It reports into the tools you already run.
Metrics and logs go to your own collector, and decisions go to your SIEM, so your team watches Swiftward where it already watches everything else.
Built into the Swiftward service you run.
Two streams, two destinations
| What | How | Where |
|---|---|---|
| Metrics and logs | OpenTelemetry: metrics over OTLP gRPC or HTTP, logs over OTLP HTTP; a Prometheus exporter for teams that scrape | your collector |
| A decision a rule sends | syslog, or webhooks for anything else | your SIEM |
Application logs go through OpenTelemetry, so in your own tooling you can link a decision to the rule version behind it and the request that carried it.
Nothing leaves your network to get there
Swiftward sends all of this to systems you own, and nothing to us.