Skip to content
Skip to main content
Logs, Records & Provider Evidence Technical Explainer

What is an ingestion delay?

An ingestion delay is the interval between an event being created at its source and a receiving platform accepting or processing it. It describes the collection pipeline, not necessarily the timing of the underlying activity.

Delay can arise at several collection stages

A source may buffer records; a collector or message queue may build a backlog; an API may rate-limit requests; or a network, connector or destination may be unavailable. Recovery can deliver many older records together after normal service resumes.

Dashboards ordered by ingestion time can therefore show activity later than it occurred or in a different sequence from source records.

Measuring delay requires two trustworthy clocks

Subtracting source time from ingestion time is meaningful only when both field definitions and clocks are understood. Otherwise, the result combines actual delivery time with clock offset and conversion effects.

Collector health, queue depth, retry and outage records can show whether delay affected one source or the wider platform. A common increase across sources may indicate a central bottleneck; an isolated pattern may point to local buffering or connectivity.

Preserve source and ingestion values rather than silently replacing one with the other. State which layer supports any timing conclusion.

The point to remember

Ingestion delay measures movement through a collection pipeline only when the endpoint timestamps and their clocks are reliable.

Reference: LOG-068Logs, Records & Provider Evidence