Search across long time spans in large datasets (preview)
Use a search job when you start an investigation to find specific events in logs within a given time frame. You can search all your logs, filter through them, and look for events that match your criteria.
Before you start a search job, see Start an investigation by searching large datasets (preview) and Search jobs in Azure Monitor.
Important
The search job feature is currently in PREVIEW. The Azure Preview Supplemental Terms include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
Start a search job
Go to Search in Microsoft Sentinel to enter your search criteria.
In the Azure portal, go to Microsoft Sentinel and select the appropriate workspace.
Under General, select Search (preview).
In the Search box, enter the search term.
Select the appropriate Time range.
Select the Table that you want to search.
When you're ready to start the search job, select Search.
When the search job starts, a notification and the job status show on the search page.
Wait for your search job to complete. Depending on your dataset and search criteria, the search job may take a few minutes or up to 24 hours to complete. If your search job takes longer than 24 hours, it will time out. If that happens, refine your search criteria and try again.
View search job results
View the status and results of your search job by going to the Saved Searches tab.
In your Microsoft Sentinel workspace, select Search > Saved Searches.
On the search card, select View search results.
By default, you see all the results that match your original search criteria.
In the search query, notice the time columns referenced.
TimeGenerated
is the date and time the data was ingested into the search table._OriginalTimeGenerated
is the date and time the record was created.
To refine the list of results returned from the search table, edit the KQL query.
As you're reviewing your search job results, bookmark rows that contain information you find interesting so you can attach them to an incident or refer to them later.
Next steps
To learn more, see the following topics.
Feedback
Submit and view feedback for