The NDR Scheduled Queries feature allows you to regularly query network traffic. The results of these scheduled queries are viewable in the NDR Web UI dashboard. You can also forward results in CEF format to a SIEM.
This section describes how to use the Scheduled Queries to perform the following tasks:
Important
IPv4 and IPv6 CIDR format addresses are not supported in scheduled searches.
Prerequisites
In order to schedule queries, your NDR appliance must be running NDR software version 1.2.0 or above.
Adding a scheduled search
The Scheduled Queries feature is located under the CONFIGURATION tab and is used to access the Scheduled Setup window. When you are ready to schedule a query, access this window and enter your scheduling parameters.

There are two types of scheduled searches: schedule and interval. A scheduled search runs weekly, daily, or hourly on a specified hour, minute, and day. An interval search is a fixed time period in minutes or hours. For example, the interval 1h means the query is run every hour from now on.
When scheduling searches, you can use a saved query or enter a new custom query.
The Scheduled Setup also features a Look Back Period, which is defined as the historical period of data that is searched by the scheduled search. The Look Back Period has two setting options: auto and custom. By default, when you enter a query in the Query Bar, NDR searches the past 5 minutes of session data. Select auto when you want NDR to apply the default time to the scheduled search. Select custom to define a specific time frame you want NDR to search. For example, you if you want to search the last 7 days of session data, you would enter 7d in the Look Back Period field. You can enter any value between 1 to 23 hours or 1 to <Retention period: The period for which the data is available on your appliance> days.
The Condition setting allows you to control when you want to receive a report of the search results. When the condition is met, NDR generates a report on the Scheduled Queries page. For example, if you want to trigger a report when more than 5 search results are returned, select > and enter 5 in the Condition field.
You can access and view a query report on the Scheduled Queries page by using the arrow next to the query name. You can also forward the results to a syslog server. You must add the hostname or IP address of the host, the port number, and the name of the syslog facility.
A maximum of 10 results are written to the syslog server with the name and timestamp of the scheduled search.
Note
Queries must be created and saved before they can be scheduled. You can save queries in the dashboard.
To add a scheduled search using the Web UI:
Click
and from CONFIGURATION, select Scheduled Queries.Select the + Add Schedule button.
Name the schedule. The name must be alphanumeric with underscores and no spaces.
Select the schedule type.
For Schedule, enter the time and day.
For Interval, enter query syntax.
Select the query type.
For Saved, select a query you saved in the NDR dashboard.
For Custom, enter the interval string.
Select the condition.
Select Yes if you want to forward the results to a syslog server.
If you select Yes, enter the hostname or IP address of the host, the port number, and the name of the syslog facility.
Activating or deactivating a scheduled search
To activate or deactivate a scheduled search using the Web UI:
Click
and from CONFIGURATION, select Scheduled Queries.In the State column, select the state to change it.
Viewing search results
The NDR retains up to ten sets of scheduled search results and lists them on the Scheduled Queries page. Older search results are automatically deleted.
To view search results using the Web UI:
Click
and from CONFIGURATION, select Scheduled Queries.Click on the arrow next to the selected query to view the results.
Editing or deleting a search
To edit or delete a scheduled search using the Web UI:
Click
and from CONFIGURATION, select Scheduled Queries.Select the Settings icon for the query that you want to edit or delete.
Select Delete or Edit.