Dear all ,
Suppose we have 20 host in Active/Passive setup sending logs to us , 10 active and 10 passive .
Only one set of hosts will send logs.
We need SPL to list all the sources not sending logs in last 24 hours from both active and passive devices.
We do not want to report as alert if any one active/passive host pair has sent logs in last 24 hours.
I.e. if both active passive devices stop sending the logs we need to report.
How do you know which host is paired with which?
I have lookup with active and passive asset listed with their respective IP addresses listed in CSV sheet .
What data do you have in your lookup? What is returned when you look up each side of the active and passive pair? For example, do you get both addresses or an identifier unique for the pair?