Vector v0.59.0 release notes
Vector Changelog
6 breaking changes
- Avro codec rejects shorthand complex type schemas
The
apache-avrolibrary has been upgraded from 0.21 to 0.22, which enforces stricter schema parsing per the Avro specification. Field-level attributes must now be nested inside a"type"object rather than specified as siblings of the"type"string:- Complex types (
array,map,enum,record,fixed): schemas using the shorthand form will fail to parse at startup. - Logical types (
timestamp-millis,date,uuid, etc.): schemas using the shorthand form will still parse, but the logical type is silently ignored and the field is treated as a plain primitive.
Thanks to omwbennett for contributing PR #26146! - Complex types (
datadog_agentsource no longer accepts pre-tracerPayloadstrace payloadsThedatadog_agentsource no longer accepts the pre-tracerPayloadsAgent-to-intake trace protobuf (traces/transactionsfields). The Datadog Agent dropped those fields in the 7.33.0 release in January 2022. An emptytracerPayloadslist now produces no events and incrementscomponent_errors_totalwitherror_codeempty_tracer_payloads. IndexedidxTracerPayloadsentries are recognized but not converted (error_codeidx_tracer_payloads).- Datadog metrics series submitted to the V3 intake by default
The
datadog_metricssink now submits series metrics to/api/intake/metrics/v3/seriesby default, using Datadog’s columnar protobuf format. This format uses dictionary-based string deduplication and delta encoding, making it more efficient thanv2for workloads with many metrics that share common names or tags.Sketch metrics (distributions and histograms) are unaffected and continue to be submitted to
/api/beta/sketches.Thanks to stephenwakely for contributing PR #26285! - Kubernetes 1.31 support removedThe
kubernetes_logssource now uses Kubernetes v1.32 API bindings. Kubernetes 1.31 reached end of life on 2025-11-11 and is no longer supported.Thanks to thomasqueirozb for contributing PR #26506! - Removed
httpsource andgreptimedbsink deprecated component aliasesThe deprecatedhttpsource andgreptimedbsink aliases have been removed. They were deprecated in Vector 0.26.0 and 0.41.0, respectively. - Boolean Vector sink compression removedThe deprecated boolean syntax for the
vectorsink’scompressionoption has been removed.
2 security changes
The
chunked_gelfframing decoder now limits the payload buffered across incomplete messages to 128 MiB. An unauthenticated sender could previously exhaust memory by sending chunks for messages it never completed, most easily on thesocketsource in UDP mode.max_lengthcan lower the per-message ceiling. Setting it above 128 MiB raises both the per-message ceiling and the aggregate limit to that value.The
chunked_gelfframing decoder now applies a configurable limit to the number of incomplete messages held in memory. An unauthenticated sender could previously exhaust memory by sending unique message IDs it never completed, most easily on thesocketsource in UDP mode.pending_messages_limitnow defaults to 4096. It was previously unset and therefore unbounded.
3 new features
- The
aggregatetransform now supports event-time aggregation via an optionalevent_timeconfiguration block. This avoids collapsing distinct samples in sinks (such as Datadog Metrics) that overwrite earlier values for an identical timestamp. Added the
files_unwatched_bytes_unread_totalinternal metric to thefileandkubernetes_logssources. It tracks known unread bytes when a file is unwatched, for example after deletion or rotation. A known count of zero means no bytes remained unread at measurement time.When the unread-byte count is unavailable, Vector increments
files_unwatched_with_unknown_bytes_totalinstead. This counter counts unwatch events with unknown unread size, including gzipped files, skipped gzip readers, and metadata failures; it does not measure lost bytes. Gzip files are not decompressed solely to calculate telemetry. Both metrics use the existingreached_eoflabel and optionalfilelabel, andfiles_unwatched_totalcontinues to count all unwatch events.Thanks to akashvbabu91 for contributing PR #24676!- The
host_metricssource now exposes amemory_oom_kill_events_totalcounter metric on Linux, reporting the number of Out-Of-Memory kill events recorded by the kernel.Thanks to simonhammes for contributing PR #25802!
