Microsoft Sentinel
Cloud and workloads

Start an Investigation by Searching Large Datasets

In brief

The article received updated wording, title capitalization, metadata, code formatting, and revised links to search and restore guidance.

What Defender admins need to know

Administrators will see clearer related-article links and refreshed documentation; no configuration change is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Start an investigationInvestigation by searching large datasets - Microsoft SentinelSearching Large Datasets description: Learn about search jobs and restoring data from long-term retention in Microsoft Sentinel. author: EdB-MSFT ms.topic: how-to ms.date: 06/15/07/02/2026 ms.author: edbaynash appliesto: - Microsoft Sentinel in the Microsoft Defender portal - Microsoft Sentinel in the Azure portal ms.collection: usx-security ms.custom: sfi-image-nochange, msecd-doc-authoring-10141016 ai-usage: ai-assisted

One of the primary activities of a security team is to search logs for specific events. For example, you might search logs for the activities of a specific user within a given time-frame.

In Microsoft Sentinel, you can search across long time periods in extremely large datasets by using a search job. WhileAlthough you can run a search job on any type of log, search jobs are ideally suited to search logs in a long-term retention (formerly known as archive) state. If you need to do a full investigation on such data, you can restore that data into an interactive retention state—like (like your regular Log Analytics tables—tables) to run high performing queries and deeper analysis.

This article shows you how to run search jobs on large datasets, restore archived log data for deeper investigation, and bookmark search results.

When you need to do a full investigation on log data in long-term retention, restore a table from the Search page in Microsoft Sentinel. Specify a target table and time range for the data you want to restore. Within a few minutes, the log data is restored and available within the Log Analytics workspace. Then you can use the data in high-performance queries that support full KQL.

A restored log table is available in a new table that has a *_RST*_RST suffix. The restored data is available as long as the underlying source data is available. But you can delete restored tables at any time without deleting the underlying source data. To save costs, we recommend you delete the restored table when you no longer need it.

The restore option appears on a saved search, as shown in the screenshot.

Related content

To learn more about searching and restoring log data, see the following articles: