we're using Splunk 4.3.6 with summary indexes. Sometimes the search that is filling the summary indexes, fails.
We can then backfill the summary index, but we would like to monitor if a saved searches fails.
Any smart ideas?
The SoS app can show you when scheduled saved searches were skipped. This can help alert you to possible gaps in your summary indexes. I'd start there.