published on Monday, Sep 21, 2026 by Formal
published on Monday, Sep 21, 2026 by Formal
Defines field-level actions for matching Formal logs before they are exported or stored.
Create LogSchema Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new LogSchema(name: string, args: LogSchemaArgs, opts?: CustomResourceOptions);@overload
def LogSchema(resource_name: str,
args: LogSchemaArgs,
opts: Optional[ResourceOptions] = None)
@overload
def LogSchema(resource_name: str,
opts: Optional[ResourceOptions] = None,
paths: Optional[Sequence[LogSchemaPathArgs]] = None,
scope_cel: Optional[str] = None,
encryption_key_id: Optional[str] = None,
name: Optional[str] = None)func NewLogSchema(ctx *Context, name string, args LogSchemaArgs, opts ...ResourceOption) (*LogSchema, error)public LogSchema(string name, LogSchemaArgs args, CustomResourceOptions? opts = null)
public LogSchema(String name, LogSchemaArgs args)
public LogSchema(String name, LogSchemaArgs args, CustomResourceOptions options)
type: formal:LogSchema
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "formal_log_schema" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args LogSchemaArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args LogSchemaArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args LogSchemaArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args LogSchemaArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args LogSchemaArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var logSchemaResource = new Pulumi.LogSchema("logSchemaResource", new()
{
Paths = new[]
{
new Pulumi.Inputs.LogSchemaPathArgs
{
Name = "string",
Drop = false,
Encrypt = false,
EncryptSql = false,
StripSql = false,
Truncate = new Pulumi.Inputs.LogSchemaPathTruncateArgs
{
MaxSizeBytes = 0,
},
},
},
ScopeCel = "string",
EncryptionKeyId = "string",
Name = "string",
});
example, err := formal.NewLogSchema(ctx, "logSchemaResource", &formal.LogSchemaArgs{
Paths: formal.LogSchemaPathArray{
&formal.LogSchemaPathArgs{
Name: pulumi.String("string"),
Drop: pulumi.Bool(false),
Encrypt: pulumi.Bool(false),
EncryptSql: pulumi.Bool(false),
StripSql: pulumi.Bool(false),
Truncate: &formal.LogSchemaPathTruncateArgs{
MaxSizeBytes: pulumi.Int(0),
},
},
},
ScopeCel: pulumi.String("string"),
EncryptionKeyId: pulumi.String("string"),
Name: pulumi.String("string"),
})
resource "formal_log_schema" "logSchemaResource" {
lifecycle {
create_before_destroy = true
}
paths {
name = "string"
drop = false
encrypt = false
encrypt_sql = false
strip_sql = false
truncate = {
max_size_bytes = 0
}
}
scope_cel = "string"
encryption_key_id = "string"
name = "string"
}
var logSchemaResource = new LogSchema("logSchemaResource", LogSchemaArgs.builder()
.paths(LogSchemaPathArgs.builder()
.name("string")
.drop(false)
.encrypt(false)
.encryptSql(false)
.stripSql(false)
.truncate(LogSchemaPathTruncateArgs.builder()
.maxSizeBytes(0)
.build())
.build())
.scopeCel("string")
.encryptionKeyId("string")
.name("string")
.build());
log_schema_resource = formal.LogSchema("logSchemaResource",
paths=[{
"name": "string",
"drop": False,
"encrypt": False,
"encrypt_sql": False,
"strip_sql": False,
"truncate": {
"max_size_bytes": 0,
},
}],
scope_cel="string",
encryption_key_id="string",
name="string")
const logSchemaResource = new formal.LogSchema("logSchemaResource", {
paths: [{
name: "string",
drop: false,
encrypt: false,
encryptSql: false,
stripSql: false,
truncate: {
maxSizeBytes: 0,
},
}],
scopeCel: "string",
encryptionKeyId: "string",
name: "string",
});
type: formal:LogSchema
properties:
encryptionKeyId: string
name: string
paths:
- drop: false
encrypt: false
encryptSql: false
name: string
stripSql: false
truncate:
maxSizeBytes: 0
scopeCel: string
LogSchema Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The LogSchema resource accepts the following input properties:
- Paths
List<Formal.
Pulumi. Inputs. Log Schema Path> - A log field path and the actions to apply to it.
- Scope
Cel string - A CEL expression that determines which logs this schema applies to.
- Encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- Name string
- The name of this log schema.
