Welcome to the Microsoft Q&A Platform! Thank you for asking your question here.
The query is set to check logs from the "Last 4 hours." Please confirm that logs have been generated within this period. You might want to expand the time range to cover a longer period to see if logs are available beyond the initial window.
check that the "MICROSOFT.SEARCH" resource provider is selected, as this is the one for the logs you're analyzing. Double-check that your resources are generating logs under this provider.
The query filters for logs where the "ResultType" is "Failed" and excludes "Success." Verify that this matches the logs you're interested in. You can temporarily adjust or remove this filter to check if it’s too restrictive.
The query is excluding logs where the "OperationName" is "Indexes.Update." Check if this is hiding any important logs. You can try removing or adjusting this filter to see if it’s causing the issue.
Confirm that logs are being ingested properly into the Log Analytics workspace. Check for any issues with log data sources or recent changes that could affect data ingestion.
Refer
https://learn.microsoft.com/en-us/azure/azure-monitor/logs/get-started-queries?tabs=kql
https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-query-overview
https://learn.microsoft.com/en-us/azure/azure-monitor/logs/log-analytics-tutorial
https://learn.microsoft.com/en-us/azure/azure-monitor/reference/logs-index
If you have any further queries, do let us know.
If the answer is helpful, please and "Upvote it".