---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Define, save, and share a log data search

# Define, save, and share a log data search {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

Define, save, and share searches of log data to help determine the causes of Log Analytics alerts.

## Before you begin

Role required: evt_mgmt_operator or evt_mgmt_admin

## Procedure

1. Open the Log Viewer using one of the following methods:
   * Navigate to WorkspacesService Operations Workspace and select the Log Viewer icon (![Log Viewer icon.]()).
   * While viewing log entries for an alert on the Surrounding logs tab, select Log Viewer.
   {#hla-op-search-queries-manage-sow__choices_kbd_bww_stb}
2. Define a search.
   1. Select the selection icon (![Selection icon.]()) and then select New search.
   2. Set the values of the search parameters in the search fields.  
      {#hla-op-search-queries-manage-sow__table_yp2_2cf_ftb__entry__2}

      | Search field | Description |
      |-|-|
      | Query | Search query. Tip: The Log viewer uses the Elasticsearch search engine, so you can use any supported search term structure in the Query field. |
      | Component | Logical component of the service instance that generated the event. Multiple CIs can sometimes perform the same function. |
      | Time range | Time range to apply to the X-axis when displaying the returned data. The setting that you specify appears in the Start time and End time fields. Use one of the following methods: * Select a time period from the list. * Click Custom range to use the date and time picker to specify a range. {#hla-op-search-queries-manage-sow__ul_yfx_2df_ftb} Note: You can modify the settings in the Start time and End time fields manually. The selected time range shown in Select range then changes to Custom range. This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). Note: Saved searches do not include time range settings. |
      [Table 1. Search fields]

      {#hla-op-search-queries-manage-sow__table_yp2_2cf_ftb}
   3. Select Search.  
      The system returns the full list of log lines that match the search values. The information is displayed in the Results over time chart.
   {#hla-op-search-queries-manage-sow__substeps_zp5_xbf_ftb}
3. **Optional:** Save the search.  
   The saved search includes any selected filters. For information about filters, see [Filter search results on the Log Viewer in Health Log Analytics](https://www.servicenow.com/docs/YHhho2ZwUIn12tzyQMoX5g "Apply filters on the Log Viewer to show only your desired data.").  
   Note:  
   Saved searches do not include time range settings.
   1. Select Save As.
   2. In the Search name field, specify a unique and descriptive name for the search and then click Save.

   {#hla-op-search-queries-manage-sow__substeps_vp4_14f_ftb}  
   Note:  
   If you are using Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) , you can define an alert rule without saving the search. For more information, see [Define a custom Log Analytics alert rule in Health Log Analytics](https://www.servicenow.com/docs/Jk8rQDzN~inCPKKlfRwZZg "Define a custom Log Analytics alert rule for log data that might not generate alerts automatically. A custom rule enables you to specify the metric, threshold, and alert properties directly.").
4. **Optional:** Share the saved search with an assignment group.
   1. Select Share.
   2. Select an assignment group from the list.
   3. Select Save.
   {#hla-op-search-queries-manage-sow__substeps_o1z_fht_ypb}
{#hla-op-search-queries-manage-sow__steps_gn1_w5w_stb}
**Related tasks**   

* [Use or modify a saved log data search in Health Log Analytics](https://www.servicenow.com/docs/E_VCBTiCqsPSIlRe71ANSQ "Use a saved search of log data to better understand the causes of an alert. As the owner of a saved search, you can modify the search values and save your changes.")
* [Define a custom Log Analytics alert rule in Health Log Analytics](https://www.servicenow.com/docs/Jk8rQDzN~inCPKKlfRwZZg "Define a custom Log Analytics alert rule for log data that might not generate alerts automatically. A custom rule enables you to specify the metric, threshold, and alert properties directly.")

*[\>]: and then


