Skip to main content
The Data usage tab on an integration shows what its log forwarder received from your sources, what it turned away, and how much data reached Wirespeed. Use it to confirm a source is connected and to find out why logs are missing. To open it, navigate to Integrations, open an integration that receives logs through a forwarder, such as Generic Syslog, and select the Data usage tab.
The forwarder samples its metrics and sends them to Wirespeed in batches, so recent activity can take a few minutes to appear.

Summary cards

HTTP error responses are not counted in Events Refused or Errors. They appear in the HTTP Status chart.

No data or inactivity banner

If the forwarder has not received any data in a while, a banner appears at the top of the tab. A source that has gone quiet looks the same as a forwarder that is down, so start with the source:
  1. Confirm the source is on and configured to send logs
  2. Compare the destination address, port, and protocol on the source with Forwarder Details
  3. Check that the source’s TLS setting matches TLS: Enabled or TLS: Disabled in Forwarder Details. For TLS, see Syslog over TLS
  4. Confirm your firewalls allow traffic from the source to the forwarder

Errors

This chart shows events and connections the forwarder could not accept, one series per cause. An empty chart is healthy.
Forwarders are reachable from the internet, so automated scanners sometimes connect to them. This can show up as Rejected, TCP frame failed, or TLS handshake failed. These usually appear in short bursts, are harmless, and do not mean anything is wrong with your sender. You can ignore an occasional burst, but investigate if the errors continue over a longer period or your events stop showing up.

HTTP Status

This chart applies to integrations that receive logs over HTTP or HTTPS. It shows the responses the forwarder sent, by status code.
  • 2xx responses are healthy
  • 4xx responses mean the request was refused. Check the sender’s address, credentials, and payload format against the integration’s setup instructions
  • 5xx responses are usually temporary. Make sure the sender retries, and contact support if they persist

Data Volume

The Data Volume (Bytes) chart shows how much data Wirespeed ingested from this integration. A sudden spike usually means a new source or a change in logging on an existing one, such as debug logging being turned on.

Need more help?

If you need additional assistance, reach out to Wirespeed support. Include the integration name, the date range, and the chart you are looking at.