Skip to content

SIEM And Observability Egress

MeshGuard exports tenant-scoped audit, decision, metric, and trace data to the customer's security and observability stack.

Connector Targets

TargetModeNotes
SplunkHECMap to Splunk CIM and OCSF.
Microsoft SentinelLog Analytics ingestionKeep MeshGuard neutral while supporting Microsoft SOC workflows.
DatadogLogs and Cloud SIEMEmit audit events plus p99 and decision-rate metrics.
Elastic/OpenSearchBulk HTTPPreserve event IDs for deduplication.
OTLPLogs, metrics, tracesPreferred vendor-neutral observability path.
S3/GCS/Azure BlobArchiveCustomer-managed keys and retention policies.
Generic webhookHMAC-signed JSONDefault integration for unsupported destinations.

OCSF Mapping

MeshGuard fieldOCSF field
tenant_idmetadata.tenant_uid
source_typeclass_name
actor.idactor.user.uid or actor.process.uid
actor.spiffe_idactor.process.uid_alt
actionactivity_name
decisiondisposition
policy_versionpolicy.uid
trace_idtrace.uid
request_idmetadata.uid

Delivery Semantics

  • At-least-once delivery.
  • Per-destination dedup tokens.
  • Dead-letter queue visible in the operator console.
  • Disk buffering when a destination is slow.
  • Connector credentials encrypted with customer-controlled keys where available.

Governance Control Plane for AI Agents