Destinations

Deliver to observability platforms, SIEMs, object storage, Kafka, ELK and Splunk.

What you will do: define a destination once and route streams to it in the format it expects.

A destination is an address, a credential, a format and delivery settings. Policies reference it by name. PortX routes one stream to any number of destinations at the same time.

Destination types

  • Observability platforms — metrics, logs and traces back-ends that accept HTTP ingestion. Typical format: JSON.
  • SIEM — security platforms that expect normalised events. Typical format: CEF; JSON where the SIEM accepts it.
  • Object storage — S3-compatible buckets and cloud blob storage for the archive/cold tier. Typical format: JSON or CSV, compressed, in time-partitioned objects.
  • Kafka — produce to a topic for downstream consumers. Format as the consumers expect.
  • ELK and Splunk — index into an Elasticsearch or OpenSearch stack, or send to Splunk through its ingestion endpoint.
Supported destinations: <placeholder>

Steps: add a destination

  1. In the PortX console, open destinations and choose Add destination:
Console path: <placeholder>
  1. Pick the type, set the address and the credential. Credentials are stored once and referenced by name.
  2. Choose the output format: JSON, CEF or CSV. The no-code mapping UI shows how fields land; see Formats.
  3. Set delivery options: batch size, compression, retry policy, and whether to use the persistent queue when the destination is unavailable.
  4. Send a test event and confirm it arrives at the destination.
  5. Reference the destination in a routing policy; see Control and route.

Multi-destination routing

Route the full stream to object storage and the reduced stream to the SIEM in one policy. Each destination gets its own filters, transformations and format, so the archive stays complete while the premium platform gets only what it needs.

When a destination is down

Events wait in the persistent queue and are delivered in order when the destination recovers. If the queue fills, the archive keeps the full copy and replay on demand fills the gap later.

Next: Formats

Verify with XPLG engineering before publishing.