Skip to main content

Responses are generated using AI and may contain mistakes.

Exabeam SearchExabeam Search Guide

Search Results

When a search has completed, the results of your search are displayed directly below the search bar, including a histogram view of events. The total number of events is presented at the top. Depending on which view of results is open, events that match the query are displayed in a timeline, a list, or a table. Search can display up to 5,000 results.

Note

If you have a Long-Term Search license, note that Search can only return long-term search results that are within the licensed capacity. Results from data that exceed that volume will not be returned. For information about tracking long-term search consumption, see Long-Term Search in the Service Health and Consumption guide. For information about setting log retention periods, see Global Log Retention in the Search guide.

SearchResults.png

Note

In rare instances you may notice a duplicate event in the results returned by a search query. This type of duplication can be a result of the Google Pub/Sub messaging policy that Exabeam uses. Like many highly scalable, distributed systems, Exabeam follows the at least once policy of log ingestion. The policy guarantees that all logs are ingested and stored, but does not guarantee that they are ingested and stored only once.

In the Exabeam event-driven architecture, the at least once policy ensures that no data is lost, even if some duplication occurs. The rate of duplication should remain below 0.03% of events, a rate that is considered small enough to be statistically negligible. If the occurence of duplication appears higher than this threshold, report it to your Exabeam support representative.