I have a rule, that report to me each time source stop sending logs to my splunk.
I try to make an exception, that when a specific source from a specific host will stop sending logs, it wont trigger an alert.
i will get alerts from
but not when its
Is it possible to do that? because i try to work on it for a few days already.
... View more