Tasks
When viewing all tasks, use these keywords to search and filter them.
Name
Search the Name field with name:<text>.
name:"test scan"
Description
Search the Description field with description:<text>.
description:"full scan"
Created by
Search the Created By field with created_by:<term>.
created_by:"admin"
Type
Search the task type with type:<text>.
type:scan
Status
Search the task status with status:<text>.
status:error
Error
Search the task error message with error:<text>.
error:"no disk space"
Recurrence frequency
Search the recurrence frequency (the “Freq” column) with recur_frequency:<text> or freq:<text>. To find tasks by whether they recur at all, use recurring:<boolean> or recur:<boolean>.
recur_frequency:hourly
freq:daily
freq:continuous
recur:true
For tasks with a frequency of Nth Weekday of Month, a query such as freq:nth_weekday,2 freq:monday finds tasks that repeat on the second Monday of each month.
Timestamps (created at, updated at)
Search the timestamp fields, created_at and updated_at, with created_at:<term> and updated_at:<term>. The term supports the standard runZero time comparison syntax.
created_at:>2weeks
created_at:<30minutes
updated_at:>1month
updated_at:2hours
Next/last run time
Search by last and next recurrence with recur_last:<term> and recur_next:<term>. The term supports the standard runZero time comparison syntax.
recur_last:<2hours
recur_next:>1day
Start time
Search by start time with start_time:<term>. The term supports the standard runZero time comparison syntax.
start_time:<2hour
Grace period
Search the grace period with grace_period:<term> or just grace:<term>. The term supports the standard runZero time comparison syntax.
grace:<2hour
Site name or ID
Use site:<term> to filter by site name or ID.
site:Primary
site:"Branch Office"
site:ad67d649-041b-439d-af59-f200053a8899
Template ID
Use template_id:<term> to filter by scan template ID.
template_id:de657459-041b-439d-af59-ff1f153a7722
Source
Search the task data source with source:<text> or source_id:<number>.
source:censys
Sources are:
| ID | Name | Description |
|---|---|---|
| 1 | runzero |
runZero |
| 2 | miradore |
Miradore |
| 3 | aws |
Amazon Web Services |
| 4 | crowdstrike |
CrowdStrike |
| 5 | azure |
Microsoft Azure |
| 6 | censys |
Censys |
| 7 | vmware |
VMWare |
| 8 | gcp |
Google Cloud Platform |
| 9 | sentinelone |
SentinelOne |
| 10 | tenable |
Tenable.io & Nessus |
| 12 | rapid7 |
Rapid7 Nexpose & InsightVM |
| 14 | qualys |
Qualys VMDR |
| 15 | shodan |
Shodan |
| 16 | azuread |
Azure AD |
| 17 | ldap |
Active Directory (LDAP) |
| 18 | ms365defender |
Microsoft 365 Defender |
| 19 | intune |
Microsoft Intune |
| 20 | googleworkspace |
Google Workspace |
| 21 | sample |
runZero traffic sampling |
| 22 | tenablesecuritycenter |
Tenable Security Center |
| 23 | packet |
runZero packet capture import |
| 24 | wiz |
Wiz |
Credential ID
Find tasks that use a specific set of credentials with credential_id:<id>.
credential_id:d7931a68-6e56-11ec-ad72-f875a414a63a
Parameters
Search task parameters with params:<text>. This can be useful for finding scan tasks that had specific probes enabled.
params:bacnet
Asset counts
Search completed tasks by the asset counts in their results. The search terms are:
- New assets:
assets_new:<number> - Assets back online:
assets_back_online:<number> - Assets marked offline:
assets_marked_offline:<number> - Assets changed:
assets_changed:<number> - Assets unchanged:
assets_unchanged:<number> - Assets ignored:
assets_ignored:<number> - Assets updated:
assets_updated:<number>
These terms support numerical comparison operators (>, >=, <, <=, =).
assets_new:>0
assets_unchanged:>=1