> ## Documentation Index
> Fetch the complete documentation index at: https://docs.wirespeed.co/llms.txt
> Use this file to discover all available pages before exploring further.

# Forwarder Data Usage

> Read the Data usage charts for a log forwarder and troubleshoot the errors they report

The **Data usage** tab on an integration shows what its [log forwarder](/integrations/log-forwarders) received from your sources, what it turned away, and how much data reached Wirespeed. Use it to confirm a source is connected and to find out why logs are missing.

To open it, navigate to Integrations, open an integration that receives logs through a forwarder, such as [Generic Syslog](/integrations/generic-syslog), and select the **Data usage** tab.

<Info>
  The forwarder samples its metrics and sends them to Wirespeed in batches, so recent activity can take a few minutes to appear.
</Info>

## Summary cards

| Card | What it means |
| - | - |
| **Events Forwarded** | Events the forwarder accepted from your sources |
| **Total Data Volume** | Total data ingested from this integration in the selected date range, matching the [Data Volume (Bytes)](#data-volume) chart |
| **HTTP Success Rate** | Share of HTTP and HTTPS requests that succeeded. Shows `-` for TCP and UDP forwarders, or when there were no requests. |
| **Events Refused** | Events the forwarder dropped because they were throttled or rejected. See [Errors](#errors). |
| **Errors** | Other problems in the [Errors](#errors) chart, such as unreadable data and connection errors |
| **Last Reported** | When the forwarder last reported receiving data |

HTTP error responses are not counted in **Events Refused** or **Errors**. They appear in the [HTTP Status](#http-status) chart.

## No data or inactivity banner

If the forwarder has not received any data in a while, a banner appears at the top of the tab. A source that has gone quiet looks the same as a forwarder that is down, so start with the source:

1. Confirm the source is on and configured to send logs
2. Compare the destination address, port, and protocol on the source with **Forwarder Details**
3. Check that the source's TLS setting matches **TLS: Enabled** or **TLS: Disabled** in **Forwarder Details**. For TLS, see [Syslog over TLS](/integrations/log-forwarders#syslog-over-tls)
4. Confirm your firewalls allow traffic from the source to the forwarder

## Errors

This chart shows events and connections the forwarder could not accept, one series per cause. An empty chart is healthy.

| Series | What it means | What to check |
| - | - | - |
| **Throttled** | The source sent events faster than the forwarder allows | Reduce what the source sends, for example by turning off verbose or debug logging, or split high-volume sources across [multiple forwarders](/integrations/log-forwarders#when-do-i-need-multiple-forwarders) |
| **Rejected** | Syslog events were not in the expected format | Set the source to standard syslog output and confirm it is sending to this integration's port |
| **Invalid JSON** | The listener expected JSON and received something else | Check the source's output format or payload template |
| **Invalid compressed body** | A compressed HTTP request could not be decompressed | Check the sender's compression settings, or turn compression off |
| **Malformed framing** | Incoming data could not be split into messages | Check the source's message format and separator settings |
| **TCP frame failed** | A message on a TCP listener could not be read | Check the source's framing, encoding, and TLS settings |
| **TLS handshake failed** | A source could not establish a TLS connection | Match the source's TLS setting to **Forwarder Details** and make sure the device trusts the certificate. See [Syslog over TLS](/integrations/log-forwarders#syslog-over-tls) |
| **Connection rejected** | An HTTP or HTTPS connection failed before the request was handled | Check for proxies or firewalls interrupting connections, and the sender's timeout |

<Note>
  Forwarders are reachable from the internet, so automated scanners sometimes connect to them. This can show up as **Rejected**, **TCP frame failed**, or **TLS handshake failed**. These usually appear in short bursts, are harmless, and do not mean anything is wrong with your sender. You can ignore an occasional burst, but investigate if the errors continue over a longer period or your events stop showing up.
</Note>

## HTTP Status

This chart applies to integrations that receive logs over HTTP or HTTPS. It shows the responses the forwarder sent, by status code.

* **2xx** responses are healthy
* **4xx** responses mean the request was refused. Check the sender's address, credentials, and payload format against the integration's setup instructions
* **5xx** responses are usually temporary. Make sure the sender retries, and contact support if they persist

## Data Volume

The **Data Volume (Bytes)** chart shows how much data Wirespeed ingested from this integration. A sudden spike usually means a new source or a change in logging on an existing one, such as debug logging being turned on.

## Need more help?

If you need additional assistance, reach out to Wirespeed support. Include the integration name, the date range, and the chart you are looking at.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.