Good afternoon,
I want to generate an alert to control the loss of ingestion of the events in the different indexes, but I want to do it that for according to the index that is, the time of ingestion varies.
That is to say, the windows servers, ingest me almost every minute, on the other hand the antivirus only ingests if it detects something, which can be that it generates at least one event every 5 days. So it does not make sense to check every minute, because the antivirus would generate a lot of noise, and not every 2 days, because in the case of losing communication with the forwarder I would realize 2 days later, and the service would not work efficiently.
Does anyone know if it is possible to generate this alert, without having to generate an alert by index?
Thank you very much in advance!
How does Splunk know how long an interval between events being ingested is deemed intolerable for each index?