Log Ingest

The Log Ingest dashboard shows how much data your sensors are sending to Investigator each day. Use it to monitor your daily ingest volume against your licensed allocation and to identify which log types are contributing the most data.

To access Log Ingest, click the Settings icon in the left navigation, then click Platform Monitoring. The page opens to the Log Ingest tab by default.

Overview

The top of the page shows two summary metrics:

  • Today’s Ingest — The total volume ingested so far today, shown as GB used against your daily allocation (for example, “1.29 GB of 200 GB used”). A progress bar provides a visual indicator of where you are relative to your limit.

  • 7-day Average — Your rolling seven-day average daily ingest volume, with the percentage change compared to the prior week.

Your daily allocation is based on your licensed sensor throughput. For details, see Data ingest limits.

Daily Log Ingest Volume chart

The chart shows your daily ingest volume as a stacked bar chart, with each bar representing one day and each color segment representing a log type. The chart displays up to 14 days of data.

An orange line across the chart marks your daily license limit.

Log type filter

Above the chart, a row of colored chips shows the top five log types by volume: CONN, Suricata_stats, Suricata_corelight, DNS, HTTP, and an Other group. Click a chip to toggle that log type on or off in the chart. When one or more log types are toggled off, a Reset button appears to restore the full view.

Click the Other dropdown to see the individual log types grouped within it, each with its volume. Examples include Files, SSH, Weird, Ecat_arp_info, SSL, Tunnel, Telnet, Dce_rpc, Known_remotes, Ldap_search, Notice, NTP, SSDP, and X509. The list varies by environment and is scrollable when it contains many log types. Click any log type in the dropdown to add it as a chip in the filter row; it will appear highlighted to indicate it is selected from the Other group. You can select multiple types from the dropdown independently.

Hovering over the chart

  • Hover over a colored bar segment to see the log type name and its volume for that day.

  • Hover over the empty space above the bars to see a full breakdown of all log types for that day, including each log type’s color, individual GB values, the total, and your license limit.

Empty state

If no data has been ingested yet, the summary metrics show “0 GB of [your allocation] GB used” and a dash for the 7-day average. The chart area displays a “No data available yet” message.

Error state

If ingest data cannot be loaded, an “Ingest data failed to load” banner appears with a Refresh to try again link. The summary metric cards and chart each display an “Unable to load ingest data” message. Click Refresh to try again to retry.

Usage guidance banner

An information banner appears above the chart showing what percentage of customers ingest under your license limit per day, along with suggestions for reducing your data volume without losing visibility or threat coverage — including reviewing your tap deployment, verifying packet broker configurations, and using default Investigator export configurations.

See also

Ingest Optimization Guide

Recommendations for reducing your daily ingest volume without losing security coverage.