Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How to write a search to alert if one host stops forwarding logs for a certain sourcetype?

$
0
0
Hello guys, I want to make an alert if number of hosts is lower than 5 in a sourcetype search. To be more specific, I have 5 hosts that send logs into `sourcetype=test`. If one of the hosts stops publish logs into this sourcetype for the last 30 minutes, I would like to get an alert for it. I'll be glad if you can help me.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>