Use cases

What teams typically do with PortX first, and which pages get them there.

What you will do: pick the use case closest to yours and follow its path through the documentation.

Cut observability and SIEM cost

Send only what dashboards and detections need to the premium platform, and keep the rest in low-cost storage with replay. Path: Collect → Reduce → Destinations.

One pipeline, many destinations

Route the same stream to observability, SIEM, object storage and Kafka at once, each in the format it expects (JSON, CEF, CSV). Path: Control and route → Formats.

Migrate between platforms

Point PortX at the old and the new platform in parallel, compare, then switch the policy. No source needs to change. Path: Control and route.

Protect sensitive data before it leaves

Mask, encrypt or tokenize fields in motion so that vendors and shared platforms never see raw secrets. Path: Secure → Data handling.

Collect from Kubernetes and OpenShift

Gather pod logs and cluster events without a separate agent per platform, tag them by namespace and team, and route per team. Path: Kubernetes (Helm) → Collect.

Self-service for application teams

Let teams add their own sources and routes within limits set by the platform team. Path: Control and route → Users and roles (under Administration, once you sign in).

Keep a full-fidelity archive with replay

Archive everything with checksums, then replay a time range into any destination for an investigation or audit. Path: Reduce → Data handling.

Next: XpoLog