My setup - graylog 6.0.3
I have a firewall stream and in this stream 10 firewalls send the logs
Now I would like to know, when a firewall no longer send logs?
I would like to receive an alarm message - SMS or notification
The links provided by @patrickmann will help you to create an alert if the Stream has no log, which means all firewall stopped to send logs.
Unfortunately as far as I know it isn’t possible to create a rule to be alerted if only one firewall stop to send logs (or you need to create a specific rule for each firewall but it’s really not handy)