Skip to content

This document provides details on the filters supported by each provider for each API operation. Filters can be used to restrict the results of an API operation, such as filtering by a specific field or value. If a provider or operation does not support filters, it will not be listed here.

They are used in conjunction with the filter query parameter in the API request.

CrowdStrike Falcon® Spotlight filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegte, ltedatetime
device.maceqstring

Microsoft Defender for Endpoint filters for query_assets

FieldOperatorsSupported Values
device.hostnameeq, ne, like, instring
device.ipeq, ne, instring
device.last_seen_timegt, gte, lt, ltedatetime
device.os.nameeq, ne, like, instring
device.risk_leveleq, ne, inInfo, Low, Medium, High
device.uideq, ne, instring
metadata.labelseqstring
status_codeeq, ne, instring

Nucleus VM filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring

Qualys VMDR filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegtedatetime
device.maceqstring
device.uideq, instring

Rapid7 InsightVM filters for query_assets

FieldOperatorsSupported Values
device.hostnameeq, instring
device.ipeq, instring
device.last_seen_timegte, ltedatetime
device.maceq, instring

ServiceNow Vulnerability Response filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegtedatetime
device.maceqstring
device.nameeqstring

Tanium VM filters for query_assets

FieldOperatorsSupported Values
device.hostnameeq, instring
device.ipeq, instring
device.last_seen_timegtedatetime
device.maceq, instring

Tenable VM filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegtedatetime
device.maceqstring

[MOCK] Qualys VMDR filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegtedatetime
device.maceqstring

[MOCK] Rapid7 InsightVM Cloud filters for query_assets

FieldOperatorsSupported Values
device.hostnameeq, instring
device.ipeq, instring
device.last_seen_timegte, ltedatetime
device.maceq, instring

[MOCK] Tanium Vulnerability Management filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegtedatetime
device.maceqstring

[Mock] CrowdStrike Falcon® Spotlight filters for query_assets

FieldOperatorsSupported Values
device.hostnameeqstring
device.ipeqstring
device.last_seen_timegte, ltedatetime
device.maceqstring

Amazon Inspector filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
severityeq, inCritical, High, Medium, Low, Informational

CrowdStrike Falcon® Spotlight filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
severityeq, incritical, high, medium, low, info

Microsoft Defender for Endpoint filters for query_findings

FieldOperatorsSupported Values
finding.desceq, likestring
finding.first_seen_timegt, gte, lt, ltedatetime
finding.last_seen_timegt, gte, lt, ltedatetime
finding.titleeq, likestring
finding.uideq, in, likestring
resources.nameeq, ne, like, instring
severityeq, ne, inCritical, High, Medium, Low, Informational

Nucleus VM filters for query_findings

FieldOperatorsSupported Values
resources.ipeqstring
resources.nameeqstring
severityeqcritical, high, medium, low, info

Qualys VMDR filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
resources.ipeq, instring
resources.labelseq, instring
severityeq, incritical, high, medium, low, info

Rapid7 InsightVM filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
finding.uideq, in, likestring
resources.ipeq, instring
resources.last_seen_timegte, ltedatetime
resources.nameeq, in, likestring
severityeq, incritical, high, medium, low, info

ServiceNow Vulnerability Response filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
finding.uideq, in, likestring
resources.ipeq, instring
resources.last_seen_timegte, ltedatetime
resources.maceq, instring
resources.nameeq, instring
severityeq, incritical, high, medium, low, info

Tanium VM filters for query_findings

FieldOperatorsSupported Values
finding.desceq, likestring
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
finding.titleeq, likestring
finding.uideq, in, likestring
resources.ipeq, instring
resources.last_seen_timegtedatetime
resources.maceq, instring
resources.nameeq, instring
resources.os_typeeq, instring
severityeq, incritical, high, medium, low, info, unknown

Tenable VM filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegtedatetime
finding.last_seen_timegtedatetime
finding.uideq, instring
severityeq, incritical, high, medium, low, info

[MOCK] Qualys VMDR filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
severityeq, incritical, high, medium, low, info

[MOCK] Rapid7 InsightVM Cloud filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
finding.uideq, in, likestring
resources.ipeq, instring
resources.last_seen_timegte, ltedatetime
resources.nameeq, in, likestring
severityeq, incritical, high, medium, low, info

[MOCK] Tanium Vulnerability Management filters for query_findings

FieldOperatorsSupported Values
finding.desceq, likestring
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
finding.titleeq, likestring
finding.uideq, in, likestring
resources.ipeq, instring
resources.last_seen_timegtedatetime
resources.maceq, instring
resources.nameeq, instring
resources.os_typeeq, instring
severityeq, incritical, high, medium, low, info, unknown

[Mock] CrowdStrike Falcon® Spotlight filters for query_findings

FieldOperatorsSupported Values
finding.first_seen_timegte, ltedatetime
finding.last_seen_timegte, ltedatetime
severityeq, incritical, high, medium, low, info