Fluentd v1.19.4 has been released

Hi users!

We have released v1.19.4 on 2026-09-29. ChangeLog is here.

This release is a maintenance release of v1.19 series.

This release will be bundled for fluent-package LTS version v6.0.5!

Security Fixes

Many vulnerabilities were fixed in this release.

In most cases, there is no problem using deployed Fluentd within a closed, trusted network. If you could not update Fluentd immediately, consider to take advised mitigation in above advisories.

Bug Fixes

Many bugs were also fixed in this release.

  • output: fix JSON::GeneratorError as unrecoverable error. (#5423)
    • Failure for content reasons (e.g. non-UTF-8 bytes, NaN/Infinity), is treated as a bad chunk.
  • Set allow_duplicate_key parameter for JSON.parse. It accept duplicate keys silently (last value wins) on every path. It keeps compatibility with older versions even though newer json gem is used. (#5430)
  • Set allow_comments parameter for JSON.parse. It accepts JSON with comments. It keeps compatibility with older versions even though newer json gem is used. (#5432)
  • Accept a bare scalar for an array option in YAML syntax (#5433)
  • parser_syslog: Optimize RFC5424 structured data parsing (#5444)
    • It avoids excessive backtracking when parsing malformed RFC5424 structured data.
  • out_forward: drop keepalive sockets with failed or mismatched acks (#5445)
    • It stops the endless "ack in response and chunk id in sent data are different" warning storm by discarding (instead of reusing) a keepalive socket.
  • buffer: fix stage_byte_size leak when a staged chunk is unstaged (#5456)
    • There was a possibility that it could eventually raise spurious BufferOverflowError. It affects plugins which implementing #format.
  • plugin base: bound the number of worker lock files by hashing the path into a fixed set of buckets. (#5471)
  • supervisor: reduce memory usage of cleanup_lock_dir with huge number of lock files (#5472)
  • config: accept empty lines in quoted strings (#5478)
  • chunk: ensure to close the Tempfile for decompressed data (#5486)
  • buffer: fix spurious BufferOverflowError caused by queue_size leaking when a chunk purge fails (#5487)
  • buffer: clamp exported buffer size metrics to non-negative values (#5488)
  • Support json gem v3.x (#5493)
  • parser_syslog: fix NameError when RFC3164 timestamp has repeated spaces (#5497)
  • parser_syslog: fix NameError when RFC5424 timestamp has repeated spaces (#5500)

Accept a bare scalar for an array option in YAML syntax

In the previous versions, a single scalar value for an array option is rejected in YAML config syntax.

Since v1.19.4, it accepts the following example.

config:
  - match:
      $tag: "**"
      $type: http
      retryable_response_codes: 503

plugin base: bound the number of worker lock files by hashing the path into a fixed set of buckets

When workers > 1, out_file (with append) and out_secondary_file take an inter-worker lock per output path, and get_lock_path derives one lock file per path: /tmp/fluentd-lock-*/fluentd-<sanitized path>.lock.

In the previous versions, a lock file is never removed while fluentd is running; the only cleanup is cleanup_lock_dir at a graceful shutdown. So the number of lock files grows with the number of unique output paths, and with a date or a tag placeholder in path that set is effectively unbounded over time.

In this release, the number of lock files is now bounded by a constant instead of by the number of unique paths. The accumulation, the mass deletion at shutdown, and the dependence on an external tmp cleaner all disappear structurally rather than being mitigated.

Enjoy logging!

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

fluent-package v6.0.5 has been released

Hi users!

We have released fluent-package v6.0.5 on 2026-09-29. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

Fluent Package v6.0.5

Fluent Package v6.0.5 includes the following improvements:

  • Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities
  • Updated bundled Ruby to 3.4.11
  • Updated bundled gems which fix vulnerabilities and crashes (oj, json)
  • msi: Fixed a broken link to enterprise services on the popup window of the Windows installer
  • rpm: Kept compatibility with older RHEL 9.x and 10.x
  • deb rpm: Reduced build time by disabling LTO on RHEL 10 and Ubuntu

This article explains the changes in Fluent Package v6.0.5.

Changes

Updated bundled Fluentd to v1.19.4 which fixes some vulnerabilities

In this release, some critical vulnerabilities were fixed.

The above vulnerabilities affects to older than v1.19.4, thus the following packages also will be affected.

  • fluent-package LTS v6.0.4 or earlier
  • fluent-package Standard edition v6.0.0 (NOTE: no patched version planned yet, please consider to use LTS)
  • fluent-package LTS v5.0.9 or earlier (NOTE: v5.0.x already reached EOL, no patched updates anymore)
  • fluent-package Standard edition v5.2.0 or earlier (NOTE: v5.x already reached EOL, no patched updates anymore)
  • All of td-agent (NOTE: td-agent already reached EOL, no patched updates anymore)

We recommend upgrading fluent-package to v6.0.5.

