Skip to main content

Data Lake

The Data Lake menu contains the pages used to search stored events and manage where and how event data is stored:

In this section

  • Search — search all collected events across data lake indexes.
  • Investigations — review saved investigation runs.
  • Management — add and manage data lakes and their indexes.
  • Schemas — create and manage the schemas that describe stored data.
  • KQL Query Builder — build and run KQL queries against data lake indexes.
  • KQL Search History — reopen the stored results of past KQL runs.