I'm trying to get more detailed information about my scheduled saved searches, especially when they complete with success but contain errors and warnings in the stack trace.
I see that all details are stored in the $SPLUNK_HOME/var/run/splunk/dispatch folder and I am wondering if this folder can be monitored by Splunk.
Is this possible?
Thank you and best regards,
I don't see why not, any directory or file can be monitored. You'd probably want to index this into a dedicated and short-lived index since this can possibly be a significant amount of data.