Skip to content

This document provides details on the query order fields and directions that are supported by each provider for each operation. Orders can be used to specify the direction of the results of an operation, such as ordering by a specific field in ascending or descending order. If a provider or operation does not support ordering, it will not be listed here.

Query Alerts

FieldCrowdStrike Falcon® Insight EDR[MOCK] CrowdStrike Falcon® Insight EDRMicrosoft Defender for EndpointESET ConnectThreatDown Endpoint Detection & ResponseSentinelOne Singularity™ EndpointSophos EndpointTanium EDR
attacks.tactic.nameasc, desc
attacks.tactic.uidasc, desc
attacks.technique.nameasc, desc
attacks.technique.uidasc, desc
commentasc, desc
composite_idasc, desc
confidence_scoreasc, desc
device.first_seen_timeasc, desc
device.first_seen_time_dtasc, desc
device.hostnameasc, desc
device.last_seen_timeasc, desc
device.last_seen_time_dtasc, desc
device.os.typeasc, desc
device.uidasc, desc
device.uid_altasc, desc
finding_info.created_timeasc, desc
finding_info.created_time_dtasc, desc
finding_info.last_seen_timeasc, desc
finding_info.last_seen_time_dtasc, desc
finding_info.typesasc, desc
finding_info.uidasc, desc
metadata.loggers.logged_timeasc, desc
metadata.tenant_uidasc, desc
resources.nameasc, desc
resources.uidasc, desc
risk_scoreasc, desc
start_timeasc, desc
start_time_dtasc, desc
timeasc, desc
time_dtasc, desc
vulnerabilities.descasc, desc
vulnerabilities.titleasc, desc

Query Applications

FieldCrowdStrike Falcon® Insight EDR[MOCK] CrowdStrike Falcon® Insight EDRMicrosoft Defender for EndpointESET ConnectThreatDown Endpoint Detection & ResponseSentinelOne Singularity™ EndpointSophos EndpointTanium EDR
product.nameasc, descasc, descasc, descasc, descasc, descasc, desc

Query Endpoints

FieldCrowdStrike Falcon® Insight EDR[MOCK] CrowdStrike Falcon® Insight EDRMicrosoft Defender for EndpointESET ConnectThreatDown Endpoint Detection & ResponseSentinelOne Singularity™ EndpointSophos EndpointTanium EDR
statusasc, descasc, desc
timeasc, descasc, descasc, desc