# Log Source Stopped Working

**URL:** <https://discuss.elastic.co/t/log-source-stopped-working/389423>\
**Category:** Monitoring\
**Created:** [August 11, 2026, 10:46am UTC](https://discuss.elastic.co/t/log-source-stopped-working/389423 "2026-08-11T10:46:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![tortnike.e](https://avatars.discourse-cdn.com/v4/letter/t/ecae2f/32.png) [@tortnike.e](https://discuss.elastic.co/u/tortnike.e)\
**Post date:** [August 11, 2026, 10:46am UTC](https://discuss.elastic.co/t/log-source-stopped-working/389423/1 "2026-08-11T10:46:49Z")

</div>

Hello Guys,

How do you monitor log sources? I need to monitor some of Data Streams, when they are not sending logs, I need to be alerted. What do you suggest?

I have created esql rule but sometimes it is not woking:  
FROM logs-hashicorp\_vault.audit-default  
| WHERE @timestamp \> NOW() - 24 hours  
| STATS count = COUNT(\*)  
| WHERE count == 0

---

<div class="post-metadata">

**Author:** ![val](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/val/32/138203_2.png) [@val](https://discuss.elastic.co/u/val)\
**Post date:** [August 11, 2026, 11:35am UTC](https://discuss.elastic.co/t/log-source-stopped-working/389423/2 "2026-08-11T11:35:49Z")

</div>

Hey, here is a question on a similar topic that has a good answer

> [@Alerting when data stops coming in from variety of sources](https://discuss.elastic.co/t/alerting-when-data-stops-coming-in-from-variety-of-sources/379787/3):
>
> I've had some issues in the past while trying to use the built-in threshold alert, it missed the alerts a lot of time, generated some false positive about the data recovering when it didn't recover. Afte some tickets with support with no solution and they not being able to replicated we gave up and looked for other ways to alert on the data. What solved our problem was using ES|QL security rules that will trigger based on the difference from the time when the rule is executed and the last even…
