Queued (unparsed) Hot storage Warm storage Cold storage
drag to pan ↔

SIEM Ingestion Queue Console: Backlog, Drops & Tier Aging

Every SIEM platform is built on a queueing problem before it is a detection problem: log events stream in from hosts at some ingestion rate, a parsing/normalization stage can only drain that queue so fast, and once the buffer fills, events start getting dropped rather than analyzed. This 2D console renders that pipeline as a flat diagram — six host sources feed events into a live queue in front of a parser gate, and tuning the ingestion rate against the parser throughput shows the backlog and drop counter respond exactly as the λ vs. μ queueing model predicts. Events that clear the parser fly into a hot storage zone and age through warm and cold tiers on a retention timer you control, two scrolling strip charts track backlog% and tier populations over time, live readouts track ingest/parse EPS and drops, and a collapsible section spells out the underlying queueing and retention formulas.