Hi everyone,
I'm used application: "nmon performance by octamis" and "Splunk app for Windows infrastructure' to monitor servers unix, windows. I want to create an alert when servers downtime or service splunkd off. Can someone help me please?
The best way to identify is to alert when the data/messages stop flowing in
Please find similar query and answer: https://answers.splunk.com/answers/748530/alert-when-forwarer-stops-and-sourcetype-stops.html#answer...
thanks your answer, I have some questions: what is "last_logged" and "timeDiff"?