Formats

Convert data to JSON, CEF and CSV per destination with the no-code UI.

What you will do: map a stream's fields to the format a destination expects, without writing code.

Sources rarely produce what destinations want. PortX converts between formats per destination, so one stream can arrive as JSON in observability, CEF in the SIEM and CSV in the archive.

Supported formats

  • JSON — structured objects with the parsed fields; the default for observability platforms, Kafka consumers and most APIs. Choose flat or nested, and which fields to include.
  • CEF — Common Event Format for SIEMs: a fixed header (vendor, product, version, signature, name, severity) plus extension key-value pairs. The mapping UI assigns stream fields to CEF keys.
  • CSV — delimited rows with a chosen column order and header, for archives, spreadsheets and bulk loaders.

Steps: map a format

  1. Open the destination and choose Format:
Console path: <placeholder>
  1. Pick JSON, CEF or CSV.
  2. In the no-code mapping UI, drag or select stream fields into the target fields, columns or CEF keys. Fields can be renamed, combined, cast and given defaults.
  3. Preview on live events from the stream. The preview shows exactly what the destination will receive.
  4. Save. The mapping applies to every policy that routes to this destination.

Reusing mappings

Save a mapping as a template and apply it to other destinations of the same type. A template for a SIEM's expected CEF layout, for instance, is defined once and reused per environment.

Parsing in, formatting out

Parsing (see Collect) produces fields from raw input; formatting produces output from fields. Keep raw copies in the archive so that a mapping mistake can be corrected by replay rather than lost.

Next: API overview and authentication

Verify with XPLG engineering before publishing.