# Alert when Log Source last event received is \< 24 Hours

**URL:** <https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665>\
**Category:** Elastic Security\
**Created:** [September 9, 2023, 7:06pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665 "2023-09-09T19:06:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 9, 2023, 9:40pm UTC](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665/2 "2023-09-09T21:40:50Z")

</div>

Hi @Shinej

There is a pretty cool way to do this using a latest transform with the `host.name`

Take a look at this this particular example is it about users

But I actually did this same thing for last log from each host.

Basically the latest transform just keeps the latest log from each host.

Then you can just check / alert which host have not reported in in the last 24 hours.

> [@Detecting inactive users in Active Directory](https://discuss.elastic.co/t/detecting-inactive-users-in-active-directory/323650/4):
>
> I think a [latest transform](https://www.elastic.co/guide/en/elasticsearch/reference/8.6/transform-overview.html#latest-transform-overview) could perhaps be a good solution. I Did this for host not users But same concept. We wanted to see what hosts had not sent logs lately. Basically if you do a latest transform using a user ID as the unique identifier and the timestamp as the latest time then you will see the user that has not logged in in the last day or two days or a week etc. Most your users will have logged in recently, but you'll see the tail of the users that have not. It's actually could be pr…

---

_[View the full topic](https://discuss.elastic.co/t/alert-when-log-source-last-event-received-is-24-hours/342665)._
