Monitoring integration

Send BusinessProxy events into your SOC workflow

Security teams need events where they already investigate incidents. BusinessProxy can deliver signed event notifications and provide stable mappings for SIEM collectors without pretending to be the SIEM.

V1 is signed HTTPS export with deterministic Syslog/CEF adapter mapping. Native syslog transport, OpenTelemetry and vendor-certified marketplace connectors are not included in V1.

Signed webhook deliveryAccess and deny eventsRouting and egress contextSyslog JSON / CEF mapping

SOC workflow

Events feed the SOC tools you already use

Access review should not depend on an administrator opening the dashboard. Event export gives SOC tooling the data needed for correlation, alerting and incident timelines.

Who opened what

Private app launches, denied attempts and session context become machine-readable events.

Where traffic exited

Routing and region context helps explain why a work domain used a specific egress path.

Collector-friendly mapping

Syslog JSON and CEF mappings let teams feed existing collectors without waiting for a marketplace app.

Delivery contract

Signed, bounded and auditable

Event export should be treated as a security integration: signed payloads, replay-safe timestamps, sanitized fields and explicit retry/failure behavior.

  • Payloads are signed for receiver verification.
  • Sensitive tokens and raw secrets are not exported.
  • Retries are bounded; after the retry budget the delivery is marked failed.

Current boundary

Integration feed, not UEBA or SOAR

BusinessProxy exports the signals; the customer SIEM, SOAR or data lake performs advanced analytics and response orchestration. Response APIs are planned separately and are not a completed SOAR platform.

  • Vendor-certified SIEM connectors are not included in V1.
  • Native syslog and OpenTelemetry transport are not included in V1.
  • Built-in UEBA and SOAR are not part of the product.

Next step

Review the rollout details before turning it on

The documentation page shows what to configure, how to verify the setup and which operational boundaries to review before rollout.