Splunk Enterprise Security

Pleas help with an SPL to find the reason for saved / skipped searches in ES.


I have MC on the ES & tried my SPLs but need your help please. I need to find the apps, name of skipped searches & why the searches were skipped? Thank u in advance.

It should be in the MC already, but maybe this will help you.

index=_internal host=* sourcetype=scheduler status="skipped" 
| stats count(savedsearch_name) as "Total Skipped" by app search_type reason savedsearch_name 
| sort - "Total Skipped" 
