Scheduling Hunts
Scheduling hunts provide you with the ability to search selected assets using forensic jobs to detect suspicious behavior.
To schedule a hunt:
- Click Investigations from the InsightIDR menu.
- From the Investigations page, click the Schedule Hunt link.
- When the New Scheduled Hunt screen appears, enter the name of the Hunt in the Hunt Name field.
- Enter the asset(s) to include. A list displays after you type in a few characters in the Assets field.
- Select the frequency you want to schedule the hunt from the Frequency dropdown menu.
- Enter the time you want to run the Hunt in the Schedule Time field. Use the HH:MM:SS format.
- Select a job from the Job dropdown menu.
- Enter the job parameters in the Job Parameters field.
- Click the Schedule button.
The Scheduled Hunt returns results based on the parameters you selected. The following screen capture displays the results from a Scheduled Hunt.
What's Next?