We are using Elastic Stack (ELK) to monitor our hosts, and we have around 465 hosts that need to be tracked by their status. We would like to understand how we can determine when hosts are not in the Healthy status in fleet. We are looking to write a rule for this. Could you please advise how to achieve this?
I created the "Missing monitoring data" rule. Is everything set up correctly? I can see that there have been no logs from one host for 22 hours, but this rule has not triggered.
These hosts are workstations, and we are a SOC. Is there an alternative way we could set this up?
As you suggested I created 3 monitors. Can you check if I'm doing it right.
I have to add all 465 hosts so it turns out? I can give the same settings to all 465 hosts except (Host, Monitor name).
Here are my settings:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.