10 enhancements
The
azure_blobsink now supportsblob_type: append, which writes data as Azure Append Blobs. Unlike the default block blob mode that creates a new uniquely-named blob per batch, append mode reuses a stable blob name and extends it on each flush — ideal for continuous log streaming where you want a single growing file per time window.When
blob_typeis set toappend,blob_append_uuiddefaults tofalseandblob_time_formatdefaults to%Y-%m-%dT%H(hourly rotation), which keeps the Azure limit of 50,000 blocks per append blob out of reach at realistic throughput. Both can still be overridden explicitly. The Azure hard limit of 4 MiB perappend_blockcall is enforced at startup viabatch.max_bytes.Compression is supported in append mode with
gzip,zstd, ornone. Because each batch is compressed independently,snappyandzlibare rejected at startup: neither format can be decoded as a concatenated sequence of streams.Because a batch is appended to whatever the blob already holds, append mode takes the same stream-oriented encoding defaults as the
filesink: withcodec: jsonand no explicitframingit writes newline-delimited JSON, rather than the one-array-per-batch framing used for block blobs. Explicitly configuredframingis always used as given.Thanks to danielku15 for contributing PR #25627!- The
prometheus_scrapesource now supports configuring HTTP request headers. - The
lokisink now supports thehealthcheck.urifield to customize the healthcheck endpoint.Thanks to simonhammes for contributing PR #24651! - HTTP-based sources (
http_server,datadog_agent,splunk_hec,aws_kinesis_firehose,opentelemetry,prometheus_remote_write,prometheus_pushgateway,heroku_logs) now support OS-level TCP keepalive on accepted connections via a newkeepalive.tcp_keepaliveconfiguration option. When configured, the OS will send TCP keepalive probes after the specified idle time, detecting and closing connections where the remote peer has disappeared without sending a FIN or RST packet (for example, due to an abrupt machine failure). - Add
max_payload_bytesconfiguration option to thedatadog_logssink, allowing the payload size limit to be raised above the default 5 MB for endpoints that accept larger payloads. The batch goal is derived automatically asmax_payload_bytes - 750,000bytes, keeping the same safety headroom as the previous hardcoded defaults.Thanks to dd-sebastien-lb for contributing PR #26396! - The
datadog_logssink can now optionally truncate logs that exceed Datadog’s per-log size limit. Configuretruncate_oversized_logsto set the encoded log limit, mark shortened messages, and tag reduced logs. Logs whose non-message fields leave no room for a truncated message, or have no string message, are forwarded unchanged when they fit the payload limit, allowing the Datadog intake to truncate them. - Added bearer authentication strategy to HTTP server sources. The
http_server,heroku_logs, andwebsocket_servercomponents now supportstrategy = "bearer"in theirauthconfiguration, allowing token-based authentication via theAuthorization: Bearer <token>header.Thanks to steveduan-IDME for contributing PR #25073! - Add two optional configuration fields to the OpenTelemetry source:
max_concurrent_requestslimits concurrent requests across HTTP and gRPC, andrequest_timeout_secslimits request processing time. Both are disabled by default and can be enabled to help prevent out-of-memory errors in some deployments.Thanks to ArunPiduguDD for contributing PR #26457! Sink
endpointoptions now require an absolute URL that includes a host.Before:
- Endpoints without a scheme (for example
endpoint: "localhost:8080") were accepted at configuration load and failed only when the sink attempted to send data. - Empty, host-less, or non-
http(s)endpoints (for exampleendpoint: "",endpoint: "http:///", orendpoint: "ftp://example.com") were accepted at configuration load and either failed only when the sink attempted to send data or were silently completed with a default scheme and host.
After:
- Endpoints without a scheme are defaulted to
https://(for exampleendpoint: "localhost:8080"becomeshttps://localhost:8080) and work as expected. - Empty, host-less, or non-
http(s)endpoints (for exampleendpoint: "",endpoint: "http:///", orendpoint: "ftp://example.com") are rejected at configuration load with a clear error, including withvector validate --no-environment.
