Stream health
A source’s summary badge reflects its most severe stream state. Inspect the individual streams to identify which one needs attention.
Each stream’s details say who needs to act and what to do.
Notifications
In Platform > Notifications, the Log ingest tab sends a notification to the destinations you choose when a stream enters one of the states you select: No access, Degraded, Stalled, or Failing. All four are selected by default. Recovering, backfilling, and waiting streams never notify. See Notifications for the full settings workflow. Every notification states who needs to act. When a provider truncates a run, the notification names the time window whose events were not ingested; a later run does not re-read that window. A stream that keeps flipping in and out of a state, or keeps truncating run after run, notifies once rather than on every change; it notifies again after three hours out of that state.Read the timestamps
Ingested through is the event-time boundary up to which logs have been durably ingested. Last success is when an ingestion run succeeded. A recent success does not necessarily mean the newest provider events are already available. Where supported, Reconciled through shows how far Cotool has re-read older time ranges to collect late-arriving events. It can lag behind the main ingestion boundary. Oldest event indicates the oldest event still retained. It does not promise that every event between that timestamp and now is present, or that every source has the same retention period.Inspect tables and volume
The overview includes stream health, indexed event counts, and table inventory. Select a table to inspect column names, types, and comments before writing a query. Table inventory is refreshed separately from the status view. A dash or an initially missing table can mean the inventory has not measured the source yet. Indexed (recent runs) totals the indexed-event counts of the runs listed under Recent runs. That list holds only the most recent runs, so this is not a count for a fixed time window.Troubleshoot missing events
- Confirm the required stream is enabled and its credentials have the necessary permissions.
- For push sources, verify that the provider is sending to the current Cotool endpoint.
- Inspect Last run, including errors, skipped reasons, or truncation. A truncated run means the provider capped pagination before the window was drained.
- Compare the ingestion and reconciliation boundaries with the event time you are looking for.
- In Log Search, confirm the table, timestamp column, and query filters.