Skip to main content

Telemetry

The Telemetry page is where you manage the events your log shippers send to Huntbase. Each telemetry ingest key is one source. The page answers "is my data arriving?" without a query, and it's where you create, configure and revoke the keys themselves.

Open Telemetry from the sidebar, below Endpoints. The page has four tabs:

TabWhat it's for
OverviewHow every source is doing, what's wrong, and how to fix it.
SourcesOne row per ingest key: create, configure, revoke, and copy shipper config.
DestinationsThe Huntbase data lake, where your sources send, and whether queries read each lake of your own.
BrowseThe raw events, filtered by clicking. See Browse telemetry.

The header has Browse and New ingest key. Each tab has its own address (/telemetry, /telemetry/sources, /telemetry/destinations, /telemetry/browse), so you can link straight to one.

Beta

This feature is currently rolling out and may not be enabled for your organization.

If your scope can't list ingest keys, each tab shows the Send telemetry to Huntbase card instead, with a Request access button that fills in the details support needs to turn ingest on.

Overview​

The Overview refreshes on its own every 30 seconds while it's open.

The numbers at the top​

TileWhat it shows
Events, last hourEvents accepted across every source in your scope, and the rate per minute.
Sources receivingHow many sources are Receiving out of the total, and how many are quiet or rejecting. All receiving means nothing needs attention.
Rejected at ingestThe share of records refused in the last hour, and the source rejecting the largest share.
Ingest lag, p95How long after an event's own timestamp Huntbase received it, for the slowest 5% of events, with the Median.

The tiles and the Sources table read from the same counts, so they always agree.

Issues and Fix​

Below the tiles, one row appears for each problem, worst first:

IssueMeansActions
QuietThe source was sending and has stopped. Data is missing now.Fix, View last events
RejectingThe source is sending, but more than 1% of what it sent in the last hour was refused.Fix, View events
ExcludedQueries skip a lake of your own, so its data is missing from results. There's one row per lake, with the reason.Fix in Connections
Never seenThe key was created at least 15 minutes ago and no event has arrived yet.Fix, View events

View events opens Telemetry › Browse on that source for the last hour. View last events opens the last 24 hours, since a quiet source's last events are older.

Fix opens Fix source in a side sheet. It starts with what the counts show. For example, whether the key is still being used even though nothing is accepted, or which rejection reasons came up most, such as Invalid JSON, Too large, Unsupported encoding, Empty body, Rate limited or Store unavailable. Then:

  1. Check the host can reach Huntbase (a copyable command).
  2. Check the shipper is running and its output still matches the generated config. For a rejecting source, check it sends JSON or NDJSON, under 10 MB a request.
  3. Send a test event and watch it arrive with Open live tail.

Fix in Connections opens the lake's connection page. A lake of your own is a connection, so it's fixed there: retry provisioning from the trail if its schema sync hasn't finished or has failed, or turn the connection back on if it's inactive. See When provisioning fails.

Events per hour​

A stacked bar chart of the events accepted in each of the last 24 hours, split by source Category, with Uncategorised last. Hover a bar for the hour's total and each category's share. The total for the 24 hours is under the chart.

By category​

How many active sources you have in each Category (Identity, Endpoint, Network, Cloud, Email, Other, or Uncategorised) and how many of them are reporting, for example 3 of 4. A receiving or rejecting source is reporting; a quiet or never-seen one isn't. Set a source's category in its settings. All sources opens the Sources tab.

Source statuses​

Huntbase works out each source's status from what it accepted and rejected. The first rule that matches wins:

StatusRule
RevokedThe key has been revoked.
Never seenNo event has ever been accepted on the key. A key that authenticated but only sent things that were refused is still never seen.
QuietNo event has been accepted for longer than the source's quiet threshold (30 minutes unless you change it). The chip says for how long, for example Quiet 48 min.
RejectingMore than 1% of the records received in the last hour were rejected. The chip gives the share, for example Rejecting 3.8%.
ReceivingNone of the above.

The same chip appears in Browse's source picker.

Unclassified events aren't rejections

An accepted event that doesn't match any format Huntbase recognizes is still stored as it was sent, and you can browse it. It isn't counted as rejected and doesn't affect the status.

Next steps​

  • Sources — create a key, configure your shipper, and manage each source
  • Destinations — the Huntbase data lake, and whether queries read each lake of your own
  • Browse telemetry — filter shipped events by clicking
  • Data lake — bring your own Iceberg store, and what the ingest endpoint accepts