Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖 🔔 ੆Help button for documentation
    • Terminology Reference
      • Actions
      • Aggregate Alert
      • Aggregation
      • Alert
      • Anomaly Detection
      • API (Application Programming Interface)
      • API Tokens
      • archiving
      • Arrays of Arrays
      • Arrays of Objects
      • Asset
      • Asset Permissions
      • Authentication
      • Authorization
      • Automated Actions
      • Automatic user provisioning
      • Auxiliary node
      • Backfilling
      • Backup
      • Baseline
      • Bearer Token
      • Beats
      • Blocklist
      • Bloom Filter
      • Bucket
      • Built-in Parsers
      • Cardinality
      • Cartesian Product
      • Checksum
      • Cluster
      • Cluster Management
      • Cold Storage
      • Compression
      • Configuration
      • Correlation
      • Cost Points
      • CrowdStrike Query Language (CQL)
      • Cron
      • CrowdStrike Parsing Standard (CPS)
      • Custom Resource Definitions (CRD)
      • customKey
      • Dashboard
      • Data Export
      • Data Ingestion
      • Data Retention
      • Data Visualization
      • Datasource
      • Deployment
      • Dynamic Configuration
      • Elastic Bulk API
      • Endpoint
      • Enrichment
      • Environment Variables
      • Ephemeral User Token
      • Event
      • Event Fields
      • Event List
      • externalQueryId
      • Extraction
      • extraLogFields
      • Field
      • Field Aliasing
      • Field Data Types
      • Field Mapping
      • Fields Panel
      • Filter
      • Filter Alert
      • Format Event List Panel
      • Function
      • Glob Pattern
      • GraphQL
      • Group synchronization
      • groupBy()
      • Groups
      • HEC (HTTP Event Collector)
      • Histogram
      • Hot Storage
      • Humio Operator
      • HumioCluster
      • Identity Provider (IdP)
      • Immutability
      • Indexing
      • Ingest Rate
      • Ingest Token
      • Ingestion
      • @ingesttimestamp
      • Inspection Panel
      • Installation
      • Integration
      • IP Filters
      • Join
      • Kubernetes
      • LDAP (Lightweight Directory Access Protocol)
      • License Management
      • Live Query
      • Load Balancing
      • Log Shipper
      • Falcon LogScale Collector
      • LogScale Query Language (CQL)
      • Lookup Files
      • Lookup Table
      • LZ4
      • Multi-Cluster-Search
      • Multi-Cluster View
      • Memory Limits
      • Metadata
      • Metadata Fields
      • Monitoring
      • Multi-Cluster Search
      • Nested Arrays
      • Node
      • Non-Sensitive Events
      • Notification
      • OAuth
      • OpenID Connect (OIDC)
      • Operator
      • Organization
      • Organization-owned queries
      • Organization Owner
      • Package
      • Parser
      • Parser Assignment
      • Parser Editor
      • Permissions
      • Persisted Aggregation
      • Persisted Aggregation Backfill
      • Persisted Aggregation Repository
      • Persistent queries
      • Pipeline
      • Proxy Authentication
      • Query
      • Query Coordinator
      • Query Editor
      • Query prefix
      • Query Profiling
      • Query Quotas
      • Query Work
      • RBAC (Role-Based Access Control)
      • Real-time
      • Regex (Regular Expression)
      • Regular Expression Engine V2
      • Repository
      • Repository Permissions
      • REST API
      • Result
      • Reverse Proxy
      • Roles
      • Security Assertion Markup Language (SAML)
      • Saved Search
      • Scheduled Search
      • Scheduled Search Backfill
      • Search
      • Search Interface
      • Security
      • Security Policies
      • Segment
      • Sensitive Events
      • SIEM (Security Information and Event Management)
      • Static Query
      • Structured Array Syntax
      • Syslog
      • Tag
      • Tag Fields
      • Tagging
      • Template Language
      • Threshold
      • Throttling Period
      • Time Interval Selector
      • TimeChart
      • @timestamp
      • Timestamp Parsing
      • Token
      • Tool Panel
      • Transformation
      • Triggers
      • User Account
      • User Interface (UI)
      • User Management
      • User Roles
      • Vhost
      • View
      • View-based Access Control
      • Visualization
      • Webhook
      • Widget
      • Widget Selector
      • Worker Node
      • Zstd
Falcon LogScale Documentation
/ LogScale Terminology

Scheduled Search

A query that runs automatically at specified intervals (hourly, daily, weekly, etc.). Scheduled searches can generate reports, populate summary data, or trigger actions based on their results. They're useful for regular reporting, data maintenance tasks, and batch processing workflows.

