Skip to content

Supported CEL macros

Sophos XDR supports Google's CEL macros for evaluating and manipulating data. Some macros are built in, while others are specific to Sophos XDR. This page describes commonly used macros.

You can also use CEL Explorer, which provides context-aware autocomplete for CEL macros. For details, see CEL Explorer.

In these examples, the following data structure is used:

{
    "plant": {
        "type": "tree",
        "name": "white oak",
        "uses": [
            "lumber",
            "firewood",
            "furniture"
        ],
        "traits": {
            "produces_fruit": true,
            "genus": "Quercus",
            "height": 100,
            "extinct": false,
            "related_to": [
                {
                    "name": "chestnut",
                    "genus": "Castanea"
                },
                {
                    "name": "beech",
                    "genus": "Fagus"
                }
           ]
        },
        "locations": [
            "usa",
            "europe",
            "new york",
            "New York",
            "new york  ",
            "usa",
            "worldwide",
            "eu"
        ]
    }
}

Available macros

? (optional operator)

? is an optional operator for safe navigation, safe indexing, and conditional inclusion in CEL expressions.

The ? operator provides the following capabilities:

  • Safe field navigation (obj.?field): Access fields without errors.
  • Safe map indexing (map[?key]): Access map values safely.
  • Safe list indexing (list[?index]): Access list elements safely.
  • Optional map fields ({?key: value}): Conditionally include map fields.
  • Optional list elements ([?element]): Conditionally include list elements.

After the first ? operator, subsequent accesses are automatically safe (viral chaining): obj.?field.subfield == obj.?field.?subfield.

Notes

  • The ? operator returns optional values that need .orValue() or .hasValue().
  • Safe navigation never throws errors on missing fields, keys, or indices.
  • Optional field/element syntax requires optional-typed values.
  • Use with optional.of(), optional.none(), or optional.ofNonZeroValue().

Examples

{'name': 'John'}.?name.orValue('Unknown')
{'name': 'John'}.?name.orValue('Unknown')

Output: 'John'

Safe field navigation.

{}.?name.orValue('Unknown')
{}.?name.orValue('Unknown')

Output: 'Unknown'

Field missing returns optional.none().

{'a': 1, 'b': 2}[?'a'].orValue(0)
{'a': 1, 'b': 2}[?'a'].orValue(0)

Output: 1

Safe map indexing.

{'a': 1}[?'c'].orValue(0)
{'a': 1}[?'c'].orValue(0)

Output: 0

Missing key returns optional.none().

[1, 2, 3][?0].orValue(0)
[1, 2, 3][?0].orValue(0)

Output: 1

Safe list indexing.

[1, 2, 3][?10].orValue(0)
[1, 2, 3][?10].orValue(0)

Output: 0

Out-of-bounds index returns optional.none().

{?'key': optional.of(5)}.size()
{?'key': optional.of(5)}.size()

Output: 1

Optional map field is included.

{?'key': optional.none()}.size()
{?'key': optional.none()}.size()

Output: 0

Optional map field is omitted.

[1, ?optional.of(2), 3].size()
[1, ?optional.of(2), 3].size()

Output: 3

Optional list element is included.

[1, ?optional.none(), 3].size()
[1, ?optional.none(), 3].size()

Output: 2

Optional list element is omitted.

abs

Returns the absolute value of the provided argument.

Input and output

abs(double) -> double
abs(int) -> int
abs(uint) -> uint

Examples

abs(-1.0)
abs(-1.0)

Output: 1.0

abs(1.0)
abs(1.0)

Output: 1.0

all

Iterates on a list or map and validates that a condition is true for all elements in the list.

Input and output

all(list, predicate) -> bool
all(map, predicate) -> bool

Examples

[1,2,3,4].all(x, x > 0)
[1,2,3,4].all(x, x > 0)

Output: true

[1,2,3,0].all(x, x > 0)
[1,2,3,0].all(x, x > 0)

Output: false

append

Adds elements to an existing list.

Input and output

append(list, any) -> list

Examples

append([1, 2, 3], 4)
append([1, 2, 3], 4)

Output: [1, 2, 3, 4]

append([], "newElement")
append([], "newElement")

Output: ["newElement"]

assetTags

Returns a list of asset tag key/value pairs from an asset. By default, returns both keys and values. Optionally returns only keys or values.

Input and output

assetTags(map) -> list
assetTags(map, string) -> list

Examples

assetTags(inputs)
assetTags(inputs)

Output: ["t1:v1", "t2:v2"]

assetTags(inputs, "keys")
assetTags(inputs, "keys")

Output: ["t1", "t2"]

assetTags(inputs, "values")
assetTags(inputs, "values")

Output: ["v1", "v2"]

base64.decode

Decodes a base64-encoded string to bytes.

Input and output

base64.decode(string) -> bytes

Decodes a base64-encoded string back to its original byte sequence.

Returns empty bytes for empty input.

The input must be a valid base64-encoded string.

Use cases

Decode encoded credentials.
base64.decode('dXNlcm5hbWU6cGFzc3dvcmQ=')

Output: b'username:password'

Decode Basic Authentication credentials.

Convert to string.
string(base64.decode('aGVsbG8='))

Output: "hello"

Decode and convert bytes to a string.

Decode API responses.
string(base64.decode(api_response.encoded_data))

Decode base64-encoded API response data.

Validate encoding.
base64.decode(base64.encode(b'test'))

Output: b'test'

Verify round-trip encoding and decoding.

Process encoded input.
string(base64.decode(input.encoded_value))

Decode user-provided base64 input.

Empty input handling.
base64.decode('')

Output: b''

Empty string produces empty bytes.

Chain with string operations.
string(base64.decode('aGVsbG8=')).upperAscii()

Output: "HELLO"

Decode, convert to a string, then uppercase.

Working with JSON.
string(base64.decode('eyJrZXkiOiJ2YWx1ZSJ9'))

Output: '{"key":"value"}'

Decode base64-encoded JSON.

Error handling

  • Invalid base64 strings will cause an error.
  • Padding characters (=) are handled automatically.
  • Whitespace in input may cause decoding errors.

Notes

  • Input must be a valid base64-encoded string.
  • Output is always a bytes type.
  • Use string() conversion to get a string from bytes.
  • Uses standard base64 decoding (RFC 4648).
  • This coexists with the custom decodeBase64() function.

Common patterns

Decode and use as string:

string(base64.decode(encoded_input))

Most common pattern: decode and convert to a string.

Decode and process:

cel.bind(decoded, base64.decode(input), decoded.size() > 0 ? string(decoded) : 'empty')

Decode, check size, then convert or return a default value.

