I would like to be able to receive an alert if certain Syslog nodes do not send any logs within a specific amount of time, for an example: A firewall or other device that is regularly sending Syslog alerts.
On the "Ops Center" tab, there is the "Node Health" section that shows the Last Event time for nodes, including Syslog nodes, but there does not appear to be a way to alert based on this value. If I do not receive any data from my firewalls within 15 minutes, I would like an alert to fire, for example.
Thank you.