pls can i get a query to set up an alert for when a scheduled job failed to run
Hi @whitecat001,
Alerts (scheduled searches with alert actions enabled) can fail to run for many reasons. For example, searches can fail because of SPL syntax errors, searches can be skipped because of scheduling contention, actions can fail, or splunkd may not be running.
What is your definition of "failed to run?"