For the complete documentation index, see llms.txt. This page is also available as Markdown.
Cortex XDR 3.x

Manage scheduled queries

Learn how to manage your scheduled and recurring queries.

Notice

Building Cortex Query Language (XQL) queries in the Query Builder requires a Cortex XDR Pro license.

The Scheduled Queries page displays information about your scheduled and recurring queries. From this page, you can edit scheduled query parameters, view previous executions, disable, and remove scheduled queries. Right-click a query to see the available options.

View executed queries
  1. Select Investigation → Scheduled Queries.

  2. Locate the scheduled query for which you want to view previous executions.

    If necessary, use the Filter to reduce the number of queries returned.

  3. Right-click anywhere in the query row, and select Show executed queries.

    Cortex XDR filters the queries on the Query Center.

Edit the query frequency
  1. Select Investigation → Scheduled Queries.

  2. Locate the scheduled query that you want to edit.

    If necessary, use the Filter to reduce the number of queries returned.

  3. Right-click anywhere in the query row and then select Edit.

  4. Adjust the schedule settings, and then click OK.

Last updated

Was this helpful?