Skip to content
LogoLogScale DocumentationLibraryGuidance Release Notes Integrations Query Examples Training APIGraphQLSearch Archives Contact Support
🔖੆Help button for documentation
    • Terminology Reference
      • Actions
      • Aggregate Alert
      • Aggregation
      • Alert
      • Anomaly Detection
      • API (Application Programming Interface)
      • API Tokens
      • archiving
      • Arrays of Arrays
      • Arrays of Objects
      • Asset
      • Asset Permissions
      • Authentication
      • Authorization
      • Automated Actions
      • Automatic user provisioning
      • Auxiliary node
      • Backfilling
      • Backup
      • Baseline
      • Bearer Token
      • Blocklist
      • Bloom Filter
      • Bucket
      • Built-in Parsers
      • Cardinality
      • Checksum
      • Cluster
      • Cluster Management
      • Cold Storage
      • Compression
      • Configuration
      • Correlation
      • Cost Points
      • CrowdStrike Query Language (CQL)
      • Cron
      • CrowdStrike Parsing Standard (CPS)
      • Custom Resource Definitions (CRD)
      • customKey
      • Dashboard
      • Data Export
      • Data Ingestion
      • Data Retention
      • Data Visualization
      • Datasource
      • Deployment
      • Dynamic Configuration
      • Endpoint
      • Enrichment
      • Environment Variables
      • Ephemeral User Token
      • Event
      • Event Fields
      • Event List
      • externalQueryId
      • Extraction
      • extraLogFields
      • Field
      • Field Aliasing
      • Field Data Types
      • Field Mapping
      • Fields Panel
      • Filter
      • Filter Alert
      • Format Event List Panel
      • Function
      • Glob Pattern
      • GraphQL
      • Group synchronization
      • groupBy()
      • Groups
      • Histogram
      • Hot Storage
      • Humio Operator
      • HumioCluster
      • Identity Provider (IdP)
      • Immutability
      • Indexing
      • Ingest Token
      • Ingestion
      • @ingesttimestamp
      • Inspection Panel
      • Installation
      • Integration
      • IP Filters
      • Join
      • Kubernetes
      • LDAP (Lightweight Directory Access Protocol)
      • License Management
      • Live Query
      • Load Balancing
      • Log Shipper
      • LogScale Query Language (CQL)
      • Lookup Table
      • LZ4
      • Multi-Cluster-Search
      • Multi-Cluster View
      • Memory Limits
      • Metadata
      • Metadata Fields
      • Monitoring
      • Multi-Cluster Search
      • Nested Arrays
      • Node
      • Non-Sensitive Events
      • Notification
      • OAuth
      • OpenID Connect (OIDC)
      • Operator
      • Organization
      • Organization-owned queries
      • Organization Owner
      • Parser
      • Permissions
      • Persistent queries
      • Pipeline
      • Proxy Authentication
      • Query
      • Query Coordinator
      • Query Editor
      • Query prefix
      • Query Profiling
      • Query Quotas
      • Query Work
      • RBAC (Role-Based Access Control)
      • Real-time
      • Regex (Regular Expression)
      • Regular Expression Engine V2
      • Repository
      • Repository Permissions
      • REST API
      • Result
      • Reverse Proxy
      • Roles
      • Security Assertion Markup Language (SAML)
      • Saved Search
      • Scheduled Search
      • Search
      • Search Interface
      • Security
      • Security Policies
      • Segment
      • Sensitive Events
      • SIEM (Security Information and Event Management)
      • Structured Array Syntax
      • Tag
      • Tag Fields
      • Tagging
      • Template Language
      • Threshold
      • Throttling Period
      • Time Interval Selector
      • TimeChart
      • @timestamp
      • Timestamp Parsing
      • Token
      • Tool Panel
      • Transformation
      • Triggers
      • User Account
      • User Interface (UI)
      • User Management
      • User Roles
      • Vhost
      • View
      • View-based Access Control
      • Visualization
      • Webhook
      • Widget
      • Widget Selector
      • Worker Node
      • Zstd
Falcon LogScale Documentation
/ LogScale Terminology

Saved Search

A query that has been stored for future use, including its configuration settings and parameters. For example, for sharing with other users or to make it reusable across dashboards. Saved searches are not owned by the user and are shared by all users in the view; this means that they persist even if the user is removed.

Related Content
  • How-To: Reference Saved Searches Within Queries

  • Save Results

  • Saved Searches (User Functions)

  • Save Searches

Support
  • Twitter
  • LinkedIn
  • Youtube

© 2026 CrowdStrike All other marks contained herein are the property of their respective owners.

  • Other articles on this topic

    • Grammar Subset
    • Grant Permissions for Saved Queries
    • Manage Existing Saved Searches
    • Save Results
    • Save Searches
  • Related Language Syntax

    • Referencing Resources
    • Saved Searches (User Functions)
    • User Parameters (Variables)

Enter search term