Skip to main content

Sources

Telemetry › Sources lists every telemetry ingest key in your scope, one row per key. It's where you create keys, configure shippers, change a source's settings and revoke it.

Filter the list​

The chips above the table narrow it:

ChipShows
AllEvery key, including revoked ones.
Needs attentionThe sources the Overview's issues name: quiet, rejecting, or never seen after 15 minutes.
RevokedRevoked keys, kept for audit.

Each chip shows its count. The chip you pick is kept in the page address, so you can share a link to, say, just the sources that need attention.

The table​

Problems come first and revoked keys last.

ColumnShows
StatusThe source's status chip. See Source statuses.
SourceThe source label, with the key prefix beneath.
CategoryThe category you gave the source, or —.
ShipperFluent Bit, Vector, rsyslog, syslog-ng or Other. Huntbase recognizes these from what the shipper sends; it's blank until the first request.
Per minute, 24hA sparkline of the last 24 hours and the current rate per minute.
Last eventWhen the last event was accepted, or Never.

View events opens Telemetry › Browse on the source for the last hour. If you can manage ingest keys, ⋯ offers Settings, Shipper config and Revoke.

Under the table, Ingest endpoint unfolds the endpoint for configuring a shipper by hand: the full URL, host, port, path and auth header, what the endpoint accepts, and a command that checks it's reachable. The check needs no key, so you can run it from the machine that will do the shipping first.

New ingest key​

Click New ingest key in the page header.

  1. Name it. Give it a Source label that names the sender, something like edge-fluentbit-eu, and optionally a Category. One key per shipper or source means a single noisy or compromised sender can be revoked on its own. Every key sends to the Huntbase data lake: there's no destination to choose. Your own lakes are only read, never sent to.
  2. Copy the token. Click Mint key. The dialog shows the token and ready-to-paste configuration for Fluent Bit, Vector, rsyslog and syslog-ng with the key filled in.
warning

The token is shown once, when you create it. It is stored only as a hash, so it cannot be recovered or shown again. Copy it before you close the dialog. The dialog asks you to confirm if you try to dismiss it without doing so.

Afterwards the key is identified only by its prefix (for example hbik_3f9a2c1). For what the endpoint accepts and what Huntbase adds to each event, see Ship logs to Huntbase.

Shipper config​

⋯ › Shipper config brings the generated configuration back for an existing source, opening on the shipper it reported. The token is a placeholder, since it can't be shown again: paste the one you stored.

Source settings​

⋯ › Settings opens Source settings. The token and owner of a key never change. You can change these:

SettingWhat it does
Source labelThe name shown everywhere for this source.
CategoryIdentity, Endpoint, Network, Cloud, Email, Other or Not set. Counts the source toward coverage in Pulse and in the Overview's By category.
Quiet after (minutes)How long without an accepted event before the source shows as Quiet. The default is 30. Use a longer threshold for a source that sends in batches, and a shorter one for a firewall. It can be 1 to 10,080 minutes (7 days).

Revoke a key​

⋯ › Revoke, then confirm. Shippers using the key start failing immediately. The row stays listed, marked Revoked, so the history of what existed is preserved. A revoked key can't be turned back on.

note

If you can't see any sources, that may be because your role can't list ingest keys rather than because none exist.