Hello, I have Wincollect agent sending me Microsoft events from Windows server to Qradar. It's sending following types of event, security, system, application. In case the Qradar stops receiving any single one of these windows log types, I would like to have rule which will create offense to let me know. Any idea how to do it? Thank you.
------------------------------
tysa
------------------------------