Otel Ottl

dash0hq/agent-skills/skills/otel-ottl

by dash0hq51a0324eb0c991f66fe9c5987799f4246ec1db44No licenseListed Oct 9, 2026Updated Oct 9, 2026

OpenTelemetry Transformation Language (OTTL) expert. Use when writing or debugging OTTL expressions for any OpenTelemetry Collector component that supports OTTL (processors, connectors, receivers, exporters). Triggers on tasks involving telemetry transformation, filtering, attribute manipulation, data redaction, sampling policies, routing, or Collector configuration. Covers syntax, contexts, functions, error handling, and performance.

Instructions onlyDevOps & Cloud
AI-generated overview

Reference for writing and debugging OpenTelemetry Transformation Language (OTTL) expressions in Collector configurations.

What it does
This skill provides guidance on the OpenTelemetry Transformation Language (OTTL) used by OpenTelemetry Collector components. It covers syntax, path expressions, contexts, enumerations, operators, converters and editors, conditional statements, nil checks, error handling modes, and performance tips. It also points to companion rule files on components, functions, patterns, redaction, cardinality, and enrichment, and outlines a validation workflow using otelcol validate and the debug exporter.
When to use it
Use it when writing or debugging OTTL expressions for Collector processors, connectors, receivers, or exporters. It fits tasks such as telemetry transformation, filtering, attribute manipulation, data redaction, sampling policies, routing, and Collector configuration.
Requirements
Instructions only; no scripts are shipped. Working with the examples assumes an OpenTelemetry Collector installation (for example the otelcol validate command) and a Collector configuration file; no credentials are specified.

OpenTelemetry Transformation Language (OTTL)

Components that use OTTL

OTTL is not limited to the transform and filter processors. Processors (transform, filter, attributes, span, tailsampling, cumulativetodelta, logdedup, lookup), connectors (routing, count, sum, signaltometrics), and the hostmetrics receiver all accept OTTL expressions. See components for the full list with use cases.

OTTL syntax

Path expressions

Navigate telemetry data using dot notation:

span.namespan.attributes["http.method"]resource.attributes["service.name"]

Contexts (first path segment): resource, scope, span, spanevent, metric, datapoint, log.

Enumerations

Use int64 constants for enumeration fields:

span.status.code == STATUS_CODE_ERRORspan.kind == SPAN_KIND_SERVER

Operators

Assignment: = — Comparison: ==, !=, >, <, >=, <= — Logical: and, or, not

Functions

Converters (uppercase, return values):

ToUpperCase(span.attributes["http.request.method"])Substring(log.body.string, 0, 1024)Concat(["prefix", span.attributes["request.id"]], "-")IsMatch(metric.name, "^k8s\\..*$")

Editors (lowercase, modify data in-place):

set(span.attributes["region"], "us-east-1")delete_key(resource.attributes, "internal.key")limit(log.attributes, 10, [])

See function-reference for the full list of editors and converters.

Conditional statements

Use where to apply transformations conditionally:

<!-- eval:skip -->
span.attributes["db.statement"] = "REDACTED" where resource.attributes["service.name"] == "accounting"

Nil checks

Use nil for absence checking (not null):

resource.attributes["service.name"] != nil

Validation workflow

  1. Validate config syntax — run otelcol validate --config=config.yaml to catch compilation errors before starting the Collector.
  2. Test with the debug exporter — route transformed telemetry to a debug exporter and inspect the output:
yaml
exporters:  debug:    verbosity: detailed
service:  pipelines:    traces:      receivers: [otlp]      processors: [transform]      exporters: [debug]   # swap in production exporter once validated
  1. Set error_mode: ignore in production — see Error handling.
  2. Promote to production exporters — replace debug with the production exporter.

Common patterns

<!-- keep-in-sync: each entry must match a ## heading in ./rules/patterns.md -->
  • Set attributes
  • Drop telemetry by pattern
  • Drop stale data
  • Backfill missing timestamps
  • Filter processor example
  • Transform processor example
  • Defensive nil checks
  • Redact sensitive data — strategies: replace, mask, hash, delete, and drop.
  • Normalize high-cardinality attributes — path segments, IP masking, and attribute count/length limits.
  • Enrich telemetry with static attributes

Error handling

Compilation errors

Occur during processor initialization and prevent Collector startup:

  • Invalid syntax (missing quotes)
  • Unknown functions
  • Invalid path expressions
  • Type mismatches

Runtime errors

Occur during telemetry processing:

  • Accessing non-existent attributes
  • Type conversion failures
  • Function execution errors

Error mode configuration

Set error_mode explicitly for clarity; ignore is the default.

ModeBehaviorWhen to use
ignore (default)Logs the error and continues to the next statementProduction and general use — the default for the transform and filter processors
propagateReturns the error up the pipeline, dropping the payload from the CollectorDevelopment and strict environments where you want to catch every error
silentIgnores errors without loggingHigh-volume pipelines with known-safe transforms where error logs are noise
yaml
processors:  transform:    error_mode: ignore    trace_statements:      - set(span.attributes["parsed"], ParseJSON(span.attributes["json_body"]))

Statements are a flat list; the Collector infers the context (span, metric, datapoint, log, and so on) from the path prefixes. Use the object form with an explicit context: only when a statement group mixes paths that cannot be inferred to a single context, or when you need a group-level condition or error_mode.

Performance

Use where clauses to skip items early.

# BAD — runs replace_pattern on every spanreplace_pattern(span.attributes["url.path"], "/\\d+", "/{id}")
# GOOD — skips spans that lack the attributereplace_pattern(span.attributes["url.path"], "/\\d+", "/{id}") where span.attributes["url.path"] != nil

References

Source and attribution

Source:dash0hq/agent-skillsinskills/otel-ottlat commit51a0324

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal