# Detection of no log received

**URL:** <https://community.graylog.org/t/detection-of-no-log-received/8141>\
**Category:** Graylog Central (peer support)\
**Created:** [December 21, 2018, 2:12am UTC](https://community.graylog.org/t/detection-of-no-log-received/8141 "2018-12-21T02:12:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kelvin.ng](https://avatars.discourse-cdn.com/v4/letter/k/b77776/32.png) [@kelvin.ng](https://community.graylog.org/u/kelvin.ng)\
**Post date:** [December 21, 2018, 2:12am UTC](https://community.graylog.org/t/detection-of-no-log-received/8141/1 "2018-12-21T02:12:48Z")

</div>

Hi all,

Is there any simple and efficient way to detect the missing log from each host in a specific period. I could only come up a solution by creating stream for each host and set alert to check NO message recevied by this stream. However, I would need to create 500 streams if the GLS accepting logs from 500 devices!!

any other smarter way to do this? thank for advise

---

<div class="post-metadata">

**Author:** ![macko003](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/macko003/32/3175_2.png) [@macko003](https://community.graylog.org/u/macko003)\
**Post date:** [December 24, 2018, 3:52pm UTC](https://community.graylog.org/t/detection-of-no-log-received/8141/2 "2018-12-24T15:52:33Z")

</div>

I suggest do two search via api.  
Do a Quick overview on source, and chech the URL with your browser’s debug tool.  
First search eg. 2 weeks to 1 week, and last week. You can compare the two lists. Or you can just do the last search, and compare with your manual list.

---

<div class="post-metadata">

**Author:** ![karlt](https://avatars.discourse-cdn.com/v4/letter/k/f4b2a3/32.png) [@karlt](https://community.graylog.org/u/karlt)\
**Post date:** [January 2, 2019, 6:21pm UTC](https://community.graylog.org/t/detection-of-no-log-received/8141/3 "2019-01-02T18:21:33Z")

</div>

you’d be better off making an rsyslog config that drops the hostname to a log on the graylog server. then having a cron job compare that log to a list of known hostnames, send out an email alert if no match occurs. it will take some development

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [January 16, 2019, 6:21pm UTC](https://community.graylog.org/t/detection-of-no-log-received/8141/4 "2019-01-16T18:21:34Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
