Instruments and log sources
An instrument is the stable identity Chipper uses to organize files, runs, events, alerts, methods, and analysis. A log source describes how data for that instrument reaches Chipper.
Each log source belongs to exactly one instrument. That explicit link is what lets Chipper attribute activity correctly even when several devices produce similar filenames or event types.
Instrument records
Go to View → Instruments to see the fleet as a dashboard or table. Each instrument has:
- A recognizable name.
- An instrument type, which determines how its logs are parsed and which rules are available.
- A timezone for interpreting timestamps.
- Optional profile imagery.
- One or more connected log sources.
- Activity summaries for events, alerts, files, and monitoring.
Use a workcell when several instruments belong to one operational unit. The workcell groups the components, but each component instrument still needs its own source.
Ways to connect data
Chipper supports three continuous patterns:
- Agent → Chipper cloud: a Chipper Log Collector watches specific local files and streams changes to a Chipper-managed landing location.
- Existing cloud storage: Chipper reads from customer-owned AWS S3, Azure Blob Storage, or Google Cloud Storage.
- Standalone agent → your cloud: the collector writes to customer-owned storage and Chipper reads it from there.
Manual upload is the quickest path for historical analysis, format validation, or a first test. Open Investigate → Log Files, select Upload Files, choose the instrument, and add the files.
Choose a precise source boundary
For a local collector, use include patterns that select only the intended logs. For a cloud source, use a bucket prefix that belongs to only one instrument. Avoid overlapping prefixes and catch-all local patterns: they make attribution ambiguous and can ingest unrelated files.
Verify a source
Open Configure → Log Sources, then select a source to review:
- Current source status.
- Linked instrument and ingestion method.
- Last import time and number of files ingested.
- Recent connection or ingestion failures.
- Import-now controls where the source type supports them.
Then check Log Files. A healthy file moves through ingestion and reaches Processed. From the file details you can follow its runs, methods, events, alerts, and original text.
Continue with the platform walkthrough, or open the provider-specific setup under Log Sources.