Detect log outage for different application running on same server that sending log
Is there any way I can create a rule to detect missing logs for an application/event type? Since I have two different applications running on the same server and both use CEF format to send logs to FortiSIEM, in this way, the "PH_DEV_MON_LOG_DEVICE_DELAY_HIGH" can't be used since it detects the log source device missing logs. How should I create the rule to detect such a scenario?
