Routing¶
Routes connect a pipeline to one or more emitters. A route can add a second condition after pipeline matching, allowing the same normalized event to be delivered differently by status, action or severity.
routes:
- name: frontdoor-http-errors
pipeline: azure_frontdoor
condition: 'http_status_code >= 400'
emitters: [sentinel-dcr]
- name: frontdoor-archive
pipeline: azure_frontdoor
condition: 'true'
emitters: [archive-jsonl]
Semantics¶
pipelineselects the normalized event shape.conditionis evaluated against the transformed event.emittersnames must exist in the top-levelemitterslist.- Multiple matching routes can intentionally fan out one event to multiple destinations.
- A catch-all route uses
trueand should be placed deliberately because it can archive events already sent to a security destination.
Use distinct route names for operations and metrics. Keep routing conditions simple enough to audit during an incident; move complicated normalization into the pipeline transform stage.