If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory. Please check each advisory and take care of it.

Fluentd v1.19.4 also contains many bug fixes. See the release announcement of Fluentd v1.19.4 for details.

Updated bundled Ruby to 3.4.11

Ruby 3.4.11 is a maintenance release. Compared to Ruby 3.4.9 which was bundled in the previous version, it includes the following security fixes in bundled gems:

For details, please see the Ruby 3.4.10 and Ruby 3.4.11 release notes.

msi: fixed a broken link to enterprise services on popup window

The link to the enterprise services page on the popup window of the Windows installer was broken. It has been fixed in this release. (#1079)

rpm: keep compatibility with older RHEL 9.x and 10.x

The packages for RHEL 9.x and 10.x were built on the latest minor version of each series. As a result, the built binaries required newer symbols such as GLIBC_2.35 or OPENSSL_3.4.0, and they did not work on older minor versions like RHEL 9.6 or RHEL 10.1.

To keep the ABI compatible in the whole 9.x and 10.x series, the build environment is now pinned to RHEL 9.2 and RHEL 10.0. (#1089, #1090)

This issue was fixed and shipped as 6.0.4-2 on above platforms which had been implemented in advance, has now been officially released.

rpm deb: disable LTO for RHEL 10 and Ubuntu

RPM 4.19 (AlmaLinux 10) and dpkg-buildflags on Ubuntu export LTO (Link Time Optimization) flags (-flto=auto -ffat-lto-objects) into the build process. These flags leaked into jemalloc, Ruby and native gem extensions, and made the build much slower. For example, the total build time on AlmaLinux 10 grew extraordinaly.

Since the bundled Ruby uses its own optimization settings, LTO gives no measurable benefit here. So we removed the LTO flags and the annobin plugin from the build environment. The hardening flags such as stack protection, control flow protection and FORTIFY_SOURCE are kept as before.

This change also means that native extensions which users build with fluent-gem install no longer inherit the LTO overhead. (#1102)

Download

Please visit the download page.

Announcement

About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.6 at Dec 2026. The content of updates are still TBD.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

Scheduled support lifecycle announcement about Fluent Package v7

Hi users!

We had launched fluent-package v6 series last year, recently shipped v6.0.4 in LTS release channel.

In this blog article, we explain the planned next major updates - v7.0.0.

When the next LTS (Long Term Support) version available?

In short, we will ship fluent-package v7 in Aug, 2027.

We keep two release channels as follows:

  • Normal release
  • LTS (Long Term Support)

Here is the difference of these channels.

  • Normal release (7.x series)
    • Recommended for early adopters (eager to try new features of Fluentd)
    • Regular releases are not guaranteed. (planned semi-annually releases, but it may vary. In some cases, the LTS version may actually be newer.)
    • Fluentd will be upgraded occasionally
      • Minor upgrade will be applied. e.g. 1.20 => 1.21 and so on.
      • e.g. v7.0.1 (Fluentd v1.20.1), v7.0.2 (Fluentd v1.20.2), ... v7.1.0 (Fluentd v1.21.0)
    • The only latest version will be supported
  • LTS (Long Term Support, 7.0.x series)
    • Recommended for enterprise services
    • Security and bug fix release only
    • Fluentd will be upgraded only in the teeny version and will stick to 1.20.x series. (T.B.D.)
      • Thus, the version number will be 7.0.x. (7.1 series will not be shipped for LTS channel)
      • e.g. v7.0.1 (Fluentd v1.20.1), v7.0.2 (Fluentd v1.20.2), v7.0.3 (Fluentd v1.20.3) ... v7.0.x (Fluentd v1.20.x) and so on.
    • Next major version will be fluent-package v8.0.0, and will be shipped in 2029 (T.B.D.).

As for fluent-package v7,

  • fluent-package v6 LTS will be supported until Dec, 2027.
    • We expect users upgrade from v6 to v7 during the grace period.
  • Until 7.1.0 is released, normal release channel and LTS channel are the same package.
  • Upgrade from v4 or older version is not supported. Upgrade to v5 or v6 first, then upgrade it to v7.

Current releases and future plans:

Release Version Release Date End of life
v6.0.x (LTS) Aug, 2025 Dec, 2027
v7.0.0 (LTS) Aug, 2027 Dec, 2029 (T.B.D.)
v8.0.0 (LTS) Aug, 2029 (T.B.D.) T.B.D.

