Manage データエクスプローラ search results

Edit columns in the search results table

After running a search in データエクスプローラ, you can change the columns that appear in the search results table.

  1. Run an analyzed log search.
  2. Click Columns.
  3. Select the fields that you want to add.
  4. Deselect the fields that you want to remove.
  5. Click Apply.

Create a custom column set

You can save a custom column set based on the current search results table view. The next time you run an analyzed log search, you can load a saved column set to quickly reconfigure the search results table view.

  1. Run an analyzed log search.
  2. Edit columns in the search results table.
  3. Click Save Columns.
  4. Review the column set.
  5. Click Save.

Apply a custom column set

You can load a custom column set to quickly reconfigure the search results table view.

You can only apply a custom column set if you created one previously. For instructions, see Create a custom column set.
  1. Run an analyzed log search.
  2. Click Load Columns.
  3. Select a custom column set.
  4. Click Load.

Filter and refine search results

You can filter データエクスプローラ search results to narrow down data without modifying your original query.

After running a search, you can add or exclude field values as filters directly from the results table. Filters refine the displayed results in real-time and update any visualizations you have created. Your original query remains unchanged.

  1. Run an analyzed log search.
  2. In the Event Logs table, locate a field value that you want to filter by.
  3. Click the field value to open the actions menu, and then select one of these options:
    • Add Key — Filters results to show only events that contain this field value.
    • Exclude Key — Filters results to hide events that contain this field value.
    • Group By — Creates a bar chart visualization showing the top 5 values for this field.
    The search results and any existing visualizations update to reflect the applied filter or new visualization.
  4. Optional: To add additional filters, repeat the previous step for other field values.
    Note:

    Filters are cumulative. Each new filter further narrows the results. Adding or removing a filter updates all visualizations on the page.

  5. Optional: To create a custom visualization, click Add Summary and configure the visualization in the drawer that opens.

    For more information, see Add a visualization to search results .