Marketplace Architecture
End-to-end event flow from a Noxys-enabled endpoint to Splunk or Elastic dashboards.
Delivery channels
| Channel | Transport | Auth |
|---|---|---|
| Splunk HEC | HTTPS POST /services/collector | HEC token (per-tenant) |
| Elastic Agent | Pull via Elastic Agent | API key (per-tenant) |
| Webhook (fallback) | HTTPS POST | HMAC SHA-256 signature |
Data residency
All events are processed inside the customer's chosen Noxys region (EU-WEST, EU-CENTRAL). Marketplace add-ons are stateless connectors — no Noxys-side data is copied into the customer SIEM beyond what the customer has already ingested.
Retention
Noxys does not enforce retention on the SIEM side. Customers retain full control over index lifecycle, ILM policies, and Splunk frozen-bucket archival.