Schedule a Background Search in the Event Viewer
Schedule a recurring query in the background in the event viewer page. You can modify or cancel the scheduled search at any time. You can also modify an existing query to be a recurring search.
|
|
Use the following steps to create a scheduled background search:
Procedure
1 |
In the Security Cloud Control platform menu, choose . |
2 |
In the navigation bar, choose . |
3 |
Click the Historical tab to view historical events. |
4 |
In the search bar, type the search expression you want to search for. Click the Search drop-down button and choose Search in Background. |
5 |
(Optional) Rename the search. |
6 |
The Search now check box is checked by default. When checked, the search starts upon saving; if unchecked, the background query runs only as a future search. |
7 |
Check the Setup recurring schedule and configure the following settings:
|
8 |
Confirm the scheduled search criteria at the bottom of the window. Click Schedule and Search Now. If you did not opt for the search to start immediately, click Schedule Search. |
What to do next
Results from a scheduled background search are available for review for up to 7 days before Security Cloud Control automatically deletes them.