v0.55.0

envoyproxy/envoyv0.55.0Apr 22, 2026by github-actions[bot]

AI Summary

Vector 0.55.0 introduces a new Windows Event Log source and Parquet encoding support for AWS S3, while restoring native Azure authentication and optimizing Datadog metrics. The release also improves internal metrics for capacity planning and fixes a CPU performance regression, though it introduces breaking changes regarding the API migration from GraphQL to gRPC.

Key Highlights

  • New `windows_event_log` source for collecting Windows logs
  • AWS S3 sink now supports Apache Parquet batch encoding
  • Azure Blob sink restores first-class Azure authentication
  • Datadog metrics sink defaults to Series v2 with zstd compression
  • Fixed performance regression in file and kubernetes_logs sources

Breaking Changes

  • Vector observability API moved from GraphQL to gRPC
  • Removed top-level `headers` option on `http` and `opentelemetry` sinks
  • Azure logs ingestion sink requires explicit `azure_credential_kind` for Client Secret credentials

New Features

  • Windows Event Log source with pull-mode subscriptions
  • AWS S3 Parquet batch encoding with configurable compression
  • Native Azure authentication for Azure Blob sink
  • Series v2 endpoint for Datadog metrics with zstd compression
  • New internal metrics for source-send latency and task-transform utilization

Full Release Notes

The [COSE team](https://opensource.datadoghq.com/about/#the-community-open-source-engineering-team) is excited to announce version 0.55.0!

### Release highlights

- New `windows_event_log` source that collects logs from Windows Event Log channels using the native Windows Event Log API, with pull-mode subscriptions, bookmark-based checkpointing, and configurable field filtering.
- The `aws_s3` sink now supports Apache Parquet batch encoding. Events can be written as Parquet columnar files with either an auto-generated native schema or a supplied `.schema` file, and configurable compression (Snappy, ZSTD, GZIP, LZ4, or none).
- The `azure_blob` sink re-gains first-class [Azure authentication](https://learn.microsoft.com/en-us/azure/storage/blobs/authorize-access-azure-active-directory): Azure CLI, Managed Identity, Workload Identity, and Managed Identity-based Client Assertion credential kinds are all supported again.
- The `datadog_metrics` sink now defaults to the Series v2 endpoint (/api/v2/series) and uses `zstd` compression for Series v2 and Sketches, which should yield smaller payloads and more efficient batching and intake. A new `series_api_version` option (v1 or v2) is available to opt back to the legacy v1 endpoint; Series v1 continues to use `zlib`.
- `vector top` is more trustworthy: per-output events for components with multiple output ports are now shown in the correct Events Out column, and the Memory Used column now reports disabled when the target Vector instance was started without `--allocation-tracing` instead of a misleading 0.
- Better internal metrics for capacity planning and alerting:
  - New source-send latency distributions (`source_send_latency_seconds`, `source_send_batch_latency_seconds`) surface backpressure close to the source.
  - Task-transform utilization no longer counts time spent waiting on downstream components, giving a more representative view of transform saturation.
  - Fixed a regression in buffer utilization metric tracking around underflow.
- Fixed a performance regression in the file and kubernetes_logs sources that could cause unexpectedly high CPU usage, introduced in `0.50.0`.

### Breaking Changes
See the [0.55 upgrade guide](https://website.d1a7j77663uxsc.amplifyapp.com/highlights/2026-04-20-0-55-0-upgrade-guide/) for full details and migration steps. At a glance, you are affected if you:

- query or tail the Vector observability API in any way: the API has moved from GraphQL to gRPC. This includes `vector top`, `vector tap`, and anything that talked to /graphql or the /playground. The HTTP `GET /health` endpoint is unchanged and continues to serve Kubernetes HTTP probes as before.
- set the top-level headers option on the `http` or `opentelemetry` sinks: it has been removed.
- use the `azure_logs_ingestion` sink with Client Secret credentials: `azure_credential_kind` must now be set explicitly.

[View release notes](https://vector.dev/releases/0.55.0)