Related Content
  • Scheduled searches

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

  • Other articles on this topic

    • Actions Properties
    • Advanced Settings
    • Aggregate Alert Errors and Solutions
    • Automation
    • Automations
    • Configuration Properties
    • Create Scheduled Reports
    • Create Triggers
    • Create a Scheduled PDF Role using the web interface
    • Cron Scheduling
    • Delay run
    • Edit Scheduled Reports
    • Edit Triggers
    • Errors when Using Live join() Functions
    • Filter Alert Errors and Solutions
    • General Information About Triggers
    • General Properties
    • Ingest delay handling for aggregate alerts
    • Ingest delay handling for legacy alerts
    • Legacy Alert Errors and Solutions
    • LogScale Overview
    • Manage Triggers
    • Managing Scheduled Reports
    • Monitor Trigger Execution through the humio-activity Repository
    • Monitor, Diagnose, and Troubleshoot Triggers
    • Retry for aggregate alerts
    • Schedule PDF Reports
    • Scheduled Report Errors and Resolutions
    • Scheduled Report Operation and Limitations
    • Scheduled Reports Security
    • Scheduled Search Errors and Solutions
    • Throttling for aggregate alerts
    • Throttling for legacy alerts
    • Time window for aggregate alerts
    • Time window for legacy alerts
    • Timestamp for aggregate alerts
    • Timestamp for legacy alerts
    • Trigger Management
    • Trigger Properties
    • Triggers
    • What Trigger Type to Choose
  • Related Guidance Articles

    • How-To: Edit schedule and timestamp in scheduled searches
  • Related Release Notes

    • Falcon LogScale 1.100.0 LTS (2023-08-16)
    • Falcon LogScale 1.100.1 LTS (2023-10-28)
    • Falcon LogScale 1.100.2 LTS (2023-11-15)
    • Falcon LogScale 1.100.3 LTS (2024-01-22)
    • Falcon LogScale 1.102.0 GA (2023-08-08)
    • Falcon LogScale 1.106.0 GA (2023-09-05)
    • Falcon LogScale 1.106.2 LTS (2023-09-27)
    • Falcon LogScale 1.106.4 LTS (2023-10-28)
    • Falcon LogScale 1.106.5 LTS (2023-11-15)
    • Falcon LogScale 1.106.6 LTS (2024-01-22)
    • Falcon LogScale 1.109.0 GA (2023-09-26)
    • Falcon LogScale 1.112.1 LTS (2023-11-15)
    • Falcon LogScale 1.112.2 LTS (2024-01-22)
    • Falcon LogScale 1.112.3 LTS (2024-01-30)
    • Falcon LogScale 1.112.4 LTS (2024-02-23)
    • Falcon LogScale 1.113.0 GA (2023-11-09)
    • Falcon LogScale 1.118.2 LTS (2024-01-17)
    • Falcon LogScale 1.118.3 LTS (2024-02-06)
    • Falcon LogScale 1.118.4 LTS (2024-02-23)
    • Falcon LogScale 1.79.0 GA (2023-02-28)
    • Falcon LogScale 1.85.0 GA (2023-04-13)
    • Falcon LogScale 1.88.0 LTS (2023-05-24)
    • Falcon LogScale 1.88.1 LTS (2023-06-22)
    • Falcon LogScale 1.88.2 LTS (2023-07-04)
    • Falcon LogScale 1.89.0 GA (2023-05-11)
    • Falcon LogScale 1.94.0 LTS (2023-07-05)
    • Falcon LogScale 1.94.1 LTS (2023-10-28)
    • Falcon LogScale 1.94.2 LTS (2023-11-15)
    • Falcon LogScale 1.97.0 GA (2023-07-04)
  • Related GraphQL API

    • createAggregateAlert()
    • createAlert()
    • createFilterAlert()
    • deleteAggregateAlertV2()
    • deleteAlert()
    • deleteFilterAlert()
    • deleteFilterAlertV2()
    • deleteLegacyAlert()
  • Security (humio-audit) Events

    • Audit Log Event scheduled-search.create
    • Audit Log Event scheduled-search.delete
    • Audit Log Event scheduled-search.update

Enter search term