Happy logging!

Read More

fluent-package v6.0.4 has been released

Hi users!

We have released fluent-package v6.0.4 on 2026-06-26. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

Fluent Package v6.0.4

Fluent Package v6.0.4 includes the following improvements:

  • Updated bundled Fluentd to v1.19.3 which fixes some vulnerabilities.

This article explains the changes in Fluent Package v6.0.4.

Changes

Updated bundled Fluentd to v1.19.3 which fixes some vulnerabilities.

In this release, some critical vulnerabilities were fixed.

The above vulnerabilities affects to older than v1.19.3, thus the following packages also will be affected.

  • fluent-package LTS v6.0.3 or earlier
  • fluent-package Standard edition v6.0.0 (NOTE: no patched version planned yet, please consider to use LTS)
  • fluent-package LTS v5.0.9 or earlier (NOTE: v5.0.x already reached EOL, no patched updates anymore)
  • fluent-package Standard edition v5.2.0 or earlier (NOTE: v5.x already reached EOL, no patched updates anymore)
  • All of td-agent (NOTE: td-agent already reached EOL, no patched updates anymore)

We recommend upgrading fluent-package to v6.0.4.

If you can't upgrade it immediately, there is a case that mitigation method is explained in above advisory. Please check each advisory and take care of it.

Download

Please visit the download page.

Announcement

About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.5 at Sep 2026. The content of updates are still TBD.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

Fluentd v1.19.3 has been released

Hi users!

We have released v1.19.3 on 2026-06-25. ChangeLog is here.

This release is a maintenance release of v1.19 series.

This release is bundled for fluent-package LTS version v6.0.4!

Security Fixes

Many vulnerabilities were fixed in this release.

Additionally, similar vulnerability was also fixed in the following fluentd plugins:

In most cases, there is no problem using deployed Fluentd within a closed, trusted network. If you could not update Fluentd immediately, consider to take advised mitigation in above advisories.

Bug Fixes

Many bugs were also fixed in this release.

  • in_debug_agent: accept only from local machine by default
  • buffer: resume buffer correctly even though path contains []
  • out_forward: avoid reusing closed keepalive sockets after remote
  • storage_local: fix encoding error when fix encoding error when reading non-ASCII characters

in_debug_agent: accept only from local machine by default

Historically, in_debug_agent accepts remote access by default.

This behavior is not problem because usually in_debug_agent must be explicitly enabled by users who know what you do.

But, there is an security concern which accepts external access by default even though user must enable it explicitly.

To mitigate security concern, changed that behavior a bit secure by default.

If you dare to keep previous non-secure behavior, specify 0.0.0.0 explicitly.

<source>
  @type monitor_agent
  bind 0.0.0.0   # prior to v1.19.3 default behavior
  bind 127.0.0.1 # since v1.19.3 default behavior
  ...
</source>

buffer: resume buffer correctly even though path contains []

If buffer path contains [] in tag something like "path test/${tag[0]}", when resuming buffer process can't find them without escaping bracket.

Thus buffer files remains under that directory.

In this release, that can be resumed correctly.

Note that recommended tag spec is specified in routing documentation, but it is easily shoot your legs in practical use-case if you use [] characters. so it is changed to take care of that case.

avoid reusing closed keepalive sockets after remote disconnects

In the previous versions, there was a keepalive socket reuse bug.

When a cached keepalive connection has already been closed by the remote side, out_forward could pick that socket back up and try to write to it again.

As a result, that left the flush thread spinning on a dead socket and can drive CPU usage to 100%.

storage_local: fix encoding error when fix encoding error when reading non-ASCII characters

If data containing non-latin characters are stored onto disk using the storage_local plugin, the file is properly written but cannot be read again once fluentd restarts. Now that behaviour was fixed by properly handling the file encoding.

Improvements

In this release, added some warnings for problematic use-cases.

If there are any potential issues with your configuration, Fluentd detects above cases additionally.

Enjoy logging!

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

fluent-package v6.0.3 has been released

Hi users!

We have released fluent-package v6.0.3 on 2026-03-27. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

Fluent Package v6.0.3

Fluent Package v6.0.3 includes the following improvements:

  • Fixed a severe memory leak issue in the bundled cool.io v1.9.3 under specific conditions
  • Updated bundled Ruby to 3.4.9
  • Updated bundled Nokogiri to v1.19.2 (Windows only) for vulnerability fix

This article explains the changes in Fluent Package v6.0.3.

Changes

Fixed a severe memory leak issue in the bundled cool.io v1.9.3

In fluent-package v6.0.2, a critical issue was discovered where memory usage continuously increases over time. This release completely resolves this problem.

