> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Export Logs to Your Storage

> Continuously mirror newly ingested Cotool logs into object storage you control.

Logging sinks continuously copy newly ingested Cotool logs into object storage you own. Use them when you want long-term retention outside Cotool, a lakehouse feed for downstream analytics, or a copy of selected security data in your own cloud environment.

Open [Platform > Log Ingest](https://app.cotool.ai/platform/log-ingest) to view existing sinks or create a new one.

## Before you begin

* A logging sink only exports logs that Cotool ingests after the sink is created. It does not backfill historical data.
* The source you want to export must already be connected and ingesting into Cotool Logs.
* You need a destination bucket or container that Cotool can write to.

## What you can export

### Destinations

Cotool can write to:

* Amazon S3
* Google Cloud Storage
* Azure Blob Storage
* S3-compatible storage such as Cloudflare R2, MinIO, Wasabi, or Backblaze B2

### Sources

For each sink, choose either:

* **All sources** to export every supported log source in the workspace
* **Selected sources** to export only the integrations or named sources you choose

Source detail pages also show which logging sinks export that source.

### Output formats

Choose one of these output styles:

| Output | Best for | Notes |
| - | - | - |
| **Normalized** | Lakehouse analytics, typed schemas, downstream pipelines | Exports typed columns by dataset. You can choose **Parquet** or **JSON Lines**. Records that fail normalization stay in Cotool and are counted on the sink, but are not written to normalized output. |
| **Raw** | Archival copies, reprocessing, preserving the original source payload | Exports each record exactly as the source sent it. Raw output is written as gzipped **JSON Lines** and includes records that failed normalization. |

## Create a logging sink

<Steps>
  <Step title="Choose a destination">
    In **Platform > Log Ingest**, select **New sink**. Name the sink, then choose where Cotool should write the exported files and the prefix to use inside that bucket or container.
  </Step>

  <Step title="Choose or create a connection">
    Select the credentials Cotool should use for writes.

    If you already use **AWS S3 + SQS**, **GCP Pub/Sub**, or **Azure Event Hub** for log ingest, you can often reuse that cloud connection instead of creating a new one. Otherwise, create a dedicated sink connection for the destination.
  </Step>

  <Step title="Pick sources and output">
    Choose all sources or only selected sources, then choose **Normalized** or
    **Raw** output. The setup flow previews the example object path and a sample
    record before you activate the sink.
  </Step>

  <Step title="Run the write test">
    Cotool writes a small test object under the destination prefix to confirm
    that the connection can write to the destination. If the test fails, fix the
    permissions or destination details before activating the sink.
  </Step>

  <Step title="Activate the sink">
    After the write test passes, activate the sink. Newly ingested logs that match the selected sources are then mirrored to your storage automatically.
  </Step>
</Steps>

## Understand sink health

Each sink shows its current delivery state:

| State | What it means |
| - | - |
| **Waiting for logs** | No new matching logs have been ingested since the sink was created. |
| **Healthy** | Cotool is delivering new matching batches successfully. |
| **Retrying** | Cotool hit a temporary delivery problem and is retrying with backoff. |
| **Failing** | Delivery has continued to fail and needs attention. |
| **Paused** | Delivery is intentionally paused. New matching logs are held temporarily instead of being dropped immediately. |

If a batch cannot be delivered before its hold window expires, Cotool records it as a **gap**. Gaps remain searchable in Cotool, but they are missing from that destination.

## What happens when you pause, edit, or delete a sink

### Pause

Pausing a sink stops new writes to the destination. Matching logs are held for a limited time so they can still be delivered if you resume quickly. If they wait too long, they become gaps.

### Edit

Edits apply going forward. Newly ingested logs use the new settings after you save. Batches already queued for delivery continue with the configuration they were staged with.

If you change the destination or write credentials, Cotool requires a fresh write test before the sink can stay active.

### Delete

Deleting a sink stops future exports and drops batches that were not yet delivered. Objects already written to your bucket or container are not deleted.

## Troubleshoot common issues

* **Access denied**: confirm that the selected connection still has permission to write to the destination.
* **Bucket or container not found**: verify the destination name, region, endpoint, or container path.
* **Write test fails after changing settings**: rerun the test after correcting the destination or connection details.
* **No files appear yet**: confirm the selected sources are actively ingesting, and remember that sinks export only logs ingested after the sink was created.

## Related guides

<CardGroup cols={2}>
  <Card title="Connect log sources" href="/log-ingest/connect-sources" icon="plug">
    Enable and verify the sources a sink can export.
  </Card>

  <Card title="Monitor ingestion" href="/log-ingest/monitoring" icon="heart-pulse">
    Check whether the sources feeding your sink are healthy.
  </Card>

  <Card title="Search logs" href="/log-ingest/search" icon="magnifying-glass">
    Validate that the data you want to export is present in Cotool Logs.
  </Card>

  <Card title="Integrations overview" href="/integrations/overview" icon="grid-2">
    See which integrations support managed log ingest.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.