# Elastic Security - Host No longer logging Alert

**URL:** <https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043>\
**Category:** SIEM\
**Created:** [August 3, 2023, 12:22pm UTC](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043 "2023-08-03T12:22:58Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![g.spasov](https://avatars.discourse-cdn.com/v4/letter/g/e36b37/32.png) [@g.spasov](https://discuss.elastic.co/u/g.spasov)\
**Post date:** [August 3, 2023, 12:22pm UTC](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043/1 "2023-08-03T12:22:58Z")

</div>

Hello,

I want to create a detection rule in Elastic Security that would trigger when no logs have been injested to Elastic for more than 24 hours from a particular host.name.

The idea is to detect potential logging problems on the different hosts.

We currently use Elastic 8.6.0. We don't have the ML functionality available and I don't have access to the Watcher and Index Settings (I don't have admin rights) unfortunately.

I have the option to create detection rules (Custom Query, Threshold, Event Correlation, Indicator Match, New Terms).

Is there a way to achieve this with the current access I have? I believe there is a way to do this with a watcher but if I can avoid it, I would be very happy.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 31, 2023, 12:23pm UTC](https://discuss.elastic.co/t/elastic-security-host-no-longer-logging-alert/340043/2 "2023-08-31T12:23:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