- Paths
[]Log
Schema Path Args - A log field path and the actions to apply to it.
- Scope
Cel string - A CEL expression that determines which logs this schema applies to.
- Encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- Name string
- The name of this log schema.
- paths list(object)
- A log field path and the actions to apply to it.
- scope_
cel string - A CEL expression that determines which logs this schema applies to.
- encryption_
key_ stringid - The ID of the asymmetric encryption key used by encrypt actions.
- name string
- The name of this log schema.
- paths
List<Log
Schema Path> - A log field path and the actions to apply to it.
- scope
Cel String - A CEL expression that determines which logs this schema applies to.
- encryption
Key StringId - The ID of the asymmetric encryption key used by encrypt actions.
- name String
- The name of this log schema.
- paths
Log
Schema Path[] - A log field path and the actions to apply to it.
- scope
Cel string - A CEL expression that determines which logs this schema applies to.
- encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- name string
- The name of this log schema.
- paths
Sequence[Log
Schema Path Args] - A log field path and the actions to apply to it.
- scope_
cel str - A CEL expression that determines which logs this schema applies to.
- encryption_
key_ strid - The ID of the asymmetric encryption key used by encrypt actions.
- name str
- The name of this log schema.
- paths List<Property Map>
- A log field path and the actions to apply to it.
- scope
Cel String - A CEL expression that determines which logs this schema applies to.
- encryption
Key StringId - The ID of the asymmetric encryption key used by encrypt actions.
- name String
- The name of this log schema.
Outputs
All input properties are implicitly available as output properties. Additionally, the LogSchema resource produces the following output properties:
- created_
at string - When the log schema was created.
- id string
- The provider-assigned unique ID for this managed resource.
- updated_
at string - When the log schema was last updated.
- created_
at str - When the log schema was created.
- id str
- The provider-assigned unique ID for this managed resource.
- updated_
at str - When the log schema was last updated.
Look up Existing LogSchema Resource
Get an existing LogSchema resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: LogSchemaState, opts?: CustomResourceOptions): LogSchema@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
created_at: Optional[str] = None,
encryption_key_id: Optional[str] = None,
name: Optional[str] = None,
paths: Optional[Sequence[LogSchemaPathArgs]] = None,
scope_cel: Optional[str] = None,
updated_at: Optional[str] = None) -> LogSchemafunc GetLogSchema(ctx *Context, name string, id IDInput, state *LogSchemaState, opts ...ResourceOption) (*LogSchema, error)public static LogSchema Get(string name, Input<string> id, LogSchemaState? state, CustomResourceOptions? opts = null)public static LogSchema get(String name, Output<String> id, LogSchemaState state, CustomResourceOptions options)resources: _: type: formal:LogSchema get: id: ${id}import {
to = formal_log_schema.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Created
At string - When the log schema was created.
- Encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- Name string
- The name of this log schema.
- Paths
List<Formal.
Pulumi. Inputs. Log Schema Path> - A log field path and the actions to apply to it.
- Scope
Cel string - A CEL expression that determines which logs this schema applies to.
- Updated
At string - When the log schema was last updated.
- Created
At string - When the log schema was created.
- Encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- Name string
- The name of this log schema.
- Paths
[]Log
Schema Path Args - A log field path and the actions to apply to it.
- Scope
Cel string - A CEL expression that determines which logs this schema applies to.
- Updated
At string - When the log schema was last updated.
- created_
at string - When the log schema was created.
- encryption_
key_ stringid - The ID of the asymmetric encryption key used by encrypt actions.
- name string
- The name of this log schema.
- paths list(object)
- A log field path and the actions to apply to it.
- scope_
cel string - A CEL expression that determines which logs this schema applies to.
- updated_
at string - When the log schema was last updated.
- created
At String - When the log schema was created.
- encryption
Key StringId - The ID of the asymmetric encryption key used by encrypt actions.
- name String
- The name of this log schema.
- paths
List<Log
Schema Path> - A log field path and the actions to apply to it.
- scope
Cel String - A CEL expression that determines which logs this schema applies to.
- updated
At String - When the log schema was last updated.
- created
At string - When the log schema was created.
- encryption
Key stringId - The ID of the asymmetric encryption key used by encrypt actions.
- name string
- The name of this log schema.
- paths
Log
Schema Path[] - A log field path and the actions to apply to it.
- scope
Cel string - A CEL expression that determines which logs this schema applies to.
- updated
At string - When the log schema was last updated.
