---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Define, save, and share a log data search

# Define, save, and share a search of log data in Health Log Analytics {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 Minuten Lesedauer

Define, save, and share searches of log data to help determine the causes of Log Analytics alerts.

## Vorbereitungen

Role required: evt_mgmt_operator or evt_mgmt_admin  
Wichtig:  
From the Vancouver release onward, the Operator Workspace is deprecated and replaced with Service Operations Workspace. For the new procedure, see the corresponding topic in the Service Operations Workspace for ITOM documentation: [Define, save, and share a search of log data in Health Log Analytics](https://servicenow-prod.fluidtopics.net/iOxC2d1egh7Mecad~BMlvw "Define, save, and share searches of log data to help determine the causes of Log Analytics alerts.").

## Prozedur

1. Open the Log Viewer tab using one of the following methods:
   * In the Agent Workspace, select the Log Viewer icon (![Log Viewer icon]()).
   * While viewing log entries for an alert on the Surrounding logs tab, select Log Viewer.
   * Navigate to Health Log AnalyticsLog Viewer.
   {#hla-op-search-queries-manage__choices_tg5_srl_hnb}
2. Define a search.
   1. Select the selection icon (![Selection icon.]()) and then select New search.
   2. Set the values of the search parameters in the search fields.  
      {#hla-op-search-queries-manage__table_avm_tbs_2pb__entry__2}

      | Search field | Description |
      |-|-|
      | Query | Search query. Tipp: The Log viewer uses the Elasticsearch search engine, so you can use any supported search term structure in the Query field. |
      | Component | Logical component of the service instance that generated the event. Multiple CIs can sometimes perform the same function. |
      | Time range | Time range to apply to the X-axis when displaying the returned data. The setting that you specify appears in the Start time and End time fields. Use one of the following methods: * Select a time period from the list. * Click Custom range to use the date and time picker to specify a range. {#hla-op-search-queries-manage__ul_bws_d15_2nb} Hinweis: You can modify the settings in the Start time and End time fields manually. The selected time range shown in Select range then changes to Custom range. This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). Hinweis: Saved searches do not include time range settings. |
      [Tabelle : 1. Search fields]

      {#hla-op-search-queries-manage__table_avm_tbs_2pb}
   3. Select Search.  
      The system returns the full list of log lines that match the search values. The information is displayed in the Results over time chart.
   {#hla-op-search-queries-manage__substeps_jkz_vtw_54b}
3. **Wahlweise:** Filter the search results that are shown on the Log viewer.
   1. On the right side of the screen, select the filter icon (![Filter icon.]()).
   2. On the Filters pane, set filters to display the data you want to see on the Log viewer.

   {#hla-op-search-queries-manage__substeps_evx_s1z_cpb}  
   This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home).
4. **Wahlweise:** Set a filter for the data you want to see in a single field.
   1. Right-click in a field.
   2. Set a filter to display the data you want to see for that field.  
      The most frequently set conditions are listed at the top of the filters list.
   3. Select Apply.

   {#hla-op-search-queries-manage__substeps_ebg_br2_dpb}  
   This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home).
5. **Wahlweise:** Save the search.  
   The saved search includes the selected filters.  
   Hinweis:  
   Saved searches do not include time range settings.
   1. Select Save As.
   2. In the Search name field, specify a unique and descriptive name for the search and then click Save.

   {#hla-op-search-queries-manage__substeps_pgd_xzw_54b}  
   Hinweis:  
   If you are using Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) , you can define an alert rule without saving the search. For more information, see [Add a Log Analytics alert rule in Health Log Analytics](https://servicenow-prod.fluidtopics.net/lilIaSiwF42ygo6l~9rbZg "Define a Log Analytics alert rule when you encounter log data that should generate an alert. The alert rule generates an alert for a specified metric with a threshold that you specify and sets the properties of the generated alert.").
6. **Wahlweise:** Share the saved search with an assignment group.
   1. Select Share.
   2. Select an assignment group from the list.
   3. Select Save.
   {#hla-op-search-queries-manage__substeps_o1z_fht_ypb}
**Zugehörige Tasks**   

* [Use or modify a saved log data search in Health Log Analytics](https://servicenow-prod.fluidtopics.net/33RcG_pmFNtROo03~4_Fqg "Use a saved search of log data to better understand the causes of an alert. As the owner of a saved search, you can modify the search values and save your changes.")
* [Add a Log Analytics alert rule in Health Log Analytics](https://servicenow-prod.fluidtopics.net/lilIaSiwF42ygo6l~9rbZg "Define a Log Analytics alert rule when you encounter log data that should generate an alert. The alert rule generates an alert for a specified metric with a threshold that you specify and sets the properties of the generated alert.")

