I am not sure this is running the reports every 5 minutes, 1hour, or 24 hours as I think I set it up. I tried to trip an alert with logging in wrong but didn't get anything on my dash board. If I set up send email I get one every 5 minutes but I that I am not running the search again - just getting the PDF every 5 minutes....
Do I need to set these up as alerts? I was hoping on using the dash board - here is one of the dash boards:
eventtype=failed_login hoursago=24 | stats latest(_time) AS time, count by username, host | search count > 3 | convert ctime(time)
I need this to run every 24 hours same with the 1 hour and 5 minute dashboards
I clicked the autorun in the editing of dashboards...I found some stuff in XML reference manua for refresh but no examples...
thanks
... View more