Control scheduled execution
Open a detection from Detections, then select its Settings tab. A detection needs a published version before scheduled execution can be enabled. Use Enabled to start or pause scheduled runs. Run cadence offers no schedule, every 10 minutes, every 30 minutes, hourly, every 6 hours, or every 24 hours. Check both the enabled state and cadence when a detection is not running. Disabling a schedule does not erase the published version. Draft edits do not affect scheduled execution until they are published.Inspect executions
Open Executions and select a run to inspect its status, error, and emitted rows. Distinguish an execution failure from a successful run with no findings. If expected alerts are missing:- Verify the detection has a published version and an enabled schedule.
- Confirm its required integrations and log streams are available.
- Check ingestion freshness for the time window being evaluated.
- Inspect the scheduled execution’s output and any errors.
- Check the minimum severity and existing alert activity before assuming every emitted row should create a new alert.