Kaspersky Unified Monitoring and Analysis Platform
Managing saved search queries

In KUMA, in the Events section, you can organize saved SQL queries in a tree of folders for structured storage and quick search of SQL queries. You can edit previously saved queries, rename them, arrange queries in groups (folders) of accessible tenants, and search for previously saved queries in the search bar.

Saved queries follow the tenant access model and are visible to all users that have access to the corresponding tenants.

Saved queries are placed in the Saved queries pane. You can open or close the Saved queries pane using the (bookmark) button on the toolbar of the query window.

The Saved queries navigation pane on the left contains the following:

  • The query search window where you can search by folder name and query name.
  • Tree of folders and queries, the Favorites folder.
  • The query filter that displays the queries you have created (on the My tab) and all queries (on the All tab)

Displaying a query in the query window

To display a query in the query window:

  1. In the Events section, click the (bookmark) button.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, click to select the relevant query.

The text of the selected query is displayed in the query window.

Saving a query to a folder or a tenant

In the Events section, after entering a query in the query window and clicking the Save current query button (floppy disk icon), you can save the SQL query to one of the folders or tenants that you can select.

To save a query to a folder:

  1. In the New query window, in the Filter name field, enter a name for the filter.

    Consider the following when naming the filter:

    • The name can contain Unicode characters.
    • The minimum length of a name is 1 character, and the maximum length is 128 characters.
    • Names must be unique within a tenant.
    • Tab characters, new line characters, and paragraph characters are replaced with space characters.

    When saving the name:

    • Leading and trailing spaces are removed.
    • Multiple spaces between characters are replaced with a single space character.
  2. In the Query field, enter the text of the SQL query.
  3. Select a tenant, a folder from the list of folders created in the tenant that is available to you, or create a new folder by clicking the Add folder button.

    You can also add a folder in the Saved queries window: click the AD_plus button next to the tenant to open the New folder window and add the folder in that window.

  4. Click the Save button.

The query is saved in the selected folder or tenant.

Viewing the text of a query

To view the text of a query:

  1. In the Events section, click the (bookmark) button.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, click the icon_viewing request button next to the relevant query.

This opens a window with the text of the query.

Setting the default query

You can set your default query that the Events section displays when opened.

To set the default query:

  1. In the Events section, click the (bookmark) button.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, select the relevant query.
  3. Click the button and in the displayed menu, select Use by default.

The selected query becomes the default query.

Adding folders and queries to favorites

To add a folder or individual query to favorites:

  1. In the Events section, click the (bookmark) button.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, select the relevant folder or query.
  3. Click the button and in the displayed menu, select Add to favorites.

The selected folder or resource is added to the Favorites folder.

Editing a query

To edit a query:

  1. In the Events section, click the (bookmark) button.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, select the relevant query.
  3. Click the button and in the displayed menu, select Edit.

    This opens the window for editing the saved query.

  4. In the window, edit the query name or text, or the folder in which you want to save the query.
  5. Click the Save button.

The query is updated and saved in the selected folder.

Deleting a query

To delete a query from a folder (if you have sufficient rights):

  1. In the Events section, click the bookmark () icon.

    This opens the Saved queries navigation pane.

  2. In the tree of folders in the Saved queries pane, select the relevant query.
  3. Click the three-dot icon () and in the menu that appears, select Delete.
  4. Confirm deletion in the displayed window.

The query is deleted.