Loading

Schedule runs from the Attacks view

Create a schedule so Attack Discovery runs automatically at intervals you choose. From the Attacks view, define how often analysis runs, which alerts to include, and optionally notify your team when discoveries are found.

Important

After you turn on Attack Discovery Workflows, existing schedules keep their previous configuration until you edit and save them. Each scheduled run also opens a new Elastic Agent Builder conversation you can view later from Workflow execution details.

To create a schedule:

  1. Go to DetectionsViewsAttacks, then select ScheduleCreate new schedule.
  2. Name the schedule and choose an LLM connector for generation.
  3. Configure which alerts to analyze. For example, keep skill retrieval on and add an ES|QL query to focus on high-severity alerts.
  4. Set how often the schedule runs, such as every 24 hours.
  5. (Optional) Add notification connectors and actions, then select Create & enable schedule. Supported notification connectors include Slack, ServiceNow, Jira, PagerDuty, Cases, Email, and Webhook.

To create a schedule:

  1. Go to DetectionsViewsAttacks, then select ScheduleCreate new schedule.
  2. Name the schedule and choose an LLM connector for generation.
  3. Configure which alerts to analyze.
  4. Set how often the schedule runs, such as every 24 hours.
  5. (Optional) Add notification connectors and actions, then select Create & enable schedule. For example, send a Slack or email notification when discoveries are found.

After creating a schedule, you can edit, enable, disable, or delete it. To change several at once, select them in the table and use Bulk actions. Schedule management requires the Schedules → Allow changes privilege. To manage schedules programmatically, use the Attack discovery API.

Scheduled discoveries show a calendar icon. For how to recognize scheduled versus manually generated attacks, refer to Recognize manually generated and scheduled attacks.