Wireless inventory

View as Markdown

When viewing WiFi networks, use these keywords to search and filter.

SSID and ESSID

Use ssid:<text> to search the SSID/ESSID field.

ssid:"Guest Network"
ssid:"Corporate"

BSSID (MAC)

Use bssid:<text> or mac:<text> to search the BSSID field.

bssid:"00:01:02:03:04:05"
mac:"00:01:%"

Vendor

Use mac_vendor:<text> to search the vendor field.

mac_vendor:"Google"
mac_vendor:"Netgear"
mac_vendor:"Cisco"

Family

Use family:<term> to search the family field.

family:"010304"

Channels

Use channel:<term> to search the channels field.

channel:"11"

Type

Use type:<text> to search the network type field.

type:"infrastructure"

Interface

Use interface:<text> to search the network interface field.

interface:"wlan0"

Encryption

Use encryption:<term> to search the encryption field.

encryption:"aes"
encryption:"none"

Authentication

Use authentication:<term> to search the authentication field.

authentication:"wpa2-psk"
authentication:"open"

Timestamps

Use first_seen:<term>, last_seen:<term>, and created_at:<term> to search the timestamp fields. The term supports the standard runZero time comparison syntax.

first_seen:<30seconds
first_seen:>2019-08-01
last_seen:<1week
last_seen:<2months
created_at:>2weeks
created_at:<30minutes

Signal

Use signal:<number> or sig:<number> to search the signal field. The term can include the operators >, =, <=, and =. The default operator is =.

signal:">75"
signal:"<=25"
signal:99

Organization name or ID

Use organization:<term> to filter by organization name or ID.

organization:runZero
organization:"Temporary Project"
organization:f1c3ef6d-cb41-4d55-8887-6ed3cfb3d42d

Site name or ID

Use site:<term> to filter by site name or ID.

site:Primary
site:"Branch Office"
site:ad67d649-041b-439d-af59-f200053a8899

Explorer name or ID

Use explorer:<term> to filter by Explorer name or ID.

explorer:DESKTOP-AB451F
explorer:8b927a8e-d405-40e9-aa47-d6afc9bff237

Wireless ID

Use id:<uuid> to search the ID field, the wireless network’s unique identifier written as a UUID.

id:cdb084f9-4811-445c-8ea1-3ea9cf88d536

Last task ID

Use task:<uuid> to search the Last Task ID field, the UUID of the task that most recently reported the wireless network.

task:39ab0e71-3cf1-4176-b6b0-4ed495288229

Wireless attributes

Use <attribute>:<term> to search any wireless attribute.

radio_type:"802.11n"
Updated