Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex SIEM
  • Getting started
    • All guides
      • Overview
      • Investigation management
      • Working with the investigations list
  • KQL reference
  • Access management
  • Pricing policy

In this article:

  • Getting started
  • Opening the investigation list
  • Filtering by creation date
  • Searching by name or tag
  • Sorting by modification date
  • Viewing investigation information
  1. Step-by-step guides
  2. Investigations
  3. Working with the investigations list

Working with the investigations list

Written by
Yandex Cloud
Updated at July 23, 2026
View in Markdown
  • Getting started
  • Opening the investigation list
  • Filtering by creation date
  • Searching by name or tag
  • Sorting by modification date
  • Viewing investigation information

Note

This feature is at the Preview stage. To get access, contact tech support or your account manager.

This section describes how to work with the investigations list: filter investigations by date, search by name and tags, and sort by modification date.

Getting startedGetting started

The Yandex SIEM section will appear in the Cloud Center interface as a Security Deck module after the access request is approved.

You need the ycem.editor role to use the service.

Opening the investigation listOpening the investigation list

To open the investigation list:

Cloud Center UI
  1. Go to Security Deck.
  2. In the left-hand panel, select Yandex SIEM.
  3. Navigate to the Investigations tab.

The list displays all investigations for which you have access permissions.

Filtering by creation dateFiltering by creation date

To filter investigations by creation date:

Cloud Center UI
  1. Navigate to Investigations.
  2. Click the date filter.
  3. Select a period:
    • Certain date.
    • Date range.
  4. Apply the filter.

The list will refresh to only show investigations created within the selected period.

Searching by name or tagSearching by name or tag

To find an investigation:

Cloud Center UI
  1. Navigate to Investigations.
  2. Enter your keywords in the search field.
  3. The results will be displayed automatically.

The system will search for keywords in the following fields:

  • Investigation name.
  • Investigation description.
  • Tags.

Tip

Use tags for quick category-based searches, e.g., prod, security-incident, february-2024.

Sorting by modification dateSorting by modification date

To sort investigations:

Cloud Center UI
  1. Navigate to Investigations.
  2. Click the Modified column header.
  3. Select the sort order:
    • Ascending, i.e., from oldest to newest.
    • Descending, i.e., from newest to oldest.

By default, investigations are sorted by modification date in descending order.

Viewing investigation informationViewing investigation information

The investigations list displays the following details for each investigation:

  • Name: Brief description of the investigation's purpose.
  • Creation date: Timestamp when the investigation was created.
  • Last modified date: Timestamp of the most recent modification.
  • Tags: Keywords to group and search for investigations.

To open an investigation, click its name in the list.

Useful linksUseful links

  • Investigations
  • Queries
  • Investigation management
  • Working with queries

Was the article helpful?

Previous
Investigation management
Next
Overview
© 2026 Direct Cursus Technology L.L.C.