Would you consider creating an output module for email? It would be quite useful for generating alerts. While one can use exec_async to send email, it is rather cludgy.
NXlog (last vrsion from this site) installed on windows server 2012R2
Configured to get win-logs:
I have multiple windows hosts sending events in binary to a single tcp listener.<Input windows>
I am trying to track the rate of logs from the servers and create email alerts when the rate either drops or crosses a high watermark per hour.
To do that I need to create a stat / variable appending the hostname and hourstamp such as