SIEM Alert for Logging Failures
Tim
Upvoted. I just happened to login this morning to work on another device and noticed that one of our firewalls hasn't uploaded logs in since early May. An alert would seem to be a no-brainer.
C
Cody Arnold
I assume the thought here is get an alert if the collector is not seen for more than X period of time, or if it's not uploaded any logs for a time that is greater than a specified value, I would probably also see value in being able to toggle something per syslog source in the portal and have it alert if it's not seeing any logs from that within a period of time, and then also have a place it can send those to which is a customizable destination for those specific alerts.