Skip to content

This document provides details on the filters supported by each provider for each API operation. Filters can be used to restrict the results of an API operation, such as filtering by a specific field or value. If a provider or operation does not support filters, it will not be listed here.

They are used in conjunction with the filter query parameter in the API request.

CrowdStrike Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.typeeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
cloud.serviceeq, ne, like, not_like, in, not_instring
controls.benchmarks.frameworkeq, ne, like, not_like, in, not_instring
controls.benchmarks.nameeq, ne, like, not_like, in, not_instring
controls.benchmarks.versioneq, ne, like, not_like, in, not_instring
device.created_timegt, gte, lt, ltedatetime
device.created_time_atgt, gte, lt, ltedatetime
device.first_seen_timegt, gte, lt, ltedatetime
device.first_seen_time_dtgt, gte, lt, ltedatetime
device.modified_timegt, gte, lt, ltedatetime
device.modified_time_dtgt, gte, lt, ltedatetime
device.nameeq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring

Microsoft Defender for Cloud filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
device.created_timeeq, ne, gt, gte, lt, ltedatetime
device.modified_timeeq, ne, gt, gte, lt, ltedatetime
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring

Palo Alto Networks Cortex Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, in, not_in, likestring
cloud.account.uideq, ne, in, not_in, likestring
cloud.providereq, ne, in, not_instring
cloud.regioneq, ne, in, not_in, likestring
device.first_seen_timeeq, ne, gt, gte, lt, ltedatetime
device.ipeq, ne, in, not_in, likestring
device.last_seen_timeeq, ne, gt, gte, lt, ltedatetime
device.maceq, ne, in, not_in, likestring
device.nameeq, ne, in, not_in, likestring
device.regioneq, ne, in, not_in, likestring
device.typeeq, ne, in, not_in, likestring
device.uideq, ne, in, not_in, likestring
resource.nameeq, ne, in, not_in, likestring
resource.regioneq, ne, in, not_in, likestring
resource.typeeq, ne, in, not_in, likestring
resource.uideq, ne, in, not_in, likestring

Upwind Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
categoryeq, instring
cloud.providereq, instring
resource.typeeq, instring

Wiz Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.uideq, instring
cloud.providereq, inAWS, Azure, GCP, Kubernetes
device.created_timegte, ltedatetime
device.created_time_dtgte, ltedatetime
device.first_seen_timegte, ltedatetime
device.first_seen_time_dtgte, ltedatetime
resource.nameeqstring
resource.typeeq, inenum
resource.uideq, instring
start_timegte, ltedatetime
start_time_dtgte, ltedatetime
statuseq, inenum
timegte, ltedatetime
time_dtgte, ltedatetime

[MOCK] CrowdStrike Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.typeeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
cloud.serviceeq, ne, like, not_like, in, not_instring
controls.benchmarks.frameworkeq, ne, like, not_like, in, not_instring
controls.benchmarks.nameeq, ne, like, not_like, in, not_instring
controls.benchmarks.versioneq, ne, like, not_like, in, not_instring
device.created_timegt, gte, lt, ltedatetime
device.created_time_atgt, gte, lt, ltedatetime
device.first_seen_timegt, gte, lt, ltedatetime
device.first_seen_time_dtgt, gte, lt, ltedatetime
device.modified_timegt, gte, lt, ltedatetime
device.modified_time_dtgt, gte, lt, ltedatetime
device.nameeq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring

AWS Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.assessments.categoryeq, ne, like, not_like, in, not_instring
compliance.assessments.nameeq, ne, like, not_like, in, not_instring
compliance.controleq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, like, not_like, in, not_instring
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.typeseq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
metadata.product.nameeq, ne, like, not_like, in, not_instring
metadata.product.vendor_nameeq, ne, like, not_like, in, not_instring
resources.typeeq, ne, like, not_like, in, not_instring
resources.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_idgte, lte, eqnumber
statuseq, ne, like, not_like, in, not_instring
status_idgte, lte, eqnumber
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

CrowdStrike Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
actor.authorizations.policy.is_appliedeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring
timegt, gte, lt, ltedatetime

Microsoft Defender for Cloud filters for query_compliance_findings

FieldOperatorsSupported Values
compliance.controleqstring
compliance.requirementseqstring
compliance.standardseqstring

