question

HillmanCorey-4611 avatar image
0 Votes"
HillmanCorey-4611 asked ·

Is it possible to create an alert in Azure Sentinel for when a data source stops feeding logs?

I am trying to create an alert query that will let me know if a specific source has not provided logs within 7 days, but I am not sure the what syntax would allow for this. It is simple to find entries older than 7 days, but is it possible to alert if there are no entries younger than 7 days available? Thanks in advance for any assistance.

azure-monitorazure-sentinel
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

RoyKim-2230 avatar image
1 Vote"
RoyKim-2230 answered ·

You can make a log analytics query to to count the number of logs returned for a certain period and create an alert based on that. But no direct feature for that.

· 1 · Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Excellent, this will work for my purposes! Thanks!

0 Votes 0 ·