Log Ingest¶
The Log Ingest dashboard shows how much data your sensors are sending to Investigator each day. Use it to monitor your daily ingest volume against your licensed allocation and to identify which log types are contributing the most data.
To access Log Ingest, click the Settings icon in the left navigation, then click Platform Monitoring. The page opens to the Log Ingest tab by default.
Overview¶
The top of the page shows two summary metrics:
Today’s Ingest — The total volume ingested so far today, shown as GB used against your daily allocation (for example, “1.29 GB of 200 GB used”). A progress bar provides a visual indicator of where you are relative to your limit.
7-day Average — Your rolling seven-day average daily ingest volume, with the percentage change compared to the prior week.
Your daily allocation is based on your licensed sensor throughput. For details, see Data ingest limits.
Daily Log Ingest Volume chart¶
The chart shows your daily ingest volume as a stacked bar chart, with each bar representing one day and each color segment representing a log type. The chart displays up to 14 days of data.
An orange line across the chart marks your daily license limit.
Log type filter
Above the chart, a row of colored chips shows the top five log types by volume: CONN, Suricata_stats, Suricata_corelight, DNS, HTTP, and an Other group. Click a chip to toggle that log type on or off in the chart. When one or more log types are toggled off, a Reset button appears to restore the full view.
Click the Other dropdown to see the individual log types grouped within it, each with its volume. Examples include Files, SSH, Weird, Ecat_arp_info, SSL, Tunnel, Telnet, Dce_rpc, Known_remotes, Ldap_search, Notice, NTP, SSDP, and X509. The list varies by environment and is scrollable when it contains many log types. Click any log type in the dropdown to add it as a chip in the filter row; it will appear highlighted to indicate it is selected from the Other group. You can select multiple types from the dropdown independently.
Hovering over the chart
Hover over a colored bar segment to see the log type name and its volume for that day.
Hover over the empty space above the bars to see a full breakdown of all log types for that day, including each log type’s color, individual GB values, the total, and your license limit.
Empty state¶
If no data has been ingested yet, the summary metrics show “0 GB of [your allocation] GB used” and a dash for the 7-day average. The chart area displays a “No data available yet” message.
Error state¶
If ingest data cannot be loaded, an “Ingest data failed to load” banner appears with a Refresh to try again link. The summary metric cards and chart each display an “Unable to load ingest data” message. Click Refresh to try again to retry.