Which feeds are running, which have stopped, and exactly what the SOC cannot see while they are down — across seventeen tenants on one connector.
Ten source-level errors and sixteen integration misconfigurations across nine tenants. Two failure patterns dominate: SentinelOne agents that will not load, and S3-backed feeds returning errors.
Six named detection blind spots — endpoint telemetry, Defender alerts, DNS and proxy visibility, and cross-resource enrichment — each with what can no longer be detected.
Eight ranked actions. Three are P1 and all three restore a primary control surface that has been dark for at least 24 hours.
Nine of seventeen Apex MSSP tenants are in an error verdict — over half the book. Two failure patterns dominate: SentinelOne agents that will not load (customer-04 ×2, customer-01), and S3-backed feeds (CiscoUmbrella, JudySecurity) returning errors. A second cluster — customer-13, customer-07, customer-10, customer-08 — has integration_misconfigured findings: sources claim integrations that Fluency does not see a matching resource for. No tenant is unreachable; the platform side is healthy.
§2| Tenant | Verdict | Sources (ok/err/inactive) | 24h bytes | Findings |
|---|---|---|---|---|
| customer-13 · Customer 13 — Materials | Error | 9 / 2 / 1 | 12.4 GB | 2 source_error, 5 integration_misconfigured |
| customer-08 · Apex MSSP | Error | 8 / 1 / 4 | 55.7 GB | 1 source_error, 5 integration_misconfigured |
| customer-07 · Customer 07 — Recording SaaS | Error | 7 / 1 / 1 | 3.4 GB | 1 source_error, 4 integration_misconfigured |
| customer-04 · Customer 04 — Cloud Telecom | Error | 5 / 2 / 2 | 313 MB | 2 source_error (SentinelOne) |
| customer-10 · Customer 10 — Maritime Auth. | Error | 5 / 0 / 2 | 23.9 GB | 2 integration_misconfigured |
| customer-02 · Customer 02 — Retail Pharmacy | Error | 2 / 1 / 1 | 18.2 GB | 1 source_error (BehaviorSummary) |
| customer-11 · O&L | Error | 4 / 1 / 1 | 86.4 GB | 1 source_error (FluencyCollector) |
| customer-01 · Customer 01 — Retail Holdings | Error | 7 / 1 / 0 | 21.7 GB | 1 source_error (SentinelOne) |
| customer-16 · Customer 16 — Partner MSP | Error | 5 / 1 / 3 | 146 MB | 1 source_error (DefenderATP) |
| customer-06 · Customer 06 — Insurance | OK | 7 / 0 / 2 | 93.1 GB | — |
| customer-12 · Customer 12 — Industrial Tech | OK | 5 / 0 / 1 | 6.8 GB | — |
| customer-14 · Customer 14 — Research | OK | 4 / 0 / 2 | 15.4 GB | — |
| customer-03 · Customer 03 — Manufacturing | OK | 7 / 0 / 2 | 8.4 GB | — |
| customer-17 · Customer 17 — IT Services | OK | 4 / 0 / 0 | 8.7 GB | — |
| customer-05 · Customer 05 — Public Sector B | OK | 7 / 0 / 2 | 2.8 GB | — |
| customer-15 · Customer 15 — Identity Svc | OK | 4 / 0 / 0 | 2.3 GB | — |
| customer-09 · Customer 09 — Public Sector A | OK | 7 / 0 / 3 | 2.1 GB | — |
Inactive sources are quiet — not a finding. Inactive is not the same as broken; without time-comparison data the platform cannot distinguish "always quiet" from "stopped working." Resource fetchers (BlackKite, Office365, SentinelOne) are verified via freshness probe, not throughput.
