You may follow below link
https://community.ibm.com/community/user/security/discussion/monitoring-log-source-stopped-sending-logs-for-cluster-log-sources-1
------------------------------
Sarat Sekhar
------------------------------
Original Message:
Sent: Tue February 21, 2023 10:28 PM
From: Cyber Post
Subject: Should not trigger the log stoppage [Service disruption] rule !!
Hi,
We have a requirement not to trigger a Log stoppage (Service Disruption) Rule when one Firewall is working in HA mode and when one take active and another becomes standby.
Should not trigger a Rule for log stoppage from one FW when the other one in HA is working fine and sending logs .
Only Create an offense if both firewalls are stopped sending events to QRadar?
Could someone give me the condition or logic of the same ?