how to see when a set of host send under 100 logs per hour? stats count wont show a value of 0. and you cant use HEAD with fields(that i know of). Whats the best way to do this?
you can use | tstats command, for the last 60 minutes every hour
| tstats count where index = * by host | where count < 100
save as an alert and triger where count = 0
hope it helps
you can use | tstats command, for the last 60 minutes every hour
| tstats count where index = * by host | where count < 100
save as an alert and triger where count = 0
hope it helps
need to alert on hosts sending under 100 or so logs per hour.
when you say logs you mean events or source?
logs as in events.