Round trip validation:

string(base64.decode(base64.encode(b'test'))) == 'test'

Validate that encoding and decoding work correctly.

Examples

base64.decode('aGVsbG8=')
base64.decode('aGVsbG8=')

Output: b'hello'

base64.decode('aGVsbG8gd29ybGQ=')
base64.decode('aGVsbG8gd29ybGQ=')

Output: b'hello world'

base64.decode('dGVzdDEyMw==')
base64.decode('dGVzdDEyMw==')

Output: b'test123'

base64.decode('')
base64.decode('')

Output: b''

base64.encode

Encodes bytes to a base64-encoded string.

Input and output

base64.encode(bytes) -> string

Encodes a byte sequence to a base64-encoded string using standard base64 encoding.

Returns an empty string for empty input.

The output is a URL-safe base64 string.

Use cases

Encode text for transmission.
base64.encode(b'username:password')

Output: "dXNlcm5hbWU6cGFzc3dvcmQ="

Encode credentials for Basic Authentication.

Encode binary data.
base64.encode(file_content)

Convert binary file content to a text representation.

Data serialization.
base64.encode(b'{"key": "value"}')

Encode JSON data for URL parameters.

Safe string encoding.
base64.encode(b'data with special chars: !@#$%')

Encode strings containing special characters.

Round-trip encoding.
string(base64.decode(base64.encode(b'test')))

Output: "test"

Verify that encoding and decoding work correctly.

Working with string conversion.
base64.encode(bytes(input.text))

Convert a string to bytes, then encode.

Empty input handling.
base64.encode(b'')

Output: ""

Empty bytes produce an empty string.

Notes

  • Input must be a bytes type. Use b'...' syntax or bytes() conversion.
  • Output is always a string.
  • Uses standard base64 encoding (RFC 4648).
  • Padding characters (=) are included as needed.
  • This coexists with the custom encodeBase64() function.

Examples

base64.encode(b'hello')
base64.encode(b'hello')

Output: "aGVsbG8="

base64.encode(b'hello world')
base64.encode(b'hello world')

Output: "aGVsbG8gd29ybGQ="

base64.encode(b'test123')
base64.encode(b'test123')

Output: "dGVzdDEyMw=="

base64.encode(b'')
base64.encode(b'')

Output: ""

caseArchivedAt

Parses a case record and returns the date and time it was archived.

Input and output

caseArchivedAt(map) -> string

Examples

caseArchivedAt(inputs)
caseArchivedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseAssetEvidence

Parses a case record and returns the list of asset evidence objects.

Input and output

caseAssetEvidence(map) -> list

Examples

caseAssetEvidence(inputs)
caseAssetEvidence(inputs)

Output: [, ...]

caseAssigneeId

Parses a case record and returns the ID of the assignee.

Input and output

caseAssigneeId(map) -> string

Examples

caseAssigneeId(inputs)
caseAssigneeId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseChangeAfter

Returns an optional containing the after value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.

Input and output

caseChangeAfter(map, string) -> optional

Examples

caseChangeAfter(inputs, 'severity').orValue(0)
caseChangeAfter(inputs, 'severity').orValue(0)

Output: 6

caseChangeAfter(inputs, 'severity').hasValue()
caseChangeAfter(inputs, 'severity').hasValue()

Output: true

caseChangeAfter(inputs, 'nonexistent').orValue(0)
caseChangeAfter(inputs, 'nonexistent').orValue(0)

Output: 0

caseChangeAfter(inputs, 'nonexistent').hasValue()
caseChangeAfter(inputs, 'nonexistent').hasValue()

Output: false

caseChangeBefore

Returns an optional containing the before value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.

Input and output

caseChangeBefore(map, string) -> optional

Examples

caseChangeBefore(inputs, 'severity').orValue(0)
caseChangeBefore(inputs, 'severity').orValue(0)

Output: 4

caseChangeBefore(inputs, 'severity').hasValue()
caseChangeBefore(inputs, 'severity').hasValue()

Output: true

caseChangeBefore(inputs, 'nonexistent').orValue(0)
caseChangeBefore(inputs, 'nonexistent').orValue(0)

Output: 0

caseChangeBefore(inputs, 'nonexistent').hasValue()
caseChangeBefore(inputs, 'nonexistent').hasValue()

Output: false

caseChanges

Returns the delta.changes map from a case record. Each key is a field name, and each value is a map with before and after entries.

Input and output

caseChanges(map) -> map

Examples

caseChanges(inputs)
caseChanges(inputs)

Output: {"severity": {"before": 4, "after": 6}, "title": {"before": "Original Case Title", "after": "Updated Case Title"}}

caseCloseReason

Parses a case record and returns the reason it was closed.

Input and output

caseCloseReason(map) -> string

Examples

caseCloseReason(inputs)
caseCloseReason(inputs)

Output: "reason for closing"

caseClosedAt

Parses a case record and returns the date and time it was closed (RFC3339), or an empty string when unset.

Input and output

caseClosedAt(map) -> string

Examples

caseClosedAt(inputs)
caseClosedAt(inputs)

Output: "2026-03-09T11:57:04.205591Z"

caseComment

Parses a case record and returns the comment associated with it.

Input and output

caseComment(map) -> string

Examples

caseComment(inputs)
caseComment(inputs)

Output: "This is a sample comment for the case."

caseCommentAuthorId

Parses a case record and returns the ID of the author of the comment.

Input and output

caseCommentAuthorId(map) -> string

Examples

caseCommentAuthorId(inputs)
caseCommentAuthorId(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCommentCreatedAt

Parses a case record and returns the date and time the comment was created.

Input and output

caseCommentCreatedAt(map) -> string

Examples

caseCommentCreatedAt(inputs)
caseCommentCreatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseCommentMentions

Parses a case record and returns a list of mentions in the comment.

Input and output

caseCommentMentions(map) -> list

Examples

caseCommentMentions(inputs)
caseCommentMentions(inputs)

Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]

caseCommentOperation

Parses a case record and returns the operation type of the comment.

Input and output

caseCommentOperation(map) -> string

Examples

caseCommentOperation(inputs)
caseCommentOperation(inputs)

Output: "create"

caseContributorIds

Parses a case record and returns a list of contributor IDs.

Input and output

caseContributorIds(map) -> list

Examples

caseContributorIds(inputs)
caseContributorIds(inputs)

Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]

caseCreatedAt

Parses a case record and returns the date and time it was created.

Input and output

caseCreatedAt(map) -> string

Examples

caseCreatedAt(inputs)
caseCreatedAt(inputs)

Output: "2024-06-20T17:57:45.592464Z"

caseCreatedById

Parses a case record and returns the ID of the user that created it.

