View ingested container statistics using Ingestion Status
Use the Ingestion Status page to see high-level statistics about ingested containers.
To view ingestion status details, perform the following steps:
- From the Main Menu, select Administration.
- Select System Health > Ingestion Status.
The Ingestion Stats table shows one row for each unique combination of ingestion status, container label, asset, and action. These rows allow you to get a better sense of how many containers are being ingested through each ingestion mechanism. Some containers don't come from an asset because they are manually added by a user, which results in a row with an action such as "User add container".
The Ingestion Errors table lists any failed ingestions. Use the information in the start time, end time, asset, app, and action fields to start debugging the failure.
View how much data is ingested in Splunk Phantom using ingestion summary
Configure the logging levels for Splunk Phantom daemons
This documentation applies to the following versions of Splunk® Phantom: 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7