Scenario / Evaluation model
Illustrative deployment scenario
One-Way Security Log Export
An illustrative evaluation model in which system and security events are exported one way from the Source Zone for use by centralized logging and analytics environments in the Destination Zone.
This content is only for identifying source, hardware-enforced one-way boundary, and destination conditions.

Scenario context image; not a record of a product deployment.
Photo: BalticServers data centerAuthor: BalticServers.comLicense: CC BY-SA 3.0Source:Wikimedia Commons
Source → boundary → destination
Complete Data Path
Source / Source Zone
Source Zone systems and data
- Sources
- Network devices and hosts, Security control equipment
- Data
- Syslog system events, Security and audit records
Hardware-enforced boundary
Hardware-enforced one-way boundary
Source Modulesource-to-destination one-way fiber data transferReceiving ModuleWithin the listed hardware version, topology, and test scope, the Source Module receives event data from defined sources and sends it across the specified physical one-way link as source-to-destination one-way fiber data transfer; the Receiving Module then receives the data and provides a Syslog stream that destination systems can ingest.
Destination / Destination Zone
Destination Zone systems and uses
- Destinations
- SIEM, SOC and centralized logging systems
- Use
- For event aggregation, review, correlation analysis, and audit retention in the Destination Zone.
Evaluation inputs
Evaluation Considerations
- 01
Inventory the in-scope devices, hosts, and event formats.
- 02
Confirm event volume, data freshness, and acceptable loss conditions.
- 03
Confirm how the destination SIEM or logging system will receive and parse the data.
