Looking to see what others do for missing data - an example being a universal forwarder on a linux server, stops sending logs from bash history for root.. assuming it's a source type - what are others doing to make sure an alert is triggered when a situation similar happens? Any help would be great!
I am a big fan of the meta woot app. You can repurpose some of the dashboard searches into alerts: https://splunkbase.splunk.com/app/2949/#/details
You can have a list of sourcetypes which you want to monitor in a lookup along with max allowed delay time and using metadata, you can monitor them.
https://answers.splunk.com/answers/730503/query-to-see-the-forwarder-does-not-send-logs.html#answer-...
I am a big fan of the meta woot app. You can repurpose some of the dashboard searches into alerts: https://splunkbase.splunk.com/app/2949/#/details