What is log ingestion?¶
Log ingestion is when a destination platform receives and accepts records for parsing, storage and analysis. It records the data pipeline stage, not necessarily when the underlying activity occurred.
Acceptance may include processing¶
At ingestion a platform can parse, add metadata, reject malformed rows, remove duplicates, queue processing or route data to different stores. A source event may have waited on an endpoint or collector first, and ingestion only proves the destination accepted a purported source record.
Use ingestion to diagnose delivery¶
Preserve source, collector and ingestion timestamps and identify which the dashboard displays. Old source times arriving under one ingestion time can reveal backlog rather than simultaneous events.
Ingestion metadata explains availability, outages and delay but does not validate source clock or event accuracy.
The point to remember
Ingestion time describes platform receipt, so keep it separate from source activity when reconstructing events.