Fluency Security Data-Source Health & Status

Apex MSSP — Data-Source Health & Status

Which feeds are running, which have stopped, and exactly what the SOC cannot see while they are down — across seventeen tenants on one connector.

Connector 00000000-0000-0000-0000-000000000000 · 17 tenants · Generated 2026-05-30 · 24h window · Read-only

17
Tenants
134
Configured sources
361.8 GB
24h ingest
26
Total findings
01 — What is broken

Ten source-level errors and sixteen integration misconfigurations across nine tenants. Two failure patterns dominate: SentinelOne agents that will not load, and S3-backed feeds returning errors.

02 — What it costs

Six named detection blind spots — endpoint telemetry, Defender alerts, DNS and proxy visibility, and cross-resource enrichment — each with what can no longer be detected.

03 — What to fix first

Eight ranked actions. Three are P1 and all three restore a primary control surface that has been dark for at least 24 hours.

§1

Health summary

9
Error verdictAction required
8
OK verdictNo action
0
UnreachablePlatform healthy
10
Source-level errorsAction required

Nine of seventeen Apex MSSP tenants are in an error verdict — over half the book. Two failure patterns dominate: SentinelOne agents that will not load (customer-04 ×2, customer-01), and S3-backed feeds (CiscoUmbrella, JudySecurity) returning errors. A second cluster — customer-13, customer-07, customer-10, customer-08 — has integration_misconfigured findings: sources claim integrations that Fluency does not see a matching resource for. No tenant is unreachable; the platform side is healthy.

§2

Per-tenant verdict

TenantVerdictSources (ok/err/inactive)24h bytesFindings
customer-13 · Customer 13 — MaterialsError9 / 2 / 112.4 GB2 source_error, 5 integration_misconfigured
customer-08 · Apex MSSPError8 / 1 / 455.7 GB1 source_error, 5 integration_misconfigured
customer-07 · Customer 07 — Recording SaaSError7 / 1 / 13.4 GB1 source_error, 4 integration_misconfigured
customer-04 · Customer 04 — Cloud TelecomError5 / 2 / 2313 MB2 source_error (SentinelOne)
customer-10 · Customer 10 — Maritime Auth.Error5 / 0 / 223.9 GB2 integration_misconfigured
customer-02 · Customer 02 — Retail PharmacyError2 / 1 / 118.2 GB1 source_error (BehaviorSummary)
customer-11 · O&LError4 / 1 / 186.4 GB1 source_error (FluencyCollector)
customer-01 · Customer 01 — Retail HoldingsError7 / 1 / 021.7 GB1 source_error (SentinelOne)
customer-16 · Customer 16 — Partner MSPError5 / 1 / 3146 MB1 source_error (DefenderATP)
customer-06 · Customer 06 — InsuranceOK7 / 0 / 293.1 GB
customer-12 · Customer 12 — Industrial TechOK5 / 0 / 16.8 GB
customer-14 · Customer 14 — ResearchOK4 / 0 / 215.4 GB
customer-03 · Customer 03 — ManufacturingOK7 / 0 / 28.4 GB
customer-17 · Customer 17 — IT ServicesOK4 / 0 / 08.7 GB
customer-05 · Customer 05 — Public Sector BOK7 / 0 / 22.8 GB
customer-15 · Customer 15 — Identity SvcOK4 / 0 / 02.3 GB
customer-09 · Customer 09 — Public Sector AOK7 / 0 / 32.1 GB

Inactive sources are quiet — not a finding. Inactive is not the same as broken; without time-comparison data the platform cannot distinguish "always quiet" from "stopped working." Resource fetchers (BlackKite, Office365, SentinelOne) are verified via freshness probe, not throughput.

§3

Ingestion & data flow

Total 24h ingest across the connector: 361.8 GB. Top tenants by volume:

customer-06
93.1 GB
customer-11
86.4 GB
customer-08
55.7 GB
customer-10
23.9 GB
customer-01
21.7 GB
customer-02
18.2 GB
customer-14
15.4 GB
customer-13
12.4 GB
TenantTop source
customer-06SyslogEndpoint (46.5 GB)
customer-11FluencyCollector (43.2 GB)
customer-08LocalSyslog (27.8 GB)
customer-10FluencyCollector (11.9 GB)
customer-01LocalSyslog (10.8 GB)
customer-02SyslogEndpoint (9.1 GB)
customer-14LocalSyslog (7.7 GB)
customer-13LocalSyslog (6.2 GB)
§4

Errored / silent sources

Ten source-level errors across the book. Each below is a configured source that is failing or producing no events.

Integration misconfigurations

Sixteen integration_misconfigured findings across four tenants. Each is a source claiming an integration (for example Office365) where Fluency's get_system_config reports no matching resource — typically the integration was renamed, removed, or never finished the discovery handshake.

