Hi, I would like to use it as an alert, but a bit confused the trigger index=_internal group=per_index_thruput source=*metrics.log NOT series=_* | eval last_seen=now()-_time | stats max(last_seen) as seconds_since_seen by series | rename series as index | where seconds_since_seen < 120 Specifically, a value for the 'seconds_since_seen', if most indices are about the 800 second range, I am not sure if a low value like 120 seconds going to cause false positives. Any suggestions for a proper value to monitor indices would be greatly appreciated. Cheers, Paul
... View more