Dear all ,
Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .
Only one set of hosts will send logs.
We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.
We do not want to report as alert if any one active/passive host pair has sent logs in last 24 hours.
I.e. if both active passive devices stop sending the logs we need to report.
any help will be appreciated
Finding something that is not there is not Splunk's strong suit. See this blog entry for a good write-up on it.
https://www.duanewaddle.com/proving-a-negative/