Input and output

caseCreatedById(map) -> string

Examples

caseCreatedById(inputs)
caseCreatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

caseCreatedByPartner

Parses a case record and returns true if it was created by a parent of the tenant.

Input and output

caseCreatedByPartner(map) -> bool

Examples

caseCreatedByPartner(inputs)
caseCreatedByPartner(inputs)

Output: false

caseDetectionEvidence

Parses a case record and returns the list of detection evidence objects.

Input and output

caseDetectionEvidence(map) -> list

Examples

caseDetectionEvidence(inputs)
caseDetectionEvidence(inputs)

Output: [{id, isGenesis}, ...]

caseEventEvidence

Parses a case record and returns the list of event evidence objects.

Input and output

caseEventEvidence(map) -> list

Examples

caseEventEvidence(inputs)
caseEventEvidence(inputs)

Output: [, ...]

caseFieldChanged

Parses a case record and returns true if the provided field was modified.

Input and output

caseFieldChanged(map, string) -> bool

Examples

caseFieldChanged(inputs, 'priority')
caseFieldChanged(inputs, 'priority')

Output: true

caseFieldChanged(inputs, 'nonexistent_field')
caseFieldChanged(inputs, 'nonexistent_field')

Output: false

caseFileId

Parses a case record and returns the file ID from delta.file (File Added events).

Input and output

caseFileId(map) -> string

Examples

caseFileId(inputs)
caseFileId(inputs)

Output: "f1e2d3c4-b5a6-7890-1234-567890abcdef"

caseFileName

Parses a case record and returns the file name from delta.file (File Added events).

Input and output

caseFileName(map) -> string

Examples

caseFileName(inputs)
caseFileName(inputs)

Output: "evidence.pdf"

caseFileSize

Parses a case record and returns the file size from delta.file (File Added events).

Input and output

caseFileSize(map) -> int

Examples

caseFileSize(inputs)
caseFileSize(inputs)

Output: 102400

caseFileStatus

Parses a case record and returns the file lifecycle status from delta.file (File Added/Deleted events).

Input and output

caseFileStatus(map) -> string

Examples

caseFileStatus(inputs)
caseFileStatus(inputs)

Output: "SCHEDULED"

caseFileUploadedById

Parses a case record and returns the user ID that uploaded the file from delta.file (File Added/Deleted events).

Input and output

caseFileUploadedById(map) -> string

Examples

caseFileUploadedById(inputs)
caseFileUploadedById(inputs)

Output: "auth0user123"

caseId

Parses a case record and returns the ID.

Input and output

caseId(map) -> string

Examples

caseId(inputs)
caseId(inputs)

Output: "a251201f-9a26-4cd5-81f6-20509999933d"

caseIncidentAdvisorId

Parses a case record and returns the incident advisor ID.

Input and output

caseIncidentAdvisorId(map) -> string

Examples

caseIncidentAdvisorId(inputs)
caseIncidentAdvisorId(inputs)

Output: "adv-123"

caseKeyFindings

Parses a case record and returns the key findings content.

With an optional second argument, returns a specific field from the keyFindings object (for example, documentType or documentVersion).

Input and output

caseKeyFindings(map) -> string
caseKeyFindings(map, string) -> string

Examples

caseKeyFindings(inputs)
caseKeyFindings(inputs)

Output: "Sample Case Key Findings"

caseKeyFindings(inputs, 'documentType')
caseKeyFindings(inputs, 'documentType')

Output: "DOCUMENT_TYPE_MARKDOWN"

caseKeyFindings(inputs, 'documentVersion')
caseKeyFindings(inputs, 'documentVersion')

Output: "1"

caseLinkCreatedAt

Returns the link creation timestamp from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkCreatedAt(map) -> string

Examples

caseLinkCreatedAt(inputs)
caseLinkCreatedAt(inputs)

Output: "2026-04-30T18:53:00.483028Z"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))

Output: ["2026-04-30T18:53:00.483028Z"]

caseLinkIsInternal

Returns whether the link is internal from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkIsInternal(map) -> bool

Examples

caseLinkIsInternal(inputs)
caseLinkIsInternal(inputs)

Output: false

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))

Output: [false]

caseLinkReference

Returns the link reference from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkReference(map) -> string

Examples

caseLinkReference(inputs)
caseLinkReference(inputs)

Output: "EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))

Output: ["EXT-12345"]

caseLinkTitle

Returns the link title from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkTitle(map) -> string

Examples

caseLinkTitle(inputs)
caseLinkTitle(inputs)

Output: "External Ticket"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))

Output: ["External Ticket"]

caseLinkType

Returns the link type from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkType(map) -> string

Examples

caseLinkType(inputs)
caseLinkType(inputs)

Output: "External"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')

Output: []

caseLinkUrl

Returns the link URL from a case-change event (delta.link) or a bare link record.

Input and output

caseLinkUrl(map) -> string

Examples

caseLinkUrl(inputs)
caseLinkUrl(inputs)

Output: "https://example.com/tickets/EXT-12345"

caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))

Output: ["https://example.com/tickets/EXT-12345"]

Parses a case record and returns the full list of link objects.

Input and output

caseLinks(map) -> list

Examples

caseLinks(inputs)
caseLinks(inputs)

Output: [, ]

caseLinksReference

Parses a case record and returns the list of reference strings from all links.

Input and output

caseLinksReference(map) -> list

Examples

caseLinksReference(inputs)
caseLinksReference(inputs)

Output: ["EXT-12345", "JIRA-456"]

caseLinksTitle

Parses a case record and returns the list of title strings from all links.

Input and output

caseLinksTitle(map) -> list

Examples

caseLinksTitle(inputs)
caseLinksTitle(inputs)

Output: ["External Ticket", "Jira Ticket"]

caseLinksType

Parses a case record and returns the list of type strings from all links (for example, External or Jira).

Input and output

caseLinksType(map) -> list

Examples

caseLinksType(inputs)
caseLinksType(inputs)

Output: ["External", "Jira"]

caseLinksUrl

Parses a case record and returns the list of URL strings from all links.

Input and output

caseLinksUrl(map) -> list

Examples

caseLinksUrl(inputs)
caseLinksUrl(inputs)

Output: ["https://example.com/tickets/EXT-12345", "https://jira.example.com/..."]

caseManagedBy

Parses a case record and returns the managed-by value (PROVIDER, CUSTOMER, UNKNOWN).

Input and output

caseManagedBy(map) -> string

Examples

caseManagedBy(inputs)
caseManagedBy(inputs)

Output: "CUSTOMER"

casePrimaryStatusId

Parses a case record and returns the primary status ID.

Input and output

casePrimaryStatusId(map) -> string

Examples

casePrimaryStatusId(inputs)
casePrimaryStatusId(inputs)

Output: "8dafe9bc-cbf6-4b27-aff4-8959682f859c"

casePrimaryStatusName

Parses a case record and returns the primary status name.

Input and output

casePrimaryStatusName(map) -> string

Examples

casePrimaryStatusName(inputs)
casePrimaryStatusName(inputs)

Output: "draft"

casePrimaryStatusTitle

Parses a case record and returns the primary status title.

Input and output

casePrimaryStatusTitle(map) -> string

Examples

casePrimaryStatusTitle(inputs)
casePrimaryStatusTitle(inputs)

Output: "Draft"

casePrimaryVerdictId

Parses a case record and returns the primary verdict ID.

Input and output

casePrimaryVerdictId(map) -> string

Examples

casePrimaryVerdictId(inputs)
casePrimaryVerdictId(inputs)

Output: "pv-1"

casePrimaryVerdictName

Parses a case record and returns the primary verdict name.

Input and output

casePrimaryVerdictName(map) -> string

Examples

casePrimaryVerdictName(inputs)
casePrimaryVerdictName(inputs)

Output: "confirmed"

casePrimaryVerdictTitle

Parses a case record and returns the primary verdict title.

Input and output

casePrimaryVerdictTitle(map) -> string

Examples

casePrimaryVerdictTitle(inputs)
casePrimaryVerdictTitle(inputs)

Output: "Confirmed"

casePriority

Parses a case record and returns the priority of the case as a word (Low, Medium, High, Critical).

An optional second argument of true returns the priority as an integer (1-4).

Input and output

casePriority(map) -> string
casePriority(map, bool) -> int

Examples

casePriority(inputs)
casePriority(inputs)

Output: "High"

casePriority(inputs, true)
casePriority(inputs, true)

Output: 3

caseProcessingStatus

Parses a case record and returns the processing status map.

Input and output

caseProcessingStatus(map) -> map

Examples

caseProcessingStatus(inputs)
caseProcessingStatus(inputs)

Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}

caseRiskScore

Parses a case record and returns the risk score.

Input and output

caseRiskScore(map) -> double

Examples

caseRiskScore(inputs)
caseRiskScore(inputs)

Output: 7.2

caseRuleId

Parses a case record and returns the auto case rule ID that created it.

Input and output

caseRuleId(map) -> string

Examples

caseRuleId(inputs)
caseRuleId(inputs)

Output: "12345"

caseSearchEvidence

Parses a case record and returns the list of search evidence objects.

Input and output

caseSearchEvidence(map) -> list

Examples

caseSearchEvidence(inputs)
caseSearchEvidence(inputs)

Output: [, ...]

caseSecondaryStatusId

Parses a case record and returns the secondary status ID.

Input and output

caseSecondaryStatusId(map) -> string

Examples

caseSecondaryStatusId(inputs)
caseSecondaryStatusId(inputs)

Output: "ss-1"

caseSecondaryStatusName

Parses a case record and returns the secondary status name.

Input and output

caseSecondaryStatusName(map) -> string

Examples

caseSecondaryStatusName(inputs)
caseSecondaryStatusName(inputs)

Output: "under_review"

caseSecondaryStatusReason

Parses a case record and returns the list of secondary status reasons.

Input and output

caseSecondaryStatusReason(map) -> list

Examples

caseSecondaryStatusReason(inputs)
caseSecondaryStatusReason(inputs)

Output: ["reason1", "reason2"]

caseSecondaryStatusTitle

Parses a case record and returns the secondary status title.

Input and output

caseSecondaryStatusTitle(map) -> string

Examples

caseSecondaryStatusTitle(inputs)
caseSecondaryStatusTitle(inputs)

Output: "Under Review"

caseSecondaryVerdictId

Parses a case record and returns the secondary verdict ID.

Input and output

caseSecondaryVerdictId(map) -> string

Examples

caseSecondaryVerdictId(inputs)
caseSecondaryVerdictId(inputs)

Output: "sv-1"

caseSecondaryVerdictName

Parses a case record and returns the secondary verdict name.

Input and output

caseSecondaryVerdictName(map) -> string

Examples

caseSecondaryVerdictName(inputs)
caseSecondaryVerdictName(inputs)

Output: "malicious"

caseSecondaryVerdictTitle

Parses a case record and returns the secondary verdict title.

Input and output

caseSecondaryVerdictTitle(map) -> string

Examples

caseSecondaryVerdictTitle(inputs)
caseSecondaryVerdictTitle(inputs)

Output: "Malicious"

caseSeverity

Parses a case record and returns the severity as a word (Informational, Low, Medium, High, Critical).

For inputs.case, uses severity values 2, 4, 6, 8, and 10. For V1/V2 records, uses priority values 1-4.

An optional second argument of false returns the raw numeric value.

Input and output

caseSeverity(map) -> string
caseSeverity(map, bool) -> int

Examples

caseSeverity(inputs)
caseSeverity(inputs)

Output: "Medium"

caseSeverity(inputs, false)
caseSeverity(inputs, false)

Output: 6

caseShortId

Parses a case record and returns the short ID.

Input and output

caseShortId(map) -> string

Examples

caseShortId(inputs)
caseShortId(inputs)

Output: "INV41773"

caseSourceId

Parses a case record and returns the source ID.

Input and output

caseSourceId(map) -> string

Examples

caseSourceId(inputs)
caseSourceId(inputs)

Output: "src-auto-001"

caseSourceName

Parses a case record and returns the source name.

Input and output

caseSourceName(map) -> string

Examples

caseSourceName(inputs)
caseSourceName(inputs)

Output: "auto_case_rule"

caseSourceTitle

Parses a case record and returns the source display title.

Input and output

caseSourceTitle(map) -> string

Examples

caseSourceTitle(inputs)
caseSourceTitle(inputs)

Output: "Auto-Generated"

caseStatus

Parses a case record and returns the status.

Input and output

caseStatus(map) -> string
caseStatus(map, string) -> string

Examples

caseStatus(inputs)
caseStatus(inputs)

Output: "OPEN"

caseStatus(inputs, 'v1')
caseStatus(inputs, 'v1')

Output: "Open"

caseTags

Parses a case record and returns the list of tags.

Input and output

caseTags(map) -> list

Examples

caseTags(inputs)
caseTags(inputs)

Output: ["automation", "playbook"]

caseTenantId

Parses a case record and returns the ID of the tenant.

