Control and route

Centralized, policy-based routing with parsing, filtering, transformation, tagging and enrichment on the way.

What you will do: write a routing policy that sends one stream to the right destinations in the right format.

Routing in PortX is centralized and policy-based: a policy says which events from which streams go where, and what happens to them on the way. Policies are managed in one place, so changing a destination does not mean touching every source.

What a policy can do

  • Parse — AI-driven parsing turns raw lines into fields; out-of-the-box parsers cover common formats.
  • Filter — smart filtering keeps or drops events by field, pattern or sampling rule.
  • Transform — rename, reshape, compute and redact fields.
  • Tag and enrich — add tags, lookups and context such as environment, team or asset data.
  • Route to many — send the same stream to several destinations, each in its own format (JSON, CEF, CSV).

Steps: a first policy

  1. In the PortX console, open routing and choose New policy:
Console path: <placeholder>
  1. Select the source stream(s) the policy applies to.
  2. Add a filter if only part of the stream should go on, for example only errors to the alerting platform.
  3. Add transformations and enrichment. Preview shows the result on live events before you save.
  4. Add one or more destinations and the output format for each. Destinations are configured once and reused; see Integrations: Destinations.
  5. Save and enable. The policy page shows events in, events out and events dropped per destination.

Self-service stream management

Teams can own their own streams and policies within the limits an administrator sets, so platform and security teams stop being a bottleneck for every new source or dashboard. Roles are described under Administration, which appears once you sign in.

Persistent queue

When a destination is slow or down, events wait in the persistent queue and are delivered when it recovers. Size the queue for the longest outage you want to ride through; see Sizing and capacity planning.

Next: Reduce

Verify with XPLG engineering before publishing.