Supported CEL macros
Sophos XDR supports Google's CEL macros for evaluating and manipulating data. Some macros are built in, while others are specific to Sophos XDR. This page describes commonly used macros.
You can also use CEL Explorer, which provides context-aware autocomplete for CEL macros. For details, see CEL Explorer.
In these examples, the following data structure is used:
{
"plant": {
"type": "tree",
"name": "white oak",
"uses": [
"lumber",
"firewood",
"furniture"
],
"traits": {
"produces_fruit": true,
"genus": "Quercus",
"height": 100,
"extinct": false,
"related_to": [
{
"name": "chestnut",
"genus": "Castanea"
},
{
"name": "beech",
"genus": "Fagus"
}
]
},
"locations": [
"usa",
"europe",
"new york",
"New York",
"new york ",
"usa",
"worldwide",
"eu"
]
}
}
Available macros
? (optional operator)
? is an optional operator for safe navigation, safe indexing, and conditional inclusion in CEL expressions.
The ? operator provides the following capabilities:
- Safe field navigation (
obj.?field): Access fields without errors. - Safe map indexing (
map[?key]): Access map values safely. - Safe list indexing (
list[?index]): Access list elements safely. - Optional map fields (
{?key: value}): Conditionally include map fields. - Optional list elements (
[?element]): Conditionally include list elements.
After the first ? operator, subsequent accesses are automatically safe (viral chaining): obj.?field.subfield == obj.?field.?subfield.
Notes
- The
?operator returns optional values that need.orValue()or.hasValue(). - Safe navigation never throws errors on missing fields, keys, or indices.
- Optional field/element syntax requires optional-typed values.
- Use with
optional.of(),optional.none(), oroptional.ofNonZeroValue().
Examples
{'name': 'John'}.?name.orValue('Unknown')
{'name': 'John'}.?name.orValue('Unknown')
Output: 'John'
Safe field navigation.
{}.?name.orValue('Unknown')
{}.?name.orValue('Unknown')
Output: 'Unknown'
Field missing returns optional.none().
{'a': 1, 'b': 2}[?'a'].orValue(0)
{'a': 1, 'b': 2}[?'a'].orValue(0)
Output: 1
Safe map indexing.
{'a': 1}[?'c'].orValue(0)
{'a': 1}[?'c'].orValue(0)
Output: 0
Missing key returns optional.none().
[1, 2, 3][?0].orValue(0)
[1, 2, 3][?0].orValue(0)
Output: 1
Safe list indexing.
[1, 2, 3][?10].orValue(0)
[1, 2, 3][?10].orValue(0)
Output: 0
Out-of-bounds index returns optional.none().
{?'key': optional.of(5)}.size()
{?'key': optional.of(5)}.size()
Output: 1
Optional map field is included.
{?'key': optional.none()}.size()
{?'key': optional.none()}.size()
Output: 0
Optional map field is omitted.
[1, ?optional.of(2), 3].size()
[1, ?optional.of(2), 3].size()
Output: 3
Optional list element is included.
[1, ?optional.none(), 3].size()
[1, ?optional.none(), 3].size()
Output: 2
Optional list element is omitted.
abs
Returns the absolute value of the provided argument.
Input and output
abs(double) -> double
abs(int) -> int
abs(uint) -> uint
Examples
abs(-1.0)
abs(-1.0)
Output: 1.0
abs(1.0)
abs(1.0)
Output: 1.0
all
Iterates on a list or map and validates that a condition is true for all elements in the list.
Input and output
all(list, predicate) -> bool
all(map, predicate) -> bool
Examples
[1,2,3,4].all(x, x > 0)
[1,2,3,4].all(x, x > 0)
Output: true
[1,2,3,0].all(x, x > 0)
[1,2,3,0].all(x, x > 0)
Output: false
append
Adds elements to an existing list.
Input and output
append(list, any) -> list
Examples
append([1, 2, 3], 4)
append([1, 2, 3], 4)
Output: [1, 2, 3, 4]
append([], "newElement")
append([], "newElement")
Output: ["newElement"]
assetTags
Returns a list of asset tag key/value pairs from an asset. By default, returns both keys and values. Optionally returns only keys or values.
Input and output
assetTags(map) -> list
assetTags(map, string) -> list
Examples
assetTags(inputs)
assetTags(inputs)
Output: ["t1:v1", "t2:v2"]
assetTags(inputs, "keys")
assetTags(inputs, "keys")
Output: ["t1", "t2"]
assetTags(inputs, "values")
assetTags(inputs, "values")
Output: ["v1", "v2"]
base64.decode
Decodes a base64-encoded string to bytes.
Input and output
base64.decode(string) -> bytes
Decodes a base64-encoded string back to its original byte sequence.
Returns empty bytes for empty input.
The input must be a valid base64-encoded string.
Use cases
Decode encoded credentials.
base64.decode('dXNlcm5hbWU6cGFzc3dvcmQ=')
Output: b'username:password'
Decode Basic Authentication credentials.
Convert to string.
string(base64.decode('aGVsbG8='))
Output: "hello"
Decode and convert bytes to a string.
Decode API responses.
string(base64.decode(api_response.encoded_data))
Decode base64-encoded API response data.
Validate encoding.
base64.decode(base64.encode(b'test'))
Output: b'test'
Verify round-trip encoding and decoding.
Process encoded input.
string(base64.decode(input.encoded_value))
Decode user-provided base64 input.
Empty input handling.
base64.decode('')
Output: b''
Empty string produces empty bytes.
Chain with string operations.
string(base64.decode('aGVsbG8=')).upperAscii()
Output: "HELLO"
Decode, convert to a string, then uppercase.
Working with JSON.
string(base64.decode('eyJrZXkiOiJ2YWx1ZSJ9'))
Output: '{"key":"value"}'
Decode base64-encoded JSON.
Error handling
- Invalid base64 strings will cause an error.
- Padding characters (
=) are handled automatically. - Whitespace in input may cause decoding errors.
Notes
- Input must be a valid base64-encoded string.
- Output is always a bytes type.
- Use
string()conversion to get a string from bytes. - Uses standard base64 decoding (RFC 4648).
- This coexists with the custom
decodeBase64()function.
Common patterns
Decode and use as string:
string(base64.decode(encoded_input))
Most common pattern: decode and convert to a string.
Decode and process:
cel.bind(decoded, base64.decode(input), decoded.size() > 0 ? string(decoded) : 'empty')
Decode, check size, then convert or return a default value.
Round trip validation:
string(base64.decode(base64.encode(b'test'))) == 'test'
Validate that encoding and decoding work correctly.
Examples
base64.decode('aGVsbG8=')
base64.decode('aGVsbG8=')
Output: b'hello'
base64.decode('aGVsbG8gd29ybGQ=')
base64.decode('aGVsbG8gd29ybGQ=')
Output: b'hello world'
base64.decode('dGVzdDEyMw==')
base64.decode('dGVzdDEyMw==')
Output: b'test123'
base64.decode('')
base64.decode('')
Output: b''
base64.encode
Encodes bytes to a base64-encoded string.
Input and output
base64.encode(bytes) -> string
Encodes a byte sequence to a base64-encoded string using standard base64 encoding.
Returns an empty string for empty input.
The output is a URL-safe base64 string.
Use cases
Encode text for transmission.
base64.encode(b'username:password')
Output: "dXNlcm5hbWU6cGFzc3dvcmQ="
Encode credentials for Basic Authentication.
Encode binary data.
base64.encode(file_content)
Convert binary file content to a text representation.
Data serialization.
base64.encode(b'{"key": "value"}')
Encode JSON data for URL parameters.
Safe string encoding.
base64.encode(b'data with special chars: !@#$%')
Encode strings containing special characters.
Round-trip encoding.
string(base64.decode(base64.encode(b'test')))
Output: "test"
Verify that encoding and decoding work correctly.
Working with string conversion.
base64.encode(bytes(input.text))
Convert a string to bytes, then encode.
Empty input handling.
base64.encode(b'')
Output: ""
Empty bytes produce an empty string.
Notes
- Input must be a bytes type. Use
b'...'syntax orbytes()conversion. - Output is always a string.
- Uses standard base64 encoding (RFC 4648).
- Padding characters (
=) are included as needed. - This coexists with the custom
encodeBase64()function.
Examples
base64.encode(b'hello')
base64.encode(b'hello')
Output: "aGVsbG8="
base64.encode(b'hello world')
base64.encode(b'hello world')
Output: "aGVsbG8gd29ybGQ="
base64.encode(b'test123')
base64.encode(b'test123')
Output: "dGVzdDEyMw=="
base64.encode(b'')
base64.encode(b'')
Output: ""
caseArchivedAt
Parses a case record and returns the date and time it was archived.
Input and output
caseArchivedAt(map) -> string
Examples
caseArchivedAt(inputs)
caseArchivedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseAssetEvidence
Parses a case record and returns the list of asset evidence objects.
Input and output
caseAssetEvidence(map) -> list
Examples
caseAssetEvidence(inputs)
caseAssetEvidence(inputs)
Output: [, ...]
caseAssigneeId
Parses a case record and returns the ID of the assignee.
Input and output
caseAssigneeId(map) -> string
Examples
caseAssigneeId(inputs)
caseAssigneeId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseChangeAfter
Returns an optional containing the after value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.
Input and output
caseChangeAfter(map, string) -> optional
Examples
caseChangeAfter(inputs, 'severity').orValue(0)
caseChangeAfter(inputs, 'severity').orValue(0)
Output: 6
caseChangeAfter(inputs, 'severity').hasValue()
caseChangeAfter(inputs, 'severity').hasValue()
Output: true
caseChangeAfter(inputs, 'nonexistent').orValue(0)
caseChangeAfter(inputs, 'nonexistent').orValue(0)
Output: 0
caseChangeAfter(inputs, 'nonexistent').hasValue()
caseChangeAfter(inputs, 'nonexistent').hasValue()
Output: false
caseChangeBefore
Returns an optional containing the before value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.
Input and output
caseChangeBefore(map, string) -> optional
Examples
caseChangeBefore(inputs, 'severity').orValue(0)
caseChangeBefore(inputs, 'severity').orValue(0)
Output: 4
caseChangeBefore(inputs, 'severity').hasValue()
caseChangeBefore(inputs, 'severity').hasValue()
Output: true
caseChangeBefore(inputs, 'nonexistent').orValue(0)
caseChangeBefore(inputs, 'nonexistent').orValue(0)
Output: 0
caseChangeBefore(inputs, 'nonexistent').hasValue()
caseChangeBefore(inputs, 'nonexistent').hasValue()
Output: false
caseChanges
Returns the delta.changes map from a case record. Each key is a field name, and each value is a map with before and after entries.
Input and output
caseChanges(map) -> map
Examples
caseChanges(inputs)
caseChanges(inputs)
Output: {"severity": {"before": 4, "after": 6}, "title": {"before": "Original Case Title", "after": "Updated Case Title"}}
caseCloseReason
Parses a case record and returns the reason it was closed.
Input and output
caseCloseReason(map) -> string
Examples
caseCloseReason(inputs)
caseCloseReason(inputs)
Output: "reason for closing"
caseClosedAt
Parses a case record and returns the date and time it was closed (RFC3339), or an empty string when unset.
Input and output
caseClosedAt(map) -> string
Examples
caseClosedAt(inputs)
caseClosedAt(inputs)
Output: "2026-03-09T11:57:04.205591Z"
caseComment
Parses a case record and returns the comment associated with it.
Input and output
caseComment(map) -> string
Examples
caseComment(inputs)
caseComment(inputs)
Output: "This is a sample comment for the case."
caseCommentAuthorId
Parses a case record and returns the ID of the author of the comment.
Input and output
caseCommentAuthorId(map) -> string
Examples
caseCommentAuthorId(inputs)
caseCommentAuthorId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseCommentCreatedAt
Parses a case record and returns the date and time the comment was created.
Input and output
caseCommentCreatedAt(map) -> string
Examples
caseCommentCreatedAt(inputs)
caseCommentCreatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseCommentMentions
Parses a case record and returns a list of mentions in the comment.
Input and output
caseCommentMentions(map) -> list
Examples
caseCommentMentions(inputs)
caseCommentMentions(inputs)
Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]
caseCommentOperation
Parses a case record and returns the operation type of the comment.
Input and output
caseCommentOperation(map) -> string
Examples
caseCommentOperation(inputs)
caseCommentOperation(inputs)
Output: "create"
caseContributorIds
Parses a case record and returns a list of contributor IDs.
Input and output
caseContributorIds(map) -> list
Examples
caseContributorIds(inputs)
caseContributorIds(inputs)
Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]
caseCreatedAt
Parses a case record and returns the date and time it was created.
Input and output
caseCreatedAt(map) -> string
Examples
caseCreatedAt(inputs)
caseCreatedAt(inputs)
Output: "2024-06-20T17:57:45.592464Z"
caseCreatedById
Parses a case record and returns the ID of the user that created it.
Input and output
caseCreatedById(map) -> string
Examples
caseCreatedById(inputs)
caseCreatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseCreatedByPartner
Parses a case record and returns true if it was created by a parent of the tenant.
Input and output
caseCreatedByPartner(map) -> bool
Examples
caseCreatedByPartner(inputs)
caseCreatedByPartner(inputs)
Output: false
caseDetectionEvidence
Parses a case record and returns the list of detection evidence objects.
Input and output
caseDetectionEvidence(map) -> list
Examples
caseDetectionEvidence(inputs)
caseDetectionEvidence(inputs)
Output: [{id, isGenesis}, ...]
caseEventEvidence
Parses a case record and returns the list of event evidence objects.
Input and output
caseEventEvidence(map) -> list
Examples
caseEventEvidence(inputs)
caseEventEvidence(inputs)
Output: [, ...]
caseFieldChanged
Parses a case record and returns true if the provided field was modified.
Input and output
caseFieldChanged(map, string) -> bool
Examples
caseFieldChanged(inputs, 'priority')
caseFieldChanged(inputs, 'priority')
Output: true
caseFieldChanged(inputs, 'nonexistent_field')
caseFieldChanged(inputs, 'nonexistent_field')
Output: false
caseFileId
Parses a case record and returns the file ID from delta.file (File Added events).
Input and output
caseFileId(map) -> string
Examples
caseFileId(inputs)
caseFileId(inputs)
Output: "f1e2d3c4-b5a6-7890-1234-567890abcdef"
caseFileName
Parses a case record and returns the file name from delta.file (File Added events).
Input and output
caseFileName(map) -> string
Examples
caseFileName(inputs)
caseFileName(inputs)
Output: "evidence.pdf"
caseFileSize
Parses a case record and returns the file size from delta.file (File Added events).
Input and output
caseFileSize(map) -> int
Examples
caseFileSize(inputs)
caseFileSize(inputs)
Output: 102400
caseFileStatus
Parses a case record and returns the file lifecycle status from delta.file (File Added/Deleted events).
Input and output
caseFileStatus(map) -> string
Examples
caseFileStatus(inputs)
caseFileStatus(inputs)
Output: "SCHEDULED"
caseFileUploadedById
Parses a case record and returns the user ID that uploaded the file from delta.file (File Added/Deleted events).
Input and output
caseFileUploadedById(map) -> string
Examples
caseFileUploadedById(inputs)
caseFileUploadedById(inputs)
Output: "auth0user123"
caseId
Parses a case record and returns the ID.
Input and output
caseId(map) -> string
Examples
caseId(inputs)
caseId(inputs)
Output: "a251201f-9a26-4cd5-81f6-20509999933d"
caseIncidentAdvisorId
Parses a case record and returns the incident advisor ID.
Input and output
caseIncidentAdvisorId(map) -> string
Examples
caseIncidentAdvisorId(inputs)
caseIncidentAdvisorId(inputs)
Output: "adv-123"
caseKeyFindings
Parses a case record and returns the key findings content.
With an optional second argument, returns a specific field from the keyFindings object (for example, documentType or documentVersion).
Input and output
caseKeyFindings(map) -> string
caseKeyFindings(map, string) -> string
Examples
caseKeyFindings(inputs)
caseKeyFindings(inputs)
Output: "Sample Case Key Findings"
caseKeyFindings(inputs, 'documentType')
caseKeyFindings(inputs, 'documentType')
Output: "DOCUMENT_TYPE_MARKDOWN"
caseKeyFindings(inputs, 'documentVersion')
caseKeyFindings(inputs, 'documentVersion')
Output: "1"
caseLinkCreatedAt
Returns the link creation timestamp from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkCreatedAt(map) -> string
Examples
caseLinkCreatedAt(inputs)
caseLinkCreatedAt(inputs)
Output: "2026-04-30T18:53:00.483028Z"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
Output: ["2026-04-30T18:53:00.483028Z"]
caseLinkIsInternal
Returns whether the link is internal from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkIsInternal(map) -> bool
Examples
caseLinkIsInternal(inputs)
caseLinkIsInternal(inputs)
Output: false
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
Output: [false]
caseLinkReference
Returns the link reference from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkReference(map) -> string
Examples
caseLinkReference(inputs)
caseLinkReference(inputs)
Output: "EXT-12345"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
Output: ["EXT-12345"]
caseLinkTitle
Returns the link title from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkTitle(map) -> string
Examples
caseLinkTitle(inputs)
caseLinkTitle(inputs)
Output: "External Ticket"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
Output: ["External Ticket"]
caseLinkType
Returns the link type from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkType(map) -> string
Examples
caseLinkType(inputs)
caseLinkType(inputs)
Output: "External"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
Output: []
caseLinkUrl
Returns the link URL from a case-change event (delta.link) or a bare link record.
