Skip to main content
Log Search lets you query a workspace’s logs with KQL (Kusto Query Language) without leaving ContraForce, so you can hunt or dig into an incident from the same place you triage it.
Who is this for? SOC analysts and security engineers who hunt or investigate across customer workspaces. Log Search is included with the XDR + SIEM Module.

Running a Query

1

Open Log Search

Select Log Search in the left navigation.
2

Choose the Workspace

Pick the workspace and data source from the Workspace list, for example [workspace] — Microsoft Sentinel.
3

Write the Query

Type KQL in the editor. Use the Schema panel to browse the tables available in the workspace.
4

Run It

Select Run or press Ctrl + Enter. Results appear in the Results panel.

Ask IRIS

Not fluent in KQL? Select Ask IRIS and describe what you’re looking for in plain language. IRIS turns your description into KQL, which you can review before you run it.

Exporting Results

After a query returns results, select Export to download them.

Opening Log Search from an Incident

On a full incident page, select the Log Search icon (Go to log search) next to Actions to jump to Log Search while you investigate.

Incident Management

Investigate incidents end to end

Microsoft Sentinel Module

Connect Sentinel to a workspace

Questions about Log Search? Contact us at support@contraforce.com.