Hi Folks,
I am working on creating an alert for endpoint where we have to check if its service came up after it got stop during upgrade.
For eg: - Host A service stop and didnt came up for 3 days then an alert will be triggered.
Also we can compare on basis of filedname state=Stopped and state=Running, but host should be same
Please let me know if there is any way we can create alert for this scenario
Thanks,
Have you tried something like this?
<your base search>
| stats last(state) AS state last(_time) AS _time by host service
| eval time_diff = now() - _time
| where (state="Stopped" AND time_diff > 259200)