Input and output
caseLinkUrl(map) -> string
Examples
caseLinkUrl(inputs)
caseLinkUrl(inputs)
Output: "https://example.com/tickets/EXT-12345"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
Output: ["https://example.com/tickets/EXT-12345"]
caseLinks
Parses a case record and returns the full list of link objects.
Input and output
caseLinks(map) -> list
Examples
caseLinks(inputs)
caseLinks(inputs)
Output: [, ]
caseLinksReference
Parses a case record and returns the list of reference strings from all links.
Input and output
caseLinksReference(map) -> list
Examples
caseLinksReference(inputs)
caseLinksReference(inputs)
Output: ["EXT-12345", "JIRA-456"]
caseLinksTitle
Parses a case record and returns the list of title strings from all links.
Input and output
caseLinksTitle(map) -> list
Examples
caseLinksTitle(inputs)
caseLinksTitle(inputs)
Output: ["External Ticket", "Jira Ticket"]
caseLinksType
Parses a case record and returns the list of type strings from all links (for example, External or Jira).
Input and output
caseLinksType(map) -> list
Examples
caseLinksType(inputs)
caseLinksType(inputs)
Output: ["External", "Jira"]
caseLinksUrl
Parses a case record and returns the list of URL strings from all links.
Input and output
caseLinksUrl(map) -> list
Examples
caseLinksUrl(inputs)
caseLinksUrl(inputs)
Output: ["https://example.com/tickets/EXT-12345", "https://jira.example.com/..."]
caseManagedBy
Parses a case record and returns the managed-by value (PROVIDER, CUSTOMER, UNKNOWN).
Input and output
caseManagedBy(map) -> string
Examples
caseManagedBy(inputs)
caseManagedBy(inputs)
Output: "CUSTOMER"
casePrimaryStatusId
Parses a case record and returns the primary status ID.
Input and output
casePrimaryStatusId(map) -> string
Examples
casePrimaryStatusId(inputs)
casePrimaryStatusId(inputs)
Output: "8dafe9bc-cbf6-4b27-aff4-8959682f859c"
casePrimaryStatusName
Parses a case record and returns the primary status name.
Input and output
casePrimaryStatusName(map) -> string
Examples
casePrimaryStatusName(inputs)
casePrimaryStatusName(inputs)
Output: "draft"
casePrimaryStatusTitle
Parses a case record and returns the primary status title.
Input and output
casePrimaryStatusTitle(map) -> string
Examples
casePrimaryStatusTitle(inputs)
casePrimaryStatusTitle(inputs)
Output: "Draft"
casePrimaryVerdictId
Parses a case record and returns the primary verdict ID.
Input and output
casePrimaryVerdictId(map) -> string
Examples
casePrimaryVerdictId(inputs)
casePrimaryVerdictId(inputs)
Output: "pv-1"
casePrimaryVerdictName
Parses a case record and returns the primary verdict name.
Input and output
casePrimaryVerdictName(map) -> string
Examples
casePrimaryVerdictName(inputs)
casePrimaryVerdictName(inputs)
Output: "confirmed"
casePrimaryVerdictTitle
Parses a case record and returns the primary verdict title.
Input and output
casePrimaryVerdictTitle(map) -> string
Examples
casePrimaryVerdictTitle(inputs)
casePrimaryVerdictTitle(inputs)
Output: "Confirmed"
casePriority
Parses a case record and returns the priority of the case as a word (Low, Medium, High, Critical).
An optional second argument of true returns the priority as an integer (1-4).
Input and output
casePriority(map) -> string
casePriority(map, bool) -> int
Examples
casePriority(inputs)
casePriority(inputs)
Output: "High"
casePriority(inputs, true)
casePriority(inputs, true)
Output: 3
caseProcessingStatus
Parses a case record and returns the processing status map.
Input and output
caseProcessingStatus(map) -> map
Examples
caseProcessingStatus(inputs)
caseProcessingStatus(inputs)
Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}
caseRiskScore
Parses a case record and returns the risk score.
Input and output
caseRiskScore(map) -> double
Examples
caseRiskScore(inputs)
caseRiskScore(inputs)
Output: 7.2
caseRuleId
Parses a case record and returns the auto case rule ID that created it.
Input and output
caseRuleId(map) -> string
Examples
caseRuleId(inputs)
caseRuleId(inputs)
Output: "12345"
caseSearchEvidence
Parses a case record and returns the list of search evidence objects.
Input and output
caseSearchEvidence(map) -> list
Examples
caseSearchEvidence(inputs)
caseSearchEvidence(inputs)
Output: [, ...]
caseSecondaryStatusId
Parses a case record and returns the secondary status ID.
Input and output
caseSecondaryStatusId(map) -> string
Examples
caseSecondaryStatusId(inputs)
caseSecondaryStatusId(inputs)
Output: "ss-1"
caseSecondaryStatusName
Parses a case record and returns the secondary status name.
Input and output
caseSecondaryStatusName(map) -> string
Examples
caseSecondaryStatusName(inputs)
caseSecondaryStatusName(inputs)
Output: "under_review"
caseSecondaryStatusReason
Parses a case record and returns the list of secondary status reasons.
Input and output
caseSecondaryStatusReason(map) -> list
Examples
caseSecondaryStatusReason(inputs)
caseSecondaryStatusReason(inputs)
Output: ["reason1", "reason2"]
caseSecondaryStatusTitle
Parses a case record and returns the secondary status title.
Input and output
caseSecondaryStatusTitle(map) -> string
Examples
caseSecondaryStatusTitle(inputs)
caseSecondaryStatusTitle(inputs)
Output: "Under Review"
caseSecondaryVerdictId
Parses a case record and returns the secondary verdict ID.
Input and output
caseSecondaryVerdictId(map) -> string
Examples
caseSecondaryVerdictId(inputs)
caseSecondaryVerdictId(inputs)
Output: "sv-1"
caseSecondaryVerdictName
Parses a case record and returns the secondary verdict name.
Input and output
caseSecondaryVerdictName(map) -> string
Examples
caseSecondaryVerdictName(inputs)
caseSecondaryVerdictName(inputs)
Output: "malicious"
caseSecondaryVerdictTitle
Parses a case record and returns the secondary verdict title.
Input and output
caseSecondaryVerdictTitle(map) -> string
Examples
caseSecondaryVerdictTitle(inputs)
caseSecondaryVerdictTitle(inputs)
Output: "Malicious"
caseSeverity
Parses a case record and returns the severity as a word (Informational, Low, Medium, High, Critical).
For inputs.case, uses severity values 2, 4, 6, 8, and 10. For V1/V2 records, uses priority values 1-4.
An optional second argument of false returns the raw numeric value.
Input and output
caseSeverity(map) -> string
caseSeverity(map, bool) -> int
Examples
caseSeverity(inputs)
caseSeverity(inputs)
Output: "Medium"
caseSeverity(inputs, false)
caseSeverity(inputs, false)
Output: 6
caseShortId
Parses a case record and returns the short ID.
Input and output
caseShortId(map) -> string
Examples
caseShortId(inputs)
caseShortId(inputs)
Output: "INV41773"
caseSourceId
Parses a case record and returns the source ID.
Input and output
caseSourceId(map) -> string
Examples
caseSourceId(inputs)
caseSourceId(inputs)
Output: "src-auto-001"
caseSourceName
Parses a case record and returns the source name.
Input and output
caseSourceName(map) -> string
Examples
caseSourceName(inputs)
caseSourceName(inputs)
Output: "auto_case_rule"
caseSourceTitle
Parses a case record and returns the source display title.
Input and output
caseSourceTitle(map) -> string
Examples
caseSourceTitle(inputs)
caseSourceTitle(inputs)
Output: "Auto-Generated"
caseStatus
Parses a case record and returns the status.
Input and output
caseStatus(map) -> string
caseStatus(map, string) -> string
Examples
caseStatus(inputs)
caseStatus(inputs)
Output: "OPEN"
caseStatus(inputs, 'v1')
caseStatus(inputs, 'v1')
Output: "Open"
caseTags
Parses a case record and returns the list of tags.
Input and output
caseTags(map) -> list
Examples
caseTags(inputs)
caseTags(inputs)
Output: ["automation", "playbook"]
caseTenantId
Parses a case record and returns the ID of the tenant.
Input and output
caseTenantId(map) -> string
Examples
caseTenantId(inputs)
caseTenantId(inputs)
Output: "12345"
caseThirdPartyId
Parses a case record and returns the ID of a third-party record associated with it.
Input and output
caseThirdPartyId(map) -> string
Examples
caseThirdPartyId(inputs)
caseThirdPartyId(inputs)
Output: "bdf9f35a8383121055c9e330ceaad3b8"
caseThirdPartyType
Parses a case record and returns the type of a third-party record associated with it.
Input and output
caseThirdPartyType(map) -> string
Examples
caseThirdPartyType(inputs)
caseThirdPartyType(inputs)
Output: "SNOW"
caseTitle
Parses a case record and returns the title.
Input and output
caseTitle(map) -> string
Examples
caseTitle(inputs)
caseTitle(inputs)
Output: "Taegis Watchlist Case"
caseType
Parses a case record and returns the type.
An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.
Input and output
caseType(map) -> string
caseType(map, string) -> string
Examples
caseType(inputs)
caseType(inputs)
Output: "SECURITY_INVESTIGATION"
caseType(inputs, 'v1')
caseType(inputs, 'v1')
Output: "Security Investigation"
caseTypeId
Parses a case record and returns the raw type ID from the structured type object.
Returns an empty string when the type is absent or not an object.
Input and output
caseTypeId(map) -> string
Examples
caseTypeId(inputs)
caseTypeId(inputs)
Output: "00000006-0000-4000-a000-000000000001"
caseTypeTitle
Parses a case record and returns the type display title from the structured type object.
Returns an empty string when the type is absent or not an object.
Input and output
caseTypeTitle(map) -> string
Examples
caseTypeTitle(inputs)
caseTypeTitle(inputs)
Output: "Investigation"
caseUpdatedAt
Parses a case record and returns the date and time of the last update.
Input and output
caseUpdatedAt(map) -> string
Examples
caseUpdatedAt(inputs)
caseUpdatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseUpdatedById
Parses a case record and returns the ID of the user that last updated it.
Input and output
caseUpdatedById(map) -> string
Examples
caseUpdatedById(inputs)
caseUpdatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
cel.bind
Creates a local variable binding within an expression to avoid recomputing expensive operations.
Input and output
cel.bind(var_name, value, expression) -> any
Creates a local variable that can be referenced within the expression.
The variable is only available in the scope of the third argument (expression).
This is useful for:
- Avoiding repeated computation of expensive operations.
- Making complex expressions more readable.
- Creating intermediate values for cleaner logic.
The variable name is provided as an identifier (not a string).
The value can be any CEL expression.
The expression is evaluated with the variable in scope.
Use cases
Avoid repeated computation.
cel.bind(name, inputs.user.name.uppercase(), name + ' - ' + string(name.size()))
Avoid repeating expensive operations and improve readability.
Simplify complex conditions.
cel.bind(withTax, inputs.price * 1.2, withTax > 100 ? withTax * 0.9 : withTax)
Calculate an intermediate value and reuse it.
Chain multiple bindings.
cel.bind(x, 5, cel.bind(y, x * 2, cel.bind(z, y + 3, x + y + z)))
Output: 26
Create nested variable bindings.
Work with lists.
cel.bind(nums, [1, 2, 3, 4, 5], cel.bind(doubled, nums.map(n, n * 2), doubled.filter(n, n > 5)))
Output: [6, 8, 10]
Double all values, then filter the result.
Complex object access.
cel.bind(user, inputs.users[0], user.name + ' (' + user.email + ')')
Access an object once and reuse it multiple times.
Examples
cel.bind(x, 10, x * x)
cel.bind(x, 10, x * x)
Output: 100
cel.bind(user, 'John', 'Hello ' + user)
cel.bind(user, 'John', 'Hello ' + user)
Output: "Hello John"
cel.bind(list, [1,2,3], list.size() + list[0])
cel.bind(list, [1,2,3], list.size() + list[0])
Output: 4
charAt
Returns the character at the specified index in the string.
Input and output
string.charAt(int) -> string
Returns the character (as a single-character string) at the specified zero-based index.
Returns an empty string if the index is out of bounds.
Examples
'hello'.charAt(0)
'hello'.charAt(0)
Output: "h"
'hello'.charAt(4)
'hello'.charAt(4)
Output: "o"
collect
Returns a list of map values that match the provided path argument.
Input and output
collect(list, string) -> list
Examples
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
Output: ["value1", "value3"]
contains
Returns true if any element in the string or list matches the provided string or list (case-sensitive).
An optional second argument of true causes the match to ignore case.
Input and output
contains(string, string) -> bool
contains(string, string, bool) -> bool
contains(string, list) -> bool
contains(string, list, bool) -> bool
contains(list, string) -> bool
contains(list, string, bool) -> bool
contains(list, list) -> bool
contains(list, list, bool) -> bool
Examples
"apple".contains("app")
"apple".contains("app")
Output: true
"apple".contains("APP", true)
"apple".contains("APP", true)
Output: true
"apple".contains(["app"])
"apple".contains(["app"])
Output: true
"apple".contains(["APP"], true)
"apple".contains(["APP"], true)
Output: true
["apple", "banana"].contains("app")
["apple", "banana"].contains("app")
Output: true
["apple", "banana"].contains("APP", true)
["apple", "banana"].contains("APP", true)
Output: true
["apple", "banana"].contains(["app"])
["apple", "banana"].contains(["app"])
Output: true
["apple", "banana"].contains(["APP"], true)
["apple", "banana"].contains(["APP"], true)
Output: true
count
Returns a count of the list elements that match the provided string argument, or the keys in a map that match it.
Input and output
count(list, string) -> int
Examples
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
Output: 2
createShareLink
Returns a Taegis Sharelink for an alert, investigation, or asset.
Input and output
createShareLink(map) -> string
Examples
createShareLink(inputs)
createShareLink(inputs)
Output: "https://ctpx.secureworks.com/share/14f-ca9d-ad47-34db-2243b945ce2112f"
decodeBase64
Returns a decoded base64 input string.
Input and output
decodeBase64(string) -> string
Examples
decodeBase64("aGVsbG8gd29ybGQ=")
decodeBase64("aGVsbG8gd29ybGQ=")
Output: "hello world"
decodeJSON
Returns a JSON object after decoding the input string.
Input and output
decodeJSON(string) -> any
Examples
decodeJSON('{"key": "value"}')
decodeJSON('{"key": "value"}')
Output: {"key":"value"}
decodeYAML
Decodes YAML input to any data type.
Input and output
decodeYAML(string) -> any
Examples
decodeYAML("key: value")
decodeYAML("key: value")
Output: {"key":"value"}
detectionAttackTechniqueIds
Parses a detection record and returns the attack technique IDs value.
Input and output
detectionAttackTechniqueIds(map) -> list
Examples
detectionAttackTechniqueIds(inputs)
detectionAttackTechniqueIds(inputs)
Output: ["T1096", "T1214"]
detectionConfidence
Parses a detection record and returns the confidence value.
Input and output
detectionConfidence(map) -> double
Examples
detectionConfidence(inputs)
detectionConfidence(inputs)
Output: 0.5
detectionCreatedAtNanos
Parses a detection record and returns the nanoseconds value of the time the detection was created.
Input and output
detectionCreatedAtNanos(map) -> int
Examples
detectionCreatedAtNanos(inputs)
detectionCreatedAtNanos(inputs)
Output: 796357058
detectionCreatedAtSeconds
Parses a detection record and returns the created_at value as a measure of seconds from epoch.
Input and output
detectionCreatedAtSeconds(map) -> int
Examples
detectionCreatedAtSeconds(inputs)
detectionCreatedAtSeconds(inputs)
Output: 1636029855
detectionDescription
Parses a detection record and returns the description value.
Input and output
detectionDescription(map) -> string
Examples
detectionDescription(inputs)
detectionDescription(inputs)
Output: "This is a sample Taegis Watchlist Detection"
detectionDestinationIPs
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled destinationIPAddress (case insensitive).
Input and output
detectionDestinationIPs(map) -> list
Examples
detectionDestinationIPs(inputs)
detectionDestinationIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionDetectorId
Parses a detection record and returns the detector ID value.
Input and output
detectionDetectorId(map) -> string
Examples
detectionDetectorId(inputs)
detectionDetectorId(inputs)
Output: "app:event-filter"
detectionDetectorName
Parses a detection record and returns the detector name value.
