Monitor search status and stop running searches
The Search History page gives you visibility into what queries are running or recently ran in your Panther instance. It displays the last 30 days of searches run in the Panther Console.
In the search history, you'll see the following details:
- A search name or UUID
- The SQL expression it ran or attempted to run
- The search type. The possible search types are:
- Ad Hoc: This is most commonly logged when a user runs a query in Data Explorer.
- Alert Detail and Alert Summary: This is populated when a user looks at details and summary pages of an alert.
- Compaction: A background process for Athena databases.
- The timestamp when the query started and stopped.
- The query status: Succeeded, Failed, Cancelled or Running.
- The user or Panther process running the query.
- 1.From the Search History page, click a query name.
- This will redirect you to Data Explorer where the query will automatically run.
- 2.While viewing the running query in Data Explorer, click Cancel below the query.
Note that the Cancel option will only appear on a query that is currently running.