  • Affected Environments
    • This issue occurs in environments where TCP connections are frequently connected and disconnected.
    • It is easily reproducible when using the out_forward plugin with the keepalive false setting (which is the default value).
  • Root cause
    • The asynchronous I/O library cool.io (v1.9.2 and v1.9.3) bundled in fluent-package v6.0.2 had a bug in its detachment process.
    • When a TCP connection was detached, the internal watcher objects were not properly garbage collected, leaving "garbage" data accumulated in the memory.
  • Resolution
    • We have released cool.io v1.9.4 which fixes this bug, and it is now bundled by default in fluent-package v6.0.3.

If operated for a long period, this memory leak will exhaust system memory resources, eventually causing the Fluentd process to be terminated unexpectedly by the OOM (Out of Memory) Killer. We strongly recommend users who are using out_forward on v6.0.2 to update to this version immediately.

Note: Users on fluent-package v6.0.1 or earlier are not affected by this specific issue.

Updated bundled Ruby to 3.4.9

Ruby 3.4.9 includes multiple bug and security fixes. Specifically, it addresses the following vulnerability:

For details, please see the Ruby 3.4.9 release notes.

Updated bundled Nokogiri (Windows only) for vulnerability fix

We have updated the bundled Nokogiri from v1.18.10 to v1.19.2 for the Windows version to address the following vulnerability:

Download

Please visit the download page.

Announcement

About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.4 at June 2026. The content of updates are still TBD.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

fluent-package v6.0.2 has been released

Hi users!

We have released fluent-package v6.0.2 on 2026-02-27. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent)

This is a maintenance release of v6.0.x LTS series.

Fluent Package v6.0.2

Fluent Package v6.0.2 includes the following improvements:

  • Updated bundled Ruby to 3.4.8
  • Updated bundled Fluentd from v1.19.1 to v1.19.2
  • rpm: fixed update error if working directory was removed
  • Fixed CVEs about bundled gems: CVE-2025-14762, CVE-2026-25765
    • When using with fluentd, usually it will not be affected by these vulnerability, but bundled fixed versions with keeping compatibility.
  • msi: fixed installation rollback issue when executing maintenance script

This article explains the changes in Fluent Package v6.0.2.

Changes

Updated bundled Ruby to 3.4.8

Ruby 3.4.8 includes multiple bug and security fixes. For details, please see the Ruby 3.4.8 release notes.

Updated bundled Fluentd from v1.19.1 to v1.19.2

Fluentd v1.19.2 includes the following fixes:

  • Fixed duplicate configuration file loading in config_include_dir
  • in_tail: fixed error when files without read permission are included in glob patterns
  • out_forward: added timeout to prevent infinite loop under unstable network connection
  • gem: use latest net-http to solve IPv6 addr error
  • warn when backed-up conf file will be included

For details, please see the Fluentd v1.19.2 has been released.

rpm: fixed update error if working directory was removed

In this release, it was fixed update error if temporary working directory was removed.

In the previous versions, if temporary working directory was removed by tmpfiles.d, there was a case that updating to v6 (up to v6.0.1) causes fatal error while rpm processes transaction.

Now, with changing temporary working directory handling, it was fixed in v6.0.2.

msi: fixed installation rollback issue when executing maintenance script

Since v6.0.0, installation maintenance script (powershell) was partially introduced for Windows. But in some environments, there is a case that the execution of powershell was prohibited in your policy. In such a case, installation process will be failed unexpectedly.

In this release, added fallback not to terminate installation process accidentally.

Download

Please visit the download page.

Announcement

About next LTS schedule

We plan to release the next LTS version of fluent-package v6.0.3 at June 2026. The content of updates are still TBD.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

Fluentd v1.19.2 has been released

Hi users!

We have released v1.19.2 on 2026-02-13. ChangeLog is here.

This release is a maintenance release of v1.19 series.

This release will be bundled for upcoming fluent-package LTS version v6.0.2!

Bug Fixes

Fixed duplicate configuration file loading in config_include_dir

Since Fluentd v1.19.0, the configuration files under/etc/fluent/conf.d were changed to load automatically.

This feature was introduced to load builtin plugins and designed to work well with fluent-package. But, as a side effect, there is a case that duplicated configuration files are loaded if user already configured to include from /etc/fluent/conf.d.

In that case, it causes startup failures. Thus, user need to disable with config_include_dir "" explicitly as a workaround.

In this release, not to raise startup failure, we fixed duplicate configured file loading in config_include_dir.

in_tail: fixed error when files without read permission are included in glob patterns

In the previous versions, if you enabled Linux capability feature with Fluentd, there is a case that it causes an error.