Input and output
detectionDetectorName(map) -> string
Examples
detectionDetectorName(inputs)
detectionDetectorName(inputs)
Output: "Taegis Watchlist"
detectionDomains
Parses a detection record and returns a unique list of domain name values from the detection entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).
Input and output
detectionDomains(map) -> list
Examples
detectionDomains(inputs)
detectionDomains(inputs)
Output: ["example.com", "a.example.com"]
detectionEnrichment
Parses a detection record and the enrichment data and returns the first value matching the path provided.
Input and output
detectionEnrichment(map, string) -> any
Examples
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
Output: ["foo.exe", "bar.exe"]
detectionEnrichment(inputs, 'doesnotexist')
detectionEnrichment(inputs, 'doesnotexist')
Output: []
detectionEntities
Parses a detection record and returns the entities value.
Input and output
detectionEntities(map) -> list
Examples
detectionEntities(inputs)
detectionEntities(inputs)
Output: ["hostname:abc", "sensorId:12345", "fileName:c:\\windows\\syswow64\\cmd.exe"]
detectionEntity
Parses a detection record and returns the entity values that match the provided entity name (case insensitive).
Input and output
detectionEntity(map, string) -> list
Examples
detectionEntity(inputs, 'username')
detectionEntity(inputs, 'username')
Output: ["sample_user", "another_sample_user"]
detectionEventIds
Parses a detection record and returns a list of event ID values.
Input and output
detectionEventIds(map) -> list
Examples
detectionEventIds(inputs)
detectionEventIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionGroupKey
Parses a detection record and returns the group_key value.
Input and output
detectionGroupKey(map) -> string
Examples
detectionGroupKey(inputs)
detectionGroupKey(inputs)
Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"
detectionHostnames
Parses a detection record and returns a unique list of values from the detection entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).
Input and output
detectionHostnames(map) -> list
Examples
detectionHostnames(inputs)
detectionHostnames(inputs)
Output: ["sample_hostname", "another_sample_hostname"]
detectionIPs
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled ipAddress (case insensitive).
Input and output
detectionIPs(map) -> list
Examples
detectionIPs(inputs)
detectionIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionId
Parses a detection record and returns the ID or UUID.
Input and output
detectionId(map) -> string
Examples
detectionId(inputs)
detectionId(inputs)
Output: "detection://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"
detectionInvestigationIds
Parses a detection record and returns a list of investigation IDs associated with the detection.
Input and output
detectionInvestigationIds(map) -> list
Examples
detectionInvestigationIds(inputs)
detectionInvestigationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionMitreAttackInfo
Parses a detection record and returns a list of mitre_attack_info values.
Input and output
detectionMitreAttackInfo(map) -> list
Examples
detectionMitreAttackInfo(inputs)
detectionMitreAttackInfo(inputs)
Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]
detectionObservationIds
Parses a detection record and returns a list of observation ID values.
Input and output
detectionObservationIds(map) -> list
Examples
detectionObservationIds(inputs)
detectionObservationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionReferences
Parses a detection record and returns a list of references associated with the detection.
Input and output
detectionReferences(map) -> list
Examples
detectionReferences(inputs)
detectionReferences(inputs)
Output: [{"description": "External Detection Ref", "url": "https://example.com/detection/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]
detectionResolution
Parses a detection record and returns the resolution value.
Input and output
detectionResolution(map) -> string
Examples
detectionResolution(inputs)
detectionResolution(inputs)
Output: "open"
detectionResolutionReason
Parses a detection record and returns the resolution reason value.
Input and output
detectionResolutionReason(map) -> string
Examples
detectionResolutionReason(inputs)
detectionResolutionReason(inputs)
Output: "Valid activity for this user."
detectionRuleId
Parses a detection record and returns the rule ID.
Input and output
detectionRuleId(map) -> string
Examples
detectionRuleId(inputs)
detectionRuleId(inputs)
Output* "267658fe-65f1-4145-8753-d45fbf9ed6d3"
detectionSensorIds
Parses a detection record and returns a list of sensor ID values.
Input and output
detectionSensorIds(map) -> list
Examples
detectionSensorIds(inputs)
detectionSensorIds(inputs)
Output: ["12345", "1234-12345-123"]
detectionSensorTypes
Parses a detection record and returns a list of unique sensor type values (in uppercase).
Input and output
detectionSensorTypes(map) -> list
Examples
detectionSensorTypes(inputs)
detectionSensorTypes(inputs)
Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]
detectionSeverity
Parses a detection record and returns the severity value.
Input and output
detectionSeverity(map) -> double
Examples
detectionSeverity(inputs)
detectionSeverity(inputs)
Output: 0.75
detectionSeverityNice
Parses a detection record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).
Input and output
detectionSeverityNice(map) -> string
Examples
detectionSeverityNice(inputs)
detectionSeverityNice(inputs)
Output: "High"
detectionSourceEntities
Returns the list of source entities from a detection's source_entities field.
Input and output
detectionSourceEntities(map) -> list
Examples
detectionSourceEntities(inputs)
detectionSourceEntities(inputs)
Output: [{"id": "...", "display_name": "...", "perspective": "SOURCE", ...}]
detectionSourceEntityProperties
Filters source_entities by property_type and returns values for the specified property keys.
Input and output
detectionSourceEntityProperties(map, string, list) -> list
Examples
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
Output: ["jdoe", "jdoe"]
detectionSourceIPs
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled sourceIPAddress (case insensitive).
Input and output
detectionSourceIPs(map) -> list
Examples
detectionSourceIPs(inputs)
detectionSourceIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionStatus
Parses a detection record and returns the status value.
Input and output
detectionStatus(map) -> string
Examples
detectionStatus(inputs)
detectionStatus(inputs)
Output: "open"
detectionTags
Parses a detection record and returns a list of tags.
Input and output
detectionTags(map) -> list
Examples
detectionTags(inputs)
detectionTags(inputs)
Output: ["detectionRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]
detectionTargetEntities
Returns the list of target entities from a detection's target_entities field.
Input and output
detectionTargetEntities(map) -> list
Examples
detectionTargetEntities(inputs)
detectionTargetEntities(inputs)
Output: [{"id": "...", "display_name": "...", "perspective": "TARGET", ...}]
detectionTargetEntityProperties
Filters target_entities by property_type and returns values for the specified property keys.
Input and output
detectionTargetEntityProperties(map, string, list) -> list
Examples
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
Output: ["abc123def456"]
detectionTenantId
Parses a detection record and returns the tenant ID.
Input and output
detectionTenantId(map) -> string
Examples
detectionTenantId(inputs)
detectionTenantId(inputs)
Output: "12345"
detectionThirdPartyDetail
Parses a detection record and the third-party detail data and returns the first value matching the path provided.
Input and output
detectionThirdPartyDetail(map, string) -> list
Examples
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]
detectionTitle
Parses a detection record and returns the title value.
Input and output
detectionTitle(map) -> string
Examples
detectionTitle(inputs)
detectionTitle(inputs)
Output: "Taegis Watchlist Detection"
detectionUpdatedAtNanos
Parses a detection record and returns the nanoseconds value of the time the detection was modified.
Input and output
detectionUpdatedAtNanos(map) -> int
Examples
detectionUpdatedAtNanos(inputs)
detectionUpdatedAtNanos(inputs)
Output: 796357058
detectionUpdatedAtSeconds
Parses a detection record and returns the updated_at value as a measure of seconds from epoch.
Input and output
detectionUpdatedAtSeconds(map) -> int
Examples
detectionUpdatedAtSeconds(inputs)
detectionUpdatedAtSeconds(inputs)
Output: 1697207995554
detectionUsernames
Parses a detection record and returns a unique list of lowercase username values from the detection entities field where the entity is labeled username (case insensitive).
Input and output
detectionUsernames(map) -> list
Examples
detectionUsernames(inputs)
detectionUsernames(inputs)
Output: ["sample_user", "another_sample_user"]
distinct
Removes duplicate elements from a list, preserving the first occurrence of each element.
Input and output
list.distinct() -> list
Returns a new list containing only unique elements from the original list.
The first occurrence of each element is preserved in the order encountered.
Duplicates are removed.
Use cases
Remove duplicates from user input.
user_tags.distinct()
Clean up duplicate tags.
Get unique values.
results.map(r, r.category).distinct()
Get all unique categories from the results.
Deduplicate IDs.
id_list.distinct()
Ensure that there are no duplicate IDs.
Clean data.
inputs.values.distinct()
Remove duplicates.
Use set-like operations.
list1.distinct().size() == list1.size()
Check whether a list has no duplicates.
Combine with a filter.
items.filter(i, i.active).map(i, i.id).distinct()
Get the unique IDs of active items.
Preserve order.
[3, 1, 2, 1, 3].distinct()
Output: [3, 1, 2]
Preserve the order of the first occurrence of each element.
Notes
- Preserves the order of the first occurrence.
- Works with any comparable type.
- Empty lists remain empty.
- Doesn't sort the output.
Examples
[1, 2, 2, 3, 3, 3].distinct()
[1, 2, 2, 3, 3, 3].distinct()
Output: [1, 2, 3]
Remove duplicate numbers.
['b', 'b', 'c', 'a', 'c'].distinct()
['b', 'b', 'c', 'a', 'c'].distinct()
Output: ['b', 'c', 'a']
Remove duplicate strings and preserve their order.
[1, 2, 3].distinct()
[1, 2, 3].distinct()
Output: [1, 2, 3]
The list is already unique.
[1, 1, 1].distinct()
[1, 1, 1].distinct()
Output: [1]
Remove all duplicate elements.
[].distinct()
[].distinct()
Output: []
An empty list remains empty.
domains
Returns true if the provided username argument is in one or more of the provided domains.
Input and output
domains(map) -> list
Examples
domains(inputs)
domains(inputs)
Output: ["example.com","foo.com"]
encodeBase64
Returns an encoded string input as a base64 string.
Input and output
encodeBase64(string) -> string
Examples
encodeBase64("hello world")
encodeBase64("hello world")
Output: "aGVsbG8gd29ybGQ="
encodeJSON
Returns an encoded string input as a JSON string.
Input and output
encodeJSON(string) -> string
Examples
encodeJSON({"key":"value"})
encodeJSON({"key":"value"})
Output: "{\"key\":\"value\"}"
encodeYAML
Encodes any value as a YAML string.
Input and output
encodeYAML(string) -> string
Examples
encodeYAML({"key":"value"})
encodeYAML({"key":"value"})
Output: "key: value\n"
entityValue
Parses an entity record and returns a list of values for the provided entity property.
Input and output
entityValue(map, string) -> list
Examples
entityValue(inputs, "username")
entityValue(inputs, "username")
Output: ["john"]
entityValue(inputs, "nonexistent")
entityValue(inputs, "nonexistent")
Output: []
entityValues
Parses an entity record and returns a list of values associated with the entity.
Input and output
entityValues(map) -> list
Examples
entityValues(inputs)
entityValues(inputs)
Output: ["example.com", "john@example.com", "john"]
exists
Iterates on a list or map and validates that a condition is true for at least one of the elements.
Input and output
exists(list, predicate) -> bool
exists(map, predicate) -> bool
Examples
[1, 2, 3].exists(i, i % 2 != 0)
[1, 2, 3].exists(i, i % 2 != 0)
Output: true
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
Output: false
exists_one
Iterates on a list or map and validates that a condition is true for exactly one of the elements.
Input and output
exists_one(list, predicate) -> bool
exists_one(map, predicate) -> bool
Examples
[1, 2, 2].exists_one(i, i < 2)
[1, 2, 2].exists_one(i, i < 2)
Output: true
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
Output: false
filehashes
Returns a list of file hashes from an alert or entity if found.
Input and output
filehashes(map) -> list
Examples
filehashes(inputs)
filehashes(inputs)
Output: ["445362b51bf855f62f9af7bb8362c8b27c7bc1ceb1dc88fd41a72de19b779969", "2e5a8590cf6848968fc23de3fa1e25f1", "9785001b0dcf755eddb8af294a373c0b87b2498660f724e76c4d53f9c217c7a3"]
filter
Iterates on a list and returns the elements that match the provided criteria.
Input and output
filter(list, predicate) -> list
Examples
["a", "ab", "c"].filter(x, x.contains("a"))
["a", "ab", "c"].filter(x, x.contains("a"))
Output: ["a", "ab"]
["a", "ab", "c"].filter(x, x.contains("d"))
["a", "ab", "c"].filter(x, x.contains("d"))
Output: []
findingCheck
Parses an identity finding record and returns the check map, or returns a specific entry when a second argument is provided.
Input and output
findingCheck(map) -> map
findingCheck(map, string) -> any
Examples
findingCheck(inputs)
findingCheck(inputs)
Output: {'autoResolutionDisabled':false,'category':'CONFIGURATION', ... }
findingCheck(inputs, "module")
findingCheck(inputs, "module")
Output: "IDENTITY"
findingCheck(inputs, "id")
findingCheck(inputs, "id")
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingCheck(inputs, "title")
findingCheck(inputs, "title")
Output: "Application shall not have unclaimed DNS names that are susceptible to takeover"
findingCheck(inputs, "description")
findingCheck(inputs, "description")
Output: "Threat actors can exploit vulnerabilities in Microsoft Entra ID applications by registering unclaimed subdomains, also known as dangling Fully Qualified Domain Names (FQDNs)."
findingCheck(inputs, "enabled")
findingCheck(inputs, "enabled")
Output: true
findingClosedAt
Parses an identity finding record and returns the closed-at timestamp.
Input and output
findingClosedAt(map) -> string
Examples
findingClosedAt(inputs)
findingClosedAt(inputs)
Output: "2025-04-28T16:57:49.591956Z"
findingConfidenceScore
Parses an identity finding record and returns the confidence score.
Input and output
findingConfidenceScore(map) -> double
Examples
findingConfidenceScore(inputs)
findingConfidenceScore(inputs)
Output: "1.0"
findingFieldChanged
Parses a finding record and returns true if the provided field was modified.
Input and output
findingFieldChanged(map, string) -> bool
Examples
findingFieldChanged(inputs, 'status')
findingFieldChanged(inputs, 'status')
Output: true
findingFieldChanged(inputs, 'nonexistent_field')
findingFieldChanged(inputs, 'nonexistent_field')
Output: false
findingFirstSeen
Parses an identity finding record and returns the first-seen timestamp.
Input and output
findingFirstSeen(map) -> string
Examples
findingFirstSeen(inputs)
findingFirstSeen(inputs)
Output: "2025-03-12T16:57:49.591956Z"
findingId
Parses an identity finding record and returns the ID.
Input and output
findingId(map) -> string
Examples
findingId(inputs)
findingId(inputs)
Output: "f1234567-89ab-cdef-0123-456789abcdef"
findingIdentityCity
Parses an identity finding record and returns the city from the identity data.
Input and output
findingIdentityCity(map) -> string
Examples
findingIdentityCity(inputs)
findingIdentityCity(inputs)
Output: "New York"
findingIdentityCompanyName
Parses an identity finding record and returns the company name from the identity data.
Input and output
findingIdentityCompanyName(map) -> string
Examples
findingIdentityCompanyName(inputs)
findingIdentityCompanyName(inputs)
Output: "Example Corp"
findingIdentityCountry
Parses an identity finding record and returns the country from the identity data.
Input and output
findingIdentityCountry(map) -> string
Examples
findingIdentityCountry(inputs)
findingIdentityCountry(inputs)
Output: "United States"
findingIdentityCreatedAt
Parses an identity finding record and returns the creation timestamp from the identity data.
Input and output
findingIdentityCreatedAt(map) -> string
Examples
findingIdentityCreatedAt(inputs)
findingIdentityCreatedAt(inputs)
Output: "2024-01-15T10:30:00Z"
findingIdentityDepartment
Parses an identity finding record and returns the department from the identity data.
Input and output
findingIdentityDepartment(map) -> string
Examples
findingIdentityDepartment(inputs)
findingIdentityDepartment(inputs)
Output: "Engineering"
findingIdentityDisplayName
Parses an identity finding record and returns the display name from the identity data.
Input and output
findingIdentityDisplayName(map) -> string
Examples
findingIdentityDisplayName(inputs)
findingIdentityDisplayName(inputs)
Output: "John Doe"
findingIdentityEmails
Parses an identity finding record and returns the email addresses from the identity data.
Input and output
findingIdentityEmails(map) -> list
Examples
findingIdentityEmails(inputs)
findingIdentityEmails(inputs)
Output: ["john.doe@example.com", "j.doe@example.com"]
findingIdentityEmployeeId
Parses an identity finding record and returns the employee ID from the identity data.
Input and output
findingIdentityEmployeeId(map) -> string
Examples
findingIdentityEmployeeId(inputs)
findingIdentityEmployeeId(inputs)
Output: "EMP12345"
findingIdentityEmployeeType
Parses an identity finding record and returns the employee type from the identity data.
Input and output
findingIdentityEmployeeType(map) -> string
Examples
findingIdentityEmployeeType(inputs)
findingIdentityEmployeeType(inputs)
Output: "Full-time"
findingIdentityExternalCreatedAt
Parses an identity finding record and returns the external creation timestamp from the identity data.
