Wireless inventory
When viewing WiFi networks, use these keywords to search and filter.
SSID and ESSID
Use ssid:<text> to search the SSID/ESSID field.
ssid:"Guest Network"
ssid:"Corporate"
BSSID (MAC)
Use bssid:<text> or mac:<text> to search the BSSID field.
bssid:"00:01:02:03:04:05"
mac:"00:01:%"
Vendor
Use mac_vendor:<text> to search the vendor field.
mac_vendor:"Google"
mac_vendor:"Netgear"
mac_vendor:"Cisco"
Family
Use family:<term> to search the family field.
family:"010304"
Channels
Use channel:<term> to search the channels field.
channel:"11"
Type
Use type:<text> to search the network type field.
type:"infrastructure"
Interface
Use interface:<text> to search the network interface field.
interface:"wlan0"
Encryption
Use encryption:<term> to search the encryption field.
encryption:"aes"
encryption:"none"
Authentication
Use authentication:<term> to search the authentication field.
authentication:"wpa2-psk"
authentication:"open"
Timestamps
Use first_seen:<term>, last_seen:<term>, and created_at:<term> to search the timestamp fields. The term supports the standard runZero time comparison syntax.
first_seen:<30seconds
first_seen:>2019-08-01
last_seen:<1week
last_seen:<2months
created_at:>2weeks
created_at:<30minutes
Signal
Use signal:<number> or sig:<number> to search the signal field. The term can include the operators >, =, <=, and =. The default operator is =.
signal:">75"
signal:"<=25"
signal:99
Organization name or ID
Use organization:<term> to filter by organization name or ID.
organization:runZero
organization:"Temporary Project"
organization:f1c3ef6d-cb41-4d55-8887-6ed3cfb3d42d
Site name or ID
Use site:<term> to filter by site name or ID.
site:Primary
site:"Branch Office"
site:ad67d649-041b-439d-af59-f200053a8899
Explorer name or ID
Use explorer:<term> to filter by Explorer name or ID.
explorer:DESKTOP-AB451F
explorer:8b927a8e-d405-40e9-aa47-d6afc9bff237
Wireless ID
Use id:<uuid> to search the ID field, the wireless network’s unique identifier written as a UUID.
id:cdb084f9-4811-445c-8ea1-3ea9cf88d536
Last task ID
Use task:<uuid> to search the Last Task ID field, the UUID of the task that most recently reported the wireless network.
task:39ab0e71-3cf1-4176-b6b0-4ed495288229
Wireless attributes
Use <attribute>:<term> to search any wireless attribute.
radio_type:"802.11n"