Activity Log Event ScheduledSearch/Action

Event for actions from a scheduled search

Field TypeTypeAvailabilityDescription
actionId   ID of triggered action; only set for the invocation of a specific action
actionIds   List of action IDs for when an alert or scheduled search trigger has been triggered for an event
actionInvocationId   Unique ID for the invocation of an action, can be used to correlate logs; only set for the invocation of a specific action
actionInvocationIds   List of action invocation IDs for when an alert or scheduled search has been triggered
actionName   Name of the triggered action; only set for the invocation of a specific action
@id   
@ingesttimestamp   
@rawstring   
@timestamp   
@timestamp.nanos   
@timezone   
category   Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch
dataspace   Repository or view name
events   Number of the events returned by the query
exception   The exception class that caused an error
exceptionMessage   Detailed error message that will include errors at the cluster-level that may have contributed; for example permission, API, or network issues
externalQueryId   External ID of the running query
#category   
#repo   
#severity   
message   Message of the alert or event
orgId   Organization ID
plannedExecutionTime   Planned execution timestamp
queryFinishedTime   Time in milliseconds when query in scheduled search finished
queryIntervalEndTime   
queryIntervalStartTime   
queryProcessedEvents   Number of events processed to return the final result set
queryTimeMillis   Time elapsed in milliseconds to execute the query. This value can be used to help indicate the load of the query (and therefore any optimization or refinement), or to find outliers during execution.
scheduledSearchId   Scheduled search ID
scheduledSearchName   Scheduled search name
severity   Severity of the event
status   Whether the alert, scheduled search, or scheduled report was successful (value Success) or failed (value Failure). An individual failure may be triggered for multiple reasons, but repeated failures over a period of time may indicate a problem that needs investigation.
subCategory   Subcategory of the event
suggestion   Suggestion text for how to resolve the error or warning from the event
timestamp   Timestamp in milliseconds of the event
viewId   View ID