Input and output

caseTenantId(map) -> string

Examples

caseTenantId(inputs)
caseTenantId(inputs)

Output: "12345"

caseThirdPartyId

Parses a case record and returns the ID of a third-party record associated with it.

Input and output

caseThirdPartyId(map) -> string

Examples

caseThirdPartyId(inputs)
caseThirdPartyId(inputs)

Output: "bdf9f35a8383121055c9e330ceaad3b8"

caseThirdPartyType

Parses a case record and returns the type of a third-party record associated with it.

Input and output

caseThirdPartyType(map) -> string

Examples

caseThirdPartyType(inputs)
caseThirdPartyType(inputs)

Output: "SNOW"

caseTitle

Parses a case record and returns the title.

Input and output

caseTitle(map) -> string

Examples

caseTitle(inputs)
caseTitle(inputs)

Output: "Taegis Watchlist Case"

caseType

Parses a case record and returns the type.

An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.

Input and output

caseType(map) -> string
caseType(map, string) -> string

Examples

caseType(inputs)
caseType(inputs)

Output: "SECURITY_INVESTIGATION"

caseType(inputs, 'v1')
caseType(inputs, 'v1')

Output: "Security Investigation"

caseTypeId

Parses a case record and returns the raw type ID from the structured type object.

Returns an empty string when the type is absent or not an object.

Input and output

caseTypeId(map) -> string

Examples

caseTypeId(inputs)
caseTypeId(inputs)

Output: "00000006-0000-4000-a000-000000000001"

caseTypeTitle

Parses a case record and returns the type display title from the structured type object.

Returns an empty string when the type is absent or not an object.

Input and output

caseTypeTitle(map) -> string

Examples

caseTypeTitle(inputs)
caseTypeTitle(inputs)

Output: "Investigation"

caseUpdatedAt

Parses a case record and returns the date and time of the last update.

Input and output

caseUpdatedAt(map) -> string

Examples

caseUpdatedAt(inputs)
caseUpdatedAt(inputs)

Output: "2024-06-20T17:57:46.700164Z"

caseUpdatedById

Parses a case record and returns the ID of the user that last updated it.

Input and output

caseUpdatedById(map) -> string

Examples

caseUpdatedById(inputs)
caseUpdatedById(inputs)

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

cel.bind

Creates a local variable binding within an expression to avoid recomputing expensive operations.

Input and output

cel.bind(var_name, value, expression) -> any

Creates a local variable that can be referenced within the expression.

The variable is only available in the scope of the third argument (expression).

This is useful for:

  • Avoiding repeated computation of expensive operations.
  • Making complex expressions more readable.
  • Creating intermediate values for cleaner logic.

The variable name is provided as an identifier (not a string).

The value can be any CEL expression.

The expression is evaluated with the variable in scope.

Use cases

Avoid repeated computation.
cel.bind(name, inputs.user.name.uppercase(), name + ' - ' + string(name.size()))

Avoid repeating expensive operations and improve readability.

Simplify complex conditions.
cel.bind(withTax, inputs.price * 1.2, withTax > 100 ? withTax * 0.9 : withTax)

Calculate an intermediate value and reuse it.

Chain multiple bindings.
cel.bind(x, 5, cel.bind(y, x * 2, cel.bind(z, y + 3, x + y + z)))

Output: 26

Create nested variable bindings.

Work with lists.
cel.bind(nums, [1, 2, 3, 4, 5], cel.bind(doubled, nums.map(n, n * 2), doubled.filter(n, n > 5)))

Output: [6, 8, 10]

Double all values, then filter the result.

Complex object access.
cel.bind(user, inputs.users[0], user.name + ' (' + user.email + ')')

Access an object once and reuse it multiple times.

Examples

cel.bind(x, 10, x * x)
cel.bind(x, 10, x * x)

Output: 100

cel.bind(user, 'John', 'Hello ' + user)
cel.bind(user, 'John', 'Hello ' + user)

Output: "Hello John"

cel.bind(list, [1,2,3], list.size() + list[0])
cel.bind(list, [1,2,3], list.size() + list[0])

Output: 4

charAt

Returns the character at the specified index in the string.

Input and output

string.charAt(int) -> string

Returns the character (as a single-character string) at the specified zero-based index.

Returns an empty string if the index is out of bounds.

Examples

'hello'.charAt(0)
'hello'.charAt(0)

Output: "h"

'hello'.charAt(4)
'hello'.charAt(4)

Output: "o"

collect

Returns a list of map values that match the provided path argument.

Input and output

collect(list, string) -> list

Examples

[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')

Output: ["value1", "value3"]

contains

Returns true if any element in the string or list matches the provided string or list (case-sensitive).

An optional second argument of true causes the match to ignore case.

Input and output

contains(string, string) -> bool
contains(string, string, bool) -> bool
contains(string, list) -> bool
contains(string, list, bool) -> bool
contains(list, string) -> bool
contains(list, string, bool) -> bool
contains(list, list) -> bool
contains(list, list, bool) -> bool

Examples

"apple".contains("app")
"apple".contains("app")

Output: true

"apple".contains("APP", true)
"apple".contains("APP", true)

Output: true

"apple".contains(["app"])
"apple".contains(["app"])

Output: true

"apple".contains(["APP"], true)
"apple".contains(["APP"], true)

Output: true

["apple", "banana"].contains("app")
["apple", "banana"].contains("app")

Output: true

["apple", "banana"].contains("APP", true)
["apple", "banana"].contains("APP", true)

Output: true

["apple", "banana"].contains(["app"])
["apple", "banana"].contains(["app"])

Output: true

["apple", "banana"].contains(["APP"], true)
["apple", "banana"].contains(["APP"], true)

Output: true

count

Returns a count of the list elements that match the provided string argument, or the keys in a map that match it.

Input and output

count(list, string) -> int

Examples

count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")

Output: 2

Returns a Taegis Sharelink for an alert, investigation, or asset.

Input and output

createShareLink(map) -> string

Examples

createShareLink(inputs)
createShareLink(inputs)

Output: "https://ctpx.secureworks.com/share/14f-ca9d-ad47-34db-2243b945ce2112f"

decodeBase64

Returns a decoded base64 input string.

Input and output

decodeBase64(string) -> string

Examples

decodeBase64("aGVsbG8gd29ybGQ=")
decodeBase64("aGVsbG8gd29ybGQ=")

Output: "hello world"

decodeJSON

Returns a JSON object after decoding the input string.

Input and output

decodeJSON(string) -> any

Examples

decodeJSON('{"key": "value"}')
decodeJSON('{"key": "value"}')

Output: {"key":"value"}

decodeYAML

Decodes YAML input to any data type.

