I can see that in Admin we have a tab for Event Sources and in Event Sources we have:
Discovery / Manage / Monitoring Policies / Alarms / Settings / Log Parser Rules
My question is:
Its possible to create a policie to see an event source?
For example in the Manage Tab we have the Event Source the Event Source Type and the log collector and log decoder like this table:
Event Souce Event Source Type Log Collector Log Decoder
22.214.171.124 apache Logdecoder1 LogDecoder 1
I want to create an alarm that can tell me that the Event Souce 126.96.36.199 in apached stopped sending logs or the quantity has diminished .
Is that possible? How?