Fluent Bit is a lightweight and extensible log processor and forwarder. It is designed to be fast and efficient, and it is optimized for low resource consumption. Fluent Bit is part of the Fluentd project ecosystem, and it is licensed under the terms of the Apache License v2.0.


To ingest fluent-bit logs into RunReveal, you will need to set up an S3 bucket to stream your fluent logs to, if you don't have one already.

Below you'll find an example configuration for fluent-bit to stream logs to an S3 bucket.

    Name                         s3
    Match                        *
    bucket                       my-fluent-bit-bucket
    region                       us-east-2
    use_put_object               Off
    compression                  None
    s3_key_format                /$TAG/%Y/%m/%d/%H_%M_%S-$UUID.ndjson
    total_file_size              10M
    upload_timeout               60s

From there, take the bucket you've configured fluent-bit to stream logs to, and follow our guide on setting up a Generic S3 source, paying close attention to the event transformation step to normalize your logs for optimal query performance.