TenantIntegrations with no matching resource
customer-13AzureAudit, BlackKite, Falcon, Office365, Office365ResourceWatch
customer-08AzureAudit, BlackKite, Office365, Office365ResourceWatch, SentinelOne
customer-07AzureAudit, AzureEventHubs, Office365, Office365ResourceWatch
customer-10BlackKite, Falcon

customer-13, customer-08 and customer-07 are still ingesting from these sources — Office365 and AzureAudit are in their top five by bytes. The misconfiguration is in the integration cross-reference, not in data flow: Fluency is receiving the events, but the integration registry has no matching resource record for downstream correlation.

Suppressed

Informational · no action needed

Seven errorStates_noise alerts suppressed across the connector — all are Office365 "failed to get access token" events occurring on sources that are passing data normally (OAuth token-refresh hiccups, not outages). Suppressed per verdict precedence rule 3.

§5

Detection blind spots

What the SOC currently cannot see, derived from the §4 errors and known-stopped sources.

SentinelOne endpoint telemetry — customer-04, customer-01

Risk: high
GapAgent load failing across three configured sources; zero EDR events in 24h
Cannot detectMalware execution, ransomware behaviors, EDR-detected lateral movement on endpoints in these tenants
Why it mattersEndpoint detection is the primary control surface for these customers
RemediationVerify SentinelOne API token validity and console URL; reload agent config in Fluency

Microsoft Defender ATP — customer-16

Risk: high
GapDefender poll failing for 24h (×9 retries observed)
Cannot detectDefender alerts, suspicious process events, sign-in risk from MDE
Why it matterscustomer-16 has no SentinelOne fallback configured
RemediationRe-auth MDE app registration; confirm Graph API permissions are still granted

Cisco Umbrella DNS & Proxy logs — customer-13

Risk: medium-high
GapBoth S3-backed Umbrella feeds erroring
Cannot detectDNS tunneling, C2 callbacks via DNS, blocked-category web access patterns
Why it mattersUmbrella is the perimeter visibility for customer-13
RemediationVerify S3 bucket access keys and Umbrella log-export config

JudySecurity S3 feed — customer-08

Risk: medium
GapS3 source erroring for 24h
Cannot detectWhatever JudySecurity provides (likely mobile / endpoint threat intel) for the customer-08 internal tenant
Why it mattersDepends on JudySecurity's role in the stack; confirm with operator
RemediationCheck S3 credentials and bucket path

BehaviorSummary transform errors — customer-02, customer-07

Risk: low
GapBehavior summarization dropping a small fraction of events (3K and 15K bytes errored in 24h)
Cannot detectThe specific events that errored out — likely malformed records, not a broad outage
Why it mattersbytes_errored is small relative to throughput; verify the pattern is not growing
RemediationPull errorStates detail via ingress_source_detail to identify the failing record shape

Integration registry drift — customer-13, customer-08, customer-07, customer-10

Risk: medium
GapSources claim integrations that Fluency's resource discovery does not see
Cannot detectCross-resource correlation (for example linking an Office365 alert to its user record) may degrade until the registry is reconciled
Why it mattersData is flowing, but enrichment and entity linking are at risk
RemediationFor each tenant, re-run integration discovery; rename the source's integration tag to match the discovered resource
§6

Integration inventory

TenantConfigured integrationsResource freshness
customer-04Office365, Office365ResourceWatch, SentinelOneO365 fresh (4h 56m); SentinelOne no_index
customer-12BlackKiteBlackKite fresh (1h 08m)
customer-06BlackKite, DefenderATP, Office365, O365ResourceWatchAll fresh
customer-02
customer-14BlackKiteBlackKite fresh (1h 06m)
customer-03BlackKite, Office365, O365ResourceWatch, SentinelOneAll fresh; SentinelOne 3m ago
customer-15
customer-13AzureAudit, BlackKite, Falcon, Office365, O365ResourceWatchAll fresh (1h–5h)
customer-07AzureAudit, AzureEventHubs, Office365, O365ResourceWatchO365 fresh (5h 19m)
customer-11BlackKiteBlackKite fresh (1h 27m)
customer-09BlackKite, DefenderATP, Mimecast, Office365, O365ResourceWatchAll fresh
customer-05BlackKite, DefenderATP, Office365, O365ResourceWatchAll fresh
customer-01AzureAudit, Office365, SentinelOne, SophosSentinelOne no_index; O365 no_index
customer-10BlackKite, FalconBlackKite fresh (58m)
customer-16DefenderATP, Office365, O365ResourceWatch, SentinelOneAll fresh; SentinelOne 37m ago
customer-08AzureAudit, BlackKite, Office365, O365ResourceWatch, SentinelOneAll fresh; SentinelOne 29m ago
customer-17

no_index on customer-01's SentinelOne and Office365 fetchers means the resource index does not exist yet — typical for sources that have never successfully synced. Worth investigating alongside customer-01's SentinelOne source error.

§7

Recommended actions

Methodology

Verdict precedence applied per health instruction group v91644c19bcb14970 (fetched this session).

Counters per data-fabric-vocabulary.md. Resource fetchers are verified via freshness probe rather than throughput, so a fresh-but-quiet fetcher is not reported as an error.

Scope. Connector 00000000-0000-0000-0000-000000000000, 17 tenants, 24h window ending 2026-05-30. Report is read-only — no platform mutations performed.