- created_
at str - When the log schema was created.
- encryption_
key_ strid - The ID of the asymmetric encryption key used by encrypt actions.
- name str
- The name of this log schema.
- paths
Sequence[Log
Schema Path Args] - A log field path and the actions to apply to it.
- scope_
cel str - A CEL expression that determines which logs this schema applies to.
- updated_
at str - When the log schema was last updated.
- created
At String - When the log schema was created.
- encryption
Key StringId - The ID of the asymmetric encryption key used by encrypt actions.
- name String
- The name of this log schema.
- paths List<Property Map>
- A log field path and the actions to apply to it.
- scope
Cel String - A CEL expression that determines which logs this schema applies to.
- updated
At String - When the log schema was last updated.
Supporting Types
LogSchemaPath, LogSchemaPathArgs
- Name string
- The protobuf field path, starting with
log. - Drop bool
- Whether to remove the field from the log.
- Encrypt bool
- Whether to encrypt the string field.
- Encrypt
Sql bool - Whether to encrypt literal values in a SQL query.
- Strip
Sql bool - Whether to remove literal values from a SQL query.
- Truncate
Formal.
Pulumi. Inputs. Log Schema Path Truncate - Truncates the string field to a maximum UTF-8 byte length.
- Name string
- The protobuf field path, starting with
log. - Drop bool
- Whether to remove the field from the log.
- Encrypt bool
- Whether to encrypt the string field.
- Encrypt
Sql bool - Whether to encrypt literal values in a SQL query.
- Strip
Sql bool - Whether to remove literal values from a SQL query.
- Truncate
Log
Schema Path Truncate - Truncates the string field to a maximum UTF-8 byte length.
- name string
- The protobuf field path, starting with
log. - drop bool
- Whether to remove the field from the log.
- encrypt bool
- Whether to encrypt the string field.
- encrypt_
sql bool - Whether to encrypt literal values in a SQL query.
- strip_
sql bool - Whether to remove literal values from a SQL query.
- truncate object
- Truncates the string field to a maximum UTF-8 byte length.
- name String
- The protobuf field path, starting with
log. - drop Boolean
- Whether to remove the field from the log.
- encrypt Boolean
- Whether to encrypt the string field.
- encrypt
Sql Boolean - Whether to encrypt literal values in a SQL query.
- strip
Sql Boolean - Whether to remove literal values from a SQL query.
- truncate
Log
Schema Path Truncate - Truncates the string field to a maximum UTF-8 byte length.
- name string
- The protobuf field path, starting with
log. - drop boolean
- Whether to remove the field from the log.
- encrypt boolean
- Whether to encrypt the string field.
- encrypt
Sql boolean - Whether to encrypt literal values in a SQL query.
- strip
Sql boolean - Whether to remove literal values from a SQL query.
- truncate
Log
Schema Path Truncate - Truncates the string field to a maximum UTF-8 byte length.
- name str
- The protobuf field path, starting with
log. - drop bool
- Whether to remove the field from the log.
- encrypt bool
- Whether to encrypt the string field.
- encrypt_
sql bool - Whether to encrypt literal values in a SQL query.
- strip_
sql bool - Whether to remove literal values from a SQL query.
- truncate
Log
Schema Path Truncate - Truncates the string field to a maximum UTF-8 byte length.
- name String
- The protobuf field path, starting with
log. - drop Boolean
- Whether to remove the field from the log.
- encrypt Boolean
- Whether to encrypt the string field.
- encrypt
Sql Boolean - Whether to encrypt literal values in a SQL query.
- strip
Sql Boolean - Whether to remove literal values from a SQL query.
- truncate Property Map
- Truncates the string field to a maximum UTF-8 byte length.
LogSchemaPathTruncate, LogSchemaPathTruncateArgs
- Max
Size intBytes - The maximum field size in bytes.
- Max
Size intBytes - The maximum field size in bytes.
- max_
size_ numberbytes - The maximum field size in bytes.
- max
Size IntegerBytes - The maximum field size in bytes.
- max
Size numberBytes - The maximum field size in bytes.
- max_
size_ intbytes - The maximum field size in bytes.
- max
Size NumberBytes - The maximum field size in bytes.
Package Details
- Repository
- formal formalco/pulumi-formal
- License
- MPL-2.0
- Notes
- This Pulumi package is based on the
formalTerraform Provider.
published on Monday, Sep 21, 2026 by Formal