Understand your Ingestion metrics dashboard
This topic describes the elements of the Ingestion metrics page.
The Ingestion metrics dashboard provides the following information. Note that some data may be squashed. For more information about squashing, see About squashing in the Ingest monitoring dashboard.
Element | Description |
---|---|
Data Entities: View by field | Select the types of data you wish to view in the Data Entities: View byfield. You can search by any combination of the following:
|
Metric field |
Select the metrics you'd like to view. Possible options are
|
Data entities with notable ingestion changes panel | Data entities with notable ingestion changes is the count of entities for which we have seen +/- 50% change in volume, or a change in the events count metric, compared to the time range in the compare to dropdown. |
Data entities with no ingestion panel |
Data entities have no ingestion when that entity’s latest index time is before the selected current time range. This can help you identify missing data sources. Note that there is a time lag, which is always 10 minutes unless there are any failed saved searches. See First time data and missing datafor more information. |
First time data entities panel | Data entities are categorized as "First time data entities" when an entity’s first seen time is within the selected current time range. See First time data and missing datafor more information. |
Search field | Enter search criteria you want to use to locate data entities. For example, you can search for an index called "firewall" by adding that as a search term in the Search field. You can search using the names of indexes, source types, sources, or hosts. |
Filter data entities field (Optional) |
(Optional) In Filter data entities, select one of the following:
|
Results table | The data in this table is calculated by joining the data with the "last_index_event_lookup" lookup table and the volume, latency, and event count metrics. This helps identify the records with time stamps that fall outside of the selected time period. The results table shows the following information:
|