Nine of seventeen Apex MSSP tenants are in an error verdict — over half the book. Two failure patterns dominate: SentinelOne agents that won't load (customer-04 ×2, customer-01), and S3-backed feeds (CiscoUmbrella, JudySecurity) returning errors. A second cluster — customer-13, customer-07, customer-10, customer-08 — has integration-misconfigured findings: sources claim integrations that Fluency does not see a matching resource for. No tenant is unreachable; the platform side is healthy.
| Tenant | Verdict | Sources (ok/err/inactive) | 24h bytes | Findings |
|---|---|---|---|---|
| customer-13 · Customer 13 — Materials | error | 9 / 2 / 1 | 12.4 GB | 2 source_error, 5 integration_misconfigured |
| customer-08 · Apex MSSP | error | 8 / 1 / 4 | 55.7 GB | 1 source_error, 5 integration_misconfigured |
| customer-07 · Customer 07 — Recording SaaS | error | 7 / 1 / 1 | 3.4 GB | 1 source_error, 4 integration_misconfigured |
| customer-04 · Customer 04 — Cloud Telecom | error | 5 / 2 / 2 | 313 MB | 2 source_error (SentinelOne) |
| customer-10 · Customer 10 — Maritime Auth. | error | 5 / 0 / 2 | 23.9 GB | 2 integration_misconfigured |
| customer-02 · Customer 02 — Retail Pharmacy | error | 2 / 1 / 1 | 18.2 GB | 1 source_error (BehaviorSummary) |
| customer-11 · O&L | error | 4 / 1 / 1 | 86.4 GB | 1 source_error (FluencyCollector) |
| customer-01 · Customer 01 — Retail Holdings | error | 7 / 1 / 0 | 21.7 GB | 1 source_error (SentinelOne) |
| customer-16 · Customer 16 — Partner MSP | error | 5 / 1 / 3 | 146 MB | 1 source_error (DefenderATP) |
| customer-06 · Customer 06 — Insurance | ok | 7 / 0 / 2 | 93.1 GB | — |
| customer-12 · Customer 12 — Industrial Tech | ok | 5 / 0 / 1 | 6.8 GB | — |
| customer-14 · Customer 14 — Research | ok | 4 / 0 / 2 | 15.4 GB | — |
| customer-03 · Customer 03 — Manufacturing | ok | 7 / 0 / 2 | 8.4 GB | — |
| customer-17 · Customer 17 — IT Services | ok | 4 / 0 / 0 | 8.7 GB | — |
| customer-05 · Customer 05 — Public Sector B | ok | 7 / 0 / 2 | 2.8 GB | — |
| customer-15 · Customer 15 — Identity Svc | ok | 4 / 0 / 0 | 2.3 GB | — |
| customer-09 · Customer 09 — Public Sector A | ok | 7 / 0 / 3 | 2.1 GB | — |
Inactive sources are quiet — not a finding. Inactive ≠ broken; without time-comparison data the platform can't distinguish "always quiet" from "stopped working." Resource fetchers (BlackKite, Office365, SentinelOne) verified via freshness probe, not throughput.
Total 24h ingest across the connector: 361.8 GB. Top tenants by volume:
| Tenant | 24h bytes_passed | Top source |
|---|---|---|
| customer-06 | 93.1 GB | SyslogEndpoint (46.5 GB) |
| customer-11 | 86.4 GB | FluencyCollector (43.2 GB) |
| customer-08 | 55.7 GB | LocalSyslog (27.8 GB) |
| customer-10 | 23.9 GB | FluencyCollector (11.9 GB) |
| customer-01 | 21.7 GB | LocalSyslog (10.8 GB) |
| customer-02 | 18.2 GB | SyslogEndpoint (9.1 GB) |
| customer-14 | 15.4 GB | LocalSyslog (7.7 GB) |
| customer-13 | 12.4 GB | LocalSyslog (6.2 GB) |
Ten source-level errors across the book. Each below is a configured source that is failing or producing no events.
Sixteen integration_misconfigured findings across four tenants. Each is a source claiming an integration (e.g. Office365) but Fluency's get_system_config reports no matching resource — typically the integration was renamed, removed, or never finished discovery handshake.
| Tenant | Integrations with no matching resource |
|---|---|
| customer-13 | AzureAudit, BlackKite, Falcon, Office365, Office365ResourceWatch |
| customer-08 | AzureAudit, BlackKite, Office365, Office365ResourceWatch, SentinelOne |
| customer-07 | AzureAudit, AzureEventHubs, Office365, Office365ResourceWatch |
| customer-10 | BlackKite, Falcon |
Note: customer-13, customer-08, and customer-07 are still ingesting from these sources (Office365, AzureAudit are in their top-5 by bytes). The misconfiguration is in the integration cross-reference, not in data flow — Fluency is receiving the events but the integration registry doesn't have a matching resource record for downstream correlation.
Seven errorStates_noise alerts suppressed across the connector — all are Office365 "failed to get access token" events occurring on sources that are passing data normally (OAuth token-refresh hiccups, not outages). Suppressed per verdict precedence rule 3.
What the SOC currently cannot see, derived from §4 errors and known-stopped sources.
| Tenant | Configured integrations | Resource freshness |
|---|---|---|
| customer-04 | Office365, Office365ResourceWatch, SentinelOne | O365 fresh (4h 56m); SentinelOne no_index |
| customer-12 | BlackKite | BlackKite fresh (1h 08m) |
| customer-06 | BlackKite, DefenderATP, Office365, O365ResourceWatch | All fresh |
| customer-02 | — | — |
| customer-14 | BlackKite | BlackKite fresh (1h 06m) |
| customer-03 | BlackKite, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 3m ago |
| customer-15 | — | — |
| customer-13 | AzureAudit, BlackKite, Falcon, Office365, O365ResourceWatch | All fresh (1h–5h) |
| customer-07 | AzureAudit, AzureEventHubs, Office365, O365ResourceWatch | O365 fresh (5h 19m) |
| customer-11 | BlackKite | BlackKite fresh (1h 27m) |
| customer-09 | BlackKite, DefenderATP, Mimecast, Office365, O365ResourceWatch | All fresh |
| customer-05 | BlackKite, DefenderATP, Office365, O365ResourceWatch | All fresh |
| customer-01 | AzureAudit, Office365, SentinelOne, Sophos | SentinelOne no_index; O365 no_index |
| customer-10 | BlackKite, Falcon | BlackKite fresh (58m) |
| customer-16 | DefenderATP, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 37m ago |
| customer-08 | AzureAudit, BlackKite, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 29m ago |
| customer-17 | — | — |
"no_index" on customer-01's SentinelOne and Office365 fetchers means the resource index does not exist yet — typical for sources that have never successfully synced. Worth investigating alongside customer-01's SentinelOne source_error.
integration= tag to match what Fluency now reports. Data is flowing — this is enrichment risk, not blind-spot risk. Tied to §4 integration misconfigurations.ingress_source_detail to pull the failing record shape. Low volume, but worth identifying the pattern before it grows. Tied to §4.Verdict precedence applied per health instruction group v91644c19bcb14970 (fetched this session). All counters per data-fabric-vocabulary.md. Report is read-only — no platform mutations performed.