Log Inactivity Detection Rules

Also known as "Up Down Monitoring," Log Inactivity Detection Rules can be used to notify you when an entire log, log group, or particular pattern becomes inactive for a given time period.

Inactivity alerting is useful for system assets that must be running constantly (such as a critical server). The ability to set the time window of inactivity gives you control over your data, your environment, and your assets, and allows for damage control and prevention of data loss.

On the Log Search page, you can create basic detection rules in two different ways:

  • Auto-populate a Log Inactivity Detection Rule
  • Manually configure a Log Inactivity Detection Rule

You can always switch to a different rule type during configuration.

Auto-populate a Log Inactivity Detection Rule

To auto-populate a log inactivity detection rule:

  1. Go to the Log Search page.
  2. Select the log or log sets you want in the rule, or use a search query to look for a specific set of logs.
  3. In the top right corner, select the Detection Rules button and choose a basic detection rule type based on the selected logs. The “Create a Basic Detection Rule" panel appears, with applicable steps already pre-populated.
  4. In the “Name” field, name your rule. Optionally provide a description.
  5. Optionally, select the Next button to complete the Trigger section.
  6. Click the Skip to alert notification link.
  7. In the “Alert Notification” section, define how you will receive notifications. Read more about Notification Settings.
  8. Define a notification throttle to control how long the log or log sets are inactive before receiving an alert, and a throttle to control the quantity of alert notifications you will receive. Read more about Alert Throttling.
  9. Click Create.

Manually configure a Log Inactivity Detection Rule

To configure a log inactivity detection rule:

  1. In InsightOps, select the Manage Alerts page, or select the Log Search page from the left menu.
  2. In the top right corner, select the Detection Rules button.
  3. Select Log Inactivity Detection Rule.
  4. In the “Name” section, name your rule.
  5. In the “Logs” section, select one or more logs or log sets you want to use in the rule.
  6. In the optional “Trigger” section, choose a saved query or optionally create a new query using keywords and regex.
    • If you do not add a trigger or pattern, the rule will automatically use the logs to detect inactivity.
  7. Optionally click the + OR button to add another pattern to monitor on the same logs.
  8. In “Trigger Settings,” customize the amount of time a log or pattern must be inactive before it triggers an alert. By default, an inactivity period of five days will trigger an alert.
  9. In the “Alert Notification” section, define how you will receive notifications. Read more about Notification Settings.
  10. Define a notification throttle to control how long the log or log sets are inactive before receiving an alert, and a throttle to control the quantity of alert notifications you will receive. Read more about Alert Throttling.
  11. Click Create.