- Search Overview
- Search Home Page
- Performing Searches
- Basic Search
- Advanced Search
- Advanced Search Building Blocks
- Running an Advanced Search Query
- Query Syntax
- Query by Subject
- Query by Vendor and Product
- Query by Field and Value
- Query by Context Table
- Query Using Regex
- Query Using Wildcards
- Free Text Search
- Query Using Advanced Query Language Operators
- Query Using Aggregation Functions
- Query Using Structured Fields
- Dynamic Field Extraction
- Natural Language Search
- Anomaly Search
- Refine a Search
- Context Tables in Search
- Search Best Practices
- Search Results
- Histogram View of Search Results
- Search Results Navigation Bar
- Timeline View of Search Results
- List View of Search Results
- Table View of Search Results
- Aggregated Search Results
- Event Details
- Detection Details
- Entity Details
- Data Insights
- Export Search Results
- View and Download Exported Search Result Files
- Dashboard Visualizations
Search Results
When a search has completed, the results of your search are displayed directly below the search bar, including a histogram view of events. The total number of events is presented at the top. Depending on which view of results is open, events that match the query are displayed in a timeline, a list, or a table. Search can display up to 5,000 results.
Note
If you have a Long-Term Search license, note that Search can only return long-term search results that are within the licensed capacity. Results from data that exceed that volume will not be returned. For information about tracking long-term search consumption, see Long-Term Search in the Service Health and Consumption guide. For information about setting log retention periods, see Global Log Retention in the Search guide.
![]() |
Note
In rare instances you may notice a duplicate event in the results returned by a search query. This type of duplication can be a result of the Google Pub/Sub messaging policy that Exabeam uses. Like many highly scalable, distributed systems, Exabeam follows the at least once policy of log ingestion. The policy guarantees that all logs are ingested and stored, but does not guarantee that they are ingested and stored only once.
In the Exabeam event-driven architecture, the at least once policy ensures that no data is lost, even if some duplication occurs. The rate of duplication should remain below 0.03% of events, a rate that is considered small enough to be statistically negligible. If the occurence of duplication appears higher than this threshold, report it to your Exabeam support representative.
