I want to create a Splunk Alert if there no log generated from source file means Cron-Job Not Run.
How would be my search query will look like?
You must first have your cron logs indexed in Splunk. Write a search that looks for a successful run of the cron job. Trigger an alert if the number of results from that search is zero.
You must first have your cron logs indexed in Splunk. Write a search that looks for a successful run of the cron job. Trigger an alert if the number of results from that search is zero.
+1
For sample search, see answer by @martin_mueller in following post
https://answers.splunk.com/answers/151532/how-to-create-an-alert-if-no-data-is-generated-from-a-host...