View how much data is ingested in Splunk SOAR (On-premises) using ingestion summary

The ingestion summary page provides a summary of container and artifact ingestion over time and currently scheduled periodic ingestions. Use the Ingestion Summary page to get a broad view of how much data is coming into Splunk SOAR (On-premises) and how that amount is trending over time.

Perform the following steps to view ingestion summary details:

  1. From the Home menu, select Administration.
  2. Select System Health > Ingestion Summary.

The Ingestion Summary table shows a line chart with the total number of successful and failed artifact and container ingestions across all Data Sources and ingestion methods. Use the drop-down list to change the time range of the chart. You can select one of the following time ranges:

  • Last 24 hours
  • Last 7 days
  • Last 30 days

The Scheduled Ingestion table lets you track the configuration of all Data Sources that currently have scheduled polling enabled:

  • Time shows the date and time when that Data Source was last set to enable scheduled polling.
  • Interval shows how often that Data Source is scheduled to poll.
  • Container shows the label that will be applied to containers ingested from that Data Source.
  • Asset shows the name of the Data Source asset.
  • App shows the name of the Data Source app.
  • Action shows the name of the action that will be used to ingest data.