Events
When viewing system events under alerts, use these keywords to search and filter them.
runZero retains event records for one year.
Action
Use action:<text> to search by the action that caused the event.
action:agent-reconnected
Created timestamp
Search the created_at timestamp field with created_at:<term>. The term supports the standard runZero time comparison syntax.
created_at:>2weeks
created_at:<30minutes
updated_at:>1month
updated_at:2hours
Details
Search the event record details with details:<text>. This can be useful for finding IP addresses.
details:192.168.0.1
Source and target name
Search the source (src) column with src:<text> or source:<text>, and the target (tgt) column with tgt:<text> or target:<text>.
src:crowdstrike
target:primary
Source and target type
Search the source type (shown at the start of the src column) with src_type:<text> or source_type:<text>, and the target type with tgt_type:<text> or target_type:<text>.
src_type:task
target_type:site
Organization, site, source and target IDs
Search the IDs of organizations, sites, sources and targets mentioned in event details with these terms:
organization_id:<uuid>site_id:<uuid>source_id:<uuid>orsrc_id:<uuid>target_id:<uuid>ortgt_id:<uuid>
The IDs are unique and are written as UUIDs.
organization_id:0eacf412-6e69-11ec-88b9-f875a414a63a