Skip to content

This document provides details on the query order fields and directions that are supported by each provider for each operation. Orders can be used to specify the direction of the results of an operation, such as ordering by a specific field in ascending or descending order. If a provider or operation does not support ordering, it will not be listed here.

Query Alerts

FieldCrowdStrike Falcon® Next-Gen SIEMElastic SIEMGoogle Security Operations (Chronicle Compatibility)Google Security OperationsSynqly Test ProviderOpenSearch SIEMIBM QRadar SIEMRapid7 InsightIDRMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEM
timestampasc, desc

Query Events

FieldCrowdStrike Falcon® Next-Gen SIEMElastic SIEMGoogle Security Operations (Chronicle Compatibility)Google Security OperationsSynqly Test ProviderOpenSearch SIEMIBM QRadar SIEMRapid7 InsightIDRMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEM
timeasc, descasc, descasc, desc

Query Investigations

FieldCrowdStrike Falcon® Next-Gen SIEMElastic SIEMGoogle Security Operations (Chronicle Compatibility)Google Security OperationsSynqly Test ProviderOpenSearch SIEMIBM QRadar SIEMRapid7 InsightIDRMicrosoft SentinelSplunk Enterprise SecuritySumo Logic Cloud SIEM
timeasc, desc