Skip to content

Routing

Routes connect a pipeline to one or more emitters. A route can add a second condition after pipeline matching, allowing the same normalized event to be delivered differently by status, action or severity.

routes:
  - name: frontdoor-http-errors
    pipeline: azure_frontdoor
    condition: 'http_status_code >= 400'
    emitters: [sentinel-dcr]

  - name: frontdoor-archive
    pipeline: azure_frontdoor
    condition: 'true'
    emitters: [archive-jsonl]

Semantics

  • pipeline selects the normalized event shape.
  • condition is evaluated against the transformed event.
  • emitters names must exist in the top-level emitters list.
  • Multiple matching routes can intentionally fan out one event to multiple destinations.
  • A catch-all route uses true and should be placed deliberately because it can archive events already sent to a security destination.

Use distinct route names for operations and metrics. Keep routing conditions simple enough to audit during an incident; move complicated normalization into the pipeline transform stage.