Palo Alto Networks Cortex Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
finding_info.analytic.categoryeq, instring
finding_info.analytic.nameeq, instring
finding_info.analytic.uideq, instring
finding_info.created_timegte, ltedatetime
finding_info.first_seen_timegte, ltedatetime
finding_info.modified_timegte, ltedatetime
finding_info.uideq, instring
metadata.correlation_uideq, instring
metadata.uideq, instring
resources.typeeq, instring
severityeq, inUnknown, Informational, Low, Medium, High, Critical
statuseq, inNew, In Progress, Resolved, Unknown
timegte, ltedatetime

Upwind Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
compliance.controleqstring
compliance.standardseqstring
compliance.statuseqPass, Fail, All
compliance.status_ideqnumber
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
resource.nameeqstring
severityeqLow, Medium, High, Critical
severity_ideqnumber
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

Wiz Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
cloud.providereq, inAWS, Azure, GCP
compliance.controleq, instring
compliance.statuseq, inUnknown, Pass, Warning, Fail, Other
finding_info.created_timegte, ltedatetime
finding_info.created_time_dtgte, ltedatetime
finding_info.first_seen_timegte, ltedatetime
finding_info.first_seen_time_dtgte, ltedatetime
finding_info.last_seen_timegte, ltedatetime
finding_info.last_seen_time_dtgte, ltedatetime
finding_info.modified_timegte, ltedatetime
finding_info.modified_time_dtgte, ltedatetime
finding_info.uideq, instring
resource.nameeqstring
resource.typeeq, instring
resource.uideq, instring
severityeq, inInformational, Low, Medium, High, Critical
start_timegte, ltedatetime
start_time_dtgte, ltedatetime
statuseq, inNew, Resolved, Suppressed
timegte, ltedatetime
time_dtgte, ltedatetime

[MOCK] CrowdStrike Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
actor.authorizations.policy.is_appliedeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring
timegt, gte, lt, ltedatetime

AWS Cloud Security filters for query_events

FieldOperatorsSupported Values
api.operationeq, ne, in, not_in, like, not_likestring
api.service.nameeq, ne, in, not_in, like, not_likestring
cloud.account.uideq, ne, in, not_in, like, not_likestring
cloud.account_uideq, ne, in, not_in, like, not_likestring
cloud.regioneq, ne, in, not_in, like, not_likestring
http_request.user_agenteq, ne, in, not_in, like, not_likestring
metadata.labelseq, ne, in, not_in, like, not_likestring
src_endpoint.ipeq, ne, in, not_in, like, not_likestring
timegt, gte, lt, ltedatetime

Microsoft Defender for Cloud filters for query_events

FieldOperatorsSupported Values
device.ipeq, nestring
src_endpoint.ipeq, nestring
timegte, ltedatetime
unmapped.appIdeq, nenumber
unmapped.device.clientIPeq, nestring

Upwind Cloud Security filters for query_events

FieldOperatorsSupported Values
cloud.account.uideqstring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.typeseqNetwork, Process, Cloud Logs
finding_info.uideqstring
severityeqLow, Medium, High, Critical
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

AWS Cloud Security filters for query_ioms

FieldOperatorsSupported Values
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.assessments.categoryeq, ne, like, not_like, in, not_instring
compliance.assessments.nameeq, ne, like, not_like, in, not_instring
compliance.controleq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, like, not_like, in, not_instring
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.typeseq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
metadata.product.nameeq, ne, like, not_like, in, not_instring
metadata.product.vendor_nameeq, ne, like, not_like, in, not_instring
resources.typeeq, ne, like, not_like, in, not_instring
resources.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_idgte, lte, eqnumber
statuseq, ne, like, not_like, in, not_instring
status_idgte, lte, eqnumber

CrowdStrike Cloud Security filters for query_ioms

FieldOperatorsSupported Values
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
device.agent_list.uideq, ne, like, not_like, in, not_instring
device.managed_byeq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.typeseq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resources.owner.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring

Palo Alto Networks Cortex Cloud Security filters for query_ioms

FieldOperatorsSupported Values
finding_info.analytic.categoryeq, instring
finding_info.analytic.nameeq, instring
finding_info.analytic.uideq, instring
finding_info.created_timegte, ltedatetime
finding_info.first_seen_timegte, ltedatetime
finding_info.modified_timegte, ltedatetime
finding_info.uideq, instring
metadata.correlation_uideq, instring
metadata.uideq, instring
resources.typeeq, instring
severityeq, inUnknown, Informational, Low, Medium, High, Critical
statuseq, inNew, In Progress, Resolved, Unknown
timegte, ltedatetime

[MOCK] CrowdStrike Cloud Security filters for query_ioms

FieldOperatorsSupported Values
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
device.agent_list.uideq, ne, like, not_like, in, not_instring
device.managed_byeq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.typeseq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resources.owner.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring

AWS Cloud Security filters for query_threats

FieldOperatorsSupported Values
activity_idgte, lte, eqnumber
activity_nameeq, ne, in, not_in, likestring
class_nameeq, ne, in, not_in, likestring
cloud.account.uideq, ne, in, not_in, likestring
cloud.providereq, ne, in, not_in, likestring
cloud.regioneq, ne, in, not_in, likestring
commenteq, ne, in, not_in, likestring
confidence_scoregte, lte, eqnumber
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, in, not_in, likestring
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.related_events.titleeq, ne, in, not_in, likestring
finding_info.related_events.uideq, ne, in, not_in, likestring
finding_info.related_events_countgte, lte, eqnumber
finding_info.src_urleq, ne, in, not_in, likestring
finding_info.titleeq, ne, in, not_in, likestring
finding_info.typeseq, ne, in, not_in, likestring
finding_info.uideq, ne, in, not_in, likestring
malware.nameeq, ne, in, not_in, likestring
metadata.product.nameeq, ne, in, not_in, like, not_likestring
metadata.product.uideq, ne, in, not_in, like, not_likestring
metadata.product.vendor_nameeq, ne, in, not_in, like, not_likestring
metadata.uideq, ne, in, not_in, like, not_likestring
remediation.desceq, ne, in, not_in, likestring
remediation.referenceseq, ne, in, not_in, likestring
resources.cloud_partitioneq, ne, in, not_in, likestring
resources.regioneq, ne, in, not_in, likestring
resources.typeeq, ne, in, not_in, likestring
resources.uideq, ne, in, not_in, likestring
severityeq, ne, in, not_in, likestring
severity_idgte, lte, eqnumber
statuseq, ne, in, not_in, likestring
status_idgte, lte, eqnumber
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime
vulnerabilities.cve.uideq, ne, in, not_in, likestring
vulnerabilities.is_exploit_availableeq, neboolean
vulnerabilities.is_fix_availableeq, neboolean

Microsoft Defender for Cloud filters for query_threats

FieldOperatorsSupported Values
cloud.providereq, ne, in, not_in, like, not_likestring
device.hostnameeq, ne, in, not_in, like, not_likestring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, in, not_in, like, not_likestring
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, in, not_in, like, not_likestring
finding_info.typeseq, ne, in, not_in, like, not_likestring
metadata.product.vendor_nameeq, ne, in, not_in, like, not_likestring
remediation.desceq, ne, in, not_in, like, not_likestring
resources.uideq, ne, in, not_in, like, not_likestring
severityeq, ne, in, not_in, like, not_likestring
statuseq, ne, in, not_in, like, not_likestring
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

Upwind Cloud Security filters for query_threats

FieldOperatorsSupported Values
cloud.account.uideqstring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.typeseqNetwork, Process, Cloud Logs
finding_info.uideqstring
metadata.event_codeeqstring
severityeqLow, Medium, High, Critical
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime

Wiz Cloud Security filters for query_threats

FieldOperatorsSupported Values
cloud.providereq, inAWS, Azure, GCP, Kubernetes
finding_info.created_timegte, ltedatetime
finding_info.created_time_dtgte, ltedatetime
finding_info.modified_timegte, ltedatetime
finding_info.modified_time_dtgte, ltedatetime
finding_info.titleeq, instring
finding_info.typeseq, inenum
finding_info.uideq, instring
resource.nameeqstring
resource.typeeq, inenum
resource.uideq, instring
severityeq, inenum
timegte, ltedatetime
time_dtgte, ltedatetime