Scheduled Ruledetection and target the
Scheduled Querycreated in above.
Scheduled Queryruns, that matchin rows will be passed through the rules engine.
Scheduled Rulereturns any hits, one or more
Alertswill be generated from the data and dispatched accordingly.
Data -> Data Explorercreate a new query or open a saved query.
Save asbutton which will popup a window. Toggle the
Is this a Scheduled Query?indicator toggle to
1-5is Monday through Friday) or commas, for example
Day of Weekfield will execute the command only on Sundays, Mondays and Thursdays. Currently, we do not support using named days of the week or month names.
+sign to create a new Detection.
Functions and Teststab either enter your own custom Python code, or if all your filtering logic is already taken care of in the SQL, you can simply make sure that the event is set to return true for each row.
Save, the rule will become active and be run over the SQL at an interval detected by the run frequency of the scheduled query, assuming any rows are returned by the query.
Data -> Saved Queries. By using the checkbox next to the query name to select multiple queries, you may also delete queries, individually or in bulk. Please note that scheduled queries must be unlinked from their respective rules in order to be deleted. This is to prevent users from accidentally erasing queries used by scheduled rules.
Is Activetoggle to off