Forum Discussion
VikramJha
Oct 13, 2021Copper Contributor
Hunting "Run all Queries"
Hi there! Is there a way that we can automate or schedule "Run all queries" button under Hunting to run every day. Let's say every day morning 8AM it run all queries automatically and se...
msraj
Oct 13, 2021Copper Contributor
If you want to run as a scheduled task, Use the same script from hunting queries and create Analytics Rules. If I am not wrong hunting queries result will not be saved, for future use.
- VikramJhaOct 13, 2021Copper Contributormsraj, Thanks for responding. With scheduled task and analytics rules you can run one query at a time. I'm looking for running all the queries mentioned under Hunting section at once. This is more of a manual job to click that button "Run all queries" to see the results.
- msrajOct 13, 2021Copper ContributorI don't think Sentinel has that option rather than creating Analytics Rules for each query, in fact, the result from hunting queries are temporary for the session.