Before you begin
- A logging sink only exports logs that Cotool ingests after the sink is created. It does not backfill historical data.
- The source you want to export must already be connected and ingesting into Cotool Logs.
- You need a destination bucket or container that Cotool can write to.
What you can export
Destinations
Cotool can write to:- Amazon S3
- Google Cloud Storage
- Azure Blob Storage
- S3-compatible storage such as Cloudflare R2, MinIO, Wasabi, or Backblaze B2
Sources
For each sink, choose either:- All sources to export every supported log source in the workspace
- Selected sources to export only the integrations or named sources you choose
Output formats
Choose one of these output styles:Create a logging sink
1
Choose a destination
In Platform > Log Ingest, select New sink. Name the sink, then choose where Cotool should write the exported files and the prefix to use inside that bucket or container.
2
Choose or create a connection
Select the credentials Cotool should use for writes.If you already use AWS S3 + SQS, GCP Pub/Sub, or Azure Event Hub for log ingest, you can often reuse that cloud connection instead of creating a new one. Otherwise, create a dedicated sink connection for the destination.
3
Pick sources and output
Choose all sources or only selected sources, then choose Normalized or
Raw output. The setup flow previews the example object path and a sample
record before you activate the sink.
4
Run the write test
Cotool writes a small test object under the destination prefix to confirm
that the connection can write to the destination. If the test fails, fix the
permissions or destination details before activating the sink.
5
Activate the sink
After the write test passes, activate the sink. Newly ingested logs that match the selected sources are then mirrored to your storage automatically.
Understand sink health
Each sink shows its current delivery state:
If a batch cannot be delivered before its hold window expires, Cotool records it as a gap. Gaps remain searchable in Cotool, but they are missing from that destination.
What happens when you pause, edit, or delete a sink
Pause
Pausing a sink stops new writes to the destination. Matching logs are held for a limited time so they can still be delivered if you resume quickly. If they wait too long, they become gaps.Edit
Edits apply going forward. Newly ingested logs use the new settings after you save. Batches already queued for delivery continue with the configuration they were staged with. If you change the destination or write credentials, Cotool requires a fresh write test before the sink can stay active.Delete
Deleting a sink stops future exports and drops batches that were not yet delivered. Objects already written to your bucket or container are not deleted.Troubleshoot common issues
- Access denied: confirm that the selected connection still has permission to write to the destination.
- Bucket or container not found: verify the destination name, region, endpoint, or container path.
- Write test fails after changing settings: rerun the test after correcting the destination or connection details.
- No files appear yet: confirm the selected sources are actively ingesting, and remember that sinks export only logs ingested after the sink was created.
Related guides
Connect log sources
Enable and verify the sources a sink can export.
Monitor ingestion
Check whether the sources feeding your sink are healthy.
Search logs
Validate that the data you want to export is present in Cotool Logs.
Integrations overview
See which integrations support managed log ingest.