security_event.v1 records
from Forge to your security data platform. Configure destinations in the
SIEM and exports section of Settings → Integrations.
Destinations
Amazon S3
Write partitioned JSONL objects to S3 or compatible storage.
Splunk
Deliver events through the Splunk HTTP Event Collector.
Exported events
Filters can limit delivery by category, minimum severity, source, product,
identity, or endpoint. Detail policies control whether exports contain metadata,
indexed summaries, retained-body references, or available inline content.
Prompt and tool detail is included only when both the source and your privacy
policy permit it.
Set up a destination
- Open Settings → Integrations, then select an export provider.
- Create a destination and enter its connection settings.
- Choose event filters and the permitted detail level.
- Send a test event and verify it at the destination.
- Keep the destination active to begin continuous delivery.