How do I alert or highlight no logs over an interval?

I have a use case, where it would be nice to highlight or alert less than a certain volume of logs from a specific query that returns logs from multiple hosts. So I have a field that identifies the actual back end host, behind a load balancer. If the host is not generating any logs, I’d like to be able to highlight that on a dashboard, or trigger an alert? Any ideas how I can do this?


Correct me if im wrong but I think your trying to do something like this?

Hope that helps



I set it up. We’ll see if it works next time it happens. Thank you for the suggestion!

