View how much data is ingested in Splunk Phantom using ingestion summary
The ingestion summary page provides a summary of container ingestion over time and currently scheduled periodic ingestions. Use the Ingestion Summary page to get a broad view of how much data is coming into Splunk Phantom and how that amount is trending over time.
Perform the following steps to view ingestion summary details:
- From the Main Menu, select Administration.
- Select System Health > Ingestion Summary.
The Ingestion Summary table shows a line chart with the total number of successful and failed container ingestions across all Data Sources and ingestion methods. Use the drop-down list to change the time range of the chart. You can select one of the following time ranges:
- Last 24 hours
- Last 7 days
- Last 30 days
The Scheduled Ingestion table lets you track the configuration of all Data Sources that currently have scheduled polling enabled:
- Time shows the datetime when that Data Source was last set to enable scheduled polling.
- Interval shows how often that Data Source is scheduled to poll.
- Container shows the label that will be applied to containers ingested from that Data Source.
- Asset shows the name of the Data Source asset.
- App shows the name of the Data Source app.
- Action shows the name of the action that will be used to ingest data.
Monitor the health of your system | View ingested container statistics using Ingestion Status |
This documentation applies to the following versions of Splunk® Phantom (Legacy): 4.8, 4.9, 4.10, 4.10.1, 4.10.2, 4.10.3, 4.10.4, 4.10.6, 4.10.7
Feedback submitted, thanks!