It was caused when accessing uninitialized instance variable.

out_forward: added timeout to prevent infinite loop under unstable network connection

In unstable network environments with proxy components, if connection drops during handshake after TLS establishment, Fluentd gets stuck in infinite loop causing logs to stop being flushed.

In this release, fixed to uses existing hard_timeout configuration to break the loop, then disable problematic nodes, and maintain log flow through healthy nodes.

This fixes improves stability of Fluentd.

gem: use latest net-http to solve IPv6 addr error

net-http gem had a bug in handling IPv6 addresses, and updating the uri gem would trigger strict checking, thus causing errors.

It was affected when you installed via gem command.

warn when backed-up conf file will be included

There is a case that unintentionally backed-up conf file will be loaded by wild card @include.

It will help to detect such a careless mistakes by warning.

For example, if you include configuration file by @include conf/*.conf, and there are unintentionally backed-up file exists (conf/dummy.bak.conf), usually it causes startup failures.

In this release, it detects such a case as a warning.

$ fluentd -c wildcard_include.conf --dry-run
2026-02-12 17:41:39 +0900 [info]: init supervisor logger path=nil rotate_age=nil rotate_size=nil
2026-02-12 17:41:39 +0900 [warn]: There is a possibility that '@include conf/*.conf' includes duplicated backed-up config file such as <dummy.bak.conf>
2026-02-12 17:41:39 +0900 [info]: parsing config file is succeeded path="wildcard_include.conf"
2026-02-12 17:41:39 +0900 [info]: configuration include directory is disabled
2026-02-12 17:41:39 +0900 [info]: gem 'fluentd' version '1.19.0'
2026-02-12 17:41:39 +0900 [info]: starting fluentd-1.19.0 as dry run mode ruby="3.4.8"
2026-02-12 17:41:39 +0900 [info]: using configuration file: <ROOT>
  <system>
    config_include_dir ""
  </system>
  <source>
    @type forward
  </source>
  <source>
    @type forward
  </source>
</ROOT>
2026-02-12 17:41:39 +0900 [info]: finished dry run mode

Enjoy logging!

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

Drop schedule announcement about EOL of Fluent Package (fluent-package) 5

Hi users and developers!

As already planned before, we announce the dropping schedule for Fluent Package 5 (LTS) development.

About Fluent Package v5

Since fluent-package 5.0.0 was released in 2023, fluent-package 5 has been maintained for a long time.

As new major version of fluent-package 6 was released in August 2025, we decided to stop maintaining fluent-package 5 in Dec 31, 2025.

LTS version of fluent-package v6 will be planned support until Dec, 2027. It will meet for your enterprise services.

Scheduled end of life - Dec 2025

As you know, already stepping down maintenance activity, new minor update for fluent-package 5 will not be shipped anymore. fluent-package v5.0.9 should be the last release of this series, it was shipped in Dec 19, 2025.

Thus, we recommend using fluent-package v6 for new deployment :)

How to migrate to Fluent Package v6

There is a good article to do it.

Follow the above instructions.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More

fluent-package v5.0.9 has been released

Hi users!

We have released fluent-package v5.0.9 on December 19, 2025. Fluent Package is a stable distribution package of Fluentd. (successor of td-agent v4)

This is a maintenance release of v5.0.x LTS series.

Fluent Package v5.0.9

This article explains the changes in Fluent Package v5.0.9.

Changes

Updated bundled Fluentd from v1.16.10 to v1.16.11

Fluentd v1.16.11 includes the following fixes:

  • out_forward: fix issue where could cause output to stop when using <security> and TLS setting together under unstable network environments
    • In an unstable network environment, if communication is lost during the forward plugin's connection process after TLS is established, the out_forward connection process could fall into an infinite loop, causing log output to stop.
    • We applied the existing hard_timeout parameter setting to this connection process to enable interruption and recovery via timeout.

Download

Please see the download page.

Announcement

The final release of v5 LTS series

This release (v5.0.9) is planned to be the final version of the v5 LTS series. We strongly recommend upgrading to Fluent Package v6 LTS series for next long term support.

Please refer to Scheduled support lifecycle announcement about Fluent Package v6.

Follow us on X

We have been posting information about Fluentd in Japanese on @fluentd_jp. We would appreciate it if you followed the X account.

Read More


About Fluentd

Fluentd is an open source data collector to simplify log management.

Learn

Want to learn the basics of Fluentd? Check out these pages.

Ask the Community

Couldn't find enough information? Let's ask the community!

Ask the Experts

You need commercial-grade support from Fluentd committers and experts?

Follow Us!