Skip to content

Commit e767f6f

Browse files
authored
Merge pull request #214695 from austinmccollum/austinmc-search-jobs
update search jobs and remove previews
2 parents 2a230f7 + 2196da7 commit e767f6f

13 files changed

+45
-37
lines changed

articles/sentinel/investigate-large-datasets.md

Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,15 +7,12 @@ ms.date: 01/21/2022
77
ms.author: cwatson
88
---
99

10-
# Start an investigation by searching for events in large datasets (preview)
10+
# Start an investigation by searching for events in large datasets
1111

1212
One of the primary activities of a security team is to search logs for specific events. For example, you might search logs for the activities of a specific user within a given time-frame.
1313

1414
In Microsoft Sentinel, you can search across long time periods in extremely large datasets by using a search job. While you can run a search job on any type of log, search jobs are ideally suited to search archived logs. If you need to do a full investigation on archived data, you can restore that data into the hot cache to run high performing queries and analytics.
1515

16-
> [!IMPORTANT]
17-
> The search job and restore features are currently in **PREVIEW**. The [Azure Preview Supplemental Terms](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) include additional legal terms that apply to Azure features that are in beta, preview, or otherwise not yet released into general availability.
18-
>
1916

2017
## Search large datasets
2118

Binary file not shown.
50.3 KB
Loading
27.2 KB
Loading
115 KB
Loading
266 KB
Loading
70.6 KB
Loading
Binary file not shown.
178 KB
Loading
206 KB
Loading

0 commit comments

Comments
 (0)