---
title: "Create a Monitor"
slug: "create-a-query"
description: "The Silent Push Monitoring feature is of particular use to security teams and/or job roles that have clearly defined defense duties focused on one or more distinct areas of an attack surface."
tags: ["Attack Surface Management", "Cyber Defense", "monitoring data", "Monitoring Feature", "Threat Intelligence"]
updated: 2026-04-23T20:28:28Z
published: 2026-04-23T20:28:28Z
---

> ## Documentation Index
> Fetch the complete documentation index at: https://help.silentpush.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Create a Query

Silent Push’s Monitoring feature is particularly useful for security teams and job roles with clearly defined defense duties focused on one or more distinct areas of an Attack Surface. By running an operation from within **DNS Data**, Defend, or **Attack Surface Managemen**t, results are generated that can be monitored to produce an email every 24 hours informing a user of any changes in the data.

## Create a Monitor

Rather than re-running the same set of queries every day, organizations can save time and resources by automating cyber defense measures across an unlimited number of attack vectors with a single click.

1. Run an operation within DNS Data, Defend, or Attack Surface Management.
  - Example: From the left navigation menu, select **DNS Data > Explore Indicator DNS Data**, type **example.com** in the **Lookup DNS Records** search bar.
2. Click the **Monitor** button to apply a monitor that runs the query once every 24 hours. You'll be alerted when Silent Push detects new results via email (filtering/sorting options are not applied)
3. Specify a **Monitor name**.
4. Enter a **Description**.
5. Toggle **Email Notifications** to receive the notifications.
6. Click **Save**.
7. The monitored query will now be visible in **Monitors > Monitored Queries.** ![](https://cdn.document360.io/8e5460b3-9d96-4b01-8bb3-6591a4af3a8c/Images/Documentation/Screenshot 2025-08-13 at 3.17.57 PM.png)

## Manage a Monitor

Control and share monitors effectively:

- **Activate or Deactivate**: Navigate to **Monitors > Monitored Queries**, move the Monitor Active Slider to turn a monitor on or off.
- **Share a Monitor**: Click the ellipsis menu on the far right, then select “**Share Monitor”** to make it visible to your organization.
- **Change Name/Description**: Click the ellipsis menu, choose **Edit Monitor Metadata**, update the **Monitor Name** and **Description**, then click **Save**.

## Analyze and View Results

Analyze monitored data with multiple options:

- **Historical Analysis**: Navigate to **Monitors > Monitored Queries**, click **History** next to a monitor to view a table of new indicators over 7 days.
  - Optionally, click the **View icon (**)**, to the left of the Monitor slider, click **Copy**, or **Download**to transfer raw data to your clipboard for integration.
  - **Graphical Data**: Mouse over the graph icon in **Monitored Queries** to see a 7-day bar chart of IoC activity. No data is rendered if no new indicators are detected.

The total set of vulnerabilities and entry points in a system or network that could be exploited by an attacker, including software, hardware, and network configurations.

A centralized module in a threat intelligence platform for organizing, searching, and analyzing data from various feeds, enabling efficient threat detection and response workflows.

A collection of user-defined queries set to run automatically at regular intervals (e.g., every 24 hours) to track changes in DNS, WHOIS, or web data, providing real-time alerts for potential threats.

A toggle feature in the Silent Push platform that enables users to activate or deactivate a monitor, controlling whether it runs automated queries and sends alerts.
