I have a few separate questions I’ve been wondering about.
First, is it possible within Graylog to monitor collector sidecars and alert if they are disconnected or haven’t received a message from one in x amount of time?
Or is it possible to alert based on not receiveing a message from host x in x amount of time globally regardless of stream?
Second, occasionally one of my indexes that recieves logs from winlogbeat will rotate and assign the wrong things from the first message received. This causes a ton of index errors until the index is rotated again. Is it possible to auto rotate the index if x amount of errors are present?