TAIL Queries
Tail queries run on real-time data after the data is indexed.
The query results display new incoming events that match the query criteria. Because of the nature of these queries, they never finish; you must cancel or delete them manually.
You can query real-time data from the Advanced Search or the Data Grid widget, by using one of the following methods:
- Use the | TAIL keyword in the query
- Select Real Time from the time filter drop-down list (only in the Advanced Search tab)
The streaming stops if you scroll up the page, and resumes when you scroll down to the end of the page.
Tail queries have the following restrictions:
Copyright © Cloud Software Group, Inc. All rights reserved.