.md
@@ -13,21 +13,21 @@ Use Observability Pipelines' Splunk HTTP Event Collector (HEC) destination to se
## Setup
+For Secrets Management: Only enter the identifiers for the Splunk HEC token, endpoint, and if applicable, the TLS key pass. Do not enter the actual values.
+
Configure the Splunk HEC destination when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
**Notes**:
- The Splunk index you send your metrics to must be a metrics index. If you send your metrics to an events index, you can't view them in Splunk using any metrics type queries, such as `mcatalog` and `mstats`.
- If you don't attach your index to the Splunk authentication token you are using for Observability Pipelines, you must enter the name of the [index](#splunk-index) when you set up the destination.
-For Secrets Management: Only enter the identifiers for the Splunk HEC token, endpoint, and if applicable, the TLS key pass. Do not enter the actual values.
-
-{{% observability_pipelines/secrets_env_var_note %}}
-
After you select the Splunk HEC destination in the pipeline UI:
1. Enter the identifier for your token. If you leave it blank, the [default](#secret-defaults) is used.
1. Enter the identifier for your endpoint URL. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Default namespace
diff --git a/content/en/observability_pipelines/destinations/sumo_logic_hosted_collector.md b/content/en/observability_pipelines/destinations/sumo_logic_hosted_collector.md
index e5ccd72f3b8..8eff7d075f9 100644
--- a/content/en/observability_pipelines/destinations/sumo_logic_hosted_collector.md
+++ b/content/en/observability_pipelines/destinations/sumo_logic_hosted_collector.md
@@ -15,14 +15,14 @@ Use Observability Pipelines' Sumo Logic destination to send logs to your Sumo Lo
## Setup
-Configure the Sumo Logic destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifier for the endpoint URL. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the Sumo Logic destination when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The steps in this section are configured in the UI.
After you select the Sumo Logic destination in the pipeline UI, enter the identifier for your endpoint URL. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
1. In the {{< ui >}}Encoding{{< /ui >}} dropdown menu, select whether you want to encode your pipeline's output in `JSON`, `Logfmt`, or `Raw` text. If no decoding is selected, the decoding defaults to JSON.
diff --git a/content/en/observability_pipelines/destinations/syslog.md b/content/en/observability_pipelines/destinations/syslog.md
index 7c178592290..a85f1bccc0f 100644
--- a/content/en/observability_pipelines/destinations/syslog.md
+++ b/content/en/observability_pipelines/destinations/syslog.md
@@ -17,16 +17,16 @@ Use Observability Pipelines' syslog destinations to send logs to rsyslog or sysl
## Setup
-Configure the rsyslog or syslog-ng destination when you [set up a pipeline][2]. You can set up a pipeline in the [UI][1], using the [API][3], or with [Terraform][4]. The steps in this section are configured in the UI.
-
For Secrets Management: Only enter the identifier for the syslog endpoint URL and, if applicable, the key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Configure the rsyslog or syslog-ng destination when you [set up a pipeline][2]. You can set up a pipeline in the [UI][1], using the [API][3], or with [Terraform][4]. The steps in this section are configured in the UI.
After you select the rsyslog or syslog-ng destination in the pipeline UI, enter the identifier for your endpoint URL. If you leave it blank, the [default](#secret-defaults) is used.
See [Matching log fields to syslog fields](#matching-log-fields-to-syslog-fields) for information on how fields are matched.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable TLS
diff --git a/content/en/observability_pipelines/sources/amazon_data_firehose.md b/content/en/observability_pipelines/sources/amazon_data_firehose.md
index c35734bd0ab..20737541f26 100644
--- a/content/en/observability_pipelines/sources/amazon_data_firehose.md
+++ b/content/en/observability_pipelines/sources/amazon_data_firehose.md
@@ -19,14 +19,14 @@ Use Observability Pipelines' Amazon Data Firehose source to receive logs from Am
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Amazon Data Firehose address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the Amazon Data Firehose source in the pipeline UI, enter the identifier for your Amazon Data Firehose address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### AWS authentication
diff --git a/content/en/observability_pipelines/sources/amazon_s3.md b/content/en/observability_pipelines/sources/amazon_s3.md
index d5164426dfc..c7c8fcce8ff 100644
--- a/content/en/observability_pipelines/sources/amazon_s3.md
+++ b/content/en/observability_pipelines/sources/amazon_s3.md
@@ -19,17 +19,17 @@ Use Observability Pipelines' Amazon S3 source to receive logs from Amazon S3.
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Amazon S3 URL and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the Amazon S3 source in the pipeline UI:
1. Enter the identifier for your Amazon S3 URL. If you leave it blank, the [default](#secret-defaults) is used.
1. Enter the AWS region.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### AWS authentication
diff --git a/content/en/observability_pipelines/sources/datadog_agent.md b/content/en/observability_pipelines/sources/datadog_agent.md
index 815e7c494a4..522423c6fbc 100644
--- a/content/en/observability_pipelines/sources/datadog_agent.md
+++ b/content/en/observability_pipelines/sources/datadog_agent.md
@@ -28,14 +28,14 @@ Use Observability Pipelines' Datadog Agent source to receive logs or metrics fro
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][6], using the [API][7], or with [Terraform][8]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifier for the Datadog Agent address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][6], using the [API][7], or with [Terraform][8]. The instructions in this section are for setting up the source in the UI.
After you select the Datadog Agent source in the pipeline UI, enter the identifier for your Datadog Agent address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/fluent.md b/content/en/observability_pipelines/sources/fluent.md
index 432a11c4a62..3f57423b46f 100644
--- a/content/en/observability_pipelines/sources/fluent.md
+++ b/content/en/observability_pipelines/sources/fluent.md
@@ -19,14 +19,14 @@ Use Observability Pipelines' Fluentd or Fluent Bit source to receive logs from t
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Fluent address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the Fluent source in the pipeline UI, enter the identifier for your Fluent address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/google_pubsub.md b/content/en/observability_pipelines/sources/google_pubsub.md
index dc1d2c62f35..801918a6ae2 100644
--- a/content/en/observability_pipelines/sources/google_pubsub.md
+++ b/content/en/observability_pipelines/sources/google_pubsub.md
@@ -34,10 +34,10 @@ After you select the Google Pub/Sub source in the pipeline UI:
For Secrets Management: Only enter the identifier for the TLS key pass. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
-
{{% observability_pipelines/tls_settings %}}
+{{% observability_pipelines/secrets_env_var_note %}}
+
## Secret defaults
{{% observability_pipelines/set_secrets_intro %}}
diff --git a/content/en/observability_pipelines/sources/http_client.md b/content/en/observability_pipelines/sources/http_client.md
index 8c67c731394..5d541abcb94 100644
--- a/content/en/observability_pipelines/sources/http_client.md
+++ b/content/en/observability_pipelines/sources/http_client.md
@@ -19,11 +19,9 @@ Use Observability Pipelines' HTTP/S Client source to pull logs from the upstream
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the HTTP/S Client endpoint URL and, if applicable, your authorization strategy secrets and TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the HTTP/S Client source in the pipeline UI:
@@ -35,6 +33,8 @@ After you select the HTTP/S Client source in the pipeline UI:
- {{< ui >}}Bearer{{< /ui >}}: Enter the identifier for your bearer token. If you leave it blank, the [default](#secret-defaults) is used.
1. Select the decoder you want to use on the HTTP messages. Logs pulled from the HTTP source must be in this format.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable TLS
diff --git a/content/en/observability_pipelines/sources/http_server.md b/content/en/observability_pipelines/sources/http_server.md
index 2ebdf5de869..e4733c2c4cf 100644
--- a/content/en/observability_pipelines/sources/http_server.md
+++ b/content/en/observability_pipelines/sources/http_server.md
@@ -21,11 +21,9 @@ You can also [send AWS vended logs with Datadog Lambda Forwarder to Observabilit
## Setup
-Set up this source when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the HTTP/S Server address and, if applicable, the username and password for plain (also known as basic) authorization and the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][3]. You can set up a pipeline in the [UI][1], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the HTTP/S Server source in the pipeline UI:
@@ -36,6 +34,8 @@ After you select the HTTP/S Server source in the pipeline UI:
1. (Optional) Set up authentication tokens. See [Configure authentication tokens](#configure-authentication-tokens) for details.
