Create an alert when a server is down

Hello Community,

Do you have any idea about how to create an alert opendistro whenever a server is down. My KPIs are sent to Elasticsearch by metricbeat that is based on multiple servers (each document contains @timestamp and host field)?

My idea was to compare the list of hosts that match documents in the last periond of time (10 min for example) with the list of hosts that sent document in the last 24h But I stuck with the creation of monitor extraction query ( just one query request is possible)

Thnak you in advance!

Hi Sana,
you should use aggregation global and filters to achieve two sections of your aggregations with the tow ranges and then compare the values.

