Reduce
Cut the data volume that reaches expensive destinations by 50–70 % while keeping a full-fidelity copy you can replay.
What you will do: reduce what you send to an expensive destination without losing the ability to get the full data back.
Most telemetry is stored at a premium price and never read. PortX separates the two: send the reduced, useful subset to the observability or SIEM platform, and keep everything in low-cost storage. Customers typically cut the volume reaching downstream systems by 50–70 %.
How reduction works
- Smart filtering drops noise: health checks, debug chatter, duplicate events, or anything a rule or sample says you do not need live.
- Transformations trim events: remove verbose fields, shorten payloads, convert to a compact format.
- Full fidelity in low-cost storage keeps the original events in the archive/cold tier, so reduction is never a loss.
- Replay on demand sends archived events back through a policy when you need them — an investigation, an audit, a destination that was down.
Steps
- Measure first. On the policy page, note events in and bytes out per destination for a normal day.
- Add filters for the largest categories of noise. Preview shows how much each rule removes.
- Add transformations for fields that add bytes but no value at the destination.
- Route the unfiltered stream to the archive destination in parallel:
Archive destination: <placeholder>
- Enable the policy and compare bytes out against the measurement from step 1.
Replay
- Open the archive and pick a time range and stream.
- Choose the policy or destination to replay into.
- Start the replay. Replayed events are marked so they can be told apart from live data.
What to watch
- Reduction changes what alerts see. Keep the fields your rules depend on.
- Licensing for PortX is by streams and daily volume; reduction lowers what you pay downstream, not what PortX collects. See How licensing works.
Next: Secure
Verify with XPLG engineering before publishing.