Telemetry
The Telemetry page is where you manage the events your log shippers send to Huntbase. Each telemetry ingest key is one source. The page answers "is my data arriving?" without a query, and it's where you create, configure and revoke the keys themselves.
Open Telemetry from the sidebar, below Endpoints. The page has four tabs:
| Tab | What it's for |
|---|---|
| Overview | How every source is doing, what's wrong, and how to fix it. |
| Sources | One row per ingest key: create, configure, revoke, and copy shipper config. |
| Destinations | The Huntbase data lake, where your sources send, and whether queries read each lake of your own. |
| Browse | The raw events, filtered by clicking. See Browse telemetry. |
The header has Browse and New ingest key. Each tab has its own address
(/telemetry, /telemetry/sources, /telemetry/destinations,
/telemetry/browse), so you can link straight to one.
This feature is currently rolling out and may not be enabled for your organization.
If your scope can't list ingest keys, each tab shows the Send telemetry to Huntbase card instead, with a Request access button that fills in the details support needs to turn ingest on.
Overview
The Overview refreshes on its own every 30 seconds while it's open.
The numbers at the top
| Tile | What it shows |
|---|---|
| Events, last hour | Events accepted across every source in your scope, and the rate per minute. |
| Sources receiving | How many sources are Receiving out of the total, and how many are quiet or rejecting. All receiving means nothing needs attention. |
| Rejected at ingest | The share of records refused in the last hour, and the source rejecting the largest share. |
| Ingest lag, p95 | How long after an event's own timestamp Huntbase received it, for the slowest 5% of events, with the Median. |
The tiles and the Sources table read from the same counts, so they always agree.
Issues and Fix
Below the tiles, one row appears for each problem, worst first:
| Issue | Means | Actions |
|---|---|---|
| Quiet | The source was sending and has stopped. Data is missing now. | Fix, View last events |
| Rejecting | The source is sending, but more than 1% of what it sent in the last hour was refused. | Fix, View events |
| Excluded | Queries skip a lake of your own, so its data is missing from results. There's one row per lake, with the reason. | Fix in Connections |
| Never seen | The key was created at least 15 minutes ago and no event has arrived yet. | Fix, View events |
View events opens Telemetry › Browse on that source for the last hour. View last events opens the last 24 hours, since a quiet source's last events are older.
Fix opens Fix source in a side sheet. It starts with what the counts show. For example, whether the key is still being used even though nothing is accepted, or which rejection reasons came up most, such as Invalid JSON, Too large, Unsupported encoding, Empty body, Rate limited or Store unavailable. Then:
- Check the host can reach Huntbase (a copyable command).
- Check the shipper is running and its output still matches the generated config. For a rejecting source, check it sends JSON or NDJSON, under 10 MB a request.
- Send a test event and watch it arrive with Open live tail.
Fix in Connections opens the lake's connection page. A lake of your own is a connection, so it's fixed there: retry provisioning from the trail if its schema sync hasn't finished or has failed, or turn the connection back on if it's inactive. See When provisioning fails.
Events per hour
A stacked bar chart of the events accepted in each of the last 24 hours, split by source Category, with Uncategorised last. Hover a bar for the hour's total and each category's share. The total for the 24 hours is under the chart.
By category
How many active sources you have in each Category (Identity, Endpoint, Network, Cloud, Email, Other, or Uncategorised) and how many of them are reporting, for example 3 of 4. A receiving or rejecting source is reporting; a quiet or never-seen one isn't. Set a source's category in its settings. All sources opens the Sources tab.
Source statuses
Huntbase works out each source's status from what it accepted and rejected. The first rule that matches wins:
| Status | Rule |
|---|---|
| Revoked | The key has been revoked. |
| Never seen | No event has ever been accepted on the key. A key that authenticated but only sent things that were refused is still never seen. |
| Quiet | No event has been accepted for longer than the source's quiet threshold (30 minutes unless you change it). The chip says for how long, for example Quiet 48 min. |
| Rejecting | More than 1% of the records received in the last hour were rejected. The chip gives the share, for example Rejecting 3.8%. |
| Receiving | None of the above. |
The same chip appears in Browse's source picker.
An accepted event that doesn't match any format Huntbase recognizes is still stored as it was sent, and you can browse it. It isn't counted as rejected and doesn't affect the status.
Next steps
- Sources — create a key, configure your shipper, and manage each source
- Destinations — the Huntbase data lake, and whether queries read each lake of your own
- Browse telemetry — filter shipped events by clicking
- Data lake — bring your own Iceberg store, and what the ingest endpoint accepts