Skip to main content
Cotool Log Ingest is the data collection layer of Cotool’s SIEM. It brings logs from supported integrations into Cotool Logs so you can search events and run detections against them.

From source to investigation

  1. Connect an integration in Integrations and enable the log streams you need.
  2. Check that those streams are ingesting successfully.
  3. Explore the resulting tables in Log Search.
  4. Use the Detections Platform to evaluate activity on a schedule and create alerts for triage.
Connecting an integration and enabling log ingestion are separate actions. A connected tool can be available to agents without its logs being collected into Cotool Logs.

Where to start

Open Integrations, then select a source to configure its Log Ingest settings. Open the Cotool Logs card in the integrations catalog to view ingestion health across sources. Use Log Search in the main navigation to query collected events. Available streams and setup requirements vary by integration. Some sources are polled through an API; others require you to configure delivery from the provider to a Cotool endpoint. Use the setup instructions shown on the integration page for your source. If you want Cotool to proactively notify your team when ingestion health changes, configure shared destinations in Settings > Notifications.

Connect log sources

Enable streams and verify your first ingestion.

Monitor ingestion

Interpret stream health, freshness, and table inventory.

Search logs

Inspect schemas and query collected events.

Detections Platform

Turn source data into scheduled detections and alerts.