I’m wondering about a way to generate an alert when one of my sources (eventlog from windows clients) goes silent (doesn’t send in messages for some time).
I was orginally thinking about using “when less than 1 messages in X minutes for source Y”, but creating a stream/condition for each of my windows clients is a bit tedious and rather messy. Also quite noisy when various clients are simply not used (not running) for a couple of days.
appreciate any ideas.