> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cotool.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Cotool Log Ingest

> Collect security logs, inspect ingestion health, and search your data in Cotool.

Cotool Log Ingest is the data collection layer of Cotool's SIEM. It brings logs from supported integrations into Cotool Logs so you can search events and run detections against them.

## From source to investigation

1. Connect an integration in [Integrations](https://app.cotool.ai/platform/integrations) and enable the log streams you need.
2. Check that those streams are ingesting successfully.
3. Explore the resulting tables in [Log Search](https://app.cotool.ai/platform/logs).
4. Use the [Detections Platform](https://app.cotool.ai/detections/overview) to evaluate activity on a schedule and create alerts for triage.

Connecting an integration and enabling log ingestion are separate actions. A connected tool can be available to agents without its logs being collected into Cotool Logs.

## Where to start

Open [Integrations](https://app.cotool.ai/platform/integrations), then select a source to configure its **Log Ingest** settings. Open the [Cotool Logs](https://app.cotool.ai/platform/log-ingest) card in the integrations catalog to view ingestion health across sources. Use [Log Search](https://app.cotool.ai/platform/logs) in the main navigation to query collected events.

Available streams and setup requirements vary by integration. Some sources are polled through an API; others require you to configure delivery from the provider to a Cotool endpoint. Use the setup instructions shown on the integration page for your source.

If you want Cotool to proactively notify your team when ingestion health changes, configure shared destinations in [Settings > Notifications](/settings/notifications).

<CardGroup cols={2}>
  <Card title="Connect log sources" href="/log-ingest/connect-sources" icon="plug">
    Enable streams and verify your first ingestion.
  </Card>

  <Card title="Monitor ingestion" href="/log-ingest/monitoring" icon="heart-pulse">
    Interpret stream health, freshness, and table inventory.
  </Card>

  <Card title="Search logs" href="/log-ingest/search" icon="magnifying-glass">
    Inspect schemas and query collected events.
  </Card>

  <Card title="Detections Platform" href="/detections-platform/overview" icon="shield">
    Turn source data into scheduled detections and alerts.
  </Card>
</CardGroup>
