> ## Documentation Index
> Fetch the complete documentation index at: https://docs-xcor.paloaltonetworks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Forward source plugin

> Configure the Forward source plugin in Palo Alto Networks Telemetry Pipeline to ingest logs, metrics, and traces for processing and routing.

export const entity_0 = "Forward source plugin"

export const plugin_0 = "Forward source plugin"

<Info>
  This information is for Palo Alto Networks Telemetry Pipeline, which is a standalone
  product separate from Palo Alto Networks Cortex XCOR.
</Info>

The Forward [source plugin](/ingest/pipeline/plugins/source-plugins)
(name: `forward`, alias: `forward`) lets you ingest data from your Forward
services into a telemetry pipeline.

This is a
[push-based](/ingest/pipeline/plugins/source-plugins#push-based-and-pull-based-source-plugins)
source plugin.

## Supported telemetry types

The {plugin_0} for Palo Alto Networks Telemetry Pipeline supports these telemetry types:

| Logs | Metrics | Traces |
| :-: | :-: | :-: |
| <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> | <Icon icon="circle-check" color="green" /> |

## Configuration parameters

Use the parameters in this section to configure the {entity_0}. The
Palo Alto Networks Telemetry Pipeline web interface uses the items in the **Name** column to
describe these parameters. [Pipeline configuration files](/ingest/pipeline/v2/configure/config-files)
use the items in the **Key** column as YAML keys.

### General

| Name | Key | Description | Default |
| - | - | - | - |
| **Host** | `listen` | Required. The listener network interface. | `0.0.0.0` |
| **Port** | `port` | Required. The TCP port used for listening for incoming messages. | `24224` |
| **Unix Socket Path** | `unix_path` | Specifies the path to Unix socket to receive a Forward message. If set, `listen` and `port` are ignored. | *none* |
| **Unix Socket** | `unix_perm` | Sets the permission of the Unix socket file. If `unix_path` isn't set, this parameter is ignored. | *none* |
| **Buffer Chunk Size** | `buffer_chunk_size` | Sets the default [chunk](https://docs.fluentbit.io/manual/administration/buffering-and-storage#chunks) size for buffered data. If a single record exceeds this size, the plugin temporarily increases the chunk size up to the value of `buffer_max_size` to accommodate it. This value must follow Fluent Bit's rules for [unit sizes](https://docs.fluentbit.io/manual/administration/configuring-fluent-bit#unit-sizes). | `1024000` |
| **Buffer Max Size** | `buffer_max_size` | Sets the maximum [chunk](https://docs.fluentbit.io/manual/administration/buffering-and-storage#chunks) size for buffered data. If a single record exceeds this size, the plugin drops that record. This value must follow Fluent Bit's rules for [unit sizes](https://docs.fluentbit.io/manual/administration/configuring-fluent-bit#unit-sizes). | `6144000` |
| **Tag Prefix** | `tag_prefix` | The prefix incoming tag with the defined value. | *none* |
| **Memory Buffer Limit** | `mem_buf_limit` | Sets a limit for how much buffered data the plugin can write to memory, which affects backpressure. This value must follow Fluent Bit's rules for [unit sizes](https://docs.fluentbit.io/manual/administration/configuring-fluent-bit#unit-sizes). If unspecified, no limit is enforced. <p />For v2 pipelines, this parameter affects only pipelines with the Deployment or DaemonSet [workload](/ingest/pipeline/v2/configure/kubernetes/workloads) type. To learn more, see the v2 [backpressure](/ingest/pipeline/v2/configure/backpressure) guide. <p />For v3 pipelines, this parameter is independent from the [OpenTelemetry `memory_limiter` and `batch` processors](/ingest/pipeline/v3#route-data-from-fluent-bit-to-opentelemetry). | *none* |

### Security and TLS

| Name | Key | Description | Default |
| - | - | - | - |
| **TLS** | `tls` | If `true`, enables TLS/SSL. If `false`, disables TLS/SSL. Accepted values: `true`, `false`. | `false` |
| **TLS Certificate Validation** | `tls.verify` | If `on`, and if `tls` is `true`, enables TLS/SSL certificate validation. If `off`, disables TLS/SSL certificate validation. Accepted values: `on`, `off`. | `on` |
| **TLS Debug Level** | `tls.debug` | Sets TLS debug verbosity level. Accepted values: `0` (No debug), `1` (Error), `2` (State change), `3` (Informational), `4` (Verbose). | `1` |
| **CA Certificate File Path** | `tls.ca_file` | Absolute path to CA certificate file. | *none* |
| **Certificate File Path** | `tls.crt_file` | Absolute path to certificate file. | *none* |
| **Private Key File Path** | `tls.key_file` | Absolute path to private key file. | *none* |
| **Private Key Path Password** | `tls.key_passwd` | Password for private key file. | *none* |
| **TLS SNI Hostname Extension** | `tls.vhost` | Hostname to be used for TLS SNI extension. | *none* |


## Related topics

- [Forward destination plugin](/ingest/pipeline/plugins/destination-plugins/forward.md)
- [Fluentd source plugin](/ingest/pipeline/plugins/source-plugins/fluentd.md)
- [Fluent Bit source plugin](/ingest/pipeline/plugins/source-plugins/fluent-bit.md)
- [Prometheus scrape source plugin](/ingest/pipeline/plugins/source-plugins/prometheus-scrape.md)
- [Ingest telemetry data with source plugins](/ingest/pipeline/plugins/source-plugins.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.