I was wondering if there was a way to have an alert sent to an email address, after a Splunk search has been running for over a certain duration of time?
index = _* sourcetype=audittrail info!=canceled | stats list(info) min(_time) as min max(_time) as max list(total_run_time) list(search) by search_id user