Skip to main content
Logging sinks continuously copy newly ingested Cotool logs into object storage you own. Use them when you want long-term retention outside Cotool, a lakehouse feed for downstream analytics, or a copy of selected security data in your own cloud environment. Open Platform > Log Ingest to view existing sinks or create a new one.

Before you begin

  • A logging sink only exports logs that Cotool ingests after the sink is created. It does not backfill historical data.
  • The source you want to export must already be connected and ingesting into Cotool Logs.
  • You need a destination bucket or container that Cotool can write to.

What you can export

Destinations

Cotool can write to:
  • Amazon S3
  • Google Cloud Storage
  • Azure Blob Storage
  • S3-compatible storage such as Cloudflare R2, MinIO, Wasabi, or Backblaze B2

Sources

For each sink, choose either:
  • All sources to export every supported log source in the workspace
  • Selected sources to export only the integrations or named sources you choose
Source detail pages also show which logging sinks export that source.

Output formats

Choose one of these output styles:

Create a logging sink

1

Choose a destination

In Platform > Log Ingest, select New sink. Name the sink, then choose where Cotool should write the exported files and the prefix to use inside that bucket or container.
2

Choose or create a connection

Select the credentials Cotool should use for writes.If you already use AWS S3 + SQS, GCP Pub/Sub, or Azure Event Hub for log ingest, you can often reuse that cloud connection instead of creating a new one. Otherwise, create a dedicated sink connection for the destination.
3

Pick sources and output

Choose all sources or only selected sources, then choose Normalized or Raw output. The setup flow previews the example object path and a sample record before you activate the sink.
4

Run the write test

Cotool writes a small test object under the destination prefix to confirm that the connection can write to the destination. If the test fails, fix the permissions or destination details before activating the sink.
5

Activate the sink

After the write test passes, activate the sink. Newly ingested logs that match the selected sources are then mirrored to your storage automatically.

Understand sink health

Each sink shows its current delivery state: If a batch cannot be delivered before its hold window expires, Cotool records it as a gap. Gaps remain searchable in Cotool, but they are missing from that destination.

What happens when you pause, edit, or delete a sink

Pause

Pausing a sink stops new writes to the destination. Matching logs are held for a limited time so they can still be delivered if you resume quickly. If they wait too long, they become gaps.

Edit

Edits apply going forward. Newly ingested logs use the new settings after you save. Batches already queued for delivery continue with the configuration they were staged with. If you change the destination or write credentials, Cotool requires a fresh write test before the sink can stay active.

Delete

Deleting a sink stops future exports and drops batches that were not yet delivered. Objects already written to your bucket or container are not deleted.

Troubleshoot common issues

  • Access denied: confirm that the selected connection still has permission to write to the destination.
  • Bucket or container not found: verify the destination name, region, endpoint, or container path.
  • Write test fails after changing settings: rerun the test after correcting the destination or connection details.
  • No files appear yet: confirm the selected sources are actively ingesting, and remember that sinks export only logs ingested after the sink was created.

Connect log sources

Enable and verify the sources a sink can export.

Monitor ingestion

Check whether the sources feeding your sink are healthy.

Search logs

Validate that the data you want to export is present in Cotool Logs.

Integrations overview

See which integrations support managed log ingest.