Security event export
Delphi can export security-relevant audit and access events from the SigNoz stack so operators can ingest them into an external SIEM or monitoring system (for example Dynatrace).
What is exported
Security and access events recorded by the platform (failed logins, lockouts, privileged role changes, and related audit actions) are available in SigNoz. The export path fans those events out through the SigNoz / collector configuration on the observability host.
Exact destination credentials and routing are deployment-specific — configure the external sink in your environment after the platform collector pipeline is enabled.
Operator checklist
- Confirm SigNoz monitoring is healthy and receiving audit / access events.
- Enable the security-event export collector / fan-out configuration shipped with the SigNoz service.
- Provide destination credentials (API tokens, endpoints) for the external system.
- Verify a test failed-login or role-change event appears both in SigNoz and in the external sink.
Related surfaces
| Surface | Use |
|---|---|
| Access logs | Super Admin UI for authentication and role-management events |
| SigNoz monitoring | Investigate raw logs, traces, and dashboards |
| PII redaction | Controls what PII leaves the collector |