I can see that in Admin we have a tab for Event Sources and in Event Sources we have:
Discovery / Manage / Monitoring Policies / Alarms / Settings / Log Parser Rules
My question is:
Its possible to create a policie to see an event source?
For example in the Manage Tab we have the Event Source the Event Source Type and the log collector and log decoder like this table:
Event Souce Event Source Type Log Collector Log Decoder
220.127.116.11 apache Logdecoder1 LogDecoder 1
I want to create an alarm that can tell me that the Event Souce 18.104.22.168 in apached stopped sending logs or the quantity has diminished .
Is that possible? How?