Skip to main content

Logrhythm - Search query

This playbook used generic polling to gets query result using the command: lr-execute-search-query

Dependencies#

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks#

GenericPolling

Integrations#

LogRhythmRest

Scripts#

This playbook does not use any scripts.

Commands#

  • lr-execute-search-query
  • lr-get-query-result

Playbook Inputs#


NameDescriptionDefault ValueRequired
number_of_daysNumber of days to search.7Required
source_typeLog source type.Optional
host_nameImpacted host name.Optional
usernameUsername.Optional
subjectEmail subject.Optional
senderEmail sender.Optional
recipientEmail recipient.Optional
hashHash.Optional
URLURL.Optional
process_nameProcess name.Optional
objectLog object.Optional
ip_addressIP address.Optional
max_massageMaximum number of log message to query.10Optional
query_timeoutExecute search query to LogRhythm log database.60Optional

Playbook Outputs#


PathDescriptionType
Logrhythm.Search.Results.TaskStatusTask status.string
Logrhythm.Search.Results.TaskIDTask ID.string
Logrhythm.Search.Results.Items.originEntityIdEntity ID.number
Logrhythm.Search.Results.Items.impactedIpImpacted IP.string
Logrhythm.Search.Results.Items.classificationTypeNameClassification name.string
Logrhythm.Search.Results.Items.logSourceNameLog source name.string
Logrhythm.Search.Results.Items.entityNameEntity .ame.string
Logrhythm.Search.Results.Items.normalDateDate.date
Logrhythm.Search.Results.Items.vendorMessageIdVendor log message.string
Logrhythm.Search.Results.Items.priorityLog priority.number
Logrhythm.Search.Results.Items.sequenceNumberSequence number.string
Logrhythm.Search.Results.Items.originHostIdOrigin host ID.number
Logrhythm.Search.Results.Items.mpeRuleIdLogRhythm rule ID.number
Logrhythm.Search.Results.Items.originIpOrigin IP.string
Logrhythm.Search.Results.Items.mpeRuleNameLogRhythm rule name.string
Logrhythm.Search.Results.Items.logSourceHostIdLog source host ID.number
Logrhythm.Search.Results.Items.originHostOrigin host.string
Logrhythm.Search.Results.Items.logDateLog date.date
Logrhythm.Search.Results.Items.classificationNameLog classification name.string

Playbook Image#


Logrhythm - Search query