Answers which tenants send their security events somewhere other than where this deployment sends them in ONE read, over the WHOLE tenant population.
On this surface a tenant can depart in TWO ways, and an exclusion is one of them. It may ADD a sink of its own, and it may OPT OUT of an inherited deployment destination. Both are divergences and each carries its own binding class — an opt-out under EXCLUDED_<sink>. Reporting an opt-out as conformity would be the quietest possible misreport: the tenant that switched off every inherited destination receives nothing, and it is precisely the tenant an operator asking who has departed most needs to see. A tenant that did both is named under both classes and counted ONCE as a diverging tenant.
An exclusion class reports ACTIVE: the opt-out is in force and there is no external system whose health it could report. The deployment plane is NOT replaced — an exclusion removes one destination for ONE tenant — so deploymentShape is still present when tenants have diverged.
The response is a CLASS-level projection, on both planes. It carries the sink a tenant forwards to — SYSLOG | SPLUNK_HEC | SENTINEL | WEBHOOK — or the sink it excluded, and a server-derived label, and nothing finer. It deliberately omits: the transport configuration and everything inside it (the splunk hec endpoint, the sentinel dcr id, the webhook url, the syslog host and port), the credential reference and its mask, the formatter, the minimum severity, the event-type and key-id filters, and the operator-authored destination name — that column is the one a naive pass-through would leak into label, and every label here comes from a server-side table keyed on the class alone. The same rule binds the DEPLOYMENT destinations.
This surface has no entitlement plane, so notEligibleCount is 0 and notEligibleTenants is empty: forwarding is not Edition-gated and no per-tenant entitlement controller exists for it. The four coverage bands still partition the whole population, so onDefaultCount + divergingCount + notEligibleCount + suspendedCount == tenantCount always holds. A suspended tenant stays INSIDE the denominator, and this read never answers 404 for a tenant that has declared nothing.
surfaceStatus is the server-composed worst-of across both planes (FR-190.21); deploymentStatus and every bindings[*].status are returned unchanged beside it. maxTenantBindings is null — this surface states no per-tenant ceiling. chain is [] — this is not an ordered-chain surface — while deploymentChain carries one position per DISTINCT class the deployment plane holds, as an UNORDERED set: it is [] only when the plane holds exactly one class (which deploymentShape names) or holds nothing. Both keys are PRESENT, which is what makes the six surfaces one envelope.
Takes no path and no query parameter, so no caller-supplied identifier enters a query. It writes nothing: no audit row, no event, no state change. Required: the ROOT platform tenant, holding admin.platform.event-forwarding.manage and admin.tenant.list.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||