Who is this for? SOC analysts and security engineers who hunt or investigate across customer workspaces. Log Search is included with the XDR + SIEM Module.
Running a Query
1
Open Log Search
Select Log Search in the left navigation.
2
Choose the Workspace
Pick the workspace and data source from the Workspace list, for example [workspace] — Microsoft Sentinel.
3
Write the Query
Type KQL in the editor. Use the Schema panel to browse the tables available in the workspace.
4
Run It
Select Run or press Ctrl + Enter. Results appear in the Results panel.
Ask IRIS
Not fluent in KQL? Select Ask IRIS and describe what you’re looking for in plain language. IRIS turns your description into KQL, which you can review before you run it.Exporting Results
After a query returns results, select Export to download them.Opening Log Search from an Incident
On a full incident page, select the Log Search icon (Go to log search) next to Actions to jump to Log Search while you investigate.Related Guides
Incident Management
Investigate incidents end to end
Microsoft Sentinel Module
Connect Sentinel to a workspace
Questions about Log Search? Contact us at support@contraforce.com.