ediscovery search
6 TopicseDiscovery keyword statistics.
Noticing with this roadmap item: https://admin.microsoft.com/AdminPortal/Home?#/MessageCenter/:/messages/MC1105008 specifically Expanded search condition builder with support for logical operators (AND, OR, NEAR) in the keywords field That when running a new search that the statistics generated for keywords claims that "Query does not contain keywords" and doesn't generate the Statistics reports for keywords anymore. Tried with keywords on multiple lines as well as same line but separated with OR statements. Is this known issue?96Views0likes3CommentsDoes anyone know what the 'CS019-009' error means for eDiscovery premium jobs?
Hello, Once in a while, a job in eDiscovery premium will fail with error "CS019-009". For example when preparing search preview, making an export or adding a collection to a review set. The job will give status "failed". When restarted, the job runs completely fine so we never create a ticket for this. I can't seem to find anywhere what "CS019-009" means. Is this a generic error? Thanks in advance!86Views1like1CommenteDiscovery is NOT working correctly with KeyQL Sensitive Type
Hello team, I am running in eDiscovery using KeyQL or Query builder data at REST in EXO (Stale emails) that contain sensitive Info like: Canada Social Insurance number. The query run correctly, however, the output statistics pull out other type of sensitive Info, this means that the eDiscovery is not discovering what is was requested in the KeyQL query. Canada Social Insurance Number a2f29c85-ecb8-4514-a610-364790c0773e KeyQL Query: (SensitiveType:a2f29c85-ecb8-4514-a610-364790c0773e|1..|85..100) AND Date>2025-01-01 Please see the output of the Query: In addition with this problem, Why we can't delete the stale emails using as condition the "Sensitive info", so, If I need to delete the emails before 2020 with "Canada Social Insurance number", how can I do it? It will be almost impossible if the cybersecurity team needs to do with the end-user email by email? Best regards,265Views1like3CommentseDiscovery Content Search for Items in Purge Folder
We have to following configuration in place User on litigation hold Purview Exchange Online delete policy The delete policy will have deleted email from the Exchange Online Archive and I believe it will now be in the purge folder for the user. I have a requirement to run an eDiscovery content search for this user against their purge folder and then restore email back into their Exchange Online Archive. I have created a content search with the data source = Exchange Email and I have used the the syntax 'folderid:purges AND ItemClass=IPM.Note' for the query. Could someone please help to understand if this will work? No syntax errors where shown in the query but I have had this search running for approx 4 hours now. Thanks in advance ChrisSolved585Views0likes3CommentsChatGPT and eDiscovery
Hi Everyone, Can someone guide me on the correct way to perform eDiscovery for ChatGPT content? I followed the article below and can see AI interactions in the activity logs, but when I run eDiscovery, it doesn’t return any results. Microsoft Purview for ChatGPT Enterprise Any help would be greatly appreciated!368Views0likes1Commentediscovery whole word query
I am trying to run an ediscovery for the example term red but I keep getting results that include redmond and redwood and Fred. I have tried the keyword with and without quotation marks and the results come back the same. Is there some other notation in KQL that would specify the exact word red?1.5KViews0likes1Comment