Question
Need SIEM 7.1.3 (Rule) method to detect when a Windows Log Agent stops reporting for more then 6 hrs
Hello,
.Not sure how to set up the rule itself, is it even possible? Our clients are not always aware when the agents stop reporting and then we wind having to tell them its been disconnected for 2 weeks we have 100+ agents between all our clients we cant possibly watch all of them so we need an alert.
how can I query to get a agent health log so I have the right event type and data source.
Thanks!
thanks, Karl
