Skip to main content

Enable a source

  1. Open Integrations and select the source you want to collect from.
  2. Connect the integration and make sure it is enabled.
  3. Find its Log Ingest settings. Complete any additional credential or provider setup shown there.
  4. Choose Enable for each required stream and confirm the change.
  5. Check the stream status and Last run after ingestion begins.
Log ingestion is opt-in per stream. Streams marked as coming soon cannot be enabled. If a stream is blocked, resolve the displayed reason, such as a missing provider permission or ingest credential, before enabling it.

API collection and provider delivery

For API-based sources, Cotool uses the configured credentials to collect logs. A successful integration connection does not guarantee that its credentials have permission to read every log stream. Follow the stream-specific requirements on the integration page. For sources that push events, complete the provider-side configuration with the endpoint and credentials issued by Cotool. Enabling a stream in Cotool alone does not configure the provider to send events. If you replace an endpoint or its credentials, update the provider’s delivery configuration as well. Some integrations support multiple delivery methods. Follow the setup for the selected method rather than configuring an unrelated webhook or token.

Verify collection

Check these signals together:
  • Last success shows when ingestion last succeeded.
  • Ingested through shows the event-time boundary reached by ingestion.
  • Last run reports indexed events, a skipped run, or a failure.
  • The table inventory shows the tables available for the source.
An empty successful run can mean there were no new events. Table counts refresh separately from stream status, so a new source can initially show an unmeasured count. Use monitoring to distinguish delayed inventory from a collection problem.

Pause collection

Use Disable on the individual stream and confirm the change. This controls collection for that stream; it is not a request to delete previously collected logs. Check detections that depend on the stream before pausing it. Next: monitor ingestion or search your logs.