Skip to content

Live Tail

Live Tail provides an operational view of events as they move through the Data Plane. It is useful for checking source shape, pipeline selection and masking during a rollout.

Use cases

  • Verify that a new source reaches the expected pipeline.
  • Confirm that sensitive values are masked before emission.
  • Inspect a controlled sample while tuning route conditions.
  • Support incident response without querying the destination SIEM.

Boundaries

Live Tail is not a queue, replay mechanism or compliance archive. It is intentionally ephemeral. Use the JSONL archive emitter, DLQ files and destination metrics for durable evidence.

The metric cards include HTTP request-body bytes attempted, events receiving HTTP 2xx acceptance responses and Splunk HEC events with positive protocol ACKs. These egress counters currently cover generic HTTP JSON, Sentinel DCR and Splunk HEC only. Retries count another body attempt, and successful retry responses can count acceptance again. They are not unique event totals, full wire traffic, durable-delivery guarantees or vendor billing measurements; see Observability for their exact scope.

The embedded UI is served by the application API. Keep the API listener private or place it behind the same authentication and network controls as other administrative endpoints. Never expose profiling endpoints publicly.

Troubleshooting workflow

  1. Check /api/v1/health.
  2. Confirm ingestion metrics on /metrics.
  3. Inspect the event in Live Tail.
  4. Compare the event against the pipeline match and route condition.
  5. Check emitter errors, retries and DLQ growth.