Hello i want to see if a log was not send to graylog.
So i write a cron which write every 10 minutes a specific statement in syslog.
Now i make a alert which send a notification if this statement was not find in query in the last minute.
This works…
BUT if i group by field host name no alert or notification was send.
It’s a math problem, by troubleshooting your issue I would see if something is working for you better then the configuration you have.
count = 0
If you have messgae count equal to 0 send alert. count > = 0
If you have message count equal or great then 0 send alert count >0
If you have message count great then 0 send alert