I have a saved search need to check the each hour the search is being executed based on the cron configuration.
Expected Result:
Savedsearch Name | Cron config | Number of time executed | Search |
Sav1 | */5 * * * * | 12 | Search ran all 12 times |
Sav2 | */10 * * * * | 6 | Search skipped at 5 run |
In alerts for splunk admins https://splunkbase.splunk.com/app/3796/ there is an example alert for skipped searches and the reason
This finds which searches were skipped.
In alerts for splunk admins https://splunkbase.splunk.com/app/3796/ there is an example alert for skipped searches and the reason
This finds which searches were skipped.