StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

Long-term data: search jobs, restore, Sentinel data lake KQL jobs

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Investigations often need data older than your interactive retention: a breach discovered months after the first intrusion, a new threat intelligence report about activity last year, or a legal request. Microsoft Sentinel keeps older data cheaply in long-term retention or the Sentinel data lake tier, but that data cannot be queried like interactive analytics data, and analytics rules cannot run on it. Three tools bring it back into reach, and the exam expects you to pick the right one for the job. A search job scans a table, including its long-term retained data, for records that match a query, and writes the matching records into a new table in the analytics tier. The results table name ends in _SRCH. Search jobs run asynchronously, so you can search very large volumes and come back later. They work on analytics tables and on lower-cost plans, and use a restricted set of Kusto Query Language (KQL) operators, essentially filters rather than joins. You pay for the data scanned and for the results stored. Use a search job when you need specific records, such as every event mentioning an IP address across the past year.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan