Cortex XDR 3.x
Scheduled Queries reference information
Descriptions of the fields in the Scheduled Queries table.
Last updated
Was this helpful?
Descriptions of the fields in the Scheduled Queries table.
Building Cortex Query Language (XQL) queries in the Query Builder requires a Cortex XDR Pro license.
The table below ists the common fields in the Scheduled Queries page.
Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.
BQL
Whether the query was created by the native search.
Native search has been deprecated, this field allows you to view data for queries performed before deprecation.
ISSUED BY
User who ran or scheduled the query.
NEXT EXECUTION
For queries that are scheduled to run at a specific frequency, this displays the next execution time.
For queries that were scheduled to run at a specific time and date, this field will show None.
PUBLIC API
Whether the source executing the query was an XQL query API.
QUERY DESCRIPTION
Query parameters used to run the query.
QUERY ID
Unique identifier of the query.
QUERY NAME
For saved queries, the Query Name identifies the query specified by the administrator.
For scheduled queries, the Query Name identifies the auto-generated name of the parent query. Scheduled queries also display an icon to the left of the name to indicate that the query is reoccurring.

QUERY SYNTAX
The exact syntax used to write the query.
SCHEDULE TIME
Frequency or time at which the query was scheduled to run.
XQL
Whether the query was created by XQL search.
Last updated
Was this helpful?
Was this helpful?
