2013-06-08 01:41 AM
Has anyone been successful in finding a way to mimic the Device Down functionality from enVision in SA? I'm looking for something as simple a way to query when a particular device (IP or hostname) last sent logs. Maybe some alerting can be handled once this timestamp is found to trespass some threshold.
2014-03-21 10:23 AM
I managed to send an alert (administration/system/monitoring/event source) if a source does not receives log after threshold. The problem is that it sends an alert email in every minutes so it is hardly usable. Is there any way to suppress these alerts? Or is there any way to use these log stats in a rule?
2014-03-24 03:23 AM
i'm opening case to check out. syslog also same.