I’m wondering about a way to generate an alert when one of my sources (eventlog from windows clients) goes silent (doesn’t send in messages for some time).
I was orginally thinking about using “when less than 1 messages in X minutes for source Y”, but creating a stream/condition for each of my windows clients is a bit tedious and rather messy. Also quite noisy when various clients are simply not used (not running) for a couple of days.
@taxter

with the current release of Graylog that is not (easy) possible. Upcoming Version will make this kind of alert possible.

The request is similar to but if you feel that this does not describe what you need and want - and no other issue makes it clear, please open a new one.

Thanks Jan, that issue sounds very much like the kind of feature i am looking for!

By “upcoming version …” you mean this particular issue is scheduled for the next release?



upcoming in this situation means not 2.5 or 3.0 - more something after that. But improving the alerting will be the next focus for us.