Input and output
findingIdentityExternalCreatedAt(map) -> string
Examples
findingIdentityExternalCreatedAt(inputs)
findingIdentityExternalCreatedAt(inputs)
Output: "2024-01-15T10:30:00Z"
findingIdentityExternalId
Parses an identity finding record and returns the external ID from the identity data.
Input and output
findingIdentityExternalId(map) -> string
Examples
findingIdentityExternalId(inputs)
findingIdentityExternalId(inputs)
Output: "ext-12345-abcd"
findingIdentityExternalUpdatedAt
Parses an identity finding record and returns the external update timestamp from the identity data.
Input and output
findingIdentityExternalUpdatedAt(map) -> string
Examples
findingIdentityExternalUpdatedAt(inputs)
findingIdentityExternalUpdatedAt(inputs)
Output: "2024-01-20T15:45:00Z"
findingIdentityField
Parses a finding and returns the value of the specified identity field.
Input and output
findingIdentityField(map, string) -> bool
Examples
findingIdentityField(inputs, 'status')
findingIdentityField(inputs, 'status')
Output: "ACTIVE"
findingIdentityField(inputs, 'nonexistent_field')
findingIdentityField(inputs, 'nonexistent_field')
Output:
findingIdentityGivenName
Parses an identity finding record and returns the given name from the identity data.
Input and output
findingIdentityGivenName(map) -> string
Examples
findingIdentityGivenName(inputs)
findingIdentityGivenName(inputs)
Output: "John"
findingIdentityHasMfa
Parses an identity finding record and returns whether MFA is enabled from the identity data.
Input and output
findingIdentityHasMfa(map) -> bool
Examples
findingIdentityHasMfa(inputs)
findingIdentityHasMfa(inputs)
Output: true
findingIdentityHasPasswordlessMfa
Parses an identity finding record and returns whether passwordless MFA is enabled from the identity data.
Input and output
findingIdentityHasPasswordlessMfa(map) -> bool
Examples
findingIdentityHasPasswordlessMfa(inputs)
findingIdentityHasPasswordlessMfa(inputs)
Output: false
findingIdentityHireDate
Parses an identity finding record and returns the hire date from the identity data.
Input and output
findingIdentityHireDate(map) -> string
Examples
findingIdentityHireDate(inputs)
findingIdentityHireDate(inputs)
Output: "2023-06-01"
findingIdentityIsAdmin
Parses an identity finding record and returns whether the identity has admin privileges.
Input and output
findingIdentityIsAdmin(map) -> bool
Examples
findingIdentityIsAdmin(inputs)
findingIdentityIsAdmin(inputs)
Output: false
findingIdentityIsGuest
Parses an identity finding record and returns whether the identity is a guest user.
Input and output
findingIdentityIsGuest(map) -> bool
Examples
findingIdentityIsGuest(inputs)
findingIdentityIsGuest(inputs)
Output: false
findingIdentityLastActiveAt
Parses an identity finding record and returns the last active timestamp from the identity data.
Input and output
findingIdentityLastActiveAt(map) -> string
Examples
findingIdentityLastActiveAt(inputs)
findingIdentityLastActiveAt(inputs)
Output: "2024-09-01T14:30:00Z"
findingIdentityLastPasswordChangeAt
Parses an identity finding record and returns the last password change timestamp from the identity data.
Input and output
findingIdentityLastPasswordChangeAt(map) -> string
Examples
findingIdentityLastPasswordChangeAt(inputs)
findingIdentityLastPasswordChangeAt(inputs)
Output: "2024-08-15T09:00:00Z"
findingIdentityLeaveDate
Parses an identity finding record and returns the leave date from the identity data.
Input and output
findingIdentityLeaveDate(map) -> string
Examples
findingIdentityLeaveDate(inputs)
findingIdentityLeaveDate(inputs)
Output: "2025-01-31"
findingIdentityLocation
Parses an identity finding record and returns the location from the identity data.
Input and output
findingIdentityLocation(map) -> string
Examples
findingIdentityLocation(inputs)
findingIdentityLocation(inputs)
Output: "New York Office"
findingIdentityManager
Parses an identity finding record and returns the manager from the identity data.
Input and output
findingIdentityManager(map) -> string
Examples
findingIdentityManager(inputs)
findingIdentityManager(inputs)
Output: "Jane Smith"
findingIdentityMfaMethods
Parses an identity finding record and returns the MFA methods from the identity data.
Input and output
findingIdentityMfaMethods(map) -> list
Examples
findingIdentityMfaMethods(inputs)
findingIdentityMfaMethods(inputs)
Output: ["SMS", "Authenticator App"]
findingIdentityOfficeLocation
Parses an identity finding record and returns the office location from the identity data.
Input and output
findingIdentityOfficeLocation(map) -> string
Examples
findingIdentityOfficeLocation(inputs)
findingIdentityOfficeLocation(inputs)
Output: "Building A, Floor 5"
findingIdentityOfficeZipCode
Parses an identity finding record and returns the office zip code from the identity data.
Input and output
findingIdentityOfficeZipCode(map) -> string
Examples
findingIdentityOfficeZipCode(inputs)
findingIdentityOfficeZipCode(inputs)
Output: "10001"
findingIdentityPhoneNumbers
Parses an identity finding record and returns the phone numbers from the identity data.
Input and output
findingIdentityPhoneNumbers(map) -> list
Examples
findingIdentityPhoneNumbers(inputs)
findingIdentityPhoneNumbers(inputs)
Output: ["+1-555-0123", "+1-555-0124"]
findingIdentityPrimaryDomain
Parses an identity finding record and returns the primary domain from the identity data.
Input and output
findingIdentityPrimaryDomain(map) -> string
Examples
findingIdentityPrimaryDomain(inputs)
findingIdentityPrimaryDomain(inputs)
Output: "example.com"
findingIdentityPrimaryEntityId
Parses an identity finding record and returns the primary entity ID from the identity data.
Input and output
findingIdentityPrimaryEntityId(map) -> string
Examples
findingIdentityPrimaryEntityId(inputs)
findingIdentityPrimaryEntityId(inputs)
Output: "entity-12345-abcd"
findingIdentityPrimaryMfaMethod
Parses an identity finding record and returns the primary MFA method from the identity data.
Input and output
findingIdentityPrimaryMfaMethod(map) -> string
Examples
findingIdentityPrimaryMfaMethod(inputs)
findingIdentityPrimaryMfaMethod(inputs)
Output: "Authenticator App"
findingIdentityPrimaryUsername
Parses an identity finding record and returns the primary username from the identity data.
Input and output
findingIdentityPrimaryUsername(map) -> string
Examples
findingIdentityPrimaryUsername(inputs)
findingIdentityPrimaryUsername(inputs)
Output: "john.doe"
findingIdentityProperties
Parses an identity finding record and returns the properties map from the identity data.
Input and output
findingIdentityProperties(map) -> map
Examples
findingIdentityProperties(inputs)
findingIdentityProperties(inputs)
Output: {"customAttribute1": "value1", "customAttribute2": "value2"}
findingIdentityProviderId
Parses an identity finding record and returns the provider ID from the identity data.
Input and output
findingIdentityProviderId(map) -> string
Examples
findingIdentityProviderId(inputs)
findingIdentityProviderId(inputs)
Output: "provider-azure-ad-12345"
findingIdentityRaw
Parses an identity finding record and returns the raw identity data.
Input and output
findingIdentityRaw(map) -> map
Examples
findingIdentityRaw(inputs)
findingIdentityRaw(inputs)
Output: {"id": "user-123", "displayName": "John Doe", "mail": "john.doe@example.com"}
findingIdentityRegion
Parses an identity finding record and returns the region from the identity data.
Input and output
findingIdentityRegion(map) -> string
Examples
findingIdentityRegion(inputs)
findingIdentityRegion(inputs)
Output: "North America"
findingIdentityStatus
Parses an identity finding record and returns the status from the identity data.
Input and output
findingIdentityStatus(map) -> string
Examples
findingIdentityStatus(inputs)
findingIdentityStatus(inputs)
Output: "ACTIVE"
findingIdentitySurname
Parses an identity finding record and returns the surname from the identity data.
Input and output
findingIdentitySurname(map) -> string
Examples
findingIdentitySurname(inputs)
findingIdentitySurname(inputs)
Output: "Doe"
findingIdentityTenant
Parses an identity finding record and returns the tenant from the identity data.
Input and output
findingIdentityTenant(map) -> int
Examples
findingIdentityTenant(inputs)
findingIdentityTenant(inputs)
Output: 12345
findingIdentityTitle
Parses an identity finding record and returns the job title from the identity data.
Input and output
findingIdentityTitle(map) -> string
Examples
findingIdentityTitle(inputs)
findingIdentityTitle(inputs)
Output: "Software Engineer"
findingIdentityUpdatedAt
Parses an identity finding record and returns the update timestamp from the identity data.
Input and output
findingIdentityUpdatedAt(map) -> string
Examples
findingIdentityUpdatedAt(inputs)
findingIdentityUpdatedAt(inputs)
Output: "2024-09-01T12:00:00Z"
findingIdentityUsageLocation
Parses an identity finding record and returns the usage location from the identity data.
Input and output
findingIdentityUsageLocation(map) -> string
Examples
findingIdentityUsageLocation(inputs)
findingIdentityUsageLocation(inputs)
Output: "US"
findingIdentityUsernames
Parses an identity finding record and returns the usernames from the identity data.
Input and output
findingIdentityUsernames(map) -> list
Examples
findingIdentityUsernames(inputs)
findingIdentityUsernames(inputs)
Output: ["john.doe", "jdoe", "john.doe@example.com"]
findingIdentityZipCode
Parses an identity finding record and returns the zip code from the identity data.
Input and output
findingIdentityZipCode(map) -> string
Examples
findingIdentityZipCode(inputs)
findingIdentityZipCode(inputs)
Output: "10001"
findingLastModified
Parses an identity finding record and returns the last modified timestamp.
Input and output
findingLastModified(map) -> string
Examples
findingLastModified(inputs)
findingLastModified(inputs)
Output: "2025-04-28T16:57:49.591956Z"
findingLastSeen
Parses an identity finding record and returns the last seen timestamp.
Input and output
findingLastSeen(map) -> string
Examples
findingLastSeen(inputs)
findingLastSeen(inputs)
Output: "2025-04-22T16:57:49.591956Z"
findingOtherReferences
Parses an identity finding record and returns the other references list. An optional second argument returns a list of specific entries.
Input and output
findingOtherReferences(map) -> list
findingOtherReferences(map, string) -> list
Examples
findingOtherReferences(inputs)
findingOtherReferences(inputs)
Output: [{"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}]
findingOtherReferences(inputs, 'type')
findingOtherReferences(inputs, 'type')
Output: ["microsoft.graph.application"]
findingOtherReferences(inputs, 'id')
findingOtherReferences(inputs, 'id')
Output: ["7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]
findingOtherReferences(inputs, 'logicalType')
findingOtherReferences(inputs, 'logicalType')
Output: ["UNKNOWN"]
findingOtherReferences(inputs, 'derivedType')
findingOtherReferences(inputs, 'derivedType')
Output: ["APP"]
findingOtherReferences(inputs, 'displayName')
findingOtherReferences(inputs, 'displayName')
Output: ["soanceawebapp"]
findingOtherReferences(inputs, 'externalLink')
findingOtherReferences(inputs, 'externalLink')
Output: ["https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]
findingPrimaryReference
Parses an identity finding record and returns the primary reference map. An optional second argument returns a specific entry.
Input and output
findingPrimaryReference(map) -> map
findingPrimaryReference(map, string) -> string
Examples
findingPrimaryReference(inputs)
findingPrimaryReference(inputs)
Output: {"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}
findingPrimaryReference(inputs, 'type')
findingPrimaryReference(inputs, 'type')
Output: "microsoft.graph.servicePrincipal"
findingPrimaryReference(inputs, 'id')
findingPrimaryReference(inputs, 'id')
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingPrimaryReference(inputs, 'logicalType')
findingPrimaryReference(inputs, 'logicalType')
Output: "IDENTITY_SERVICE_PRINCIPAL"
findingPrimaryReference(inputs, 'derivedType')
findingPrimaryReference(inputs, 'derivedType')
Output: "APP"
findingPrimaryReference(inputs, 'displayName')
findingPrimaryReference(inputs, 'displayName')
Output: "soanceawebapp"
findingPrimaryReference(inputs, 'externalLink')
findingPrimaryReference(inputs, 'externalLink')
Output: "https://portal.azure.com/%23view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/e98c0bf1-f226-4465-940f-696a79e7bdc6/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"
findingResult
Parses an identity finding record and returns the result.
Input and output
findingResult(map) -> string
Examples
findingResult(inputs)
findingResult(inputs)
Output: "{\"replyUrls\":[\"https://soanceawebapp.azurewebsites.net/.auth/login/aad/callback\"]}"
findingSeverity
Parses an identity finding record and returns the severity label (INFO, LOW, MEDIUM, HIGH, CRITICAL).
An optional second argument of true returns the severity as a double (0.0-1.0).
Input and output
findingSeverity(map) -> string
findingSeverity(map, bool) -> double
Examples
findingSeverity(inputs)
findingSeverity(inputs)
Output: "CRITICAL"
findingSeverity(inputs, true)
findingSeverity(inputs, true)
Output: "0.800000011920929"
findingSource
Parses an identity finding record and returns the source map. An optional second argument returns a specific entry.
Input and output
findingSource(map) -> map
findingSource(map, string) -> any
Examples
findingSource(inputs)
findingSource(inputs)
Output: {'id':'63258f26-1d39-4d69-9e85-e409244d9c97','resolved':{...},'type':'IDENTITY_PROVIDER'}
findingSource(inputs, 'type')
findingSource(inputs, 'type')
Output: "IDENTITY_PROVIDER"
findingSource(inputs, 'id')
findingSource(inputs, 'id')
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingSource(inputs, 'resolved')
findingSource(inputs, 'resolved')
Output: {'createdAt':'2025-02-03T08:32:21.80852Z','disabledAt':null,'expiration':'2026-06-06T05:00:03Z',...}
findingStatus
Parses an identity finding record and returns the status.
Input and output
findingStatus(map) -> string
Examples
findingStatus(inputs)
findingStatus(inputs)
Output: "OPEN"
findingStatusComments
Parses an identity finding record and returns the status comments.
Input and output
findingStatusComments(map) -> string
Examples
findingStatusComments(inputs)
findingStatusComments(inputs)
Output: "issue resolved"
findingTenantId
Parses an identity finding record and returns the tenant ID.
Input and output
findingTenantId(map) -> string
Examples
findingTenantId(inputs)
findingTenantId(inputs)
Output: "12345"
findingsStatusCommentsUserId
Parses an identity finding record and returns the user ID that added the status comments.
Input and output
findingsStatusCommentsUserId(map) -> string
Examples
findingsStatusCommentsUserId(inputs)
findingsStatusCommentsUserId(inputs)
Output: "3f59db3b-6b9c-4fb8-a26d-4c53fb334b4e"
first (optional element)
Returns an optional containing the first element of a list, or optional.none() if the list is empty.
Input and output
list.first() -> optional(T)
Returns an optional containing the first element of a list. If the list is empty, returns optional.none().
Use cases
Safe head access.
[1, 2, 3].first().orValue(0)
Get the first element or return a default value.
Check if empty.
items.first().hasValue()
Check whether the list has elements.
Process the first item.
tasks.first().optMap(t, t.priority)
Get the priority of the first task.
Conditional access.
results.first().orValue('No results')
Safely access the first result or return a message.
Chained processing.
data.filter(x, x > 0).first().orValue(-1)
Filter the data, then get the first result.
Validation.
!items.first().hasValue() ? 'Empty list' : 'Has items'
Check whether the list is empty.
Notes
- Returns
optional(T), whereTis the element type. - Safely returns
optional.none()for empty lists. - Is more expressive than
list[?0]. - Use
.orValue()to provide a default. - Doesn't modify the original list.
Examples
[1, 2, 3].first().orValue(0)
[1, 2, 3].first().orValue(0)
Output: 1
Get the first element.
[].first().hasValue()
[].first().hasValue()
Output: false
Check an empty list.
[].first().orValue(99)
[].first().orValue(99)
Output: 99
Use the default value for an empty list.
['a', 'b', 'c'].first().value()
['a', 'b', 'c'].first().value()
Output: 'a'
Extract the first string.
first (list elements)
Returns the first N elements of a list.
Input and output
first(list, int) -> list
Examples
first(["a", "c", "b"], 1)
first(["a", "c", "b"], 1)
Output: ["a"]
flatten
Returns a list where all nested lists are combined into a single top-level list.
Input and output
flatten(list) -> list
Examples
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
Output: ["row1col1", "row1col2", "row2col1", "row2col2"]
format (string)
Formats the string using printf-style formatting with the provided arguments.
Input and output
string.format(list) -> string
Formats the string using printf-style format specifiers with values from the list.
Common format specifiers:
%s: String.%d: Integer.%f: Floating-point number.%%: Literal percent sign.