Input and output

decodeYAML(string) -> any

Examples

decodeYAML("key: value")
decodeYAML("key: value")

Output: {"key":"value"}

detectionAttackTechniqueIds

Parses a detection record and returns the attack technique IDs value.

Input and output

detectionAttackTechniqueIds(map) -> list

Examples

detectionAttackTechniqueIds(inputs)
detectionAttackTechniqueIds(inputs)

Output: ["T1096", "T1214"]

detectionConfidence

Parses a detection record and returns the confidence value.

Input and output

detectionConfidence(map) -> double

Examples

detectionConfidence(inputs)
detectionConfidence(inputs)

Output: 0.5

detectionCreatedAtNanos

Parses a detection record and returns the nanoseconds value of the time the detection was created.

Input and output

detectionCreatedAtNanos(map) -> int

Examples

detectionCreatedAtNanos(inputs)
detectionCreatedAtNanos(inputs)

Output: 796357058

detectionCreatedAtSeconds

Parses a detection record and returns the created_at value as a measure of seconds from epoch.

Input and output

detectionCreatedAtSeconds(map) -> int

Examples

detectionCreatedAtSeconds(inputs)
detectionCreatedAtSeconds(inputs)

Output: 1636029855

detectionDescription

Parses a detection record and returns the description value.

Input and output

detectionDescription(map) -> string

Examples

detectionDescription(inputs)
detectionDescription(inputs)

Output: "This is a sample Taegis Watchlist Detection"

detectionDestinationIPs

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled destinationIPAddress (case insensitive).

Input and output

detectionDestinationIPs(map) -> list

Examples

detectionDestinationIPs(inputs)
detectionDestinationIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionDetectorId

Parses a detection record and returns the detector ID value.

Input and output

detectionDetectorId(map) -> string

Examples

detectionDetectorId(inputs)
detectionDetectorId(inputs)

Output: "app:event-filter"

detectionDetectorName

Parses a detection record and returns the detector name value.

Input and output

detectionDetectorName(map) -> string

Examples

detectionDetectorName(inputs)
detectionDetectorName(inputs)

Output: "Taegis Watchlist"

detectionDomains

Parses a detection record and returns a unique list of domain name values from the detection entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).

Input and output

detectionDomains(map) -> list

Examples

detectionDomains(inputs)
detectionDomains(inputs)

Output: ["example.com", "a.example.com"]

detectionEnrichment

Parses a detection record and the enrichment data and returns the first value matching the path provided.

Input and output

detectionEnrichment(map, string) -> any

Examples

detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')

Output: ["foo.exe", "bar.exe"]

detectionEnrichment(inputs, 'doesnotexist')
detectionEnrichment(inputs, 'doesnotexist')

Output: []

detectionEntities

Parses a detection record and returns the entities value.

Input and output

detectionEntities(map) -> list

Examples

detectionEntities(inputs)
detectionEntities(inputs)

Output: ["hostname:abc", "sensorId:12345", "fileName:c:\\windows\\syswow64\\cmd.exe"]

detectionEntity

Parses a detection record and returns the entity values that match the provided entity name (case insensitive).

Input and output

detectionEntity(map, string) -> list

Examples

detectionEntity(inputs, 'username')
detectionEntity(inputs, 'username')

Output: ["sample_user", "another_sample_user"]

detectionEventIds

Parses a detection record and returns a list of event ID values.

Input and output

detectionEventIds(map) -> list

Examples

detectionEventIds(inputs)
detectionEventIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionGroupKey

Parses a detection record and returns the group_key value.

Input and output

detectionGroupKey(map) -> string

Examples

detectionGroupKey(inputs)
detectionGroupKey(inputs)

Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"

detectionHostnames

Parses a detection record and returns a unique list of values from the detection entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).

Input and output

detectionHostnames(map) -> list

Examples

detectionHostnames(inputs)
detectionHostnames(inputs)

Output: ["sample_hostname", "another_sample_hostname"]

detectionIPs

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled ipAddress (case insensitive).

Input and output

detectionIPs(map) -> list

Examples

detectionIPs(inputs)
detectionIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionId

Parses a detection record and returns the ID or UUID.

Input and output

detectionId(map) -> string

Examples

detectionId(inputs)
detectionId(inputs)

Output: "detection://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"

detectionInvestigationIds

Parses a detection record and returns a list of investigation IDs associated with the detection.

Input and output

detectionInvestigationIds(map) -> list

Examples

detectionInvestigationIds(inputs)
detectionInvestigationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionMitreAttackInfo

Parses a detection record and returns a list of mitre_attack_info values.

Input and output

detectionMitreAttackInfo(map) -> list

Examples

detectionMitreAttackInfo(inputs)
detectionMitreAttackInfo(inputs)

Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]

detectionObservationIds

Parses a detection record and returns a list of observation ID values.

Input and output

detectionObservationIds(map) -> list

Examples

detectionObservationIds(inputs)
detectionObservationIds(inputs)

Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]

detectionReferences

Parses a detection record and returns a list of references associated with the detection.

Input and output

detectionReferences(map) -> list

Examples

detectionReferences(inputs)
detectionReferences(inputs)

Output: [{"description": "External Detection Ref", "url": "https://example.com/detection/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]

detectionResolution

Parses a detection record and returns the resolution value.

Input and output

detectionResolution(map) -> string

Examples

detectionResolution(inputs)
detectionResolution(inputs)

Output: "open"

detectionResolutionReason

Parses a detection record and returns the resolution reason value.

Input and output

detectionResolutionReason(map) -> string

Examples

detectionResolutionReason(inputs)
detectionResolutionReason(inputs)

Output: "Valid activity for this user."

detectionRuleId

Parses a detection record and returns the rule ID.

Input and output

detectionRuleId(map) -> string

Examples

detectionRuleId(inputs)
detectionRuleId(inputs)

Output* "267658fe-65f1-4145-8753-d45fbf9ed6d3"

detectionSensorIds

Parses a detection record and returns a list of sensor ID values.

Input and output

detectionSensorIds(map) -> list

Examples

detectionSensorIds(inputs)
detectionSensorIds(inputs)

Output: ["12345", "1234-12345-123"]

detectionSensorTypes

Parses a detection record and returns a list of unique sensor type values (in uppercase).

Input and output

detectionSensorTypes(map) -> list

Examples

detectionSensorTypes(inputs)
detectionSensorTypes(inputs)

Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]

detectionSeverity

Parses a detection record and returns the severity value.

