Run a search
Run a search to find log lines that match a specific search expression.
- Arctic Wolf Unified Portal にサインインします。
- ナビゲーションメニューで、
[データ探索] > [生ログ検索]をクリックします。
- Optional: Limit your search to log sources that have a specific tag:
- Click the Log Source field.
- Add one or more tags from the list. For example, select active directory and auth to only include log sources with the
active directorytag and log sources with theauthtag.For more information, see Log source tags.
- Optional: Set the desired time range.
Note:
- You can only retrieve up to 31 days of log data at a time. However, you can run concurrent searches in other browser tabs or windows.
- The earliest log data that you can search is based on your data retention policy.
- By default, data sent to Arctic Wolf prior to January 2019 is not searchable. If your data retention period begins before January 2019 and you would like to search your full history, contact your Concierge Security® Team (CST) at security@arcticwolf.com.
- Optional: Select a frequently run search:
- In the Query Template list, select a frequently run search.
- If prompted, enter the value that completes the search expression. For example, in the Login Successes for User template, enter a user ID.
- Click Apply to add the search expression to the Search field.
- Optional: In the Search field, enter or modify the search expression.
For more information, see Raw Log Search query syntax.
- Select or deselect the Case sensitive option.
- Click Search.
A timeline graph and a table of matching log sources load when the search is complete.