1. Select the decoder you want to use on the HTTP messages. Your HTTP client logs must be in this format. **Note**: If you select `bytes` decoding, the raw log is stored in the `message` field.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable TLS
diff --git a/content/en/observability_pipelines/sources/kafka.md b/content/en/observability_pipelines/sources/kafka.md
index 459bae0a153..f6fc66a890b 100644
--- a/content/en/observability_pipelines/sources/kafka.md
+++ b/content/en/observability_pipelines/sources/kafka.md
@@ -21,11 +21,9 @@ You can also [send Azure Event Hub logs to Observability Pipelines using the Kaf
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][7], using the [API][8], or with [Terraform][9]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Kafka servers, username, password, and if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][7], using the [API][8], or with [Terraform][9]. The instructions in this section are for setting up the source in the UI.
After you select the Kafka source in the pipeline UI:
@@ -35,6 +33,8 @@ After you select the Kafka source in the pipeline UI:
1. Enter the group ID.
1. Enter the topic name. If there is more than one, click {{< ui >}}Add Field{{< /ui >}} to add additional topics.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable SASL Authentication
diff --git a/content/en/observability_pipelines/sources/logstash.md b/content/en/observability_pipelines/sources/logstash.md
index b637c25ad9c..5f7710b4643 100644
--- a/content/en/observability_pipelines/sources/logstash.md
+++ b/content/en/observability_pipelines/sources/logstash.md
@@ -21,14 +21,14 @@ You can also use the Logstash source to [send logs to Observability Pipelines us
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][4], using the [API][5], or with [Terraform][6]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Logstash address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][4], using the [API][5], or with [Terraform][6]. The instructions in this section are for setting up the source in the UI.
After you select the Logstash source in the pipeline UI, enter the identifier for your Logstash address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/mysql.md b/content/en/observability_pipelines/sources/mysql.md
index c5f82dfc3f4..f3ad2d9f6ef 100644
--- a/content/en/observability_pipelines/sources/mysql.md
+++ b/content/en/observability_pipelines/sources/mysql.md
@@ -135,11 +135,9 @@ Store the SQL query that the Worker executes in a local file.
## Setup
-Ensure you have completed the [prerequisite steps](#prerequisites) first. Then, set up the MySQL source and its environment variables when you [set up a pipeline][1]. The information below is configured in the pipelines UI.
-
For Secrets Management: Only enter the identifier for the MySQL URI connection string. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
+Ensure you have completed the [prerequisite steps](#prerequisites) first. Then, set up the MySQL source and its environment variables when you [set up a pipeline][1]. The information below is configured in the pipelines UI.
After you select the MySQL source in the pipeline UI:
@@ -160,6 +158,8 @@ After you select the MySQL source in the pipeline UI:
| Every 1 min | `*/1 * * * *` |
| Once daily at 8 AM | `0 8 * * *` |
+{{% observability_pipelines/secrets_env_var_note %}}
+
## Secret defaults
{{% observability_pipelines/set_secrets_intro %}}
diff --git a/content/en/observability_pipelines/sources/opentelemetry.md b/content/en/observability_pipelines/sources/opentelemetry.md
index 1661b79b41b..37a55de9e92 100644
--- a/content/en/observability_pipelines/sources/opentelemetry.md
+++ b/content/en/observability_pipelines/sources/opentelemetry.md
@@ -41,17 +41,17 @@ If your forwarders are globally configured to enable SSL, you need the appropria
## Setup
-Set up this source when you [set up a pipeline][6]. You can set up a pipeline in the [UI][10], using the [API][11], or with [Terraform][12]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the OpenTelemetry HTTP and gRPC listener addresses and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][6]. You can set up a pipeline in the [UI][10], using the [API][11], or with [Terraform][12]. The instructions in this section are for setting up the source in the UI.
