Sources
Telemetry › Sources lists every telemetry ingest key in your scope, one row per key. It's where you create keys, configure shippers, change a source's settings and revoke it.
Filter the list
The chips above the table narrow it:
| Chip | Shows |
|---|---|
| All | Every key, including revoked ones. |
| Needs attention | The sources the Overview's issues name: quiet, rejecting, or never seen after 15 minutes. |
| Revoked | Revoked keys, kept for audit. |
Each chip shows its count. The chip you pick is kept in the page address, so you can share a link to, say, just the sources that need attention.
The table
Problems come first and revoked keys last.
| Column | Shows |
|---|---|
| Status | The source's status chip. See Source statuses. |
| Source | The source label, with the key prefix beneath. |
| Category | The category you gave the source, or —. |
| Shipper | Fluent Bit, Vector, rsyslog, syslog-ng or Other. Huntbase recognizes these from what the shipper sends; it's blank until the first request. |
| Per minute, 24h | A sparkline of the last 24 hours and the current rate per minute. |
| Last event | When the last event was accepted, or Never. |
View events opens Telemetry › Browse on the source for the last hour. If you can manage ingest keys, ⋯ offers Settings, Shipper config and Revoke.
Under the table, Ingest endpoint unfolds the endpoint for configuring a shipper by hand: the full URL, host, port, path and auth header, what the endpoint accepts, and a command that checks it's reachable. The check needs no key, so you can run it from the machine that will do the shipping first.
New ingest key
Click New ingest key in the page header.
- Name it. Give it a Source label that names the sender, something
like
edge-fluentbit-eu, and optionally a Category. One key per shipper or source means a single noisy or compromised sender can be revoked on its own. Every key sends to the Huntbase data lake: there's no destination to choose. Your own lakes are only read, never sent to. - Copy the token. Click Mint key. The dialog shows the token and ready-to-paste configuration for Fluent Bit, Vector, rsyslog and syslog-ng with the key filled in.
The token is shown once, when you create it. It is stored only as a hash, so it cannot be recovered or shown again. Copy it before you close the dialog. The dialog asks you to confirm if you try to dismiss it without doing so.
Afterwards the key is identified only by its prefix (for example
hbik_3f9a2c1). For what the endpoint accepts and what Huntbase adds to each
event, see Ship logs to Huntbase.
Shipper config
⋯ › Shipper config brings the generated configuration back for an existing source, opening on the shipper it reported. The token is a placeholder, since it can't be shown again: paste the one you stored.
Source settings
⋯ › Settings opens Source settings. The token and owner of a key never change. You can change these:
| Setting | What it does |
|---|---|
| Source label | The name shown everywhere for this source. |
| Category | Identity, Endpoint, Network, Cloud, Email, Other or Not set. Counts the source toward coverage in Pulse and in the Overview's By category. |
| Quiet after (minutes) | How long without an accepted event before the source shows as Quiet. The default is 30. Use a longer threshold for a source that sends in batches, and a shorter one for a firewall. It can be 1 to 10,080 minutes (7 days). |
Revoke a key
⋯ › Revoke, then confirm. Shippers using the key start failing immediately. The row stays listed, marked Revoked, so the history of what existed is preserved. A revoked key can't be turned back on.
If you can't see any sources, that may be because your role can't list ingest keys rather than because none exist.