Hi,
My cs is not raising an alerts, when I search index=_internal sourcetype=scheduler "xyz- CS" log_level=INFO
07-14-2023 12:50:00.552 +0000 INFO SavedSplunker - savedsearch_id="nobody;SplunkEnterpriseSecuritySuite;Audit - CP - PDM Uploads Non Colgate instances - Rule", search_type="scheduled", user="abc", app="SplunkEnterpriseSecuritySuite", savedsearch_name="xyz- CS - Rule", priority=default, status=continued, reason="Could not get next runtime", scheduled_time=0, window_time=-1