Overview
How sources, destinations and formats fit together across the XPLG products.
What you will do: understand the three kinds of integration and where each is configured.
Three kinds
- Sources are where data comes from: devices sending syslog, applications posting over HTTPS, Kafka topics, Kubernetes and OpenShift clusters, and SaaS or cloud platforms reached through API connectors. See Sources.
- Destinations are where data goes: observability platforms, SIEMs, object storage, Kafka, and search stacks such as ELK and Splunk. See Destinations.
- Formats are the shapes data is converted between on the way: JSON, CEF and CSV, through a no-code UI. See Formats.
Where they live
- PortX owns the full set: it collects from any source, routes to many destinations and converts formats per destination. Most integration work happens in PortX routing policies; see Control and route.
- XpoLog collects from sources directly or receives streams from PortX, and sends alerts out to notification destinations.
- LogX and Audity work on data already collected, and deliver reports and alerts to notification destinations.
- Flux moves files between sites and can feed a source or a destination at either end.
Configure once, reuse
A destination is defined once with its address, credentials and format, then referenced by any number of policies. Changing the destination changes every policy that uses it, which is the point: a platform migration is one edit.
Credentials
Credentials for sources and destinations are stored in the product and referenced by name in policies. Who may create or change them is governed by the roles described under Administration, which appears once you sign in.
Checking an integration
Every source and destination shows its state and recent throughput. A destination that is down keeps its events in the persistent queue until it recovers; see Reduce for replay from the archive when the queue is not enough.
Next: Sources