It would be great to have SIEM log failure alerting separate for Endpoints (event logs) and network equipment/other connectors. Use case: I'd like to know if a sonicwall stops sending logs to a syslog connector within 4 hours of failure, but don't want to be alerted if a workstation is offline and not sending logs. It would be great to have separately controlled thresholds/per source with a default for that type of source available as well.