Hi , We have 2 HF active and passive, I shut off the Splunk service on 1 HF. I want to be alerted only when my 2 HFs are not sending logs/splunk service is down.
I don’t want any alerts at least when one of the HF is running.
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/
Consider using the TrackMe app (https://splunkbase.splunk.com/app/4621)