Run an analyzed log search

Data Explorer allows you to search through analyzed logs from all ingested log sources. You can:

Run a predefined search

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Exploration > Data Explorer.
  3. Optional: In the Date Range fields, click Calendar to select a time range.
  4. In the Load Query (Optional) list, select a preset or saved custom query.
    Tip: Preset queries are included with Data Explorer and cannot be edited. Saved queries are defined by users in your organization. If you select a saved query from the Load Query (Optional) list, the View Settings option will appear.
    After selecting a query from the Load Query (Optional) list, predefined values are added to the Query Builder.
  5. Click Run Query .

  6. Optional: Complete any of these actions:

Create and run a query

  1. Sign in to the Arctic Wolf Unified Portal.
  2. In the navigation menu, click Data Exploration > Data Explorer.
  3. Optional: In the Date Range fields, click Calendar to select a time range.
  4. In the Query Builder section, use operators to define a dataset.
    For more information, see:
    Tip: You can start by loading a predefined query into the Query Builder. In the Load Query (Optional) list, select a predefined query. Then, modify the query as desired.
  5. Click Run Query .

  6. Optional: Complete any of these actions: