I have a set of universal forwarders that keep shutting down on their own. We have a case open with support but this bring up and important question. How do I monitor the health and availability of my forwarders?
We've set up an alert on the metadata to trigger an email alert in case if any forwarder goes missing
| metadata type=hosts | eval age = now() - lastTime | search age > 7200 | table age host lastTime
You can change the the age threshold as per your needs.