The Cloud Secure Edge (CSE) Command Center retains events for 14 days. Organizations that need events for compliance, incident investigation, or long-term analysis should export them continuously to a system they control.
Every export option in this section reads from the same Events API. The API returns events as JSON, supports filtering by time window and severity, and pages through large result sets so that each event is retrieved exactly once.
| Method | Best for | Guide |
|---|---|---|
| Filebeat and the ELK Stack | Organizations that already run Elasticsearch and Kibana. Filebeat polls the API, tracks its own position, and indexes events directly. | Forward CSE Events to the ELK Stack |
| Your own script | Any other SIEM (for example Splunk, Microsoft Sentinel, or QRadar), object storage, or a data lake. A scheduled script pulls new events and writes them wherever your pipeline expects them. | Retrieve Events with the API |
| Python library and CLI | One-off pulls and ad hoc investigation from a terminal. | Python Library and CLI |
ReadOnly scope. See Authentication with API Key and API Key Privilege Levels.created_at timestamp of the newest event you have already received, and ask the API only for events after it on the next poll.id. Every event carries a unique id. Deduplicating on it in your destination system is an inexpensive safety net.