> For the complete documentation index, see [llms.txt](https://sandyzeng.gitbook.io/kql/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://sandyzeng.gitbook.io/kql/kql-quick-guide/my-favorites/search.md).

# search

Use <mark style="color:red;">**search**</mark> when you know what are looking for, but don't know from where.

For example, I know I have a device name that starts with **THINK**, I can't remember what exact name it is and I just want to see what data do I get

{% hint style="info" %}
A faster way to filter the data that you are looking for is to \*\*\*\* use "**where".**
{% endhint %}

{% content-ref url="/pages/JqzuL0eJai7ScvfZf2zE" %}
[where](/kql/kql-quick-guide/my-favorites/where.md)
{% endcontent-ref %}

### 🔍Search everything and not case sensitive

```
search "*think*"
```

This will return all the results that contain think (not case sensitive) from all columns and all tables

![search anything and not case sensitive](https://3533425259-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fbx8yn20QqNJtsVaH9CY7%2Fuploads%2Ft4sN2lEGAL38rCt282L2%2Fimage.png?alt=media\&token=8801e1ca-324a-4fdf-a1d0-e87d18db5781)

### 🔍Search matched words with case sensitive

```
search kind=case_sensitive "THINK460"
```

![Search matched words with case sensitive](https://3533425259-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fbx8yn20QqNJtsVaH9CY7%2Fuploads%2F6N0F98iePtMCG3fLGgLt%2Fimage.png?alt=media\&token=aec198b3-08bf-4825-b407-46491936f564)

### 🔍Search from specific tables

```
search in (IntuneDevices, UCClient) "THINK460"
```

![Search from specific tables](https://3533425259-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fbx8yn20QqNJtsVaH9CY7%2Fuploads%2FwoVvXA8jKHCipt0CqALd%2Fimage.png?alt=media\&token=b787225e-c804-4ef1-a58c-bd5f1e2e0eba)

### 🔍Search the value from the specified columnIntu

```
// Some code
IntuneDevices
| search DeviceName: "THINK"
```

```
```

### 🔍Search begins with and starts with

```
// Search startswith
IntuneDevices
| search * startswith "THINK" 

//Search endswith
IntuneDevices
| search * endswith "01" 
```

### 🔍Search combined logically

```
IntuneDevices
| search * endswith "01" and ("Windows" or "iOS")
```

### 🔍Search with regex

```
IntuneDevices
| search DeviceName matches regex "[A-Z]-"
```