Examples
'Hello %s'.format(['World'])
'Hello %s'.format(['World'])
Output: "Hello World"
'Value: %d, Name: %s'.format([42, 'test'])
'Value: %d, Name: %s'.format([42, 'test'])
Output: "Value: 42, Name: test"
'Pi: %.2f'.format([3.14159])
'Pi: %.2f'.format([3.14159])
Output: "Pi: 3.14"
format (timestamp)
Returns the string representation of the timestamp using the provided format. See Constants for a list of supported formats.
Input and output
format(timestamp, string) -> string
Examples
"1/1/2012".toTimestamp().format("layout")
"1/1/2012".toTimestamp().format("layout")
Output: 2012-01-01T00:00:00Z
"1/1/2012".toTimestamp().format("dateonly")
"1/1/2012".toTimestamp().format("dateonly")
Output: 2012-01-01
"1/1/2012".toTimestamp().format("Mon")
"1/1/2012".toTimestamp().format("Mon")
Output: Sun
generateString
Returns a randomly generated string with the length specified in the first argument and the characters or alphabet provided in the second argument.
Input and output
generateString(int, string) -> string
Examples
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
Output: aPsd2
groupBy
Returns a list of map elements grouped by one or more paths and a corresponding count of each grouping.
The first argument is the list to group. The second argument is a list of paths to group by. The optional third argument sorts the list in ascending (asc) or descending (desc) order. The default is ascending.
Input and output
groupBy(list, list, string) -> list
Examples
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
Output: [{"amap.host": "test1", "amap.title": "test", "count": 1}, {"amap.host": "test", "amap.title": "test", "count": 2}]
has
Validates that a key exists, is defined, and has a non-null value.
This macro also supports checking a map for one or more paths. An optional third argument specifies the separator used in the paths.
Input and output
has(map, string) -> bool
Examples
has(inputs, "key")
has(inputs, "key")
Output: true
hasValue
Returns true if the optional contains a value. Otherwise, returns false.
Input and output
optional(T).hasValue() -> bool
Checks whether an optional contains a value.
Use cases
Check before access.
obj.?field.hasValue() ? obj.field : 'default'
Safely check for a value before accessing it.
Validate input.
input.?userId.hasValue()
Check whether the field exists.
Use guard clauses.
!optional.none().hasValue()
Output: true
Verify that an optional is empty.
Optional chaining.
data[?'key'].hasValue() && data['key'] > 10
Check that a value exists before comparing it.
Filter present values.
items.filter(i, i.?metadata.hasValue())
Keep only items that have metadata.
Notes
- Returns a Boolean value (
trueorfalse). - Is safe to call on any optional.
- Use before calling
.value()to avoid errors. - Is commonly used with conditional expressions.
- Provides an alternative to checking for errors.
Examples
optional.of(42).hasValue()
optional.of(42).hasValue()
Output: true
The optional has a value.
optional.none().hasValue()
optional.none().hasValue()
Output: false
The optional has no value.
{'a': 1}[?'a'].hasValue()
{'a': 1}[?'a'].hasValue()
Output: true
The key exists.
{'a': 1}[?'b'].hasValue()
{'a': 1}[?'b'].hasValue()
Output: false
The key is missing.
[1, 2, 3][?0].hasValue()
[1, 2, 3][?0].hasValue()
Output: true
The index exists.
[1, 2, 3][?10].hasValue()
[1, 2, 3][?10].hasValue()
Output: false
The index is out of bounds.
hostnames
Parses an alert, entity, or asset and returns the hostnames found.
Input and output
hostnames(map) -> list
Examples
hostnames(inputs)
hostnames(inputs)
Output: ["alert_hostname", "entity_hostname", "asset_hostname"]
indexOf
Returns the index of the first occurrence of a substring.
Input and output
string.indexOf(string) -> int
string.indexOf(string, int) -> int
Returns the zero-based index of the first occurrence of the substring.
Returns -1 if the substring isn't found.
The optional second argument specifies the starting position for the search.
Examples
'hello world'.indexOf('world')
'hello world'.indexOf('world')
Output: 6
'hello world'.indexOf('o')
'hello world'.indexOf('o')
Output: 4
'hello world'.indexOf('o', 5)
'hello world'.indexOf('o', 5)
Output: 7
'hello world'.indexOf('xyz')
'hello world'.indexOf('xyz')
Output: -1
ipInNetwork
Returns true if the first argument IP address is in one or more of the second argument IP network ranges.
The second argument is represented as a list of networks in CIDR notation.
Input and output
ipInNetwork(string, list) -> bool
Examples
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
Output: true
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
Output: false
ipsv4
Parses an alert or entity and returns a list of IPv4 addresses if found.
Input and output
ipsv4(map) -> list
Examples
ipsv4(inputs)
ipsv4(inputs)
Output: ["127.0.0.111", "4.3.2.1", "1.2.3.4", "9.8.7.6", "6.7.8.9"]
isCaseClosed
Parses a case record and returns whether the case is closed.
Input and output
isCaseClosed(map) -> bool
Examples
isCaseClosed(inputs)
isCaseClosed(inputs)
Output: false
isCaseVisibleToCustomers
Parses a case record and returns whether the case is visible to customers.
Input and output
isCaseVisibleToCustomers(map) -> bool
Examples
isCaseVisibleToCustomers(inputs)
isCaseVisibleToCustomers(inputs)
Output: true
isDomain
Returns true if the provided string argument represents a valid domain.
Input and output
isDomain(string) -> bool
Examples
isDomain("example.com")
isDomain("example.com")
Output: true
isDomain("not_a_domain")
isDomain("not_a_domain")
Output: false
isEmail
Returns true if the provided string argument represents a valid email address.
Input and output
isEmail(string) -> bool
Examples
isEmail("sara@example.com")
isEmail("sara@example.com")
Output: true
isEmail("not_an_email")
isEmail("not_an_email")
Output: false
isIP
Returns true if the provided string argument represents a valid IPv4 address.
Input and output
isIP(string) -> bool
Examples
isIP("127.0.0.1")
isIP("127.0.0.1")
Output: true
isIP("not_an_ip")
isIP("not_an_ip")
Output: false
isPrivateIP
Returns true if the provided string argument represents a private (RFC-1918), link-local, or loopback IPv4 address.
Input and output
isPrivateIP(string) -> bool
Examples
isPrivateIP("192.168.1.1")
isPrivateIP("192.168.1.1")
Output: true
isPrivateIP("8.8.8.8")
isPrivateIP("8.8.8.8")
Output: false
isURL
Returns true if the provided string argument represents a valid Uniform Resource Locator (URL).
Input and output
isURL(string) -> bool
isURL(list) -> bool
Examples
isURL("https://example.com")
isURL("https://example.com")
Output: true
isURL("not_a_url")
isURL("not_a_url")
Output: false
isUUID
Returns true if the provided string argument represents a valid Universally Unique Identifier (UUID).
Input and output
isUUID(string) -> bool
Examples
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
Output: true
isUUID("not_a_uuid")
isUUID("not_a_uuid")
Output: false
join
Combines the elements of a list into a string using the provided separator.
The default separator is a comma character.
Input and output
join(list) -> string
join(list, string) -> string
Examples
join(["a", 1, true])
join(["a", 1, true])
Output: "a,1,true"
join(["a", 1, true], ".")
join(["a", 1, true], ".")
Output: "a.1.true"
keys
Returns a list of top-level keys from a map.
Input and output
keys(map) -> list
Examples
keys({"foo": "bar", "a": "b"})
keys({"foo": "bar", "a": "b"})
Output: ["foo", "a"]
last (list elements)
Returns the last N elements of a list.
Input and output
last(list, int) -> list
Examples
last(["a", "c", "b"], 2)
last(["a", "c", "b"], 2)
Output: ["c", "b"]
last (optional element)
Returns an optional containing the last element of a list, or optional.none() if the list is empty.
Input and output
list.last() -> optional(T)
Returns an optional containing the last element of a list.
If the list is empty, returns optional.none().
Use cases
Safe tail access.
[1, 2, 3].last().orValue(0)
Get the last element or return a default value.
Most recent item.
events.last().optMap(e, e.timestamp)
Get the timestamp of the latest event.
Check if empty.
items.last().hasValue()
Check whether the list has elements.
Latest value.
history.last().orValue('No history')
Get the most recent value or a default message.
End of sequence.
sequence.last().orValue(-1) > threshold
Check the last value against a threshold.
Validation.
results.last().hasValue() ? 'Complete' : 'Empty'
Check the state of the list.
Notes
- Returns
optional(T), whereTis the element type. - Safely returns
optional.none()for empty lists. - Is more expressive than
list[?list.size()-1]. - Use
.orValue()to provide a default. - Doesn't modify the original list.
Examples
[1, 2, 3].last().orValue(0)
[1, 2, 3].last().orValue(0)
Output: 3
Get the last element.
[].last().hasValue()
[].last().hasValue()
Output: false
Check an empty list.
[].last().orValue(99)
[].last().orValue(99)
Output: 99
Use the default value for an empty list.
['a', 'b', 'c'].last().value()
['a', 'b', 'c'].last().value()
Output: 'c'
Extract the last string.
lastIndexOf
Returns the index of the last occurrence of a substring.
Input and output
string.lastIndexOf(string) -> int
string.lastIndexOf(string, int) -> int
Returns the zero-based index of the last occurrence of the substring.
Returns -1 if the substring isn't found.
The optional second argument specifies the ending position for the search.
Examples
'hello world'.lastIndexOf('o')
'hello world'.lastIndexOf('o')
Output: 7
'hello world'.lastIndexOf('l')
'hello world'.lastIndexOf('l')
Output: 9
'hello world'.lastIndexOf('o', 6)
'hello world'.lastIndexOf('o', 6)
Output: 4
'hello world'.lastIndexOf('xyz')
'hello world'.lastIndexOf('xyz')
Output: -1
list
Converts input to a list.
Input and output
list(any) -> list
Examples
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
Output: [1, 3]
lists.range
Generates a list of sequential integers from 0 to n-1.
Input and output
lists.range(int) -> list
Generates a list of integers from 0 (inclusive) to n (exclusive).
Returns [0, 1, 2, ..., n-1].
Returns an empty list for values less than or equal to 0.
Use cases
Generate index list.
lists.range(items.size())
Get indices for a list.
Iterate N times.
lists.range(5).map(i, processItem(i))
Execute a function five times with an index.
Create test data.
lists.range(100)
Generate 100 sequential numbers.
Batch processing.
lists.range(totalItems / batchSize).map(i, processBatch(i))
Process items in batches.
Pagination.
lists.range(totalPages)
Generate page numbers.
Fill an array.
lists.range(10).map(i, 'item-' + string(i))
Output: ['item-0', 'item-1', ..., 'item-9']
Create a list of strings.
lowerAscii
Converts all ASCII characters in the string to lowercase.
Input and output
string.lowerAscii() -> string
Converts all ASCII uppercase letters (A-Z) to lowercase (a-z).
Non-ASCII characters are left unchanged.
Examples
'HELLO World'.lowerAscii()
'HELLO World'.lowerAscii()
Output: "hello world"
'ABC123XYZ'.lowerAscii()
'ABC123XYZ'.lowerAscii()
Output: "abc123xyz"
'Café'.lowerAscii()
'Café'.lowerAscii()
Output: "café"
map
Converts input to a map.
Input and output
map(list) -> map
Examples
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
Output: {"1": {"a": 1, "b": 2}, "3": {"a": 3, "b": 4}}
matchGroup
Returns a list of strings from the provided regex capture group or groups.
Input and output
matchGroup(string, string) -> list
Examples
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
Output: ["https://www.example.com", "https://", "www.example.com"]
math.abs
Returns the absolute value of a number.
Input and output
math.abs(double) -> double
math.abs(int) -> int
math.abs(uint) -> uint
Returns the absolute (non-negative) value of the input number.
Works with int, uint, and double types.
Examples
math.abs(-5)
math.abs(-5)
Output: 5
math.abs(5)
math.abs(5)
Output: 5
math.abs(-3.14)
math.abs(-3.14)
Output: 3.14
math.abs(0)
math.abs(0)
Output: 0
math.bitAnd
Performs a bitwise AND operation on two integers.
Input and output
math.bitAnd(int, int) -> int
math.bitAnd(uint, uint) -> uint
Returns the bitwise AND of two integers.
Each bit in the result is 1 only if both corresponding bits in the operands are 1.
Examples
math.bitAnd(5, 3)
math.bitAnd(5, 3)
Output: 1 (0101 & 0011 = 0001)
math.bitAnd(12, 10)
math.bitAnd(12, 10)
Output: 8 (1100 & 1010 = 1000)
math.bitAnd(15, 15)
math.bitAnd(15, 15)
Output: 15
math.bitAnd(7, 0)
math.bitAnd(7, 0)
Output: 0
math.bitNot
Performs a bitwise NOT (complement) operation on an integer.
Input and output
math.bitNot(int) -> int
math.bitNot(uint) -> uint
Returns the bitwise complement of the integer.
Each bit is flipped: 0 becomes 1, and 1 becomes 0.
Examples
math.bitNot(0)
math.bitNot(0)
Output: -1
math.bitNot(-1)
math.bitNot(-1)
Output: 0
math.bitNot(5)
math.bitNot(5)
Output: -6
math.bitNot(10)
math.bitNot(10)
Output: -11
math.bitOr
Performs a bitwise OR operation on two integers.
Input and output
math.bitOr(int, int) -> int
math.bitOr(uint, uint) -> uint
Returns the bitwise OR of two integers.
Each bit in the result is 1 if either corresponding bit in the operands is 1.
Examples
math.bitOr(5, 3)
math.bitOr(5, 3)
Output: 7 (0101 0011 = 0111)
math.bitOr(8, 4)
math.bitOr(8, 4)
Output: 12 (1000 0100 = 1100)
math.bitOr(0, 15)
math.bitOr(0, 15)
Output: 15
math.bitOr(7, 0)
math.bitOr(7, 0)
Output: 7
math.bitShiftLeft
Shifts the bits of an integer to the left by the specified number of positions.
Input and output
math.bitShiftLeft(int, int) -> int
math.bitShiftLeft(uint, uint) -> uint
Shifts all bits to the left by the specified number of positions.
Zeros are shifted in from the right. This is equivalent to multiplying by 2^n.
Examples
math.bitShiftLeft(5, 1)
math.bitShiftLeft(5, 1)
Output: 10 (0101 << 1 = 1010)
math.bitShiftLeft(5, 2)
math.bitShiftLeft(5, 2)
Output: 20 (0101 << 2 = 10100)
math.bitShiftLeft(1, 3)
math.bitShiftLeft(1, 3)
Output: 8
math.bitShiftLeft(3, 4)
math.bitShiftLeft(3, 4)
Output: 48
math.bitShiftRight
Shifts the bits of an integer to the right by the specified number of positions.
Input and output
math.bitShiftRight(int, int) -> int
math.bitShiftRight(uint, uint) -> uint
Shifts all bits to the right by the specified number of positions.
For unsigned integers, zeros are shifted in from the left.
For signed integers, the sign bit is preserved. This is equivalent to dividing by 2^n.
Examples
math.bitShiftRight(10, 1)
math.bitShiftRight(10, 1)
Output: 5 (1010 >> 1 = 0101)
math.bitShiftRight(20, 2)
math.bitShiftRight(20, 2)
Output: 5 (10100 >> 2 = 0101)
math.bitShiftRight(8, 3)
math.bitShiftRight(8, 3)
Output: 1
math.bitShiftRight(48, 4)
math.bitShiftRight(48, 4)
Output: 3
math.bitXor
Performs a bitwise XOR (exclusive OR) operation on two integers.
Input and output
math.bitXor(int, int) -> int
math.bitXor(uint, uint) -> uint
Returns the bitwise XOR of two integers.
Each bit in the result is 1 if the corresponding bits in the operands are different.
Examples
math.bitXor(5, 3)
math.bitXor(5, 3)
Output: 6 (0101 ^ 0011 = 0110)
math.bitXor(12, 10)
math.bitXor(12, 10)
Output: 6 (1100 ^ 1010 = 0110)
math.bitXor(15, 15)
math.bitXor(15, 15)
Output: 0
math.bitXor(7, 0)
math.bitXor(7, 0)
Output: 7
math.ceil
Rounds a number up to the nearest integer (towards positive infinity).
Input and output
math.ceil(double) -> double
Returns the smallest integer value greater than or equal to the input.
Always rounds up, even for negative numbers.
Examples
math.ceil(1.2)
math.ceil(1.2)
Output: 2.0
math.ceil(1.9)
math.ceil(1.9)
Output: 2.0
math.ceil(-1.2)
math.ceil(-1.2)
Output: -1.0
math.ceil(5.0)
math.ceil(5.0)
Output: 5.0
math.floor
Rounds a number down to the nearest integer (towards negative infinity).
Input and output
math.floor(double) -> double
Returns the largest integer value less than or equal to the input.
Always rounds down, even for negative numbers.
Examples
math.floor(1.2)
math.floor(1.2)
Output: 1.0
math.floor(1.9)
math.floor(1.9)
Output: 1.0
math.floor(-1.2)
math.floor(-1.2)
Output: -2.0
math.floor(5.0)
math.floor(5.0)
Output: 5.0
math.greatest
Returns the maximum value from the provided arguments.
