Activity Log Event ScheduledSearch/Action
Event for actions from a scheduled search
Field Type | Type | Availability | Description |
---|---|---|---|
actionId | ID of triggered action; only set for the invocation of a specific action | ||
actionIds | List of action IDs for when an alert or scheduled search trigger has been triggered for an event | ||
actionInvocationId | Unique ID for the invocation of an action, can be used to correlate logs; only set for the invocation of a specific action | ||
actionInvocationIds | List of action invocation IDs for when an alert or scheduled search has been triggered | ||
actionName | Name of the triggered action; only set for the invocation of a specific action | ||
@id | |||
@ingesttimestamp | |||
@rawstring | |||
@timestamp | |||
@timestamp.nanos | |||
@timezone | |||
category | Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch | ||
dataspace | Repository or view name | ||
events | Number of the events returned by the query | ||
exception | The exception class that caused an error | ||
exceptionMessage | Detailed error message that will include errors at the cluster-level that may have contributed; for example permission, API, or network issues | ||
externalQueryId | External ID of the running query | ||
#category | |||
#repo | |||
#severity | |||
message | Message of the alert or event | ||
orgId | Organization ID | ||
plannedExecutionTime | Planned execution timestamp | ||
queryFinishedTime | Time in milliseconds when query in scheduled search finished | ||
queryIntervalEndTime | |||
queryIntervalStartTime | |||
queryProcessedEvents | Number of events processed to return the final result set | ||
queryTimeMillis | Time elapsed in milliseconds to execute the query. This value can be used to help indicate the load of the query (and therefore any optimization or refinement), or to find outliers during execution. | ||
scheduledSearchId | Scheduled search ID | ||
scheduledSearchName | Scheduled search name | ||
severity | Severity of the event | ||
status | Whether the alert, scheduled search, or scheduled report was successful (value Success) or failed (value Failure). An individual failure may be triggered for multiple reasons, but repeated failures over a period of time may indicate a problem that needs investigation. | ||
subCategory | Subcategory of the event | ||
suggestion | Suggestion text for how to resolve the error or warning from the event | ||
timestamp | Timestamp in milliseconds of the event | ||
viewId | View ID |