Have a task on a server that I want to monitor.
Can I search for specific event from that server and get an alert if it's spotted?
How does that search look like?
@mceye
It depends on the events of the task scheduler. For e.g. if you have the logs from tasks available in splunk, you can search for the string which tells you whether the task was executed successfully or not. If you do not see this event (it's either failed or didn't run) for a specific time (schedule) send an alert
For e.g. if a successful task execution shows as "task=task1, status=completed" , you can search for this event and send an alert if no results found.
It would be helpful if you could share some sample events