drop siem export or event log collector export · identify machines that stopped sending logs · calculate expected vs actual log volume per host · detect hosts that went dark · flag suspicious silences · runs locally
siem / collector export
drop siem csv exports
or click
drop siem or event collector csv exports