I need to create an alert for failed scheduled saved searches. If any scheduled saved searches fails to run due to scheduler problem or any reason, then it would trigger an alert. Can anyone please help me here?
I have tried and found different scheduling status as shown in the attachment.
Among these status values which one should I use for this purpose I'm not sure. So any guidance is welcome.
You can limit it to run on your search heads by adding a pattern or list for your search heads to the query below i.e.
host IN(host01,host02)
index=_internal sourcetype=scheduler status!=success
| table _time search_type status user app savedsearch_name