Input and output
math.greatest(...) -> number
Returns the largest value among all provided arguments.
Accepts a variable number of arguments (int, uint, or double).
All arguments must be of comparable numeric types.
Examples
math.greatest(1, 5, 3, 9, 2)
math.greatest(1, 5, 3, 9, 2)
Output: 9
math.greatest(-10, -5, -20)
math.greatest(-10, -5, -20)
Output: -5
math.greatest(1.5, 2.3, 0.9)
math.greatest(1.5, 2.3, 0.9)
Output: 2.3
math.greatest(42)
math.greatest(42)
Output: 42
math.isFinite
Checks if a value is a finite number (not NaN or infinity).
Input and output
math.isFinite(double) -> bool
Returns true if the value is a finite number (not NaN or infinity).
Returns false for NaN, positive infinity, or negative infinity.
Examples
math.isFinite(3.14)
math.isFinite(3.14)
Output: true
math.isFinite(1.0 / 0.0)
math.isFinite(1.0 / 0.0)
Output: false
math.isFinite(0.0 / 0.0)
math.isFinite(0.0 / 0.0)
Output: false
math.isFinite(-100.5)
math.isFinite(-100.5)
Output: true
math.isInf
Checks if a value is positive or negative infinity.
Input and output
math.isInf(double) -> bool
Returns true if the value is infinity.
Examples
math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)
Output: true
math.isInf(-1.0 / 0.0)
math.isInf(-1.0 / 0.0)
Output: true
math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)
Output: true
math.isInf(3.14)
math.isInf(3.14)
Output: false
math.isNaN
Checks if a value is NaN (Not a Number).
Input and output
math.isNaN(double) -> bool
Returns true if the value is NaN. Otherwise, returns false.
Only applies to floating-point values.
Examples
math.isNaN(0.0 / 0.0)
math.isNaN(0.0 / 0.0)
Output: true
math.isNaN(1.0)
math.isNaN(1.0)
Output: false
math.isNaN(math.sqrt(-1.0))
math.isNaN(math.sqrt(-1.0))
Output: true
math.isNaN(3.14)
math.isNaN(3.14)
Output: false
math.least
Returns the minimum value from the provided arguments.
Input and output
math.least(...) -> number
Returns the smallest value among all provided arguments.
Accepts a variable number of arguments (int, uint, or double).
All arguments must be of comparable numeric types.
Examples
math.least(1, 5, 3, 9, 2)
math.least(1, 5, 3, 9, 2)
Output: 1
math.least(-10, -5, -20)
math.least(-10, -5, -20)
Output: -20
math.least(1.5, 2.3, 0.9)
math.least(1.5, 2.3, 0.9)
Output: 0.9
math.least(42)
math.least(42)
Output: 42
math.round
Rounds a number to the nearest integer (half away from zero).
Input and output
math.round(double) -> double
Returns the nearest integer value, rounding half values away from zero.
For positive numbers, 0.5 rounds up. For negative numbers, -0.5 rounds down.
Examples
math.round(1.4)
math.round(1.4)
Output: 1.0
math.round(1.5)
math.round(1.5)
Output: 2.0
math.round(-1.5)
math.round(-1.5)
Output: -2.0
math.round(5.0)
math.round(5.0)
Output: 5.0
math.sign
Returns the sign of a number: -1 for negative, 0 for zero, and 1 for positive.
Input and output
math.sign(double) -> double
math.sign(int) -> int
Returns:
-1if the number is negative.0if the number is zero.1if the number is positive.
Examples
math.sign(-5)
math.sign(-5)
Output: -1
math.sign(0)
math.sign(0)
Output: 0
math.sign(5)
math.sign(5)
Output: 1
math.sign(-3.14)
math.sign(-3.14)
Output: -1.0
math.sqrt
Returns the square root of a number.
Input and output
math.sqrt(int) -> double
math.sqrt(double) -> double
Returns the square root of the input number.
Returns NaN for negative inputs.
Examples
math.sqrt(9.0)
math.sqrt(9.0)
Output: 3.0
math.sqrt(16)
math.sqrt(16)
Output: 4.0
math.sqrt(2.0)
math.sqrt(2.0)
Output: 1.414...
math.sqrt(0.0)
math.sqrt(0.0)
Output: 0.0
math.trunc
Truncates a number to its integer part (towards zero).
Input and output
math.trunc(double) -> double
Returns the integer part of the number by removing the fractional part.
Rounds towards zero for both positive and negative numbers.
Examples
math.trunc(1.9)
math.trunc(1.9)
Output: 1.0
math.trunc(-1.9)
math.trunc(-1.9)
Output: -1.0
math.trunc(5.0)
math.trunc(5.0)
Output: 5.0
math.trunc(3.14159)
math.trunc(3.14159)
Output: 3.0
md5sum
Returns the computed MD5 digest for the provided string.
Input and output
md5sum(string) -> bytes
Examples
md5sum("Hello").toHex()
md5sum("Hello").toHex()
Output: "8b1a9953c4611296a827abf8c47804d7"
merge
Adds elements to an existing map.
Input and output
merge(map, map) -> map
Examples
merge({"key1": "val1"}, {"key2": "val2"})
merge({"key1": "val1"}, {"key2": "val2"})
Output: {"key1": "val1", "key2": "val2"}
now
Returns the current local time as a timestamp.
Input and output
now() -> timestamp
Examples
now()
now()
Output: "2025-04-29T12:34:56.789Z"
nowUnixMilli
Returns the current time as the number of milliseconds since epoch.
Input and output
nowUnixMilli() -> int
Examples
nowUnixMilli()
nowUnixMilli()
Output: 1742395914211
optFlatMap
Transforms the optional's value with a function that returns an optional, flattening the result.
Input and output
optional(T).optFlatMap(var, expr) -> optional(R)
Applies a transformation that returns an optional.
Unlike optMap, this doesn't nest optionals. If the original optional is empty or the transformation returns optional.none(), the result is optional.none().
Use cases
Chained optional access.
optional.of([1, 2, 3]).optFlatMap(l, l[?0])
Get the first element as an optional.
Conditional transformation.
optional.of(value).optFlatMap(v, v > 0 ? optional.of(v * 2) : optional.none())
Transform only if the condition is met.
Safe nested access.
optional.of(user).optFlatMap(u, u.?email)
Access a nested optional value safely.
Zero-value filtering.
optional.of(input).optFlatMap(i, optional.ofNonZeroValue(i.trim()))
Filter empty strings after trimming.
Multiple optional sources.
optional.of(config).optFlatMap(c, c[?'setting'])
Perform an optional map lookup within an optional object.
Notes
- Variable binding syntax:
optFlatMap(var, expression returning optional). - Prevents nested optionals such as
optional(optional(T)). - Useful when the transformation itself returns an optional.
- Empty optionals pass through unchanged as
optional.none(). - The transformation only runs when the optional contains a value.
Examples
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
Output: 1
optional.of([]).optFlatMap(l, l[?0]).orValue(0)
optional.of([]).optFlatMap(l, l[?0]).orValue(0)
Output: 0
optional.none().optFlatMap(l, l[?0]).orValue(0)
optional.none().optFlatMap(l, l[?0]).orValue(0)
Output: 0
optMap
Transforms the optional's value if present, returning a new optional with the transformed value.
Input and output
optional(T).optMap(var, expr) -> optional(R)
Applies a transformation to the optional's value if present.
The transformation returns a new value that is wrapped in an optional.
If the optional is empty, returns optional.none().
Use cases
Transform a value.
optional.of(5).optMap(x, x * 2)
Output: optional(10)
Double the value.
String manipulation.
optional.of('hello').optMap(s, s.upperAscii())
Output: optional('HELLO')
Transform to uppercase.
Property access.
optional.of(user).optMap(u, u.email)
Extract a property from a wrapped object.
Complex calculation.
optional.of([1, 2, 3]).optMap(l, l.size())
Output: optional(3)
Get the size of a list.
Chained transformations.
optional.of(10).optMap(x, x * 2).optMap(x, x + 1).orValue(0)
Output: 21
Chain multiple transformations.
Filter with map.
optional.of([1, 2, 3, 4, 5]).optMap(l, l.filter(x, x > 2))
Transform and filter data.
Safe navigation.
data.?user.optMap(u, u.name).orValue('Anonymous')
Safe nested access with transformation.
Notes
- Variable binding syntax:
optMap(var, expression using var). - Returns
optional(R)whereRis the result type. - Empty optionals pass through unchanged.
- Use
.orValue()to extract the final result. - Compare with
.optFlatMap()when the transformation returns an optional.
Examples
optional.of(5).optMap(x, x * 2).orValue(0)
optional.of(5).optMap(x, x * 2).orValue(0)
Output: 10
optional.none().optMap(x, x * 2).orValue(0)
optional.none().optMap(x, x * 2).orValue(0)
Output: 0
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
Output: 'HELLO'
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
Output: 3
optional.none
Creates an empty optional value with no content.
Input and output
optional.none() -> optional
Creates an empty optional value that contains no value.
Use cases
Represent a missing value.
optional.none()
Explicit absence of a value.
Use as a default in a conditional.
hasError ? optional.none() : optional.of(result)
Return an empty optional when an error occurs.
Chain with .or().
optional.none().or(optional.of(5))
Fall back to another optional.
Check emptiness.
optional.none().hasValue()
Output: false
Check whether an optional is empty.
Provide a default.
optional.none().orValue('default')
Extract a value with a fallback.
Notes
- Represents the absence of a value (similar to
null). .hasValue()returnsfalseforoptional.none().- Calling
.value()onoptional.none()causes an error. - Use
.orValue()to provide a default value. - Use
.or()to chain with other optionals.
Examples
optional.none().hasValue()
optional.none().hasValue()
Output: false
optional.none().orValue(42)
optional.none().orValue(42)
Output: 42
optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)
Output: 5
optional.of
Creates an optional value containing the given value.
Input and output
optional.of(T) -> optional(T)
Creates an optional value that contains the given value.
Any value is considered valid, including zero values.
Use cases
Wrap a known value.
optional.of(42)
Create an optional containing 42.
Wrap zero or empty values.
optional.of(0)
Create an optional containing 0.
Wrap an empty string.
optional.of('')
Create an optional containing an empty string.
Chain transformations.
optional.of(5).optMap(x, x * 2)
Transform the wrapped value.
Conditional wrapping.
hasValue ? optional.of(value) : optional.none()
Wrap a value conditionally.
Default value pattern.
optional.of(userInput).orValue('default')
Wrap input with a fallback.
Notes
- Accepts any value, including zero values such as
0,'',[], or{}. - Returns
optional(T)whereTis the value type. - Compare with
optional.ofNonZeroValue(), which rejects zero values. - Use
.hasValue()to check whether a value exists. - Use
.orValue()to extract a value with a fallback.
Examples
optional.of(42)
optional.of(42)
Output: optional(42)
optional.of('hello')
optional.of('hello')
Output: optional('hello')
optional.of([1, 2, 3])
optional.of([1, 2, 3])
Output: optional([1, 2, 3])
optional.of(0).hasValue()
optional.of(0).hasValue()
Output: true
optional.ofNonZeroValue
Creates an optional containing the value only if it's non-zero. Otherwise, returns optional.none().
Input and output
optional.ofNonZeroValue(T) -> optional(T)
Creates an optional containing the given value only if it's not a zero or empty value.
Zero values such as 0, '', [], {}, and null result in optional.none().
Use cases
Filter zero values.
optional.ofNonZeroValue(userInput)
Only wrap non-empty input.
Validate non-empty values.
optional.ofNonZeroValue('').hasValue()
Output: false
Check whether a string is non-empty.
Skip empty lists.
optional.ofNonZeroValue([]).orValue([1, 2, 3])
Use a default value for an empty list.
Conditional processing.
optional.ofNonZeroValue(score).optMap(s, s * 100)
Only process non-zero scores.
Null safety.
optional.ofNonZeroValue(null).orValue('N/A')
Handle null values safely.
Notes
Zero values by type:
- Numeric:
0,0.0 - String:
'' - List:
[] - Map:
{} - Boolean:
false - Bytes:
b'' - Null:
null
Additional notes:
- Returns
optional.none()for zero values. - Use when you want to treat empty or zero values as absent.
- Compare with
optional.of(), which accepts all values. - Useful for validation and filtering.
Examples
optional.ofNonZeroValue(42).hasValue()
optional.ofNonZeroValue(42).hasValue()
Output: true
Non-zero numeric value.
optional.ofNonZeroValue(0).hasValue()
optional.ofNonZeroValue(0).hasValue()
Output: false
Zero is rejected.
optional.ofNonZeroValue('').hasValue()
optional.ofNonZeroValue('').hasValue()
Output: false
Empty string is rejected.
optional.ofNonZeroValue('hello').hasValue()
optional.ofNonZeroValue('hello').hasValue()
Output: true
Non-empty string is accepted.
or
Returns the first optional if it has a value. Otherwise, returns the second optional.
Input and output
optional(T).or(optional(T)) -> optional(T)
Chains optional values.
If the left optional has a value, it is returned. Otherwise, the right optional is returned.
Evaluation is short-circuited.
Use cases
Fallback chain.
optional.none().or(optional.of(5))
Use an alternative optional value.
Multiple sources.
cache[?key].or(database[?key]).or(optional.of(default))
Try cache, then database, then a default value.
Coalesce pattern.
primary.or(secondary).or(tertiary).orValue(fallback)
Chain multiple optional sources.
Safe navigation chain.
obj.?field1.or(obj.?field2).orValue('none')
Try multiple fields in priority order.
Priority-based selection.
premium.?feature.or(basic.?feature)
Prefer a premium feature and fall back to a basic feature.
Notes
- Returns
optional(T), notT. - Use
.orValue()at the end to extract the final value. - Short-circuits evaluation when the first optional has a value.
- Useful for chaining multiple optional sources.
- Compare with
.orValue(), which returns a concrete value.
Examples
optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)
Output: 5
optional.of(3).or(optional.of(5)).orValue(0)
optional.of(3).or(optional.of(5)).orValue(0)
Output: 3
optional.none().or(optional.none()).orValue(10)
optional.none().or(optional.none()).orValue(10)
Output: 10
orValue
Returns the value from the optional if present. Otherwise, returns the provided default value.
Input and output
optional(T).orValue(T) -> T
Extracts the value from an optional if present, otherwise returns the provided default value.
Use cases
Provide a default.
optional.none().orValue(42)
Output: 42
Use a default when the optional is empty.
Safe field access.
obj.?field.orValue('N/A')
Get a field value or return a default.
Safe map access.
config[?'timeout'].orValue(30)
Get a configuration value with a fallback.
Safe list access.
items[?0].orValue('empty')
Get the first item or return a default.
Chain operations.
optional.of(5).orValue(0) * 2
Output: 10
Use the extracted value directly in a calculation.
Nested access.
data.?user.?name.orValue('Anonymous')
Safely access nested fields.
Coalesce pattern.
primary.orValue(secondary.orValue(tertiary))
Chain multiple fallback values.
Notes
- The default value must match the optional type.
- Always returns a concrete value.
- Safe to use anywhere a normal value is expected.
- More concise than conditional expressions.
- Compare with
.value(), which throws an error for empty optionals.
Examples
optional.of(42).orValue(0)
optional.of(42).orValue(0)
Output: 42
optional.none().orValue(0)
optional.none().orValue(0)
Output: 0
optional.of('hello').orValue('default')
optional.of('hello').orValue('default')
Output: 'hello'
{'a': 1}[?'b'].orValue(0)
{'a': 1}[?'b'].orValue(0)
Output: 0
parseURL
Returns the provided URL string as a URL map structure.
Input and output
parseURL(string) -> map
Examples
parseURL("https://www.example.com")
parseURL("https://www.example.com")
Output: {"Scheme": "https", "Host": "www.example.com", "Path": "", "RawQuery": "", "Fragment": ""}
queryJSON
Returns data from the first argument using the JMESPath query provided in the second argument.
Input and output
queryJSON(map, string) -> any
Examples
queryJSON(inputs.alert2, "metadata.confidence")
queryJSON(inputs.alert2, "metadata.confidence")
Output: 0.5
random
Returns a random value between 0 and .99 (inclusive).
Input and output
random() -> double
Examples
random()
random()
Output: 0.42
regex.extract
Extracts the first match of a regular expression pattern from a string, returning an optional value.
Input and output
regex.extract(string, pattern) -> string
Applies a regular expression pattern to a string and returns the first match wrapped in an optional.
If the pattern contains a capturing group, the captured value is returned.
If the pattern contains no capturing groups, the entire match is returned.
Returns optional.none() if no match is found.
Notes
Pattern syntax:
- Uses RE2 regular expression syntax.
- Capturing groups use parentheses
(). - Backslashes must be escaped in CEL strings.
- Common patterns include
\d,\w, and\s.
Additional notes:
- Returns an optional value. Use
.orValue()or.hasValue(). - Pattern matching proceeds left-to-right and returns only the first match.
