# Stream events to your SIEM

**SIEM Export** pushes Sentilai events to your security monitoring stack as they happen.

1. Enter the destination host and port, and pick the protocol (`tcp` or `tls`).
2. **Save destination**.
3. **Send test event** and confirm it lands in your SIEM.

Destinations must be publicly resolvable addresses — an internal-only host will be
rejected, since our Gateway has to reach it.

Prefer `tls` unless the destination genuinely cannot terminate it: these events describe
your developers' AI usage and shouldn't cross the internet in the clear.

<!-- shot:siem-export -->
![SIEM Export — the OCSF pull API and the CEF/syslog push destination, with live delivery status.](https://docs.sentilai.com/uploads/images/gallery/2026-08/4Oksiem-export.png)
*SIEM Export — the OCSF pull API and the CEF/syslog push destination, with live delivery status.*