Exporting the record
Every decision an agent met is recorded on the machine. Here is how to get it out.
A signed bundle for an auditor
bash
memnox timeline --since 30d --export bundle --out audit-september.jsonThe bundle is signed and carries a hash over every event, so nobody can edit it afterwards without it showing. It states the period it covers and names anything it left out.
JSON for a script
bash
memnox timeline --export jsonl > actions.jsonl # one action a line
memnox timeline --export json --only deny # only what was stopped
memnox timeline --agent cursor --since 7d --export jsonlMost commands also take --json:
bash
memnox why --json
memnox report --since 1d --json
memnox approvals --jsonA summary for a person
bash
memnox report --since 7d # what agents did, what failed, what was redoneSpend shows only what an agent reported. Memnox never guesses a cost.
Streaming to your SIEM
On a team, every decision from every machine, the gateway and cloud agents can stream to Splunk, Datadog, S3 or Kafka. Each stream is listed under Settings, where an admin can pause or remove it.
What is never in the record
The arguments of a call, file contents and secret values. A fingerprint of the arguments is kept instead, so two identical calls can still be matched.
How long it is kept
bash
memnox config set retentionDays 90 # keep three months
memnox purge # drop what is older now