For the complete documentation index, see llms.txt. This page is also available as Markdown.

Processors

Comprehensive list of data processors supported by Bindplane for transforming, filtering, and enriching metrics, logs, and traces

Processors can be inserted into your telemetry pipeline to transform your data before it arrives at your destination. Adding attributes, filtering, and converting logs to metrics are all the types of transformations we can do using processors in Bindplane.

Unless otherwise stated, any input values in our processors are case sensitive.

Processor Categories

Data Transformation

  • Add, modify, or remove fields and attributes

  • Parse structured data from various formats

  • Convert between data types and formats

Filtering & Sampling

  • Filter telemetry based on conditions, fields, or patterns

  • Sample data to reduce volume

  • Remove duplicate or unwanted data

Data Enrichment

  • Add contextual information and metadata

  • Lookup additional data from external sources

  • Detect and add resource information

Aggregation & Statistics

  • Compute metrics from logs and traces

  • Group and aggregate data

  • Generate statistical summaries

Available Processors

Data Transformation Processors

Processor
Metrics
Logs
Traces
Description

Add Fields

✓

✓

✓

Add attributes, resources, and log record body keys

✓

✓

✓

Promote XML attributes to child elements before parsing

✓

✓

✓

Wrap element text in child elements for clean parsing

Copy Field

✓

✓

✓

Copy values from one field to another

Delete Empty Values

✓

✓

✓

Remove fields with empty or null values

Delete Fields

✓

✓

✓

Remove specific fields from telemetry

Get XML

✓

✓

✓

Extract XML node(s) matching an XPath

Insert XML Elements

✓

✓

✓

Insert an XML fragment at an XPath location

Move Field

✓

✓

✓

Move values between different field types

Remove XML

✓

✓

✓

Remove XML node(s) matching an XPath

Rename Fields

✓

✓

✓

Rename fields and attributes

Rename Metric

✓

Rename metric names

Slice to Map

✓

✓

✓

Convert a slice into a map keyed by a field

Split

✓

✓

Split telemetry records into multiple records

Transform

✓

✓

✓

Transform telemetry using custom OTTL statements

Unroll

✓

Expand arrays into separate log records

Parsing Processors

Processor
Metrics
Logs
Traces
Description

Parse CSV

✓

✓

✓

Parse CSV-formatted strings into structured data

Parse JSON

✓

✓

✓

Parse JSON strings into structured data

Parse Key Value

✓

✓

✓

Parse key-value pairs from strings

Parse Severity

✓

Extract and standardize log severity levels

Parse Simplified XML

✓

✓

✓

Parse XML into a structured map (elements only)

Parse Timestamp

✓

✓

✓

Parse timestamps from various formats

Parse with Grok

✓

✓

✓

Extract fields using named Grok patterns

Parse with Regex

✓

✓

✓

Extract data using regular expressions

Parse XML

✓

✓

✓

Parse XML strings into structured data

Filtering & Sampling Processors

Processor
Metrics
Logs
Traces
Description

Filter by Condition

✓

✓

✓

Filter based on OTTL conditions

Filter by Regex

✓

Filter using regular expressions

Filter HTTP Status

✓

Filter logs based on HTTP status codes

Filter Metric Name

✓

Filter metrics by name patterns

Filter Severity

✓

Filter logs by severity level

Log Sampling

✓

Sample logs to reduce volume

Deduplicate Logs

✓

Remove duplicate log entries

SecOps Filter

✓

Drop or keep logs by OTTL condition or body match for the Google SecOps export path

Data Enrichment Processors

Processor
Metrics
Logs
Traces
Description

Coalesce

✓

✓

✓

Combine multiple fields into a single field

Drain

✓

Detect similar logs and label each with a common pattern

GeoIP

✓

✓

✓

Add geographic location attributes from IP addresses using MaxMind databases

Group by Attributes

✓

✓

✓

Group telemetry by attribute values

Lookup Fields

✓

✓

✓

Enrich data using lookup tables

Resource Detection

✓

✓

✓

Automatically detect and add resource information

Redact Sensitive Data

✓

✓

✓

Redact sensitive data in telemetry

Rewrite Timestamp

✓

Modify timestamp values

Aggregation & Statistics Processors

Processor
Metrics
Logs
Traces
Description

Batch

✓

✓

✓

Batch telemetry for efficient processing

Compute Metric Statistics

✓

Calculate statistics from metric data

Count Telemetry

✓

✓

✓

Count telemetry records and generate metrics

Extract Metric

✓

Extract metrics from log data

Specialized Processors

Processor
Metrics
Logs
Traces
Description

ASIM Standardization

✓

Standardize logs to Microsoft Sentinel ASIM schemas

Concat

✓

✓

✓

Concatenate multiple fields into a single field

Custom

✓

✓

✓

Custom OpenTelemetry processor configuration

✓

Standardize logs for Google Security Operations

Marshal

✓

Marshal data into specific formats

OCSF Standardization

✓

Standardize logs to OCSF

Available Processors by Bindplane Plan/License

Processor
Bindplane (Google Edition)
Growth / Enterprise / Bindplane Enterprise (Google Edition)

Compute metric statistics

✓

Count telemetry

✓

Custom

✓

Delete empty values

✓

Delete fields

✓

Deduplicate logs

✓

Extract metric

✓

Filter by condition

✓

Filter HTTP status

✓

Filter metric name

✓

Filter severity

✓

Log sampling

✓

Redact sensitive data

✓

Transform

✓

Add fields

✓

✓

Batch

✓

✓

Coalesce

✓

✓

Concat

✓

✓

Copy field

✓

✓

Filter by regex

✓

✓

Group by attributes

✓

✓

✓

✓

Lookup fields

✓

✓

Marshal

✓

✓

Move field

✓

✓

OCSF Standardization

✓

✓

Parse CSV

✓

✓

Parse JSON

✓

✓

Parse key value

✓

✓

Parse severity

✓

✓

Parse timestamp

✓

✓

Parse with regex

✓

✓

Parse XML

✓

✓

Rename fields

✓

✓

Rename metric

✓

✓

Resource detection

✓

✓

Rewrite timestamp

✓

✓

Split

✓

✓

Unroll

✓

✓

For more information about our plans, see our Plans & Pricing page here.

Getting Started

To add a processor to your configuration:

  1. Navigate to the Configs tab in Bindplane

  2. Select or create a configuration

  3. Add a source to collect data

  4. Click Add Processor

  5. Choose the appropriate processor type from the list above

  6. Configure the required parameters

  7. Add destinations to route the processed data

  8. Apply the configuration to your collectors

Processor Bundles

Processor bundles are a convenient way to group multiple processors into a single unit. Each bundle can encapsulate a list of processors designed to perform complex transformations. Bundles enable the user to streamline common tasks that require multiple processors.

Click here for an in-depth view on how to use processor bundles.

Telemetry Type Support

Processors can operate on different types of telemetry data:

  • Metrics: Numerical measurements and statistics

  • Logs: Text-based event records

  • Traces: Distributed tracing data for request flows

Some processors support multiple telemetry types, allowing you to apply consistent transformations across your entire observability pipeline.

Enterprise Features

Certain processors are available only in Bindplane Enterprise Edition. Please contact sales@bindplane.com for more information about enterprise features.

Common Use Cases

  • Log Enrichment: Add environment tags, service names, and other contextual information

  • Data Normalization: Standardize log formats and field names across different sources

  • Security: Redact sensitive data like passwords, API keys, and PII

  • Performance Optimization: Filter out noise and sample high-volume logs

  • Compliance: Ensure data meets regulatory requirements through transformation and filtering

Last updated

Was this helpful?