Hi, is there any solution to create a notable event for missing forwarders? Now missing forwarders generate an alert on Monitoring Console, which runs on a separate Splunk instance than ES.
Hi,
You can write a correlation search for missing forwarders and select the alert type as a notable event.And you will get all the missing forwarder alerts as a notable event.
Hi,
Yes, but I want to find a way to forward MC Missing Forwarders Alerts to ES as a Notable Event, not creating a new Correlation search.