Scheduled Queries reference information ↗
The table below lists the common fields in the Scheduled Queries page.
Note
Certain fields are exposed and hidden by default. An asterisk (*) is beside every field that is exposed by default.
Scheduled Queries table
| Field | Description |
|---|---|
| BQL | <p>Whether the query was created by the native search.</p><p>Native search has been deprecated, this field allows you to view data for queries performed before deprecation.</p> |
| ISSUED BY | User who ran or scheduled the query. |
| MITRE ATT&CK TACTIC | MITRE ATT&CK tactics tagged in the scheduled query. |
| MITRE ATT&CK TECHNIQUE | MITRE ATT&CK techniques tagged in the scheduled query. |
| NEXT EXECUTION | <ul><li><p>For queries that are scheduled to run at a specific frequency, this displays the next execution time.</p><p>For queries that were scheduled to run at a specific time and date, this field will show None.</p></li></ul> |
| PUBLIC API | Whether the source executing the query was an XQL query API. |
| QUERY DESCRIPTION | Query parameters used to run the query. |
| QUERY ID | Unique identifier of the query. |
| QUERY NAME | <ul><li>For saved queries, the Query Name identifies the query specified by the administrator.</li><li>For scheduled queries, the Query Name identifies the auto-generated name of the parent query. Scheduled queries also display an icon to the left of the name to indicate that the query is recurring.</li></ul><p> </p> |
| QUERY SYNTAX | The exact syntax used to write the query. |
| SCHEDULE TIME | Frequency or time at which the query was scheduled to run. |
| XQL | Whether the query was created by XQL search. |
</p>