Activity Log Event ScheduledSearch/Query
Event for a query that is part of a scheduled search
Field Type | Type | Availability | Description |
---|---|---|---|
@id | |||
@ingesttimestamp | |||
@rawstring | |||
@timestamp | |||
@timestamp.nanos | |||
@timezone | |||
category | Category of the event, such as Alert, Request, IngestFeed, Fdr, Query, Action, and ScheduledSearch | ||
dataspace | Repository or view name | ||
exception | The exception class that caused an error | ||
exceptionMessage | Detailed error message that will include errors at the cluster-level that may have contributed; for example permission, API, or network issues | ||
externalQueryId | External ID of the running query | ||
#category | |||
#repo | |||
#severity | |||
message | Message of the alert or event | ||
orgId | Organization ID | ||
plannedExecutionTime | Planned execution timestamp | ||
queryID | Unique Query ID | ||
scheduledSearchId | Scheduled search ID | ||
scheduledSearchName | Scheduled search name | ||
severity | Severity of the event | ||
status | Whether the alert, scheduled search, or scheduled report was successful (value Success) or failed (value Failure). An individual failure may be triggered for multiple reasons, but repeated failures over a period of time may indicate a problem that needs investigation. | ||
subCategory | Subcategory of the event | ||
suggestion | Suggestion text for how to resolve the error or warning from the event | ||
timestamp | Timestamp in milliseconds of the event | ||
viewId | View ID |