Saving, Scheduling, and Alerting on Log Queries
A query built in the Explorer lives only as long as the browser tab, unless you do something with it. This page covers the three ways to make a query outlive that session: save it for one-click reuse, schedule it to run and deliver results automatically, or alert on it.
Saved queries
Save the exact query currently in the search bar — including its filters — with the save icon at the right edge of the search bar. Name it and pick a folder in the Save Query dialog; if RBAC is enabled, you need permission on the folder you save into.
Click Logs in the top navigation, then Saved Queries, to see every query you or your team has saved:
- Search
-
Filters the list by name.
- Name
-
Click it to re-run the query in the Explorer with its original filters.
- Created
-
How long ago the query was saved.
- Actions
-
Rename or delete the saved query.
Scheduled Search
A saved query runs when you click it. A Scheduled Search runs on a timer and delivers its results somewhere — a lookup table other queries can join against, or an email — without anyone opening the Explorer.
Click Logs in the top navigation, then Scheduled Searches, to see every configured search: Name, Folder, Status, Query, Contact point, Schedule, and the timestamp and outcome of its Last run and Next run. Click Create search to configure a new one:
- Name / Folder
-
Identifies the search. Names don’t have to be unique — each scheduled search has its own ID — but a clear name matters once you have several. RBAC, if enabled, requires permission on the folder.
- FuseQL query
-
The query to run at each tick.
- Notification
-
Where results go — a Lookup table (existing or newly created, with a Merge or Replace write mode) or Email.
- Schedule (Cron)
-
A Preset interval or a Custom cron expression. Times are UTC, and a search can’t run more often than every 15 minutes; a Next three runs preview confirms what you configured before you save.
- Time window (look-back)
-
How far back each run queries, relative to when it fires. The maximum look-back scales with how often the search runs — a search that runs every 15 minutes can look back less far than one that runs daily — and is validated at save time.
- Threshold
-
Optionally, only notify when the result row count crosses a value you set, so a scheduled search can stay quiet until there’s something worth seeing.
Configuring email delivery as the notification target requires SMTP to be configured for the platform; if it isn’t, only the lookup-table option is available.
Alerting on logs
A log-based alert rule evaluates a query continuously and notifies you the moment it crosses a threshold, rather than on a fixed schedule — the right tool when you need to know immediately, not at the next scheduled tick.
Create one from Alerts → New Alert, choosing Logs as the alert type. To see log alerts specifically rather than configure a new one, click Logs in the top navigation, then Alerts — this opens the shared Alerts view pre-filtered so only the Logs option is active under its Type filter, alongside every other alert-management control (status, severity, mute) described in that shared view.
Which one to use
| If you need… | Use… |
|---|---|
To re-run the same investigation later, on demand |
|
A recurring report, a materialized lookup table other queries can join against, or a scheduled email digest |
|
A page-worthy notification the moment a condition is true, not on a delay |
|
A continuously materialized, queryable view over a log stream — not a one-shot report |