Input and output

detectionSeverity(map) -> double

Examples

detectionSeverity(inputs)
detectionSeverity(inputs)

Output: 0.75

detectionSeverityNice

Parses a detection record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).

Input and output

detectionSeverityNice(map) -> string

Examples

detectionSeverityNice(inputs)
detectionSeverityNice(inputs)

Output: "High"

detectionSourceEntities

Returns the list of source entities from a detection's source_entities field.

Input and output

detectionSourceEntities(map) -> list

Examples

detectionSourceEntities(inputs)
detectionSourceEntities(inputs)

Output: [{"id": "...", "display_name": "...", "perspective": "SOURCE", ...}]

detectionSourceEntityProperties

Filters source_entities by property_type and returns values for the specified property keys.

Input and output

detectionSourceEntityProperties(map, string, list) -> list

Examples

detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])

Output: ["jdoe", "jdoe"]

detectionSourceIPs

Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled sourceIPAddress (case insensitive).

Input and output

detectionSourceIPs(map) -> list

Examples

detectionSourceIPs(inputs)
detectionSourceIPs(inputs)

Output: ["192.168.0.1", "192.168.0.2"]

detectionStatus

Parses a detection record and returns the status value.

Input and output

detectionStatus(map) -> string

Examples

detectionStatus(inputs)
detectionStatus(inputs)

Output: "open"

detectionTags

Parses a detection record and returns a list of tags.

Input and output

detectionTags(map) -> list

Examples

detectionTags(inputs)
detectionTags(inputs)

Output: ["detectionRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]

detectionTargetEntities

Returns the list of target entities from a detection's target_entities field.

Input and output

detectionTargetEntities(map) -> list

Examples

detectionTargetEntities(inputs)
detectionTargetEntities(inputs)

Output: [{"id": "...", "display_name": "...", "perspective": "TARGET", ...}]

detectionTargetEntityProperties

Filters target_entities by property_type and returns values for the specified property keys.

Input and output

detectionTargetEntityProperties(map, string, list) -> list

Examples

detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])

Output: ["abc123def456"]

detectionTenantId

Parses a detection record and returns the tenant ID.

Input and output

detectionTenantId(map) -> string

Examples

detectionTenantId(inputs)
detectionTenantId(inputs)

Output: "12345"

detectionThirdPartyDetail

Parses a detection record and the third-party detail data and returns the first value matching the path provided.

Input and output

detectionThirdPartyDetail(map, string) -> list

Examples

detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')

Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]

detectionTitle

Parses a detection record and returns the title value.

Input and output

detectionTitle(map) -> string

Examples

detectionTitle(inputs)
detectionTitle(inputs)

Output: "Taegis Watchlist Detection"

detectionUpdatedAtNanos

Parses a detection record and returns the nanoseconds value of the time the detection was modified.

Input and output

detectionUpdatedAtNanos(map) -> int

Examples

detectionUpdatedAtNanos(inputs)
detectionUpdatedAtNanos(inputs)

Output: 796357058

detectionUpdatedAtSeconds

Parses a detection record and returns the updated_at value as a measure of seconds from epoch.

Input and output

detectionUpdatedAtSeconds(map) -> int

Examples

detectionUpdatedAtSeconds(inputs)
detectionUpdatedAtSeconds(inputs)

Output: 1697207995554

detectionUsernames

Parses a detection record and returns a unique list of lowercase username values from the detection entities field where the entity is labeled username (case insensitive).

Input and output

detectionUsernames(map) -> list

Examples

detectionUsernames(inputs)
detectionUsernames(inputs)

Output: ["sample_user", "another_sample_user"]

distinct

Removes duplicate elements from a list, preserving the first occurrence of each element.

Input and output

list.distinct() -> list

Returns a new list containing only unique elements from the original list.

The first occurrence of each element is preserved in the order encountered.

Duplicates are removed.

Use cases

Remove duplicates from user input.
user_tags.distinct()

Clean up duplicate tags.

Get unique values.
results.map(r, r.category).distinct()

Get all unique categories from the results.

Deduplicate IDs.
id_list.distinct()

Ensure that there are no duplicate IDs.

Clean data.
inputs.values.distinct()

Remove duplicates.

Use set-like operations.
list1.distinct().size() == list1.size()

Check whether a list has no duplicates.

Combine with a filter.
items.filter(i, i.active).map(i, i.id).distinct()

Get the unique IDs of active items.

Preserve order.
[3, 1, 2, 1, 3].distinct()

Output: [3, 1, 2]

Preserve the order of the first occurrence of each element.

Notes

  • Preserves the order of the first occurrence.
  • Works with any comparable type.
  • Empty lists remain empty.
  • Doesn't sort the output.

Examples

[1, 2, 2, 3, 3, 3].distinct()
[1, 2, 2, 3, 3, 3].distinct()

Output: [1, 2, 3]

Remove duplicate numbers.

['b', 'b', 'c', 'a', 'c'].distinct()
['b', 'b', 'c', 'a', 'c'].distinct()

Output: ['b', 'c', 'a']

Remove duplicate strings and preserve their order.

[1, 2, 3].distinct()
[1, 2, 3].distinct()

Output: [1, 2, 3]

The list is already unique.

[1, 1, 1].distinct()
[1, 1, 1].distinct()

Output: [1]

Remove all duplicate elements.

[].distinct()
[].distinct()

Output: []

An empty list remains empty.

domains

Returns true if the provided username argument is in one or more of the provided domains.

Input and output

domains(map) -> list

Examples

domains(inputs)
domains(inputs)

Output: ["example.com","foo.com"]

encodeBase64

Returns an encoded string input as a base64 string.

Input and output

encodeBase64(string) -> string

Examples

encodeBase64("hello world")
encodeBase64("hello world")

Output: "aGVsbG8gd29ybGQ="

encodeJSON

Returns an encoded string input as a JSON string.

Input and output

encodeJSON(string) -> string

Examples

encodeJSON({"key":"value"})
encodeJSON({"key":"value"})

Output: "{\"key\":\"value\"}"

encodeYAML

Encodes any value as a YAML string.

Input and output

encodeYAML(string) -> string

Examples

encodeYAML({"key":"value"})
encodeYAML({"key":"value"})

Output: "key: value\n"

entityValue

Parses an entity record and returns a list of values for the provided entity property.

Input and output

entityValue(map, string) -> list

Examples

entityValue(inputs, "username")
entityValue(inputs, "username")

Output: ["john"]

entityValue(inputs, "nonexistent")
entityValue(inputs, "nonexistent")

Output: []

entityValues

Parses an entity record and returns a list of values associated with the entity.

