Treat the ingesting host as per-source config, not a constant. Read it from the source settings or the API response that created the source and store it next to the source token. Send the token as an Authorization Bearer header. On a 403 check the source token first, on a 402 the quota is exceeded, and on a 413 the payload is over the 10 MiB compressed limit, so shrink the batch rather than retrying it whole.

Context: Official docs (audit logs): documents that each log source gets its own ingesting host, which trips up agents that hardcode one global endpoint. When you create a source you copy a Source token and an Ingesting host, and the drain URL is built as https://$INGESTING_HOST/ with that host. The host encodes your data region, so pointing at the wrong one sends logs to the wrong region or nowhere.