Graph search · GraphQL query

graphSearch query

Starts a search of an organization's security graph and returns the search job immediately, without waiting for results. A search selects objects of one type with a where clause, can follow relationships from them to related objects, and can be limited to a time range, which is clamped to the organization's data retention window. Poll the job with graphSearchJob and read rows with graphSearchResults; stop it with graphSearchJobCancel. Clients that cannot poll can use graphSearchFast for small result sets.

Response

Returns a GraphSearchPayload!

Arguments

Name Description
input - GraphSearchInput! The graph search input parameters.

Example

Query

query graphSearch($input: GraphSearchInput!) {
  graphSearch(input: $input) {
    searchJob {
      id
      orgId
      requestedInput {
        ...GraphSearchInputPayloadFragment
      }
      effectiveInput {
        ...GraphSearchInputPayloadFragment
      }
      hash
      user {
        ...UserFragment
      }
      state
      errors
      resultsCount
      hasResults
      startedAt
      endedAt
      running
      duration
      updatedAt
      accessedAt
      winningTrace {
        ...SearchTraceStageFragment
      }
      unselectedTraces {
        ...SearchTraceStageFragment
      }
    }
  }
}

Variables

{"input": GraphSearchInput}

Response

{"data": {"graphSearch": {"searchJob": GraphSearchJob}}}