Saved Searches
Store and reuse search queries in Spyderbat. Enable notifications and SIEM forwarding on saved queries to automate alerting and event delivery.
Create a saved search
Example: monitor new cron jobs

Run the query to verify it returns results before saving. 
Click Save Search to open the saved search configuration dialog. 
Configure the name, description, and notification status for the saved search. 
Select a notification channel and configure its destination.
SIEM Forwarding
Manage saved searches with spyctl
Retrieve saved searches
Create a saved search
Edit a saved search
Last updated
Was this helpful?