Destinations are the external systems that receive forwarded events. A destination is a target — a local JSON file, an HTTP/HTTPS endpoint, or a syslog server — that policies and routes point at.

/home/artica/auditd-events.jsonl). Ideal for a local Filebeat/Fluent Bit shipper or quick verification.json, rfc5424 or rfc5424_json).local_jsonl), Address + Port (for syslog), or URL (for HTTP).
Each row has a Test button that sends a synthetic event and reports success or the exact error (DNS failure, connection refused, TLS handshake problem, HTTP status). Use it to validate connectivity before you enable forwarding — a misconfigured destination will otherwise fill the dead-letter queue.