I've been trying to resolve this since October and not getting traction. Turning to the community for help:
I have seemingly contradictory information within the same log line makes me question- do we have an issue or not? On the one hand, i think i do because the history command shows the search is cancelled... and I trust this information. However, there are artifacts in the logs that make me question if the search is fully running (which appears to be true since "fully_completed_search=TRUE"... so I am now confused if we have a problem or not.)
Why do searches show fully_completed_search=TRUE and has_error_warn=FALSE when the info field (and history command) show "cancelled" and have a tag of "error"
BOTTOM LINE QUESTION: Are my searches are running correctly and returning all results or not?
Sample _audit log search activity that I found - not sure if this gives any usable insight