Alert if Enabled Syslog Agent stops sending data for an extended period
complete
Canny AI
Merged in a post:
Alert if Logs Stop
S
Scott Brewster
If we could get some kind of alert if one of the log sources stopped providing logs to the SIEM, that would be really cool. DNS Filter had an error, and we lost like two weeks of logs before anyone noticed.
C
Chris
Agree this is a needed function. Otherwise, are you to check daily that all collectors are reporting seems like it could just monitor if there has been lack of activity on a collector to send an alert.
Nate O'Brien
complete
We now have support for escalating on non-reporting log sources. A full description of the capability can be found here: https://support.huntress.io/hc/en-us/articles/42917517950995-Non-Reporting-Log-Source-Escalations
J
Jacob Wiley
Nate O'Brien Thank you for this!
N
Naftuli Herzog
Escalation that will create a ticket in our PSA
Chris Bisnett
in progress
Chris Bisnett
planned