How to detect when an alert does not report events in a certain time?


hello, as of today I am looking for a little help to efficiently detect when an alert stops reporting. My idea is not to generate an alert that monitors the alert (redundant) when the result or count at a certain time is zero, rather I am a more automated mechanism that helps me, maybe some app or advice that can help me detect when this happens .


Labels (1)
0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!