DocsTeamExporting the record

Exporting the record

Every decision an agent met is recorded on the machine. Here is how to get it out.

A signed bundle for an auditor

bash
memnox timeline --since 30d --export bundle --out audit-september.json

The bundle is signed and carries a hash over every event, so nobody can edit it afterwards without it showing. It states the period it covers and names anything it left out.

JSON for a script

bash
memnox timeline --export jsonl > actions.jsonl     # one action a line
memnox timeline --export json --only deny          # only what was stopped
memnox timeline --agent cursor --since 7d --export jsonl

Most commands also take --json:

bash
memnox why --json
memnox report --since 1d --json
memnox approvals --json

A summary for a person

bash
memnox report --since 7d     # what agents did, what failed, what was redone

Spend shows only what an agent reported. Memnox never guesses a cost.

Streaming to your SIEM

On a team, every decision from every machine, the gateway and cloud agents can stream to Splunk, Datadog, S3 or Kafka. Each stream is listed under Settings, where an admin can pause or remove it.

What is never in the record

The arguments of a call, file contents and secret values. A fingerprint of the arguments is kept instead, so two identical calls can still be matched.

How long it is kept

bash
memnox config set retentionDays 90   # keep three months
memnox purge                         # drop what is older now