Im trying create an alert when when Log Source last event received is < 24 Hours OR a dashboard which displays log Source which is not sending logs since last 24 hours.
I was able to build a dashboard with latest event received timestamp but not able to compare the timestamp. like -- timestamp < 24 Hours
The idea is to identify the Log Stoppages - the hosts not sending logs to SIEM -
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.