§3Total 24h ingest across the connector: 361.8 GB. Top tenants by volume:
| Tenant | Top source |
|---|---|
| customer-06 | SyslogEndpoint (46.5 GB) |
| customer-11 | FluencyCollector (43.2 GB) |
| customer-08 | LocalSyslog (27.8 GB) |
| customer-10 | FluencyCollector (11.9 GB) |
| customer-01 | LocalSyslog (10.8 GB) |
| customer-02 | SyslogEndpoint (9.1 GB) |
| customer-14 | LocalSyslog (7.7 GB) |
| customer-13 | LocalSyslog (6.2 GB) |
Ten source-level errors across the book. Each below is a configured source that is failing or producing no events.
failed to load sentinelone agent (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
failed to load sentinelone agent (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
failed to load sentinelone agent (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
poll error (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
S3 data source Error (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
S3 data source Error (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
S3 data source Error (×9) · bytes_passed=0 · errorStates corroborated
Lineage: live_fluency_pull · histogram_24h · errorStates_corroborated
3,234 bytes errored in 24h · bytes_errored=3,234 · bytes_dropped=90,506 · bytes_aborted=3,234
Lineage: live_fluency_pull · histogram_24h
15,073 bytes errored in 24h · bytes_errored=15,073 · bytes_dropped=302,705 · bytes_aborted=15,073
Lineage: live_fluency_pull · histogram_24h
14,804 events in 24h; collector still passing 43.2 GB · bytes_passed=43.2 GB · source_errors=14,804
Lineage: live_fluency_pull · histogram_24h
Sixteen integration_misconfigured findings across four tenants. Each is a source claiming an integration (for example Office365) where Fluency's get_system_config reports no matching resource — typically the integration was renamed, removed, or never finished the discovery handshake.
| Tenant | Integrations with no matching resource |
|---|---|
| customer-13 | AzureAudit, BlackKite, Falcon, Office365, Office365ResourceWatch |
| customer-08 | AzureAudit, BlackKite, Office365, Office365ResourceWatch, SentinelOne |
| customer-07 | AzureAudit, AzureEventHubs, Office365, Office365ResourceWatch |
| customer-10 | BlackKite, Falcon |
customer-13, customer-08 and customer-07 are still ingesting from these sources — Office365 and AzureAudit are in their top five by bytes. The misconfiguration is in the integration cross-reference, not in data flow: Fluency is receiving the events, but the integration registry has no matching resource record for downstream correlation.
Seven errorStates_noise alerts suppressed across the connector — all are Office365 "failed to get access token" events occurring on sources that are passing data normally (OAuth token-refresh hiccups, not outages). Suppressed per verdict precedence rule 3.
§5What the SOC currently cannot see, derived from the §4 errors and known-stopped sources.
| Gap | Agent load failing across three configured sources; zero EDR events in 24h |
|---|---|
| Cannot detect | Malware execution, ransomware behaviors, EDR-detected lateral movement on endpoints in these tenants |
| Why it matters | Endpoint detection is the primary control surface for these customers |
| Remediation | Verify SentinelOne API token validity and console URL; reload agent config in Fluency |
| Gap | Defender poll failing for 24h (×9 retries observed) |
|---|---|
| Cannot detect | Defender alerts, suspicious process events, sign-in risk from MDE |
| Why it matters | customer-16 has no SentinelOne fallback configured |
| Remediation | Re-auth MDE app registration; confirm Graph API permissions are still granted |
| Gap | Both S3-backed Umbrella feeds erroring |
|---|---|
| Cannot detect | DNS tunneling, C2 callbacks via DNS, blocked-category web access patterns |
| Why it matters | Umbrella is the perimeter visibility for customer-13 |
| Remediation | Verify S3 bucket access keys and Umbrella log-export config |
| Gap | S3 source erroring for 24h |
|---|---|
| Cannot detect | Whatever JudySecurity provides (likely mobile / endpoint threat intel) for the customer-08 internal tenant |
