Re: Use Case - Daily Automated Report for hosts not logging to SIEM in X time frame - Anyone?
before you start with the report, I would build a query and graph first to ensure the syntax is correct.
One way that I can think of would be to start with an event Query based on Count. The one below is set to show us top talkers, so you would want to sort on descending, and maybe only pick the data sources that you are worried about..
You should be able to pick your time frame as well.
The other way would be set up an alarm based on type of device status change, with the health monitor status of idle. This can be problematic in that the heath of the data source is fine, you just want to know when its not sending events anymore. So you might need to play with that one as well.