A data ingestion alert identifies disruption in the data ingestion pipeline. For example, a data source is not sending logs, or there is a significant drop in log collection compared to the calculated ingestion baseline.
Identify the error: Alert Type = Ingestion.
Right-click and select Investigate in XQL query.
The Query Builder opens and runs a prefilled query to display related data ingestion metrics entries.
Review the query results.
The results provide context to the alert and the events leading up to it. For more information about data ingestion metrics and setting up correlation rules with your own data ingestion logic, see Monitoring Data Ingestion Health.
Investigate data collector errors. Return to the Health Alerts page, right-click the alert and select → .
Depending on the type of collector in error, the relevant data collector settings page opens, filtered by data collector.