Hello, I am trying to create a notable event in the mission control area within Enterprise Security to capture when an index has not received data within 24 hours. This should be simple and straight forward but I can't seem to figure out why this isn't working. I have the detection search as index = <target index> |stats count condition in the alert to trigger is search count = 0 I also have email alerts setup as an additional way to notify the proper people, this part of the security content works, but why doesn't the actual event appear in the Mission control area? This has me stumped, any help would be greatly appreciated.
... View more