Skip to content

SIEM And Observability Egress ​

MeshGuard exports tenant-scoped audit, decision, metric, and trace data to the customer's security and observability stack.

Connector Targets ​

TargetModeNotes
SplunkHECMap to Splunk CIM and OCSF.
Microsoft SentinelLog Analytics ingestionKeep MeshGuard neutral while supporting Microsoft SOC workflows.
DatadogLogs and Cloud SIEMEmit audit events plus p99 and decision-rate metrics.
Elastic/OpenSearchBulk HTTPPreserve event IDs for deduplication.
OTLPLogs, metrics, tracesPreferred vendor-neutral observability path.
S3/GCS/Azure BlobArchiveCustomer-managed keys and retention policies.
Generic webhookHMAC-signed JSONDefault integration for unsupported destinations.

OCSF Mapping ​

MeshGuard fieldOCSF field
tenant_idmetadata.tenant_uid
source_typeclass_name
actor.idactor.user.uid or actor.process.uid
actor.spiffe_idactor.process.uid_alt
actionactivity_name
decisiondisposition
policy_versionpolicy.uid
trace_idtrace.uid
request_idmetadata.uid

Delivery Semantics ​

  • At-least-once delivery.
  • Per-destination dedup tokens.
  • Dead-letter queue visible in the operator console.
  • Disk buffering when a destination is slow.
  • Connector credentials encrypted with customer-controlled keys where available.

Governance Control Plane for AI Agents