v0.55.0
lutzroeder/netronv0.55.0Apr 22, 2026by github-actions[bot]
AI Summary
Vector 0.55.0 introduces a new Windows Event Log source, Parquet encoding for the AWS S3 sink, restored Azure authentication methods, and updates to Datadog metrics. It also improves internal metrics for capacity planning and fixes performance regressions.
Key Highlights
- New `windows_event_log` source with native API and bookmarking
- Parquet batch encoding support for `aws_s3` sink
- Restored Azure authentication (CLI, Managed Identity, Workload Identity)
- Datadog metrics default to Series v2 with ZSTD compression
- New internal metrics for source-send latency and transform utilization
Breaking Changes
- API moved from GraphQL to gRPC (affects `vector top`, `vector tap`, observability API)
- Removal of top-level headers option on `http` and `opentelemetry` sinks
- Required explicit `azure_credential_kind` for `azure_logs_ingestion` sink
New Features
- Windows Event Log source
- Parquet encoding for AWS S3
- Azure authentication support
- Series v2 Datadog endpoint
- Source-send latency distributions
Full Release Notes
The [COSE team](https://opensource.datadoghq.com/about/#the-community-open-source-engineering-team) is excited to announce version 0.55.0! ### Release highlights - New `windows_event_log` source that collects logs from Windows Event Log channels using the native Windows Event Log API, with pull-mode subscriptions, bookmark-based checkpointing, and configurable field filtering. - The `aws_s3` sink now supports Apache Parquet batch encoding. Events can be written as Parquet columnar files with either an auto-generated native schema or a supplied `.schema` file, and configurable compression (Snappy, ZSTD, GZIP, LZ4, or none). - The `azure_blob` sink re-gains first-class [Azure authentication](https://learn.microsoft.com/en-us/azure/storage/blobs/authorize-access-azure-active-directory): Azure CLI, Managed Identity, Workload Identity, and Managed Identity-based Client Assertion credential kinds are all supported again. - The `datadog_metrics` sink now defaults to the Series v2 endpoint (/api/v2/series) and uses `zstd` compression for Series v2 and Sketches, which should yield smaller payloads and more efficient batching and intake. A new `series_api_version` option (v1 or v2) is available to opt back to the legacy v1 endpoint; Series v1 continues to use `zlib`. - `vector top` is more trustworthy: per-output events for components with multiple output ports are now shown in the correct Events Out column, and the Memory Used column now reports disabled when the target Vector instance was started without `--allocation-tracing` instead of a misleading 0. - Better internal metrics for capacity planning and alerting: - New source-send latency distributions (`source_send_latency_seconds`, `source_send_batch_latency_seconds`) surface backpressure close to the source. - Task-transform utilization no longer counts time spent waiting on downstream components, giving a more representative view of transform saturation. - Fixed a regression in buffer utilization metric tracking around underflow. - Fixed a performance regression in the file and kubernetes_logs sources that could cause unexpectedly high CPU usage, introduced in `0.50.0`. ### Breaking Changes See the [0.55 upgrade guide](https://website.d1a7j77663uxsc.amplifyapp.com/highlights/2026-04-20-0-55-0-upgrade-guide/) for full details and migration steps. At a glance, you are affected if you: - query or tail the Vector observability API in any way: the API has moved from GraphQL to gRPC. This includes `vector top`, `vector tap`, and anything that talked to /graphql or the /playground. The HTTP `GET /health` endpoint is unchanged and continues to serve Kubernetes HTTP probes as before. - set the top-level headers option on the `http` or `opentelemetry` sinks: it has been removed. - use the `azure_logs_ingestion` sink with Client Secret credentials: `azure_credential_kind` must now be set explicitly. [View release notes](https://vector.dev/releases/0.55.0)