Hi, I'm coming from a LogRhythm deployment were we could set a time threshold and subsequent alarm to notify when we stopped receiving logs from certain log sources. I'm trying to figure out how to best do that in Elastic but not sure where to start. Any suggestions?
Thanks