Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

GET /dynamic_search/schemas/{name}/fields

Gets the list of all available Fields

Gets the list of all available Fields

Table 1: GET /dynamic_search/schemas/{name}/fields Resource Details

MIME Type

application/json

Table 2: GET /dynamic_search/schemas/{name}/fields Request Parameter Details

Parameter

Type

Optionality

Data Type

MIME Type

Description

name

path

Required

String

text/plain

null

filter

query

Optional

String

text/plain

Optional - This parameter is used to restrict the elements in a list base on the contents of various fields.

fields

query

Optional

String

text/plain

Optional - Use this parameter to specify which fields you would like to get back in the response. Fields that are not named are excluded. Specify subfields in brackets and multiple fields in the same object are separated by commas.

Range

header

Optional

String

text/plain

Optional - Use this parameter to restrict the number of elements that are returned in the list to a specified range. The list is indexed starting at zero.

Table 3: GET /dynamic_search/schemas/{name}/fields Response Codes

HTTP Response Code

Unique Code

Description

200

 

A list of Fields was retrieved.

404

1011

No schema with that name was found

500

1010

null

Response Description

The list of all available Fields.

  • localized_name - String - The localized name for this simple field.

  • data_type - String - The dataType for this operator. One of (STRING, INTEGER, DOUBLE, BOOLEAN, IPADDRESS, CIDR, DATESTAMP. UUID).

  • semantic_type - String - The type that describes what kind of data this is. (e.g. HOSTNAME, MACADDRESS, SOURCE_IP)

  • contextual_type - String - The type that describes that specifically is in this field. (e.g. ASSET_HOSTNAME, OFFENSE_ATTACKER_IP)

  • child - Field structure - The argument for the supplied function.

  • function - Function structure - The function for the supplied argument.

Response Sample