About This Manual
This is the user manual for the Fluency Ingext platform: collecting audit data from across an environment, shaping it in flight, storing it in a searchable data lake, detecting behavior worth acting on, and reporting on all of it.
It is published at manual.ingext.io and maintained by Fluency Security.
A note on two names
You will see both Fluency and Ingext throughout this manual, and they are not an old name and a new one — they are two products from the same company that are usually deployed together:
- Ingext is the streaming data pipeline and lakehouse — collecting data once, cleaning it in motion, routing it by value, and storing it in open formats. See ingext.io.
- Fluency is the SIEM that sits on top of it — streaming analytics, behavior rules, risk scoring, cases and AI-assisted triage. See fluencysecurity.com.
The web interface is branded Fluency. Where a page needs to name the whole system generically, it says "the platform". The full term list is in the Glossary.
What this manual covers
The chapters follow the path data takes through the platform:
- Collect — Data Collection for collectors, syslog, HEC and LDAP, and the Integrations catalog for per-vendor setup.
- Process — Platform for the Sources → Routers → Sinks pipeline, FPL processors, and enrichment.
- Search — Search for the data lake and query languages.
- Detect and investigate — Detections, Alerts & Actions and Investigate for behavior rules, risk scoring, notifications and analyst workflow.
- Report — Reports for scheduled and on-demand reporting and dashboards.
- Run the system — Administration for users, API tokens, MSSP operations, security and compliance.
- Look things up — Reference, and Page Functionality for a screen-by-screen tour of the current web interface.
The Introduction lays this out in full and is the best place to start. If you are setting up an instance for the first time, go to Get Started.
Screenshots and examples come from a running Fluency instance. The platform is updated continuously, so an individual screen may differ in detail from what you see in your own deployment; where that matters, Page Functionality reflects the current interface.
Related resources
- Fluency Release Notes — what changed in each release of the platform.
- FPL (Programming Language) — the language reference for processors, reports and rules, also published on its own at fpl.fluencysecurity.com.
- Fluency Security and Ingext — the product sites.
- SecurityDo on GitHub — where this manual and other public projects are hosted.
Contact
For problems with this documentation site — a broken page, a missing image, an instruction that no longer matches the product — write to: