I would like to create a job to detect when there is anomaly in the number of event send by beats, mostly to detect if one of the beat stop sending logs to my ELK cluster (and to detect the name of the machine where the beat stopped working).
so for each beat I created a multy metric job, for the field
low count(Event rate) and
split field by agent.name
so the job for each beat looks like that:
I would like to know if it's the best way to do that, or there is another way to do it without spliting by
user.name or by creating one job for all the beats instead of one job for each beat