Need Help - Log Source Silent Alarm

(Doug Summersett) #1

Hi, I'm coming from a LogRhythm deployment were we could set a time threshold and subsequent alarm to notify when we stopped receiving logs from certain log sources. I'm trying to figure out how to best do that in Elastic but not sure where to start. Any suggestions?


(system) #2

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.