XPLG - Main capabilities and product modules
The XPLG platform is delivered as integrated components - Flux, PortX, XpoLog, and LogX - each with a clear role in the telemetry path from collection to insight. Together they cover movement, stream control and routing, search and operations, and advanced analytics; the sections below spell out what each module does and the core capabilities you should expect.
Flux - high-speed data movement and synchronization
Role: Move and align telemetry reliably and at scale between origins, the XPLG pipeline, and downstream consumers so ingestion keeps pace with burst traffic and distributed topologies.
Core capabilities (typical):
High-throughput collection / forwarding - sustained and bursty log and event streams with controlled backpressure.
Synchronization & delivery semantics - dependable handoff into the processing path (ordering, retries, and durability as configured for your deployment).
Edge and hub patterns - support for agent-based and agentless paths, remote sites, and consolidated hubs without forcing a single choke point.
Operational fit - tuning for latency vs. throughput where the product exposes controls (buffers, batching, parallel paths-per edition and guide).
Where it sits: Flux is the mobility layer: getting data to PortX/XpoLog and out to partners (e.g. forwarding chains) when architected that way in your environment.
PortX - stream control, parsing, enrichment, and routing
Role: Own the live stream on the way in (and selectively on the way out): accept connections, normalize payloads, enrich when applicable, and route events to the right logical destination (index partition, template, forwarder target).
Core capabilities (typical):
Stream control - listeners (e.g. syslog, HTTP/S, APIs, agent protocols) with account-level configuration, throttling, and fan-in from many senders.
Parsing at the edge - handlers and mappings that turn raw payloads into log path, log name, host, message, template, and related metadata XpoLog expects.
Enrichment - derive or attach fields (host, source type, tags, geographic or logical grouping) so downstream search and dashboards stay consistent.
Routing - direct streams to the correct templates / folders / applications and to forwarding rules for external SIEM or observability tools.
Protocol handling - transparent handling of listener framing (e.g. stripping or accounting for PortX protocol headers so patterns in XpoLog see clean payloads when handlers are used).
Console mapping: Administrative work for PortX is done in XpoLog Manager (often labeled Manager): adding sources, listener/handler configuration, forwarding, and related data-pipeline settings.
XpoLog - search, monitoring, dashboards, and visualization
Role: Indexed telemetry home - store, search, monitor, and visualize machine data in one web UI with role-appropriate access.
Core capabilities (typical):
Indexing & retention - persistent storage of parsed events with time-range navigation and lifecycle aligned to IT policy.
Search - fast, centralized queries across sources using field-aware and full-text syntax (booleans, wildcards, regex, time bucketing, aggregations-per version).
Parsing in depth - patterns and field types (ftypes) so the same semantic queries work across different vendors and formats.
Dashboards & Apps - live dashboards, marketplace and custom Apps, and reusable widgets tied to saved searches.
Monitoring & alerting - monitors on log content, thresholds, and saved-search conditions; notifications to operations channels.
Log viewer - line-by-line inspection, filtering, and export for audits and tickets.
Console mapping: Search and Apps map primarily to XpoLog; Manager covers administration that includes PortX plus platform settings as shipped in your build.
LogX - AI-driven analytics, anomaly detection, and correlation
Role: Analytical layer on top of indexed data - automatic triage, anomaly surfacing, and cross-source correlation to shorten MTTI/MTTR.
Core capabilities (typical):
AI-assisted analytics - models and assistants that highlight unusual clusters, explanations, or guided next steps (scope per edition).
Anomaly detection - baselines and deviations on volume, errors, rare sequences, or multi-metric behavior.
Correlation - linking events across logs, hosts, apps, or transactions using rules, graphs, or ML-assisted grouping (per product).
Proactive insight - scheduled or continuous scans that reduce manual query load for L1/L2 and shift-left visibility for engineering.
Alerting on analytics - raise incidents when analytical rules or risk scores cross thresholds.