> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Monitor Log Ingestion

> Understand stream status, ingestion progress, and the data available to search.

Open [Integrations > Cotool Logs](https://app.cotool.ai/platform/log-ingest) to see the Log Ingest overview. Select a source to open its integration page and inspect individual streams.

## Stream health

A source's summary badge reflects its most severe stream state. Inspect the individual streams to identify which one needs attention.

| Status | Who acts | What it means |
| - | - | - |
| Healthy | — | Collection is meeting the source's health criteria. Check event-time progress for the period you need. |
| Backfilling | — | Collection is advancing but still behind, such as the initial backfill after enabling a stream or a catch-up after a gap. It finishes on its own. |
| Recovering | — | A recent run did not complete cleanly (attempts erroring while retries remain, a skipped run, or a run that hit its time limit after making progress). It recovers on its own, or becomes Stalled or Failing. |
| Waiting | — | Collection has not yet made its first progress, the warehouse is still being provisioned, or a push endpoint is inside its setup grace period. |
| Degraded | Cotool | Logs are missing or late: a run was truncated by the provider, late-arriving events are not being re-read, push deliveries arrive but are not indexing, or the backlog is not shrinking. |
| Stalled | Depends | No progress within the source's freshness window. For push sources this includes an endpoint that never received a delivery, or a provider that stopped sending; check the provider-side setup. |
| Failing | Depends | A run exhausted its retries. An authentication error means reconnecting the integration; otherwise Cotool is notified. |
| No access | You | The provider refuses Cotool access to the stream: the credential is missing or unusable, the tenant lacks the license a log type requires, or the consent lacks a permission the stream reads with. |

Each stream's details say who needs to act and what to do.

## Notifications

In [Platform > Notifications](https://app.cotool.ai/platform/notifications), the **Log ingest** tab sends a notification to the destinations you choose when a stream enters one of the states you select: **No access**, **Degraded**, **Stalled**, or **Failing**. All four are selected by default. Recovering, backfilling, and waiting streams never notify. See [Notifications](/settings/notifications) for the full settings workflow.

Every notification states who needs to act. When a provider truncates a run, the notification names the time window whose events were not ingested; a later run does not re-read that window. A stream that keeps flipping in and out of a state, or keeps truncating run after run, notifies once rather than on every change; it notifies again after three hours out of that state.

## Read the timestamps

**Ingested through** is the event-time boundary up to which logs have been durably ingested. **Last success** is when an ingestion run succeeded. A recent success does not necessarily mean the newest provider events are already available.

Where supported, **Reconciled through** shows how far Cotool has re-read older time ranges to collect late-arriving events. It can lag behind the main ingestion boundary.

**Oldest event** indicates the oldest event still retained. It does not promise that every event between that timestamp and now is present, or that every source has the same retention period.

## Inspect tables and volume

The overview includes stream health, indexed event counts, and table inventory. Select a table to inspect column names, types, and comments before writing a query.

Table inventory is refreshed separately from the status view. A dash or an initially missing table can mean the inventory has not measured the source yet. **Indexed (recent runs)** totals the indexed-event counts of the runs listed under Recent runs. That list holds only the most recent runs, so this is not a count for a fixed time window.

## Troubleshoot missing events

1. Confirm the required stream is enabled and its credentials have the necessary permissions.
2. For push sources, verify that the provider is sending to the current Cotool endpoint.
3. Inspect **Last run**, including errors, skipped reasons, or truncation. A truncated run means the provider capped pagination before the window was drained.
4. Compare the ingestion and reconciliation boundaries with the event time you are looking for.
5. In [Log Search](https://app.cotool.ai/platform/logs), confirm the table, timestamp column, and query filters.

If collection continues to fail, provide support with the source, stream, relevant timestamps, and displayed error. Do not include ingest tokens.

[Back to Cotool Log Ingest](/log-ingest/overview)
