Greetings,
I am using a syslog setup for my data source. I am trying to create a way to search for lost connection by comparing last event received to the time now. I have events that come in about every 1-2 secs, I need a way where I can run a real-time search for any time an event is greater than, Ex: 10 secs, and notify me when that happens. I am stuck on the syntax portion of writing this expression. I have tried
host="ip" compare=latest=-10s < timenow=now()
but I am pretty sure I have the syntax wrong.
Thanks
Mac
... View more