Manage intakes
This article covers all procedures for creating and managing intakes in Sekoia, from initial setup to renaming, reconfiguring, and deleting.
Prerequisites
- You must have the appropriate role in your Sekoia community to create or modify intakes.
- For Pull intakes, you must have valid credentials for the data source you want to connect.
Create an intake
To add a new data source to Sekoia:
- Navigate to Intakes in the Operations Center.
- Click New intake.
- In the catalog, search for the format that matches your data source and select it.
- Enter a name for the intake and select the entity it belongs to.
- If the intake is a Pull intake, fill in the connector configuration fields (credentials and parameters).
- Click Save.

Custom intake formats
If your log format is not available in the catalog, you can build a custom intake format. Refer to Create a format for instructions.
Configure a notification for an inactive intake
An inactive intake can create blind spots in your security monitoring. Configure an inactivity notification to get alerted when an intake stops sending events.
To configure an inactivity notification from the intakes listing:
- Navigate to Intakes in the Operations Center.
- On the intake card, click the menu icon, then click Notifications.
- Set the inactivity duration after which the notification triggers. You can choose between 15 minutes and 24 hours.
- Select your preferred notification channel.
- Click Save.
Alternative setup paths
You can also configure this notification from the Intake details page via the intake menu, or from User Center > Notifications by selecting the No events are received trigger.

Edit an intake entity
To move an intake to a different entity:
- Navigate to Intakes and open the intake details page.
- In the intake menu, click Edit entity.
- Select the new entity from the list.
- Click Save.

Configure a pull intake
Use this procedure to update a pull intake's connector parameters, such as authentication credentials or configuration values.
Pull intakes only
The Configure option is only available for Pull intakes. It is not visible for push intakes.
To update the connector configuration:
- Navigate to Intakes and open the intake details page.
- In the intake menu, click Configure.
- Update the configuration fields as needed.
- Click Save.

Changes apply immediately
Configuration changes take effect instantly. You do not need to restart the connector.
Rename an intake
To change the display name of an intake:
- Navigate to Intakes and open the intake details page.
- In the intake menu, click Rename.
- Enter the new name.
- Click Save.

Delete an intake
The intake key becomes unusable after deletion
Deleting an intake does not remove previously ingested events. However, the associated intake key is permanently invalidated. To restore the same data source connection, you must create a new intake and deploy the new intake key in your infrastructure.
To delete an intake:
- Navigate to Intakes and open the intake details page.
- In the intake menu, click Delete.
- Confirm the deletion.
Contact support
Reach out to Sekoia support in the following situations:
- The configuration recommendations in this article do not apply to your system and you need guidance on forwarding your events.
- Your log format is not available in the intake catalog. New formats are added regularly, and support can notify you when yours becomes available.
Related articles
-
Intakes: Concept overview of what intakes are, how they connect to Sekoia, and what the different event types mean.
-
Intake details page: Reference for all metrics, indicators, and menu options available on the intake details page, including a full explanation of the event delivery metric.
-
Turn on notifications: How to configure notification channels and triggers for intake inactivity alerts.
-
Create a format: How to build a custom intake format for unsupported log sources.