- Endpoints without a scheme (for example
- The
vectorsink now rejects empty, host-less, or non-http(s)addressandrouting.endpointsvalues at configuration load with a clear error, including withvector validate --no-environment.Thanks to thomasqueirozb for contributing PR #26224!
20 bug fixes
Fix collection from systemd sockets.
Systemd sockets are passed in blocking mode, but tokio expects them to be in non-blocking mode. Therefore, always set sockets from systemd to non-blocking.
- The NATS JetStream source now automatically recovers when the pull stream terminates due to a connection close event (e.g., during NATS rolling upgrades or lame duck mode). Previously, the source would silently stop consuming messages. It now reconnects and rebuilds the pull consumer stream with exponential backoff.Thanks to benjamin-awd for contributing PR #25042!
Renamed the memory enrichment table failure and TTL-expiration internal metrics to end in
_total, matching Vector’s counter naming convention:memory_enrichment_table_failed_insertions_totalmemory_enrichment_table_failed_reads_totalmemory_enrichment_table_ttl_expirations_total
This replaces the previous non-
_totalmetric names. The previous metric names without the_totalsuffix are still emitted but are deprecated and will be removed in a future release.- gRPC-based sources (
vector,opentelemetry) now include the underlying error when a compressed request payload fails to decompress, instead of the genericreached impossible error during decompressor finalizationmessage. Decompression failures (for example, a corrupt or truncated gzip stream) are now diagnosable from the returned status and the sender’s logs. - Reduced memory allocated per log line in the
kubernetes_logssource by around 0.4–0.6 KB.Thanks to thomasqueirozb for contributing PR #26490! vector testnow reports ambiguous output names as configuration errors instead of panicking.Thanks to blackmore-technology-group for contributing PR #26504!- Renamed the aggregate transform’s
aggregate_failed_updatesinternal counter toaggregate_failed_updates_total, matching Vector’s counter naming convention. The previousaggregate_failed_updatesname is still emitted but is deprecated and will be removed in a future release.Thanks to thomasqueirozb for contributing PR #26407! - The
blackholesink now rejectsrate: 0during configuration validation instead of panicking when it receives events.Thanks to thomasqueirozb for contributing PR #26048! - Fixed the internal buffer usage reporter outliving the buffer it reports on, which would cause the reporter for the old buffer to keep publishing stale metrics under the same
buffer_idas its replacement. This also lets the metrics for a buffer that was removed rather than replaced age out underexpire_metrics_secs, which the continuously republished values previously prevented. - Fixed generated configuration schemas for flattened optional internally-tagged enums. Configs that omit the flattened block now validate: the schema encodes
Noneas a missing tag field rather than JSONnull, matchingserde. - Templates whose literal prefix started with
http://orhttps://were incorrectly given URI-specific confinement checks, even when the field was not a URI field (e.g. an object-store key prefix). Confinement is now selected by the field’s type rather than by inspecting the template content, so such templates use prefix confinement instead.Thanks to thomasqueirozb for contributing PR #26011! - The
datadog_agentsource now decodes Datadog span links (spanLinks) and span events (spanEvents) into each span on the emitted trace event. Span-linktrace_id,trace_id_high, andspan_idare 16-character lowercase hexadecimal strings so the full unsigned 64-bit range is preserved. Thedatadog_tracessink encodes those fields back into the Agent protobuf.containerDebugandrareSamplerEnabledare decoded from the wire but are not copied onto events. - Decoding Vector’s native protobuf format (
decoding.codec = "native") and disk-buffer records no longer panics when an event variant is missing or unrecognized, when a float field isNaN, or when an AgentDDSketch has mismatched bin lists. Those payloads are rejected, dropped, and reported through existing decode/buffer error telemetry. ANaNfloat in event data or metadata rejects the entire record rather than rewriting the value. - Fixed the
filesource hanging during fingerprinting when a file is smaller thanfingerprint.ignored_header_bytes. Incomplete files are retried when more data becomes available. - TCP source acknowledgement and TLS connection error logs now include the remote
peer_addr. - The
luatransform no longer panics when a metric tag contains a value that cannot be converted to a string (e.g. a boolean or a nested table). Such values now produce a Lua conversion error and the event is discarded. - Renamed the host
process_runtimecounter emitted by thehost_metricssource toprocess_runtime_total, matching Vector’s counter naming convention. The previousprocess_runtimename is still emitted but is deprecated and will be removed in a future release.Thanks to thomasqueirozb for contributing PR #26406! - Ensure the
prometheus_exportersink emits valid text exposition by escaping newlines in label values and rejecting metrics whose metric names, namespaces, or label names contain carriage returns or newlines. vector validate --no-environmentnow catches sink configurations issues that previously only surfaced when Vector booted.Thanks to thomasqueirozb for contributing PR #26048!vector validatenow resolvesSECRET[backend.key]placeholders from the configured secret backends before validating the configuration, matchingvector’s startup behavior. If--no-environmentis specified then secrets aren’t resolved by default. You can specify the new--resolve-secretsflag to resolve secrets as well.Thanks to thomasqueirozb for contributing PR #26268!
