View how much data is ingested in using ingestion summary
The ingestion summary page provides a summary of container ingestion over time and currently scheduled periodic ingestions. Use the Ingestion Summary page to get a broad view of how much data is coming into and how that amount is trending over time.
Perform the following steps to view ingestion summary details:
- From the Home menu, select Administration.
- Select System Health > Ingestion Summary.
The Ingestion Summary table shows a line chart with the total number of successful and failed container ingestions across all Data Sources and ingestion methods. Use the drop-down list to change the time range of the chart. You can select one of the following time ranges:
- Last 24 hours
- Last 7 days
- Last 30 days
The Scheduled Ingestion table lets you track the configuration of all Data Sources that currently have scheduled polling enabled:
- Time shows the date and time when that Data Source was last set to enable scheduled polling.
- Interval shows how often that Data Source is scheduled to poll.
- Container shows the label that will be applied to containers ingested from that Data Source.
- Asset shows the name of the Data Source asset.
- App shows the name of the Data Source app.
- Action shows the name of the action that will be used to ingest data.
Monitor the health of your system | View ingested container statistics using Ingestion Status |
This documentation applies to the following versions of Splunk® SOAR (On-premises): 5.0.1
Feedback submitted, thanks!