I would like to create a new rule to detect if one of my beats stop sending data to my Cluster (one rule for each beat).
For example I have installed packetbeat in 5 machines, and then the rule will verify each 1 minutes the number of
agent.host (by aggregation) and if it's less than 5, then it will send me an alert.
Could you please tell me how can I create this kind of alerts
Thanks in advance