Scheduled search

Use the Scheduled search option to schedule a search and view the results.

You can schedule a search that runs at a specific time of day or night. If you schedule a search to run in the night, you can investigate in the morning. Unlike reports, you have the option of grouping the search results and investigating further. You can search on number of failed logins in your network group. If the result is typically 10 and the result of the search is 100, you can group the search results for easier investigating. To see which user has the most failed logins, you can group by user name. You can continue to investigate further.

You can schedule a search on events or flows from the Reports tab. You must select a previously saved set of search criteria for scheduling.

  1. Create a report

    Specify the following information in the Report Wizard window:

    • The chart type is Events/Logs or Flows.
    • The report is based on a saved search.
      Note: QRadar does not support reports based on AQL searches that contain subselect statements.
    • Generate an offense.

      You can choose the create an individual offense option or the add result to an existing offense option.

      You can also generate a manual search.

  2. View search results
You can view the results of your scheduled search from the Offenses tab.
  • Scheduled search offenses are identified by the Offense Type column.

    If you create an individual offense, an offense is generated each time that the report is run. If you add the saved search result to an existing offense, an offense is created the first time that the report runs. Subsequent report runs append to this offense. If no results are returned, the system does not append or create an offense.

  • To view the most recent search result in the Offense Summary window, double-click a scheduled search offense in the offense list. To view the list of all scheduled search runs, click Search Results in the Last 5 Search Results pane.

You can assign a Scheduled search offense to a user.