Log Sources

Edge Delta source nodes that ingest logs.

Edge Delta CrowdStrike Falcon Data Replicator Source Node

The CrowdStrike FDR Source node enables Edge Delta to ingest data from CrowdStrike Falcon Data Replicator using AWS S3.

Edge Delta Docker Source

The Docker source node captures log input from Docker containers, supporting features like auto-detection of line patterns and stack trace detection.

Edge Delta Azure Event Hub Source

The Azure Event Hub Source node reads data from an Azure Event Hub, supporting specific partitions or the Event Processor Host model.

Edge Delta Exec Source

The Exec node in Edge Delta executes commands or scripts to create log items, with configurable parameters like run_interval.

Edge Delta File Source

The Edge Delta File Source captures log input from specific files, useful for system logs and testing.

Edge Delta Fluentd Source

The Fluentd node enables Edge Delta to ingest logs using the Fluentd forward protocol.

Edge Delta Journald Source

The Journald Source node collects log entries from the systemd journal using journalctl, with options for filtering and specifying journal directories.

Edge Delta Kafka Source

Configure the Edge Delta Kafka Source to ingest logs from Kafka topics with optional TLS and SASL settings.

Edge Delta Kubernetes Source

Configure the Edge Delta Kubernetes Source to monitor specific pods and namespaces, with options for log pattern detection and metadata collection.

Edge Delta Kubernetes Event Source

Use the Kubernetes Event Source node to ingest events from a Kubernetes cluster when there is a state change in a resource.

Splunk HTTP Event Collector Source

Use Edge Delta to ingest log data from Splunk’s HTTP Event Collector with the Splunk HEC source node.

Edge Delta Splunk TCP Source

The Splunk TCP source node allows Edge Delta to receive data from Splunk Universal and Heavy Forwarders over TCP, facilitating migration and hybrid deployments.

Edge Delta Windows Event Source

The Windows Event Source node captures logs from Windows Event Viewer channels for ingestion into your pipeline.