- Use
extractAll()to retrieve all matches. - Empty strings and empty patterns are handled gracefully.
- Invalid regex patterns cause compilation errors.
regex.extractAll
Extracts all matches of a regular expression pattern from a string as a list.
Input and output
regex.extractAll(string, pattern) -> list
Applies a regular expression pattern to a string and returns all matches as a list of strings.
Returns an empty list if no matches are found.
Unlike extract(), this function returns all matches, not just the first one.
Use cases
Extract all numbers.
regex.extractAll('test123foo456bar', '\\d+')
Output: ["123", "456"]
Find all numeric sequences.
Extract all words.
regex.extractAll('hello world test', '\\w+')
Output: ["hello", "world", "test"]
Split text into words.
Parse multiple values.
regex.extractAll('192.168.1.1', '\\d+')
Output: ["192", "168", "1", "1"]
Extract all numeric values from an IP address.
Find all email addresses.
regex.extractAll(text, '\\w+@\\w+\\.\\w+')
Extract all email addresses from a string.
Count matches.
regex.extractAll('test123foo456bar', '\\d+').size()
Output: 2
Count the number of numeric sequences.
Check for matches.
regex.extractAll('no-numbers-here', '\\d+').size() == 0
Output: true
Check whether the pattern matches anything.
Extract and process.
regex.extractAll('1,2,3,4,5', '\\d+').map(x, int(x))
Output: [1, 2, 3, 4, 5]
Extract numbers and convert them to integers.
Filter results.
regex.extractAll('a1 b2 c3', '\\w+').filter(x, x.size() > 1)
Output: ["a1", "b2", "c3"]
Extract tokens and filter by length.
Notes
- Returns a list instead of an optional value.
- Returns an empty list when no matches are found.
- Capturing groups are ignored. Only full matches are returned.
- Useful for extracting multiple values from a string.
- More efficient than multiple calls to
extract(). - Preserves left-to-right match order.
Examples
regex.extractAll('test123foo456bar', '\\d+')
regex.extractAll('test123foo456bar', '\\d+')
Output: ["123", "456"]
regex.extractAll('hello world test', '\\w+')
regex.extractAll('hello world test', '\\w+')
Output: ["hello", "world", "test"]
regex.extractAll('192.168.1.1', '\\d+')
regex.extractAll('192.168.1.1', '\\d+')
Output: ["192", "168", "1", "1"]
regex.extractAll('no-numbers-here', '\\d+')
regex.extractAll('no-numbers-here', '\\d+')
Output: []
regex.replace
Replaces occurrences of a regular expression pattern in a string with a replacement string.
Input and output
regex.replace(string, pattern, replacement) -> string
regex.replace(string, pattern, replacement, count) -> string
Replaces non-overlapping substrings matching the regex pattern.
Optionally limits the number of replacements using the count argument.
When count is omitted or negative, all occurrences are replaced.
Use cases
Simple text replacement.
regex.replace('hello world hello', 'hello', 'hi')
Output: "hi world hi"
Replace all occurrences of hello.
Remove all digits.
regex.replace('test123test456', '\\d+', '')
Output: "testtest"
Remove all numeric sequences.
Mask sensitive data.
regex.replace('ID: 12345', '\\d+', 'XXXXX')
Output: "ID: XXXXX"
Replace numbers with a placeholder.
Limited replacements.
regex.replace('banana', 'a', 'x', 1)
Output: "bxnana"
Replace only the first occurrence.
Replace all with negative count.
regex.replace('banana', 'a', 'x', -1)
Output: "bxnxnx"
Negative count means replace all occurrences.
Normalize whitespace.
regex.replace('hello world test', '\\s+', ' ')
Output: "hello world test"
Replace multiple spaces with a single space.
Clean special characters.
regex.replace('hello@world#test', '[^a-zA-Z0-9]', '')
Output: "helloworldtest"
Remove non-alphanumeric characters.
Format phone numbers.
regex.replace('1234567890', '(\\d{3})(\\d{3})(\\d{4})', '($1) $2-$3')
Format a phone number using capture groups.
Notes
- Pattern must be a valid regular expression.
- Replacement string is treated literally except for capture-group references.
- When
countis0, the original string is returned unchanged. - When
countis negative, all matches are replaced. - Non-matching patterns return the original string unchanged.
- Empty patterns match between characters.
Capture group references:
- Use
\1,\2,\3, and so on. - Only numeric capture groups are supported.
- Named capture groups aren't supported in replacement strings.
- Invalid capture-group references cause runtime errors.
Examples
regex.replace('hello world hello', 'hello', 'hi')
regex.replace('hello world hello', 'hello', 'hi')
Output: "hi world hi"
regex.replace('banana', 'a', 'x')
regex.replace('banana', 'a', 'x')
Output: "bxnxnx"
regex.replace('test123test456', '\\d+', 'NUM')
regex.replace('test123test456', '\\d+', 'NUM')
Output: "testNUMtestNUM"
regex.replace('banana', 'a', 'x', 1)
regex.replace('banana', 'a', 'x', 1)
Output: "bxnana"
regex.replace('foo bar', 'foo', 'hello')
regex.replace('foo bar', 'hello')
Output: "hello bar"
replace
Replaces all occurrences of a substring with another string.
Input and output
string.replace(string, string) -> string
string.replace(string, string, int) -> string
Replaces occurrences of the first substring with the second substring.
An optional third argument limits the number of replacements. Use -1 to replace all occurrences.
Examples
'hello world'.replace('o', 'a')
'hello world'.replace('o', 'a')
Output: "hella warld"
'hello world'.replace('l', 'L')
'hello world'.replace('l', 'L')
Output: "heLLo worLd"
'hello world'.replace('l', 'L', 1)
'hello world'.replace('l', 'L', 1)
Output: "heLlo world"
'hello world'.replace('world', 'universe')
'hello world'.replace('world', 'universe')
Output: "hello universe"
resolvePartnerName
Resolves a Taegis tenant ID and returns the partner name.
Input and output
resolvePartnerName(string) -> string
Examples
resolvePartnerName('12345')
resolvePartnerName('12345')
Output: "Partner Name"
resolveSubjectName
Resolves a Taegis user ID or client ID and returns a name string.
Input and output
resolveSubjectName(string) -> string
Examples
resolveSubjectName('auth0asdf')
resolveSubjectName('auth0asdf')
Output: "GivenName FamilyName"
resolveSubjectName('ff0197b0@clients')
resolveSubjectName('ff0197b0@clients')
Output: "ClientName"
resolveTenantName
Resolves a Taegis tenant ID and returns the tenant name.
Input and output
resolveTenantName(string) -> string
Examples
resolveTenantName('12345')
resolveTenantName('12345')
Output: "Tenant Name"
resolveUser
Resolves a Taegis user by ID, Auth0 ID, or email address and returns the Taegis user ID.
Input and output
resolveUser(string) -> string
Examples
resolveUser('auth0asdf')
resolveUser('auth0asdf')
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
resolveUserName
Resolves a Taegis user ID and returns the username string.
Input and output
resolveUserName(string) -> string
Examples
resolveUserName('auth0asdf')
resolveUserName('auth0asdf')
Output: "GivenName FamilyName"
reverse
Reverses the order of elements in a list.
Input and output
list.reverse() -> list
Returns a new list with elements in reverse order.
The first element becomes the last, and vice versa.
Does not modify the original list.
Use cases
Reverse chronological order.
events.reverse()
Show the most recent events first.
Process in reverse.
steps.reverse().map(s, s.execute())
Execute steps in reverse order.
Palindrome check.
list == list.reverse()
Check whether a list is a palindrome.
Last-to-first processing.
queue.reverse()
Process items in LIFO order.
Reverse and filter.
items.reverse().filter(i, i.priority > 5)
Reverse the list and then filter it.
Reverse twice.
list.reverse().reverse() == list
Output: true
Double reversing returns the original list.
Notes
- Returns a new list.
- Works with any list type.
- Empty and single-element lists are unchanged.
- Reversing twice returns the original order.
Examples
[1, 2, 3, 4].reverse()
[1, 2, 3, 4].reverse()
Output: [4, 3, 2, 1]
['a', 'b', 'c'].reverse()
['a', 'b', 'c'].reverse()
Output: ['c', 'b', 'a']
[1].reverse()
[1].reverse()
Output: [1]
[].reverse()
[].reverse()
Output: []
[5, 3, 1, 2].reverse()
[5, 3, 1, 2].reverse()
Output: [2, 1, 3, 5]
sets.contains
Checks whether the first list contains all elements from the second list (subset check).
Input and output
sets.contains(list, list) -> bool
Returns true if the first list contains all elements from the second list.
The first list is considered a superset of the second list.
Order doesn't matter.
Duplicates in either list are ignored.
Use cases
Permission checking.
sets.contains(user.roles, ['admin'])
Check whether a user has the required role.
Required tags validation.
sets.contains(resource.tags, ['production', 'critical'])
Validate that a resource contains all required tags.
Feature availability.
sets.contains(subscription.features, ['api_access', 'export'])
Check whether a subscription includes all required features.
Empty list handling.
sets.contains([1, 2, 3], [])
Output: true
An empty list is a subset of any list.
Duplicate handling.
sets.contains([1, 1, 2, 2, 3], [1, 2])
Output: true
Duplicates are ignored.
Examples
sets.contains([1, 2, 3, 4], [2, 3])
sets.contains([1, 2, 3, 4], [2, 3])
Output: true
sets.contains([1, 2, 3], [3, 2, 1])
sets.contains([1, 2, 3], [3, 2, 1])
Output: true
sets.contains([1, 2, 3], [1, 2, 4])
sets.contains([1, 2, 3], [1, 2, 4])
Output: false
sets.contains(['admin', 'user', 'guest'], ['admin'])
sets.contains(['admin', 'user', 'guest'], ['admin'])
Output: true
sets.equivalent
Checks whether two lists contain the same elements, ignoring order and duplicates (set equality).
Input and output
sets.equivalent(list, list) -> bool
Returns true if both lists contain exactly the same elements.
Order doesn't matter.
Duplicates are ignored.
Use cases
Compare user permissions.
sets.equivalent(user1.permissions, user2.permissions)
Check whether two users have identical permissions.
Tag comparison.
sets.equivalent(resource1.tags, resource2.tags)
Compare resource tags.
Validate configuration.
sets.equivalent(actual_settings, expected_settings)
Verify that configuration values match.
Empty lists.
sets.equivalent([], [])
Output: true
Empty lists are equivalent.
String comparison.
sets.equivalent(['a', 'b', 'c'], ['c', 'a', 'b'])
Output: true
Works with any comparable type.
Symmetric operation.
sets.equivalent(list1, list2) == sets.equivalent(list2, list1)
Output: true
Argument order doesn't matter.
Examples
sets.equivalent([1, 2, 3], [3, 2, 1])
sets.equivalent([1, 2, 3], [3, 2, 1])
Output: true
sets.equivalent([1, 2, 3], [1, 2, 3])
sets.equivalent([1, 2, 3], [1, 2, 3])
Output: true
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
Output: true
sets.equivalent([1, 2, 3], [1, 2, 4])
sets.equivalent([1, 2, 3], [1, 2, 4])
Output: false
sets.intersects
Checks whether two lists have any common elements (non-empty intersection).
Input and output
sets.intersects(list, list) -> bool
Returns true if the two lists share at least one common element.
Order doesn't matter.
Duplicates are ignored.
Use cases
Role-based access control.
sets.intersects(user.roles, ['admin', 'owner', 'moderator'])
Check whether a user has at least one privileged role.
Tag filtering.
sets.intersects(resource.tags, ['production', 'staging'])
Check whether a resource belongs to a target environment.
Feature flags.
sets.intersects(user.features, ['beta', 'preview'])
Check whether a user has access to beta features.
Category matching.
sets.intersects(product.categories, filter.categories)
Check whether a product belongs to any selected category.
Permission validation.
sets.intersects(user.permissions, required_permissions)
Check whether a user has at least one required permission.
Multiple values check.
sets.intersects([user.status], ['active', 'pending', 'trial'])
Apply OR-style matching across multiple values.
Examples
sets.intersects([1, 2, 3], [3, 4, 5])
sets.intersects([1, 2, 3], [3, 4, 5])
Output: true
sets.intersects([1, 2, 3], [4, 5, 6])
sets.intersects([1, 2, 3], [4, 5, 6])
Output: false
sets.intersects(['admin', 'user'], ['admin', 'owner'])
sets.intersects(['admin', 'user'], ['admin', 'owner'])
Output: true
sets.intersects([1, 2, 3], [1, 2, 3])
sets.intersects([1, 2, 3], [1, 2, 3])
Output: true
sha1sum
Returns the computed SHA-1 digest for the provided string.
Input and output
sha1sum(string) -> bytes
Examples
sha1sum("Hello").toHex()
sha1sum("Hello").toHex()
Output: "f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0"
sha256sum
Returns the computed SHA-256 digest for the provided string.
Input and output
sha256sum(string) -> bytes
Examples
sha256sum("Hello").toHex()
sha256sum("Hello").toHex()
Output: "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"
sha512sum
Returns the computed SHA-512 digest for the provided string.
Input and output
sha512sum(string) -> bytes
Examples
sha512sum("Hello").toHex()
sha512sum("Hello").toHex()
Output: "3615f80c9d293ed7402687f94b22d58e529b8cc7916f8fac7fddf7fbd5af4cf777d3d795a7a00a16bf7e7f3fb9561ee9baae480da9fe7a18769e71886b03f315"
slice
Extracts a portion of a list between two indices.
Input and output
list.slice(int, int) -> list
Extracts a sub-list from the start index (inclusive) to the end index (exclusive).
Indices are zero-based.
Use cases
Pagination.
results.slice(page * pageSize, (page + 1) * pageSize)
Extract a page of results.
Take the first N elements.
list.slice(0, 5)
Get the first five elements.
Skip the first N elements.
list.slice(3, list.size())
Skip the first three elements.
Get a middle section.
list.slice(2, 8)
Extract a middle portion of the list.
Get the last N elements.
list.slice(list.size() - 3, list.size())
Get the last three elements.
sort
Returns a copy of the provided list sorted in ascending order.
The sort order can be reversed to descending by specifying "desc" as the second argument.
Input and output
sort(list) -> list
sort(list, string) -> list
Examples
sort(["a", "c", "b"])
sort(["a", "c", "b"])
Output: ["a", "b", "c"]
sort([3, 2, 1], "desc")
sort([3, 2, 1], "desc")
Output: [3, 2, 1]
sortBy
Sorts a list by a computed key expression, allowing custom sort criteria.
Input and output
list.sortBy(var, key_expression) -> list
Sorts the list based on values computed by the key expression for each element.
The variable name is bound to each element during key computation.
Elements are sorted by their computed keys in ascending order.
Use cases
Sort by object property.
users.sortBy(u, u.name)
Sort users alphabetically by name.
Sort by age.
users.sortBy(u, u.age)
Sort users by age.
Descending sort.
scores.sortBy(s, -s.value)
Sort scores in descending order.
Sort by computed value.
products.sortBy(p, p.price * (1 - p.discount))
Sort by the final discounted price.
Sort by string length.
words.sortBy(w, w.size())
Sort words by length.
Sort by multiple criteria.
items.sortBy(i, string(i.priority) + i.name)
Sort by priority and then by name.
Sort by distance.
locations.sortBy(loc, math.abs(loc.lat - target.lat) + math.abs(loc.lon - target.lon))
Sort locations by Manhattan distance.
Sort by Boolean value.
items.sortBy(i, i.active)
Sort with false values first and true values last.
Case insensitive sorting.
names.sortBy(n, n.lowerAscii())
Sort strings without regard to case.
Sort by nested property.
orders.sortBy(o, o.customer.tier)
Sort by a nested property.
Complex calculations.
tasks.sortBy(t, t.priority * 10 + (t.dueDate - now).getHours())
Sort using a weighted priority and time calculation.
Notes
- Returns a new sorted list.
- The original list is unchanged.
- The key expression is evaluated for each element.
- Sorting is stable, meaning equal keys keep their relative order.
- Keys must be comparable.
- Negate numeric values to perform a descending sort.
Examples
[3, 1, 4, 1, 5, 9].sortBy(x, x)
[3, 1, 4, 1, 5, 9].sortBy(x, x)
Output: [1, 1, 3, 4, 5, 9]
Sort using the value itself as the key.
[3, 1, 4, 1, 5, 9].sortBy(x, -x)
[3, 1, 4, 1, 5, 9].sortBy(x, -x)
Output: [9, 5, 4, 3, 1, 1]
Sort in descending order.
split
Splits a string into a list using the specified delimiter.
Input and output
string.split(string) -> list
string.split(string, int) -> list
Splits the string into a list of substrings using the delimiter.
The optional second argument limits the number of splits. Use -1 for all splits.
Examples
'hello world'.split(' ')
'hello world'.split(' ')
Output: ["hello", "world"]
'a,b,c,d'.split(',')
'a,b,c,d'.split(',')
Output: ["a", "b", "c", "d"]
'a,b,c,d'.split(',', 2)
'a,b,c,d'.split(',', 2)
Output: ["a", "b,c,d"]
'one'.split('')
'one'.split('')
Output: ["o", "n", "e"]
substring
Extracts a portion of a string between two indices.
Input and output
string.substring(int) -> string
string.substring(int, int) -> string
Extracts a substring starting at the first index.
If a second argument is provided, extraction stops before that index.
If only one argument is provided, extraction continues to the end of the string.
Examples
'hello world'.substring(0, 5)
'hello world'.substring(0, 5)
Output: "hello"
'hello world'.substring(6)
'hello world'.substring(6)
Output: "world"
'hello world'.substring(6, 11)
'hello world'.substring(6, 11)
Output: "world"
'hello'.substring(1, 4)
'hello'.substring(1, 4)
Output: "ell"
take
Returns the first x elements of a list, or the elements between a start and end position.
Input and output
take(list, int) -> list
take(list, int, int) -> list
Examples
take(["a", "c", "b"], 1)
take(["a", "c", "b"], 1)
Output: ["a"]
take(["a", "c", "b"], 0, 2)
take(["a", "c", "b"], 0, 2)
Output: ["a", "c"]
tenantAllowResponseActions
Checks whether response actions are allowed for a tenant.
Input and output
tenantAllowResponseActions(map) -> bool
Examples
tenantAllowResponseActions(tenant)
tenantAllowResponseActions(tenant)
Output: true
tenantCentralAccountOrigin
Returns the accountOrigin value from the centralTenant map.
Input and output
tenantCentralAccountOrigin(map) -> string
Examples
tenantCentralAccountOrigin(tenant)
tenantCentralAccountOrigin(tenant)
Output: "taegis"
tenantCentralAccountType
Returns the accountType value from the centralTenant map.
Input and output
tenantCentralAccountType(map) -> string
Examples
tenantCentralAccountType(tenant)
tenantCentralAccountType(tenant)
Output: "tenant"
tenantCentralDataRegion
Returns the dataRegion value from the centralTenant map.
Input and output
tenantCentralDataRegion(map) -> string
Examples
tenantCentralDataRegion(tenant)
tenantCentralDataRegion(tenant)
Output: "us03"
tenantCentralId
Returns the central tenant ID from the centralTenant map.
Input and output
tenantCentralId(map) -> string
Examples
tenantCentralId(tenant)
tenantCentralId(tenant)
Output: "7f8f1dee-98da-4b1b-bb70-1f788254687e"
tenantCentralLastRefresh
Returns the lastRefresh value from the centralTenant map.
Input and output
tenantCentralLastRefresh(map) -> string
Examples
tenantCentralLastRefresh(tenant)
tenantCentralLastRefresh(tenant)
Output: "2025-09-23T17:28:01.113261229Z"
tenantCentralRegion
Returns the region value from the centralTenant map.
Input and output
tenantCentralRegion(map) -> string
Examples
tenantCentralRegion(tenant)
tenantCentralRegion(tenant)
Output: "us-east-2"
tenantCentralXdrOwnership
Returns the xdrOwnership value from the centralTenant map.
Input and output
tenantCentralXdrOwnership(map) -> string
Examples
tenantCentralXdrOwnership(tenant)
tenantCentralXdrOwnership(tenant)
Output: "securityOperations"
tenantDataRetentionMonths
Extracts the data retention period in months from a tenant map.
Input and output
tenantDataRetentionMonths(map) -> int
Examples
tenantDataRetentionMonths(tenant)
tenantDataRetentionMonths(tenant)
Output: 60
tenantDescription
Extracts the tenant description from a tenant map.
Input and output
tenantDescription(map) -> string
Examples
tenantDescription(tenant)
tenantDescription(tenant)
Output: "CTPx Playground"
tenantEnabled
Checks whether a tenant is enabled.
Input and output
tenantEnabled(map) -> bool
Examples
tenantEnabled(tenant)
tenantEnabled(tenant)
Output: true
tenantEnvironments
Returns a list of environment names for a tenant.
Input and output
tenantEnvironments(map) -> list
Examples
tenantEnvironments(tenant)
tenantEnvironments(tenant)
Output: ["pilot", "pilot_1", "pilot_2"]
tenantHasService
Checks whether a tenant has a specific service by name (case insensitive).
Input and output
tenantHasService(map, string) -> bool
Examples
tenantHasService(tenant, "MDR")
tenantHasService(tenant, "MDR")
Output: true
tenantId
Extracts the tenant ID from a tenant map.
Input and output
tenantId(map) -> string
Examples
tenantId(tenant)
tenantId(tenant)
Output: "11772"
tenantIsOrganization
Checks whether a tenant is an organization.
Input and output
tenantIsOrganization(map) -> bool
Examples
tenantIsOrganization(tenant)
tenantIsOrganization(tenant)
Output: false
tenantIsPartner
Checks whether a tenant is a partner.
Input and output
tenantIsPartner(map) -> bool
Examples
tenantIsPartner(tenant)
tenantIsPartner(tenant)
Output: false
tenantIsSophosMDR
Returns true when the tenant's licenseLevel is exactly "MDR".
This macro is equivalent to:
tenant.licenseLevel == 'MDR'
Input and output
tenantIsSophosMDR(map) -> bool
Examples
tenantIsSophosMDR(tenant)
tenantIsSophosMDR(tenant)
Output: true
tenantIsSophosXDR
Returns true when the tenant is an XDR customer.
Equivalent to:
tenantCentralXdrOwnership(tenant) != 'taegis' &&
tenantCentralXdrOwnership(tenant) != '' &&
tenant.licenseLevel != 'MDR'
Input and output
tenantIsSophosXDR(map) -> bool
Examples
tenantIsSophosXDR(tenant)
tenantIsSophosXDR(tenant)
Output: true
tenantLabelValue
Returns the value of a specific label for a tenant.
Input and output
tenantLabelValue(map, string) -> string
Examples
tenantLabelValue(tenant, "testing")
tenantLabelValue(tenant, "testing")
Output: "true"
tenantLabels
Returns a map of label names to values for a tenant.
Input and output
tenantLabels(map) -> map
Examples
tenantLabels(tenant)
tenantLabels(tenant)
Output: {"testing": "true", "Endpoints Licensed": "2000"}
tenantName
Extracts the tenant name from a tenant map.
Input and output
tenantName(map) -> string
Examples
tenantName(tenant)
tenantName(tenant)
Output: "CTPx Playground"
tenantOrganization
Extracts the organization from a tenant map.
Input and output
tenantOrganization(map) -> string
Examples
tenantOrganization(tenant)
tenantOrganization(tenant)
Output: ""
tenantParent
Extracts the parent tenant ID from a tenant map.
Input and output
tenantParent(map) -> string
Examples
tenantParent(tenant)
tenantParent(tenant)
Output: "5000"
tenantParentId
Extracts the parent tenant ID from a tenant map.
Input and output
tenantParentId(map) -> string
Examples
tenantParentId(tenant)
tenantParentId(tenant)
Output: "5000"
tenantPartner
Extracts the partner tenant ID from a tenant map.
Input and output
tenantPartner(map) -> string
Examples
tenantPartner(tenant)
tenantPartner(tenant)
Output: "5000"
tenantPartnerId
Extracts the partner tenant ID from a tenant map.
Input and output
tenantPartnerId(map) -> string
Examples
tenantPartnerId(tenant)
tenantPartnerId(tenant)
Output: "5000"
tenantServices
Returns a list of service names for a tenant.
Input and output
tenantServices(map) -> list
Examples
tenantServices(tenant)
tenantServices(tenant)
Output: ["Access Point", "Ask an Expert", "Data Retention: 60 mo"]
tenantSupportEnabled
Checks whether support is enabled for a tenant.
Input and output
tenantSupportEnabled(map) -> bool
Examples
tenantSupportEnabled(tenant)
tenantSupportEnabled(tenant)
Output: false
toHTML
Returns the provided string as HTML.
Input and output
toHTML(string) -> string
Examples
'**bold**'.toHTML()
'**bold**'.toHTML()
Output: "bold"
toHex
Returns the hexadecimal string representation of a byte list.
Input and output
toHex(bytes) -> string
Examples
md5sum("Hello").toHex()
md5sum("Hello").toHex()
Output: "8b1a9953c4611296a827abf8c47804d7"
toLower
Returns a copy of the string with all characters converted to lowercase.
Input and output
toLower(string) -> string
Examples
"TEST".toLower()
"TEST".toLower()
Output: "test"
toPreferredTimestamp
Returns the user's preferred timestamp format based on the specified timestamp, timezone, and language.
Input and output
toPreferredTimestamp(string, string, string) -> string
Examples
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
Output: "Jan 2 2025 15:04 UTC"
toString
Returns the provided value of any data type as a string.
Input and output
toString(any) -> string
Examples
toString(100)
toString(100)
Output: "100"
toTable
Returns a string representation of the provided data as a text or Markdown table.
Input and output
toTable(list, list, list, bool) -> string
Examples
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
Output: "+------+------+\\n HEADER1 HEADER2 \\n+------+------+\\n row1_column1 row1_column2 \\n row2_column1 row2_column2 \\n+------+------+"
toTimestamp
Returns a timestamp from a date and time string.
Input and output
toTimestamp(string) -> timestamp
Examples
'1/1/2012'.toTimestamp()
'1/1/2012'.toTimestamp()
Output: "2012-01-01T00:00:00Z"
toTitle
Returns a copy of the string with the first letter of each word converted to uppercase.
Input and output
toTitle(string) -> string
Examples
'hello world'.toTitle()
'hello world'.toTitle()
Output: "Hello World"
toURLQuery
Returns a copy of the string with URL special characters converted to escape sequences.
Input and output
toURLQuery(string) -> string
Examples
'hello world'.toURLQuery()
'hello world'.toURLQuery()
Output: "hello+world"
toUpper
Returns a copy of the string with all characters converted to uppercase.
Input and output
toUpper(string) -> string
Examples
"hello".toUpper()
"hello".toUpper()
Output: "HELLO"
transformList
Iterates on a list or map with an index/key and value, transforming each element into a new list.
Input and output
list.transformList(index, value, expression) -> list
list.transformList(index, value, condition, expression) -> list
map.transformList(key, value, expression) -> list
map.transformList(key, value, condition, expression) -> list
Provides access to both the index/key and value in the transformation expression.
Optionally supports a filter condition.
Examples
[1, 2, 3].transformList(i, v, i * v)
[1, 2, 3].transformList(i, v, i * v)
Output: [0, 2, 6]
[10, 20, 30].transformList(i, v, v + i)
[10, 20, 30].transformList(i, v, v + i)
Output: [10, 21, 32]
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
Output: [0, 6]
transformMap
Iterates on a list or map with an index/key and value, transforming values while preserving keys.
Input and output
list.transformMap(index, value, expression) -> map
list.transformMap(index, value, condition, expression) -> map
map.transformMap(key, value, expression) -> map
map.transformMap(key, value, condition, expression) -> map
Provides access to both the index/key and value in the transformation expression.
Optionally supports a filter condition.
Examples
[10, 20, 30].transformMap(i, v, v * 2)
[10, 20, 30].transformMap(i, v, v * 2)
Output: {"0": 20, "1": 40, "2": 60}
[1, 2, 3].transformMap(i, v, i * v)
[1, 2, 3].transformMap(i, v, i * v)
Output: {"0": 0, "1": 2, "2": 6}
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
Output: {"0": 0, "2": 6}
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
Output: {"a": 10, "b": 20}
transformMapEntry
Iterates on a list or map with an index/key and value, creating custom key-value pairs in a new map.
Input and output
list.transformMapEntry(index, value, expression) -> map
list.transformMapEntry(index, value, condition, expression) -> map
map.transformMapEntry(key, value, expression) -> map
map.transformMapEntry(key, value, condition, expression) -> map
The transformation expression must produce a map literal containing a single entry.
Examples
[1, 2, 3].transformMapEntry(i, v, {string(v): i})
[1, 2, 3].transformMapEntry(i, v, {string(v): i})
Output: {"1": 0, "2": 1, "3": 2}
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
Output: {"a": 0, "b": 1, "c": 2}
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
Output: {"1": 0, "3": 2}
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
Output: {"1": "a", "2": "b"}
trim (string or list)
Removes leading and trailing whitespace.
Input and output
trim(string) -> string
trim(list) -> list
Examples
" 1 ".trim()
" 1 ".trim()
Output: "1"
trim([" 1 ", " 2 ", " 3 "])
trim([" 1 ", " 2 ", " 3 "])
Output: ["1", "2", "3"]
trim (string)
Removes leading and trailing whitespace from the string.
Input and output
string.trim() -> string
Removes spaces, tabs, and newline characters from the beginning and end of the string.
Does not remove whitespace from the middle of the string.
Examples
' hello '.trim()
' hello '.trim()
Output: "hello"
'hello world'.trim()
'hello world'.trim()
Output: "hello world"
'\\n\\t test \\n'.trim()
'\\n\\t test \\n'.trim()
Output: "test"
' hello world '.trim()
' hello world '.trim()
Output: "hello world"
unique
Returns a copy of the list with duplicate elements removed.
Only elements that are exactly the same (case-sensitive) are removed.
Input and output
unique(list) -> list
Examples
unique(["a", "b", "a"])
unique(["a", "b", "a"])
Output: ["a", "b"]
unwrapOpt
Returns a list containing only the values from optional elements that have values, filtering out optional.none().
Input and output
list(optional(T)).unwrapOpt() -> list(T)
Takes a list of optional values and returns a new list containing only the values from optionals that contain values.
Filters out all optional.none() entries.
Use cases
Filter present values.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
Output: [1, 3]
Remove empty optionals.
Safe map access.
keys.map(k, data[?k]).unwrapOpt()
Get values for existing keys only.
Clean results.
items.map(i, i.?value).unwrapOpt()
Extract only values that are present.
Conditional collection.
data.map(x, x > 0 ? optional.of(x) : optional.none()).unwrapOpt()
Collect values that meet a condition.
Compact operation.
optionalList.unwrapOpt()
Remove all optional.none() values.
Safe transformations.
inputs.map(i, parseValue(i)).unwrapOpt()
Keep only successfully parsed values.
Notes
- Input:
list(optional(T)) - Output:
list(T) - Includes only optionals where
.hasValue()returnstrue. - Maintains the order of non-empty values.
- Returns an empty list when all optionals are empty.
- Also available as
optional.unwrap(list).
Examples
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
Output: [1, 2, 3]
All values are present.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
Output: [1, 3]
Filter out empty optionals.
[optional.none(), optional.none()].unwrapOpt()
[optional.none(), optional.none()].unwrapOpt()
Output: []
All values are empty.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
Output: 1
Access the first present value.
upperAscii
Converts all ASCII characters in the string to uppercase.
Input and output
string.upperAscii() -> string
Converts all ASCII lowercase letters (a-z) to uppercase (A-Z).
Non-ASCII characters are left unchanged.
Examples
'hello World'.upperAscii()
'hello World'.upperAscii()
Output: "HELLO WORLD"
'abc123xyz'.upperAscii()
'abc123xyz'.upperAscii()
Output: "ABC123XYZ"
'café'.upperAscii()
'café'.upperAscii()
Output: "CAFé"
userIds
Parses an alert or entity and returns a list of user IDs.
Input and output
userIds(map) -> list
Examples
userIds(inputs)
userIds(inputs)
Output: ["1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]
userInDomain
Returns true if the provided username belongs to one or more of the provided domains.
Input and output
userInDomain(string, list) -> bool
Examples
userInDomain("asdf@example.com", ["example.com"])
userInDomain("asdf@example.com", ["example.com"])
Output: true
userNames
Parses an alert or entity and returns a list of usernames.
Input and output
userNames(map) -> list
Examples
userNames(inputs)
userNames(inputs)
Output: ["sample_user", "another_sample_user"]
users
Parses an alert or entity and returns a list of usernames and user IDs.
Input and output
users(map) -> list
Examples
users(inputs)
users(inputs)
Output: ["sample_user", "another_sample_user", "1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]
value
Returns the value from the optional, or raises an error if the optional is empty.
Input and output
optional(T).value() -> T
Extracts the value from an optional.
If the optional is empty (optional.none()), this causes a runtime error.
Use cases
Extract a known value.
optional.of(42).value()
Output: 42
Get the value directly.
Extract after validation.
opt.hasValue() ? opt.value() : 'default'
Check before extraction.
Fail fast.
requiredField.value()
Raise an error if the field is missing.
Unwrap a result.
computation().value()
Get the result or fail.
Notes
- Calling
.value()onoptional.none()causes an error. - Always check with
.hasValue()first, or use.orValue()instead. - Use only when you're certain the optional contains a value.
- Useful when absence should be treated as an error.
- For optional chaining, use
.orValue(). - Common in fail-fast scenarios.
Examples
optional.of(42).value()
optional.of(42).value()
Output: 42
Extract an integer value.
optional.of('text').value()
optional.of('text').value()
Output: 'text'
Extract a string value.
[1, 2, 3].first().value()
[1, 2, 3].first().value()
Output: 1
Extract the first element from a list.