| Why it matters | Depends on JudySecurity's role in the stack; confirm with operator |
| Remediation | Check S3 credentials and bucket path |
| Gap | Behavior summarization dropping a small fraction of events (3K and 15K bytes errored in 24h) |
|---|---|
| Cannot detect | The specific events that errored out — likely malformed records, not a broad outage |
| Why it matters | bytes_errored is small relative to throughput; verify the pattern is not growing |
| Remediation | Pull errorStates detail via ingress_source_detail to identify the failing record shape |
| Gap | Sources claim integrations that Fluency's resource discovery does not see |
|---|---|
| Cannot detect | Cross-resource correlation (for example linking an Office365 alert to its user record) may degrade until the registry is reconciled |
| Why it matters | Data is flowing, but enrichment and entity linking are at risk |
| Remediation | For each tenant, re-run integration discovery; rename the source's integration tag to match the discovered resource |
| Tenant | Configured integrations | Resource freshness |
|---|---|---|
| customer-04 | Office365, Office365ResourceWatch, SentinelOne | O365 fresh (4h 56m); SentinelOne no_index |
| customer-12 | BlackKite | BlackKite fresh (1h 08m) |
| customer-06 | BlackKite, DefenderATP, Office365, O365ResourceWatch | All fresh |
| customer-02 | — | — |
| customer-14 | BlackKite | BlackKite fresh (1h 06m) |
| customer-03 | BlackKite, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 3m ago |
| customer-15 | — | — |
| customer-13 | AzureAudit, BlackKite, Falcon, Office365, O365ResourceWatch | All fresh (1h–5h) |
| customer-07 | AzureAudit, AzureEventHubs, Office365, O365ResourceWatch | O365 fresh (5h 19m) |
| customer-11 | BlackKite | BlackKite fresh (1h 27m) |
| customer-09 | BlackKite, DefenderATP, Mimecast, Office365, O365ResourceWatch | All fresh |
| customer-05 | BlackKite, DefenderATP, Office365, O365ResourceWatch | All fresh |
| customer-01 | AzureAudit, Office365, SentinelOne, Sophos | SentinelOne no_index; O365 no_index |
| customer-10 | BlackKite, Falcon | BlackKite fresh (58m) |
| customer-16 | DefenderATP, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 37m ago |
| customer-08 | AzureAudit, BlackKite, Office365, O365ResourceWatch, SentinelOne | All fresh; SentinelOne 29m ago |
| customer-17 | — | — |
no_index on customer-01's SentinelOne and Office365 fetchers means the resource index does not exist yet — typical for sources that have never successfully synced. Worth investigating alongside customer-01's SentinelOne source error.
§7Re-validate API tokens and console URLs in Fluency. Three EDR sources blind for at least 24h. Tied to §4, §5.
Polling failed for 24h and the tenant has no healthy SentinelOne fallback. Confirm the Azure app registration and Graph permissions. Tied to §4, §5.
Both DNS and Proxy feeds erroring — primary perimeter visibility is down. Verify S3 access keys and Umbrella export config. Tied to §4, §5.
Confirm S3 credentials and bucket path; treat as an opaque vendor feed until the owner confirms scope. Tied to §4, §5.
Run integration discovery for each; correct the source-side integration= tag to match what Fluency now reports. Data is flowing — this is enrichment risk, not blind-spot risk. Tied to §4.
SentinelOne and Office365 resource indexes do not exist. Pair with the SentinelOne source-error fix; likely the same root cause. Tied to §6.
3.2 KB and 15 KB errored respectively. Use ingress_source_detail to pull the failing record shape. Low volume, but worth identifying the pattern before it grows. Tied to §4.
14,804 events. The collector is still passing 43 GB; errors are on a subset. Pull source detail to identify the failing inputs. Tied to §4.
Verdict precedence applied per health instruction group v91644c19bcb14970 (fetched this session).
Counters per data-fabric-vocabulary.md. Resource fetchers are verified via freshness probe rather than throughput, so a fresh-but-quiet fetcher is not reported as an error.
Scope. Connector 00000000-0000-0000-0000-000000000000, 17 tenants, 24h window ending 2026-05-30. Report is read-only — no platform mutations performed.