List Arkime cron queries
arkime_cronsList scheduled Arkime cron queries and identify which automated search stamped a tag onto session data.
Instructions
List Arkime's cron queries — saved expressions that re-run on a schedule.
Use this for two questions. First, the same one arkime_views answers:
which searches has the human team thought worth keeping. Second, and
only this tool can answer it: where a tag came from. A cron query
re-runs its expression every few minutes and stamps its own tags onto
whatever matches, so those tags sit in session data with nothing in the
session explaining them — this list is the explanation. For saved
searches nobody schedules use arkime_views, for named value lists (IOC
sets) use arkime_shortcuts, and to see the tags actually present in the
data use malcolm_field_values on the `tags` field.
Disabled queries are listed too — one switched off last week still
explains tags already sitting in the data. A deployment with none
configured gets a plain sentence instead of an empty list; that is an
answer, not a fault (measured: the reference lab has none). Per-query
fields are in the output schema.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |