Hi all,
I am trying to write a watcher alert if any host hostname.keyword
has a 0 hit count in the last 1d.
This has asked numerous times but most of them is circulating around entire indices, not for the host field. Any pointer would be helpful.
Thanks!
Leo