Skip to content

This document provides details on the filters supported by each provider for each API operation. Filters can be used to restrict the results of an API operation, such as filtering by a specific field or value. If a provider or operation does not support filters, it will not be listed here.

They are used in conjunction with the filter query parameter in the API request.

CrowdStrike Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.typeeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
cloud.serviceeq, ne, like, not_like, in, not_instring
controls.benchmarks.frameworkeq, ne, like, not_like, in, not_instring
controls.benchmarks.nameeq, ne, like, not_like, in, not_instring
controls.benchmarks.versioneq, ne, like, not_like, in, not_instring
device.created_timegt, gte, lt, ltedatetime
device.created_time_atgt, gte, lt, ltedatetime
device.first_seen_timegt, gte, lt, ltedatetime
device.first_seen_time_dtgt, gte, lt, ltedatetime
device.modified_timegt, gte, lt, ltedatetime
device.modified_time_dtgt, gte, lt, ltedatetime
device.nameeq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring

Microsoft Defender for Cloud filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
device.created_timeeq, ne, gt, gte, lt, ltedatetime
device.modified_timeeq, ne, gt, gte, lt, ltedatetime
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring

Palo Alto Networks Cortex Cloud Security filters for query_cloud_resource_inventory

FieldOperatorsSupported Values
cloud.account.nameeq, ne, in, not_in, likestring
cloud.account.uideq, ne, in, not_in, likestring
cloud.providereq, ne, in, not_instring
cloud.regioneq, ne, in, not_in, likestring
device.first_seen_timeeq, ne, gt, gte, lt, ltedatetime
device.ipeq, ne, in, not_in, likestring
device.last_seen_timeeq, ne, gt, gte, lt, ltedatetime
device.maceq, ne, in, not_in, likestring
device.nameeq, ne, in, not_in, likestring
device.regioneq, ne, in, not_in, likestring
device.typeeq, ne, in, not_in, likestring
device.uideq, ne, in, not_in, likestring
resource.nameeq, ne, in, not_in, likestring
resource.regioneq, ne, in, not_in, likestring
resource.typeeq, ne, in, not_in, likestring
resource.uideq, ne, in, not_in, likestring

AWS Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.assessments.categoryeq, ne, like, not_like, in, not_instring
compliance.assessments.nameeq, ne, like, not_like, in, not_instring
compliance.controleq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, like, not_like, in, not_instring
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.typeseq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
metadata.product.nameeq, ne, like, not_like, in, not_instring
metadata.product.vendor_nameeq, ne, like, not_like, in, not_instring
resources.typeeq, ne, like, not_like, in, not_instring
resources.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_in, gt, gte, lt, ltenumber
statuseq, ne, like, not_like, in, not_instring
status_ideq, ne, like, not_like, in, not_in, gt, gte, lt, ltenumber

CrowdStrike Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
actor.authorizations.policy.is_appliedeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
compliance.standardseq, ne, like, not_like, in, not_instring
compliance.statuseq, ne, like, not_like, in, not_instring
finding_info.titleeq, ne, like, not_like, in, not_instring
finding_info.uideq, ne, like, not_like, in, not_instring
resource.nameeq, ne, like, not_like, in, not_instring
resource.typeeq, ne, like, not_like, in, not_instring
resource.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring
timegt, gte, lt, ltedatetime

Microsoft Defender for Cloud filters for query_compliance_findings

FieldOperatorsSupported Values
compliance.controleqstring
compliance.requirementseqstring
compliance.standardseqstring

Palo Alto Networks Cortex Cloud Security filters for query_compliance_findings

FieldOperatorsSupported Values
compliance.statusinstring
finding_info.created_timegte, ltedatetime
finding_info.uidinstring
resource.typeinstring
severityinstring
timegte, ltedatetime

Microsoft Defender for Cloud filters for query_events

FieldOperatorsSupported Values
device.ipeq, nestring
src_endpoint.ipeq, nestring
timegte, ltedatetime
unmapped.appIdeq, nenumber
unmapped.device.clientIPeq, nestring