6 chore
The
apache-avrolibrary has been upgraded from 0.21 to 0.22, which enforces stricter schema parsing per the Avro specification. Field-level attributes must now be nested inside a"type"object rather than specified as siblings of the"type"string:- Complex types (
array,map,enum,record,fixed): schemas using the shorthand form will fail to parse at startup. - Logical types (
timestamp-millis,date,uuid, etc.): schemas using the shorthand form will still parse, but the logical type is silently ignored and the field is treated as a plain primitive.
Thanks to omwbennett for contributing PR #26146!- Complex types (
- The
datadog_agentsource no longer accepts the pre-tracerPayloadsAgent-to-intake trace protobuf (traces/transactionsfields). The Datadog Agent dropped those fields in the 7.33.0 release in January 2022. An emptytracerPayloadslist now produces no events and incrementscomponent_errors_totalwitherror_codeempty_tracer_payloads. IndexedidxTracerPayloadsentries are recognized but not converted (error_codeidx_tracer_payloads). The
datadog_metricssink now submits series metrics to/api/intake/metrics/v3/seriesby default, using Datadog’s columnar protobuf format. This format uses dictionary-based string deduplication and delta encoding, making it more efficient thanv2for workloads with many metrics that share common names or tags.Sketch metrics (distributions and histograms) are unaffected and continue to be submitted to
/api/beta/sketches.Thanks to stephenwakely for contributing PR #26285!- The
kubernetes_logssource now uses Kubernetes v1.32 API bindings. Kubernetes 1.31 reached end of life on 2025-11-11 and is no longer supported.Thanks to thomasqueirozb for contributing PR #26506! - The deprecated
httpsource andgreptimedbsink aliases have been removed. They were deprecated in Vector 0.26.0 and 0.41.0, respectively. - The deprecated boolean syntax for the
vectorsink’scompressionoption has been removed.
VRL Changelog
0.36.0 (2026-10-01)
Breaking Changes & Upgrade Guide
- Several stdlib functions now declare element-kind constraints on array parameters, enabling the compiler to detect element-type mismatches at compile time and automatically infer call-site infallibility.
Before: passing a string-literal array required ! because the compiler assumed it could fail:
join!(["sources", "transforms", "sinks"], separator: ", ")
After: when the compiler can prove the elements are strings, ! is unnecessary (and ! now triggers a warning):
join(["sources", "transforms", "sinks"], separator: ", ")
Passing the wrong element type (e.g. join([1, 2, 3])) is now a hard compile error instead of a runtime failure.
Affected functions: join, contains_all, tally, encode_key_value, encode_logfmt, ip_cidr_contains, parse_groks.
Thanks to pront for contributing PR #1861!
New Features
- Add
breakstatement support for early loop exit withinfor_eachclosures.
Thanks to jimmystewpot for contributing PR #1931!
Enhancements
- Optimize
md5runtime performance with stack-buffered hex encoding and compile-time constant evaluation for literals.
