Long-running KQL query in a Log Analytics workspace, restricted to one table, that can look through analytics, data lake or archived data and copies as many as 100 million results into a dedicated table.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Search job in context, with comparison tables and the common traps.
Terms in this definition
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Log Analytics workspace
Where Azure Monitor keeps log data for querying with KQL. Microsoft Sentinel, VM insights and workspace-based Application Insights all depend on one.
- Event
Table in Log Analytics where entries from Windows event logs are kept.
- Data lake
Holds files of every kind, structured, semi-structured or unstructured, usually spread over a distributed file system, and lets engines like Spark apply a schema when reading. In Azure this is Data Lake Storage: Blob Storage with a hierarchical namespace enabled.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.