IRP Playbooks
  • Initial page
  • Output Types
    • Number (Num)
    • Arrays
    • Objects
    • HR (Human Readable)
  • Components
    • Notifications
      • Send SMS
    • Start Playbook (Required)
      • Incident
    • Investigation
      • SearchEvents
      • SearchLogs
      • SearchWatchList
      • SearchIncidentData
    • Incident Response
      • AbuseEmail
    • Mange Incident
      • AddNote
      • Resolve
      • Escalate
      • AddToWatchList
    • Enrichements
      • Virustotal
      • ThreatIntel
      • WhoisURL
      • GeoIP
      • DomainAvailability
    • Filters
      • Each
    • Controls
      • PublicIp
  • Version
    • Changelog
Powered by GitBook
On this page
  • Inputs
  • Outputs
  1. Components
  2. Investigation

SearchLogs

Inputs

  • Search Query (Optional)

  • Relative Date Range (Optional)

  • Use only the search query above (Optional) [Boolean]

  • Add results to the incident (Optional) [Boolean]

Outputs

  • Total Results

  • Logs (Array)

  • Add To Incident (Boolean)

  • Raw Output

PreviousSearchEventsNextSearchWatchList

Last updated 4 years ago