Starts a search of an organization's security graph and returns the search job immediately, without waiting for results. A search selects objects of one type with a where clause, can follow relationships from them to related objects, and can be limited to a time range, which is clamped to the organization's data retention window. Poll the job with graphSearchJob and read rows with graphSearchResults; stop it with graphSearchJobCancel. Clients that cannot poll can use graphSearchFast for small result sets.
Response
Returns a GraphSearchPayload!
Arguments
| Name | Description |
|---|---|
input - GraphSearchInput!
|
The graph search input parameters. |
Example
Query
query graphSearch($input: GraphSearchInput!) {
graphSearch(input: $input) {
searchJob {
id
orgId
requestedInput {
...GraphSearchInputPayloadFragment
}
effectiveInput {
...GraphSearchInputPayloadFragment
}
hash
user {
...UserFragment
}
state
errors
resultsCount
hasResults
startedAt
endedAt
running
duration
updatedAt
accessedAt
winningTrace {
...SearchTraceStageFragment
}
unselectedTraces {
...SearchTraceStageFragment
}
}
}
}
Variables
{"input": GraphSearchInput}
Response
{"data": {"graphSearch": {"searchJob": GraphSearchJob}}}