# Alert when Log Source last event received is \< 24 Hours

**URL:** <https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665>\
**Category:** Elastic Security\
**Created:** [September 9, 2023, 7:06pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665 "2023-09-09T19:06:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shinej](https://avatars.discourse-cdn.com/v4/letter/s/51bf81/32.png) [@Shinej](https://discuss.elastic.co/u/Shinej)\
**Post date:** [September 9, 2023, 7:06pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665/1 "2023-09-09T19:06:26Z")

</div>

Hello All,

Im trying create an alert when when Log Source last event received is \< 24 Hours OR a dashboard which displays log Source which is not sending logs since last 24 hours.

I was able to build a dashboard with latest event received timestamp but not able to compare the timestamp. like -- timestamp \< 24 Hours

The idea is to identify the Log Stoppages - the hosts not sending logs to SIEM -

any ideas on achieving this is appreciated.

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2023, 9:40pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665/2 "2023-09-09T21:40:50Z")

</div>

Hi @Shinej

There is a pretty cool way to do this using a latest transform with the `host.name`

Take a look at this this particular example is it about users

But I actually did this same thing for last log from each host.

Basically the latest transform just keeps the latest log from each host.

Then you can just check / alert which host have not reported in in the last 24 hours.

> [@Detecting inactive users in Active Directory](https://discuss.elastic.co/t/detecting-inactive-users-in-active-directory/323650/4):
>
> I think a [latest transform](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/transform-overview.html#latest-transform-overview) could perhaps be a good solution. I Did this for host not users But same concept. We wanted to see what hosts had not sent logs lately. Basically if you do a latest transform using a user ID as the unique identifier and the timestamp as the latest time then you will see the user that has not logged in in the last day or two days or a week etc. Most your users will have logged in recently, but you'll see the tail of the users that have not. It's actually could be pr…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2023, 9:41pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665/3 "2023-10-07T21:41:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
