Azure Security Center search
Azure Security Center uses Log Analytics search to retrieve and analyze your security data. Log Analytics includes a query language to quickly retrieve and consolidate data. From Security Center, you can leverage Log Analytics search to construct queries and analyze collected data.
Search is available in both the Free tier and Standard tier of Security Center. The data available in your log searches is dependent on the tier level applied to your workspace. See the Security Center pricing page for more information.
Security Center does not save security data for a workspace under the Free tier. You can send a variety of logs to a workspace under the Free tier and search on that data but search results do not include data from Security Center. Security Center only saves data to a workspace under the Standard tier.
Under the Security Center main menu, select Search.
Security Center lists all workspaces under your Azure subscriptions. Select a workspace. (If you have only one workspace, this workspace selector does not appear.)
Log Search opens. To query for more data under the selected workspace, enter this example query:
SecurityEvent | where EventID == 4625 | summarize count() by TargetAccount
Result shows all accounts that failed to logon (event 4625).
See Log Analytics query language for more information on how to query for data under the selected workspace.
In this article you learned how to access search in Security Center. Security Center uses Log Analytics search. To learn more about Log Analytics search, see:
- What is Log Analytics? – Overview on Log Analytics
- Understanding log searches in Log Analytics - Describes how log searches are used in Log Analytics and provides concepts that should be understood before creating a log search
- Find data using log searches in Log Analytics – Tutorial on using log search
- Log Analytics search reference – Describes the query language in Log Analytics
To learn more about Security Center, see:
- Security Center Overview – Describes Security Center’s key capabilities