Control and route
Centralized, policy-based routing with parsing, filtering, transformation, tagging and enrichment on the way.
What you will do: write a routing policy that sends one stream to the right destinations in the right format.
Routing in PortX is centralized and policy-based: a policy says which events from which streams go where, and what happens to them on the way. Policies are managed in one place, so changing a destination does not mean touching every source.
What a policy can do
- Parse — AI-driven parsing turns raw lines into fields; out-of-the-box parsers cover common formats.
- Filter — smart filtering keeps or drops events by field, pattern or sampling rule.
- Transform — rename, reshape, compute and redact fields.
- Tag and enrich — add tags, lookups and context such as environment, team or asset data.
- Route to many — send the same stream to several destinations, each in its own format (JSON, CEF, CSV).
Steps: a first policy
- In the PortX console, open routing and choose New policy:
Console path: <placeholder>
- Select the source stream(s) the policy applies to.
- Add a filter if only part of the stream should go on, for example only errors to the alerting platform.
- Add transformations and enrichment. Preview shows the result on live events before you save.
- Add one or more destinations and the output format for each. Destinations are configured once and reused; see Integrations: Destinations.
- Save and enable. The policy page shows events in, events out and events dropped per destination.
Self-service stream management
Teams can own their own streams and policies within the limits an administrator sets, so platform and security teams stop being a bottleneck for every new source or dashboard. Roles are described under Administration, which appears once you sign in.
Persistent queue
When a destination is slow or down, events wait in the persistent queue and are delivered when it recovers. Size the queue for the longest outage you want to ride through; see Sizing and capacity planning.
Next: Reduce
Verify with XPLG engineering before publishing.