@clippy I see. Yeah that makes sense. It took me quite a while to get my query schedule working on an EC2 test instance, but I finally got it. My next step is to send query log data to Kinesis and then to an S3 bucket. Our goal is to use Demisto to call back and run queries on-demand (in response to an event) so I think I'm going to give Kolide another try.