After you select the OpenTelemetry source in the pipeline UI:
1. Enter the identifier for your HTTP listener address. If you leave it blank, the [default](#secret-defaults) is used.
1. Enter the identifier for your gRPC listener address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/socket.md b/content/en/observability_pipelines/sources/socket.md
index 67f50e44062..d5ac2cc8fc1 100644
--- a/content/en/observability_pipelines/sources/socket.md
+++ b/content/en/observability_pipelines/sources/socket.md
@@ -19,13 +19,11 @@ Use Observability Pipelines' Socket source to send logs to the Worker over a soc
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
-**Note**: The Worker can only receive logs over TCP or UDP. If your application writes to a UNIX domain socket, see [UNIX domain sockets](#unix-domain-sockets) for more information.
-
For Secrets Management: Only enter the identifiers for the socket address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
+
+**Note**: The Worker can only receive logs over TCP or UDP. If your application writes to a UNIX domain socket, see [UNIX domain sockets](#unix-domain-sockets) for more information.
After you select the Socket source in the pipeline UI:
@@ -65,6 +63,8 @@ After you select the Socket source in the pipeline UI:
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
@@ -73,7 +73,7 @@ After you select the Socket source in the pipeline UI:
## UNIX domain sockets
-The Socket source only supports receiving logs over TCP or UDP. If your application writes to a UNIX domain socket, use `socat` to bridge it to a TCP or UDP socket to send logs to the Worker.
+The Socket source only supports receiving logs over TCP or UDP. If your application writes to a UNIX domain socket, use `socat` to bridge it to a TCP or UDP socket to send logs to the Worker.
### Standalone bridge
@@ -133,7 +133,7 @@ containers:
readOnlyRootFilesystem: true
```
-Point the `TCP` argument at the Worker's Kubernetes Service endpoint instead of `localhost`. The Worker's StatefulSet pods aren't guaranteed to run on every node, so the Worker pod might not be reachable at `localhost`. This is especially true if you have dedicated node groups for the Worker and your workloads.
+Point the `TCP` argument at the Worker's Kubernetes Service endpoint instead of `localhost`. The Worker's StatefulSet pods aren't guaranteed to run on every node, so the Worker pod might not be reachable at `localhost`. This is especially true if you have dedicated node groups for the Worker and your workloads.
## Secret defaults
diff --git a/content/en/observability_pipelines/sources/splunk_hec.md b/content/en/observability_pipelines/sources/splunk_hec.md
index 93a2ae115c8..9fd0612f5a2 100644
--- a/content/en/observability_pipelines/sources/splunk_hec.md
+++ b/content/en/observability_pipelines/sources/splunk_hec.md
@@ -27,11 +27,9 @@ Use Observability Pipelines' Splunk HTTP Event Collector (HEC) source to receive
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][6], using the [API][7], or with [Terraform][8]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Splunk HEC address and, if applicable, the TLS key pass and authentication token keys. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][6], using the [API][7], or with [Terraform][8]. The instructions in this section are for setting up the source in the UI.
After you select the Splunk HEC source in the pipeline UI:
@@ -40,6 +38,8 @@ After you select the Splunk HEC source in the pipeline UI:
- Use a Splunk HEC destination with the {{< ui >}}From Source{{< /ui >}} token strategy.
- Use an Enrichment Table processor to map Splunk HEC tokens from a local file.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
#### Enable TLS
diff --git a/content/en/observability_pipelines/sources/splunk_tcp.md b/content/en/observability_pipelines/sources/splunk_tcp.md
index 3496ce5d954..f42b6180289 100644
--- a/content/en/observability_pipelines/sources/splunk_tcp.md
+++ b/content/en/observability_pipelines/sources/splunk_tcp.md
@@ -19,14 +19,14 @@ Use Observability Pipelines' Splunk Heavy and Universal Forwards (TCP) source to
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][2], using the [API][3], or with [Terraform][4]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the Splunk TCP address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][2], using the [API][3], or with [Terraform][4]. The instructions in this section are for setting up the source in the UI.
After you select the Splunk TCP source in the pipeline UI, enter the identifier for your Splunk TCP address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/sumo_logic.md b/content/en/observability_pipelines/sources/sumo_logic.md
index 2ad3817e416..439a77c093f 100644
--- a/content/en/observability_pipelines/sources/sumo_logic.md
+++ b/content/en/observability_pipelines/sources/sumo_logic.md
@@ -19,14 +19,14 @@ Use Observability Pipelines' Sumo Logic Hosted Collector source to receive logs
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][2], using the [API][3], or with [Terraform][4]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifier for the Sumo Logic address. Do not enter the actual value.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][2], using the [API][3], or with [Terraform][4]. The instructions in this section are for setting up the source in the UI.
After you select the Sumo Logic source in the pipeline UI, enter the identifier for your Sumo Logic address. If you leave it blank, the [default](#secret-defaults) is used.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional settings
In the {{< ui >}}Decoding{{< /ui >}} dropdown menu, select whether your input format is raw {{< ui >}}Bytes{{< /ui >}}, {{< ui >}}JSON{{< /ui >}}, Graylog Extended Log Format ({{< ui >}}Gelf{{< /ui >}}), or {{< ui >}}Syslog{{< /ui >}}. If no decoding is selected, the decoding defaults to JSON.
diff --git a/content/en/observability_pipelines/sources/syslog.md b/content/en/observability_pipelines/sources/syslog.md
index 963b129344d..78abd4ca561 100644
--- a/content/en/observability_pipelines/sources/syslog.md
+++ b/content/en/observability_pipelines/sources/syslog.md
@@ -21,17 +21,17 @@ You can also [forward third-party log to syslog](#forward-third-party-logs-to-sy
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][7], using the [API][8], or with [Terraform][9]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the syslog address and, if applicable, the TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][7], using the [API][8], or with [Terraform][9]. The instructions in this section are for setting up the source in the UI.
After you select the Syslog source in the pipeline UI:
1. Enter the identifier for your syslog address. If you leave it blank, the [default](#secret-defaults) is used.
1. In the {{< ui >}}Socket Type{{< /ui >}} dropdown menu, select the communication protocol you want to use: {{< ui >}}TCP{{< /ui >}} or {{< ui >}}UDP{{< /ui >}}.
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
{{% observability_pipelines/tls_settings %}}
diff --git a/content/en/observability_pipelines/sources/websocket.md b/content/en/observability_pipelines/sources/websocket.md
index 561751faaf7..55f685a5713 100644
--- a/content/en/observability_pipelines/sources/websocket.md
+++ b/content/en/observability_pipelines/sources/websocket.md
@@ -27,11 +27,9 @@ To use Observability Pipelines' WebSocket source, you must have the following in
## Setup
-Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
-
For Secrets Management: Only enter the identifiers for the WebSocket URI and, if applicable, your authorization strategy secrets and TLS key pass. Do not enter the actual values.
-{{% observability_pipelines/secrets_env_var_note %}}
+Set up this source when you [set up a pipeline][1]. You can set up a pipeline in the [UI][3], using the [API][4], or with [Terraform][5]. The instructions in this section are for setting up the source in the UI.
After you select the WebSocket source in the pipeline UI:
@@ -52,6 +50,8 @@ After you select the WebSocket source in the pipeline UI:
If your messages do not match one of the formats above, select `bytes` to ingest the raw message in the `message` field, then transform it with a [Custom Processor][6].
+{{% observability_pipelines/secrets_env_var_note %}}
+
### Optional TLS settings
For `wss://` endpoints, configure TLS so that data is encrypted in transit. The WebSocket source supports two TLS modes: