Use or modify a saved log data search in Health Log Analytics
Use a saved search of log data to better understand the causes of an alert. As the owner of a saved search, you can modify the search values and save your changes.
Before you begin
Note: If you're not the owner of the saved search, save the search with a different name. You can then update search values, save your changes, and share the search with others.
Role required: evt_mgmt_operator or evt_mgmt_admin
Procedure
Open the Log Viewer using one of the following methods:
- Navigate to Workspaces > Service Operations Workspace and select the Log Viewer icon (
Image omitted: icon-log-viewer-sow.png
Log Viewer icon.\).
Log Viewer icon.\).
- While viewing log entries for an alert on the **Surrounding logs** tab, select **Log Viewer**.
Use a saved search.
- Select the selection icon (
Image omitted: icon-selection-sow.png
Selection icon.\) and then select **Load search**.
Selection icon.\) and then select **Load search**.
2. In the Load search dialog box, select the name of the search to load.
The system returns the full list of log lines that match the search values and displays the information in the Results over time chart.
Update the saved search.
- Select the selection icon (
Image omitted: icon-selection-sow.png
Selection icon.\) and then choose **Manage my searches** from the drop-down list.
Selection icon.\) and then choose **Manage my searches** from the drop-down list.
2. Modify the settings.
| Field | Description |
|---|---|
| Name | Name of the saved search. |
| Query | Search query.The Log viewer uses the Elasticsearch search engine, so you can use any supported search term structure in the Query field. |
| Assignment group | Assignment groups that can access the search. The members of the groups can use the search. |
| Filter | Column filter in standard format \(`field1=value1, field2=value2, field3=value3, ...`\). |
| Updated | Date and time the search was updated.This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the ServiceNow Store. |
To revert changes you have made to the search values, select the selection icon \(
Image omitted: icon-selection-sow.png
Selection icon.\) and then select **Discard Changes**. The changes that you made to the search values are discarded. You can continue to update the search settings.
Selection icon.\) and then select **Discard Changes**. The changes that you made to the search values are discarded. You can continue to update the search settings.
3. Save the updated search.
1. Select **Save as**.
2. In the **Search name** field, specify a unique and descriptive name for the search and then select **Save**.