Hi,
We need to create an alert to trigger if there is any new host sending data to an index. Would be good if the report runs once every 24 hrs.
Can someone please advise?
This will keep track of hosts in a CSV in case the search don't run for a day
| metadata type=hosts index=* OR index=_* NOT [|inputlookup hosts | format] | fild host |dedup host |outputlookup hosts
Try something like this. This should give you list of host who have first reported yesterday, so you can run this search daily after midnight.
| metadata type=hosts index=* OR index=_* | where firstTime>relative_time(now(),"-1d@d")