Reporting

Create Alert for Failed Scheduled Saved Search

rajim
Path Finder

I need to create an alert for failed scheduled saved searches. If any scheduled saved searches fails to run due to scheduler problem or any reason, then it would trigger an alert. Can anyone please help me here?
I have tried and found different scheduling status as shown in the attachment.

alt text

Among these status values which one should I use for this purpose I'm not sure. So any guidance is welcome.

0 Karma
1 Solution

bandit
Motivator

You can limit it to run on your search heads by adding a pattern or list for your search heads to the query below i.e.

host IN(host01,host02)

index=_internal sourcetype=scheduler status!=success 
| table _time search_type status user app savedsearch_name

View solution in original post

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...