You've landed on the exact phrase that's been in my head for a while: "owning your data pipeline vs renting access." That's the core business model shift.
The Salesforce example is perfect because they were one of the first to perfect it. The Lambda workaround is clever, but I see teams burn so much time maintaining those brittle integration pipelines. When the vendor changes an event field name in an API update, your "hack" breaks silently.
It feels like we're all just rebuilding, poorly and expensively, the data access we used to get for free with a TCP port and a syslog RFC.
Keep it constructive.
The real irony is when they sell that brittle Lambda integration back to you as a premium feature. "Event Bridge Connectors" or "Data Stream Plus". You're not just renting access, you're paying extra for the privilege of building their data export for them.
I tried the Salesforce webhook-to-syslog route last year. The breaking change wasn't even in the API, it was their internal event taxonomy. "LoginFailure" became "UserAuthenticationFailure" in the payload. Our Lambda kept humming along, dropping silently filtered logs for two weeks before we noticed the gap. The simplicity of a TCP socket never gave you that kind of silent failure mode.
prove it to me
You're hitting on the classic friction point. It's not just a trade-off for security, it's a fundamental architectural choice. The portal becomes the single pane of glass they can monetize and control.
Your "navigating dashboards and export rules" feeling is the intended user experience. It pushes you toward their analytics and away from your own. For troubleshooting, this often means you can't ask the ad-hoc questions you need in the moment.
I've seen teams get around this by using the real-time alerting or API to firehose specific high-value events to an internal system. It's never the full stream, but it can restore some of that immediate visibility for critical failures. Just be prepared to maintain that pipeline.
Integrate or die
You're absolutely right. That feeling of navigating portals instead of having a simple, reliable stream is exactly the trade-off.
It's not just iboss, it's the model for most cloud platforms now. The logging complexity gets bundled with the "powerful security features." I've found it helpful to push them hard during the trial. Ask specifically for a syslog feed or a real-time data export API. Their answer, or lack of one, tells you everything about how locked-in you'll be.
Sometimes you can cobble together a partial stream using their real-time alerts, like others mentioned, but it's never the same. You end up missing the quiet, low-priority events that are often the canary in the coal mine.
Docs save time