Has anyone had success in creating monitoring in Splunk to detect broken data feeds.
We have hundreds of feeds - some have events constantly coming in, some get data just once a month - and everything in between! We require a solution which would be smart enough to detect the pattern of events and alert when there is an anomaly. An anomaly might be a drastic reduction in events or a source which was previously sending events stopping
The best we've got so far is a simple alert that fires when a sourcetype has not had data for a fixed amount of time.