Reduce

Cut the data volume that reaches expensive destinations by 50–70 % while keeping a full-fidelity copy you can replay.

What you will do: reduce what you send to an expensive destination without losing the ability to get the full data back.

Most telemetry is stored at a premium price and never read. PortX separates the two: send the reduced, useful subset to the observability or SIEM platform, and keep everything in low-cost storage. Customers typically cut the volume reaching downstream systems by 50–70 %.

How reduction works

  • Smart filtering drops noise: health checks, debug chatter, duplicate events, or anything a rule or sample says you do not need live.
  • Transformations trim events: remove verbose fields, shorten payloads, convert to a compact format.
  • Full fidelity in low-cost storage keeps the original events in the archive/cold tier, so reduction is never a loss.
  • Replay on demand sends archived events back through a policy when you need them — an investigation, an audit, a destination that was down.

Steps

  1. Measure first. On the policy page, note events in and bytes out per destination for a normal day.
  2. Add filters for the largest categories of noise. Preview shows how much each rule removes.
  3. Add transformations for fields that add bytes but no value at the destination.
  4. Route the unfiltered stream to the archive destination in parallel:
Archive destination: <placeholder>
  1. Enable the policy and compare bytes out against the measurement from step 1.

Replay

  1. Open the archive and pick a time range and stream.
  2. Choose the policy or destination to replay into.
  3. Start the replay. Replayed events are marked so they can be told apart from live data.

What to watch

  • Reduction changes what alerts see. Keep the fields your rules depend on.
  • Licensing for PortX is by streams and daily volume; reduction lowers what you pay downstream, not what PortX collects. See How licensing works.

Next: Secure

Verify with XPLG engineering before publishing.