Thanks to jimmystewpot for contributing PR #1930!
- Improve
for_eachperformance and reduce memory allocations by iterating over collections directly, binding only the closure parameters that are used, and reusing compiler variable slots across iterations. Benchmarks show a 23–41% throughput improvement for arrays and objects.
Thanks to jimmystewpot for contributing PR #1932!
- Optimise
mergeruntime performance and memory usage with zero-clone ownership transfer, single-pass entry traversal, size-adaptive shallow merging, and compile-time constant evaluation for literals, while hardening against deep recursion stack overflows and resolving type definition unsoundness for deep merges. Benchmarks show up to a 120% throughput increase for asymmetric merges and 26% for large flat objects.
Thanks to jimmystewpot for contributing PR #1953!
- Bump
convert_casefrom 0.7.1 to 0.12.0, improving string casing function performance (camelcase,snakecase,pascalcase,kebabcase,screamingsnakecase) by approximately 70%.
Thanks to jimmystewpot for contributing PR #1961!
- Optimize
sha1,sha2, andsha3runtime performance with stack-buffered hex encoding and compile-time constant evaluation for literals.
Thanks to bruceg for contributing PR #1951!
Fixes
- Fixed
uuid_v7to preserve the supplied timestamp at millisecond precision.
Deprecation Announcements
See the deprecations page for all active and historical deprecations.
aggregate_failed_updates counter without the _total suffixThe aggregate transform now also emits the failed-updates counter with the _total suffix, matching Vector’s counter naming convention:
aggregate_failed_updates_total
The previous name without the _total suffix is deprecated and will be removed in a future release. Migrate any dashboards or alerts that reference:
aggregate_failed_updates
_total suffixThe memory enrichment table failure and TTL-expiration counters are now also emitted with the
_total suffix, matching Vector’s counter naming convention:
memory_enrichment_table_failed_insertions_totalmemory_enrichment_table_failed_reads_totalmemory_enrichment_table_ttl_expirations_total
The previous names without the _total suffix are deprecated and will be removed in a future
release. Migrate any dashboards or alerts that reference:
memory_enrichment_table_failed_insertionsmemory_enrichment_table_failed_readsmemory_enrichment_table_ttl_expirations
packages.timber.ioStable Vector release archives and packages are now hosted in the public COSE
release bucket. The packages.timber.io/vector URLs are deprecated and users should
switch to install.datadoghq.com/vector instead.
Starting with Vector 0.59.0, the Vector installer and the download
instructions on vector.dev point to artifacts
in the COSE bucket. Existing packages.timber.io URLs continue to work during
the deprecation period.
| Artifact | Migration outcome |
|---|---|
| Stable Vector releases, installers, and package-manager downloads | Migrated to exact-version paths under install.datadoghq.com/vector/<version>/; stable latest or .X aliases are not provided |
packages.timber.io/vector versioned, latest, and version-alias URLs | Remain readable through December 31, 2026, and may be deleted at any time after that date |
| Nightly and custom builds | Treated as transient artifacts that are superseded by stable releases, so existing builds are not migrated; future builds are published to install.datadoghq.com under vector/nightly/ and vector/custom/ |
| Helm charts | GitHub Release assets; https://helm.vector.dev remains the Helm repository index |
| All other legacy artifacts | Not migrated and will be deleted |
process_runtime counter without the _total suffixThe host_metrics source now also emits the process runtime counter with the _total suffix, matching Vector’s counter naming convention:
process_runtime_total
The previous name without the _total suffix is deprecated and will be removed in a future release. Migrate any dashboards or alerts that reference:
process_runtime
address and routing.endpoints values in the vector sink defaulting to httpA vector sink endpoint such as 127.0.0.1 without an explicit scheme currently defaults to http.
This behavior is deprecated and will change to https in a future release.
Note that when TLS is enabled, a scheme-less address already defaults to https.
Migrate by specifying the scheme explicitly:
sinks:
my_sink:
type: vector
address: http://127.0.0.1:6000