CrowdStrike Cloud Security filters for query_ioms

FieldOperatorsSupported Values
actor.authorizations.policy.nameeq, ne, like, not_like, in, not_instring
actor.authorizations.policy.uideq, ne, like, not_like, in, not_instring
cloud.account.nameeq, ne, like, not_like, in, not_instring
cloud.account.uideq, ne, like, not_like, in, not_instring
cloud.providereq, ne, like, not_like, in, not_instring
cloud.regioneq, ne, like, not_like, in, not_instring
device.agent_list.uideq, ne, like, not_like, in, not_instring
device.managed_byeq, ne, like, not_like, in, not_instring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.typeseq, ne, like, not_like, in, not_instring
metadata.tenant_uideq, ne, like, not_like, in, not_instring
resources.owner.uideq, ne, like, not_like, in, not_instring
severityeq, ne, like, not_like, in, not_instring
severity_ideq, ne, like, not_like, in, not_instring

AWS Cloud Security filters for query_threats

FieldOperatorsSupported Values
activity_ideq, ne, gt, gte, lt, lte, in, not_innumber
activity_nameeq, ne, in, not_in, likestring
class_nameeq, ne, in, not_in, likestring
cloud.account.uideq, ne, in, not_in, likestring
cloud.providereq, ne, in, not_in, likestring
cloud.regioneq, ne, in, not_in, likestring
commenteq, ne, in, not_in, likestring
confidence_scoreeq, ne, gt, gte, lt, lte, in, not_innumber
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, in, not_in, likestring
finding_info.first_seen_timegt, gte, lt, ltedatetime
finding_info.first_seen_time_dtgt, gte, lt, ltedatetime
finding_info.last_seen_timegt, gte, lt, ltedatetime
finding_info.last_seen_time_dtgt, gte, lt, ltedatetime
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.related_events.titleeq, ne, in, not_in, likestring
finding_info.related_events.uideq, ne, in, not_in, likestring
finding_info.related_events_counteq, ne, gt, gte, lt, lte, in, not_innumber
finding_info.src_urleq, ne, in, not_in, likestring
finding_info.titleeq, ne, in, not_in, likestring
finding_info.typeseq, ne, in, not_in, likestring
finding_info.uideq, ne, in, not_in, likestring
malware.nameeq, ne, in, not_in, likestring
metadata.product.nameeq, ne, in, not_in, like, not_likestring
metadata.product.uideq, ne, in, not_in, like, not_likestring
metadata.product.vendor_nameeq, ne, in, not_in, like, not_likestring
metadata.uideq, ne, in, not_in, like, not_likestring
remediation.desceq, ne, in, not_in, likestring
remediation.referenceseq, ne, in, not_in, likestring
resources.cloud_partitioneq, ne, in, not_in, likestring
resources.regioneq, ne, in, not_in, likestring
resources.typeeq, ne, in, not_in, likestring
resources.uideq, ne, in, not_in, likestring
severityeq, ne, in, not_in, likestring
severity_ideq, ne, gt, gte, lt, lte, in, not_innumber
statuseq, ne, in, not_in, likestring
status_ideq, ne, gt, gte, lt, lte, in, not_innumber
vulnerabilities.cve.uideq, ne, in, not_in, likestring
vulnerabilities.is_exploit_availableeq, neboolean
vulnerabilities.is_fix_availableeq, neboolean

Microsoft Defender for Cloud filters for query_threats

FieldOperatorsSupported Values
cloud.providereq, ne, in, not_in, like, not_likestring
device.hostnameeq, ne, in, not_in, like, not_likestring
finding_info.created_timegt, gte, lt, ltedatetime
finding_info.created_time_dtgt, gte, lt, ltedatetime
finding_info.desceq, ne, in, not_in, like, not_likestring
finding_info.modified_timegt, gte, lt, ltedatetime
finding_info.modified_time_dtgt, gte, lt, ltedatetime
finding_info.titleeq, ne, in, not_in, like, not_likestring
finding_info.typeseq, ne, in, not_in, like, not_likestring
metadata.product.vendor_nameeq, ne, in, not_in, like, not_likestring
remediation.desceq, ne, in, not_in, like, not_likestring
resources.uideq, ne, in, not_in, like, not_likestring
severityeq, ne, in, not_in, like, not_likestring
statuseq, ne, in, not_in, like, not_likestring
timegt, gte, lt, ltedatetime
time_dtgt, gte, lt, ltedatetime