Sheridan Posted July 1 Posted July 1 Has anyone else has much experience with the KQL search feature in Microsoft Purview? I've trying to run a search to collected all emails where a keyword could be mentioned in the subject or main body of an email so searching the syntax suggests the query should be: subject:"keyword" OR body:"keyword" Searches suggest body or contents is the correct property for the main email content but both options show as a syntax error? Trawling through MS documention and I can't find a mention of either, or an alternative which would be a real shame as this is exactly the type of search I need to do!
psydii Posted July 1 Posted July 1 If you are specifically looking for the keyword in subject lines and message bodies, but not attachments, I'm not sure that is possible. If you don't mind attachments being searched then (keyword) is all you need. I noticed recently that in ediscovery the review set seems to default to presenting the item that matched as the first item in a collapsed list, so if the attachment matched, its the attachment that shows, and the email is revealed by expanding the collapsed list, while if the email subject or body matched that is presented first with the attachments (and related emails) below. I'd not noticed that behaviour before. That said, refreshing the list this last week often causes the order to shuffle (though sometimes it reverts to expected order). It had been pretty stable the last few times I've used it.
Sheridan Posted July 1 Author Posted July 1 What I need to do is run a keyword search that includes a persons name - so any Purview options will pick up any emails they sent, or received as an individual or group so the output is enormous! Like 10gb plus of emails! I only need to find emails where the name is explicitly in the Subject or Email body but there doesn't seem to be an option for that
psydii Posted July 1 Posted July 1 Yeah, that would have been useful here too. Do the search on keyword, but then in the review set create a filter where they are not a participant. Copy the result to a new review set and then dedupe that.
Sheridan Posted July 1 Author Posted July 1 4 minutes ago, psydii said: Yeah, that would have been useful here too. Do the search on keyword, but then in the review set create a filter where they are not a participant. Copy the result to a new review set and then dedupe that. Hmm that might work - I've never tried that before. Whereabouts is the option to create a filter on the results, I can't seem to see that option
Sheridan Posted July 1 Author Posted July 1 We have A3 but it looks like its a Premium option when I go to result sets
psydii Posted July 1 Posted July 1 ahh. that would be it. I think you can get an add-on that should light up that capability.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now