Events

View as Markdown

When viewing system events under alerts, use these keywords to search and filter them.

runZero retains event records for one year.

Action

Use action:<text> to search by the action that caused the event.

action:agent-reconnected

Created timestamp

Search the created_at timestamp field with created_at:<term>. The term supports the standard runZero time comparison syntax.

created_at:>2weeks
created_at:<30minutes
updated_at:>1month
updated_at:2hours

Details

Search the event record details with details:<text>. This can be useful for finding IP addresses.

details:192.168.0.1

Source and target name

Search the source (src) column with src:<text> or source:<text>, and the target (tgt) column with tgt:<text> or target:<text>.

src:crowdstrike
target:primary

Source and target type

Search the source type (shown at the start of the src column) with src_type:<text> or source_type:<text>, and the target type with tgt_type:<text> or target_type:<text>.

src_type:task
target_type:site

Organization, site, source and target IDs

Search the IDs of organizations, sites, sources and targets mentioned in event details with these terms:

  • organization_id:<uuid>
  • site_id:<uuid>
  • source_id:<uuid> or src_id:<uuid>
  • target_id:<uuid> or tgt_id:<uuid>

The IDs are unique and are written as UUIDs.

organization_id:0eacf412-6e69-11ec-88b9-f875a414a63a
Updated