---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Use or modify a saved search

# Use or modify a saved search {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use a saved search of log data to better understand the causes of an alert. As the
owner of a saved search, you can modify the search values and save your changes.

## Before you begin

Note:  
If you are not the owner of the saved search, save the search with a different name. You can then update search values, save your changes, and share the search with others.

Role required: evt_mgmt_operator or evt_mgmt_admin

## Procedure

1. Open the Log viewer using one of the following methods:
   * Navigate to WorkspacesService Operations Workspace and select the Log Viewer icon (![Log viewer icon.]()).
   * While viewing log entries for an alert on the Surrounding logs tab, select Log viewer.
   {#hla-op-search-queries-saved-sow__choices_plc_kwh_gtb}
2. Use a saved search.
   1. Select the selection icon (![Selection icon.]()) and then select Load search.
   2. In the Load search dialog box, select the name of the search to load.

   {#hla-op-search-queries-saved-sow__substeps_itz_kgg_ftb}  
   The system returns the full list of log lines that match the search values and displays the information in the Results over time chart.
3. **Optional:** Update the saved search.
   1. Select the selection icon (![Selection icon.]()) and then choose Manage my searches from the drop-down list.
   2. Modify the settings.  
      {#hla-op-search-queries-saved-sow__table_ctn_5gg_ftb__entry__2}

      | Field | Description |
      |-|-|
      | Name | Name of the saved search. |
      | Query | Search query. The Log viewer uses the Elasticsearch search engine, so you can use any supported search term structure in the Query field. |
      | Assignment group | Assignment groups that can access the search. The members of the groups can use the search. |
      | Filter | Column filter in standard format (<kbd class="ph userinput">field1=value1, field2=value2, field3=value3, ...</kbd>). |
      | Updated | Date and time the search was updated. This feature is supported in the Health Log Analytics application, Version 20.0.11 - July 2021, and the Health Log Analytics Viewer application, Version 20.0.4 - July 2021, available from the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home). |
      [Table 1. Manage my searches form]

      {#hla-op-search-queries-saved-sow__table_ctn_5gg_ftb}

      To revert changes you have made to the search values, select the selection icon (![Selection icon.]()) and then select Discard Changes. The changes that you made to the search values are discarded. You can continue to update the search settings.
   3. Save the updated search.  
      1. Select Save as.
      2. In the Search name field, specify a unique and descriptive name for the search and then click Save.
      {#hla-op-search-queries-saved-sow__ol_yyq_fhg_ftb}
   {#hla-op-search-queries-saved-sow__substeps_e4b_qgg_ftb}
{#hla-op-search-queries-saved-sow__steps_nx5_jxw_stb}

*[\>]: and then


