Groups inventory
When viewing the Groups inventory, use these keywords to search and filter groups. To search users, see the users inventory keywords.
Source
Use source:<name> to search or filter by the name of the source that reported the groups.
source:ldap
Name fields
Use <name_field>:<text> to search or filter either of the two name fields in the group attributes.
The name fields you can search this way:
namedisplay_name
name:admin
display_name:"Domain Administrators"
Description
Use description:<text> to search the description field.
description:admin
Users
Use user_id:<uuid> to find groups with a specific member by the user’s ID. The user_id field is the user’s unique identifier, written as a UUID.
user_id:f8a26321-cbce-4fb5-a9ca-ffa809489dd5
Use email:<address> to search for users by email address.
email:john@example.com
First seen
Use first_seen_at:<date> to search for users by when they were first seen in the organization. This field supports the date comparison operators.
first_seen_at:<1day
Last seen
Use last_seen_at:<date> to search for users by when they were last seen in the organization. This field supports the date comparison operators.
last_seen_at:>2years
Site name or ID
Use site:<term> to filter by site name or ID.
site:Primary
site:"Branch Office"
site:ad67d649-041b-439d-af59-f200053a8899
Organization name or ID
Use organization:<term> to filter by organization name or ID.
organization:runZero
organization:"Temporary Project"
organization:f1c3ef6d-cb41-4d55-8887-6ed3cfb3d42d