# SIEM: push over syslog

The push option: Sentilai sends events to your collector as they happen.

## Configuring

**SIEM Export → push:**

- **Enable delivery**
- **Host** and **Port** (6514 by default)
- **Protocol** — TLS encrypted, or TCP plaintext
- **Sender hostname** — how the events identify themselves in your SIEM

**Use TLS.** Plaintext exists for collectors inside a network you already trust; audit
events describing your AI traffic are not something to put on the wire in the clear.

## Restrictions

One destination per organization. Private and internal hostnames are rejected — the
collector must be reachable from Sentilai, so a `10.x` address will not work. Terminate
TLS on something with a public name, or use the pull API from inside your network instead.

## Test it

**Send test event** delivers a `siem_push_test` event. Look for it in your SIEM before
assuming the integration works.

## Delivery status

The panel shows the delivered count, last success, last attempt, and the last error. When
push stops working — an expired certificate, a moved collector — this is where it shows up.
The status badge reads **Active** or **Paused**.

Check it occasionally. Silent failure of an audit pipeline is the failure mode that matters
most and announces itself least.