Hi , I am trying to setup an alert when a host has stopped sending logs. I would like to group by hosts and check if log count is zero.
The UI is mandating at least 1 condition. Tried setting host.name is , but it literally looking for "" as host name and triggering alert since no hosts match that name.
Is there a way to specify a wildcard