Hi there,
Kindly help me on Search to trigger an alert by scan the logs for scheduled job and check elapsed time (threshold time) for each job execution instance If the elapsed time exceeds the specified threshold for ALL the three executions.
Thanks in Advance,
Regards,
Theja
Hi
Can you provide some example events for generating this alert. Please add those events inside </> block in editor to avoid changes for those.
r. Ismo
Please find the attached event details
<9/18/22
1:20:02.949 AM
2339972421 [KNT(400345)-XXX.XXX.XX.XX-44] DEBUG 2022-09-17T21:20:02.949 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
<9/18/22
1:20:00.646 AM
2339970118 [KNT(400345)-XXX.XXX.XX.XX-44] DEBUG 2022-09-17T21:20:00.646 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
<9/18/22
1:20:00.436 AM
2339969908 [KNT(400345)-XXX.XXX.XX.-96] DEBUG 2022-09-17T21:20:00.436 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
<9/17/22
11:20:05.857 PM
2332775329 [KNT(399133)-XXX.XXX.XX.XX-44] DEBUG 2022-09-17T19:20:05.857 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
<9/17/22
11:20:03.029 PM
2332772501 [DNI(399133)-XXX.XXX.XX.XX-44] DEBUG 2022-09-17T19:20:03.029 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
<9/17/22
9:20:06.065 PM
2325575537 [KNT(397937)-XXX.XXX.XX.XX-44] DEBUG 2022-09-17T17:20:06.065 com.jip.vds.grip.ViewCachehandler [] - getViewCache: the view 'infa_dev.dev_agent_transation' already exists in cache
host = Server_details source = Sours_ details sourcetype = grip_dev />
Note:- We are trying to customize the logs with Job start timestamp and job end timestamp
Thanks in Advance,
Thanks and Regards,
Theja