We have 4 tasks that run on different schedules and log an event in the application logs when the job starts. The task is to alert if the job doesn't run on a prescribed schedule. Can this be done with a single search command ?
Yes you can achieve it. If you have Started at as a separate field then by extracting the Hours separately and compare with epoc time. Else you need to write a regex to extract Started at filed and achieve it .
Example: If this job need to start at 4 am but it started at 6 am. lets see how we can check it and trigger a alert.
started at : 8/29/2018 6:00:00 AM. You can write an alert.