Scheduled search

Prev Next

You must create a query and save it before it can be scheduled. For more information about creating a query, see Create a query by name: Request.

Use the NDR Console scheduled search feature to query network traffic regularly. When the scheduled search returns a specified number of results, a report is generated.

The NDR Console appliance retains up to 10 sets of search results. Older search results are automatically deleted. You can manually delete results. You can also create a report to save the results.

In addition to running predefined queries, the NDR Console appliance can also run queries with changing parameters. For example, you can create a query that uses a list of IP addresses from a threat feed; see Create a scheduled search: Request . You can update the IP addresses using the API; see Update a scheduled search by name: Request.

The following scheduled search endpoints are available: