Query hostname field with zero hit count

Hi all,

I am trying to write a watcher alert if any host hostname.keyword has a 0 hit count in the last 1d.

This has asked numerous times but most of them is circulating around entire indices, not for the host field. Any pointer would be helpful.

Thanks!
Leo

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.