Input and output

entityValues(map) -> list

Examples

entityValues(inputs)
entityValues(inputs)

Output: ["example.com", "john@example.com", "john"]

exists

Iterates on a list or map and validates that a condition is true for at least one of the elements.

Input and output

exists(list, predicate) -> bool
exists(map, predicate) -> bool

Examples

[1, 2, 3].exists(i, i % 2 != 0)
[1, 2, 3].exists(i, i % 2 != 0)

Output: true

{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))

Output: false

exists_one

Iterates on a list or map and validates that a condition is true for exactly one of the elements.

Input and output

exists_one(list, predicate) -> bool
exists_one(map, predicate) -> bool

Examples

[1, 2, 2].exists_one(i, i < 2)
[1, 2, 2].exists_one(i, i < 2)

Output: true

{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))

Output: false

filehashes

Returns a list of file hashes from an alert or entity if found.

Input and output

filehashes(map) -> list

Examples

filehashes(inputs)
filehashes(inputs)

Output: ["445362b51bf855f62f9af7bb8362c8b27c7bc1ceb1dc88fd41a72de19b779969", "2e5a8590cf6848968fc23de3fa1e25f1", "9785001b0dcf755eddb8af294a373c0b87b2498660f724e76c4d53f9c217c7a3"]

filter

Iterates on a list and returns the elements that match the provided criteria.

Input and output

filter(list, predicate) -> list

Examples

["a", "ab", "c"].filter(x, x.contains("a"))
["a", "ab", "c"].filter(x, x.contains("a"))

Output: ["a", "ab"]

["a", "ab", "c"].filter(x, x.contains("d"))
["a", "ab", "c"].filter(x, x.contains("d"))

Output: []

findingCheck

Parses an identity finding record and returns the check map, or returns a specific entry when a second argument is provided.

Input and output

findingCheck(map) -> map
findingCheck(map, string) -> any

Examples

findingCheck(inputs)
findingCheck(inputs)

Output: {'autoResolutionDisabled':false,'category':'CONFIGURATION', ... }

findingCheck(inputs, "module")
findingCheck(inputs, "module")

Output: "IDENTITY"

findingCheck(inputs, "id")
findingCheck(inputs, "id")

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingCheck(inputs, "title")
findingCheck(inputs, "title")

Output: "Application shall not have unclaimed DNS names that are susceptible to takeover"

findingCheck(inputs, "description")
findingCheck(inputs, "description")

Output: "Threat actors can exploit vulnerabilities in Microsoft Entra ID applications by registering unclaimed subdomains, also known as dangling Fully Qualified Domain Names (FQDNs)."

findingCheck(inputs, "enabled")
findingCheck(inputs, "enabled")

Output: true

findingClosedAt

Parses an identity finding record and returns the closed-at timestamp.

Input and output

findingClosedAt(map) -> string

Examples

findingClosedAt(inputs)
findingClosedAt(inputs)

Output: "2025-04-28T16:57:49.591956Z"

findingConfidenceScore

Parses an identity finding record and returns the confidence score.

Input and output

findingConfidenceScore(map) -> double

Examples

findingConfidenceScore(inputs)
findingConfidenceScore(inputs)

Output: "1.0"

findingFieldChanged

Parses a finding record and returns true if the provided field was modified.

Input and output

findingFieldChanged(map, string) -> bool

Examples

findingFieldChanged(inputs, 'status')
findingFieldChanged(inputs, 'status')

Output: true

findingFieldChanged(inputs, 'nonexistent_field')
findingFieldChanged(inputs, 'nonexistent_field')

Output: false

findingFirstSeen

Parses an identity finding record and returns the first-seen timestamp.

Input and output

findingFirstSeen(map) -> string

Examples

findingFirstSeen(inputs)
findingFirstSeen(inputs)

Output: "2025-03-12T16:57:49.591956Z"

findingId

Parses an identity finding record and returns the ID.

Input and output

findingId(map) -> string

Examples

findingId(inputs)
findingId(inputs)

Output: "f1234567-89ab-cdef-0123-456789abcdef"

findingIdentityCity

Parses an identity finding record and returns the city from the identity data.

Input and output

findingIdentityCity(map) -> string

Examples

findingIdentityCity(inputs)
findingIdentityCity(inputs)

Output: "New York"

findingIdentityCompanyName

Parses an identity finding record and returns the company name from the identity data.

Input and output

findingIdentityCompanyName(map) -> string

Examples

findingIdentityCompanyName(inputs)
findingIdentityCompanyName(inputs)

Output: "Example Corp"

findingIdentityCountry

Parses an identity finding record and returns the country from the identity data.

Input and output

findingIdentityCountry(map) -> string

Examples

findingIdentityCountry(inputs)
findingIdentityCountry(inputs)

Output: "United States"

findingIdentityCreatedAt

Parses an identity finding record and returns the creation timestamp from the identity data.

Input and output

findingIdentityCreatedAt(map) -> string

Examples

findingIdentityCreatedAt(inputs)
findingIdentityCreatedAt(inputs)

Output: "2024-01-15T10:30:00Z"

findingIdentityDepartment

Parses an identity finding record and returns the department from the identity data.

Input and output

findingIdentityDepartment(map) -> string

Examples

findingIdentityDepartment(inputs)
findingIdentityDepartment(inputs)

Output: "Engineering"

findingIdentityDisplayName

Parses an identity finding record and returns the display name from the identity data.

Input and output

findingIdentityDisplayName(map) -> string

Examples

findingIdentityDisplayName(inputs)
findingIdentityDisplayName(inputs)

Output: "John Doe"

findingIdentityEmails

Parses an identity finding record and returns the email addresses from the identity data.

Input and output

findingIdentityEmails(map) -> list

Examples

findingIdentityEmails(inputs)
findingIdentityEmails(inputs)

Output: ["john.doe@example.com", "j.doe@example.com"]

findingIdentityEmployeeId

Parses an identity finding record and returns the employee ID from the identity data.

Input and output

findingIdentityEmployeeId(map) -> string

Examples

findingIdentityEmployeeId(inputs)
findingIdentityEmployeeId(inputs)

Output: "EMP12345"

findingIdentityEmployeeType

Parses an identity finding record and returns the employee type from the identity data.

Input and output

findingIdentityEmployeeType(map) -> string

Examples

findingIdentityEmployeeType(inputs)
findingIdentityEmployeeType(inputs)

Output: "Full-time"

findingIdentityExternalCreatedAt

Parses an identity finding record and returns the external creation timestamp from the identity data.

Input and output

findingIdentityExternalCreatedAt(map) -> string

Examples

findingIdentityExternalCreatedAt(inputs)
findingIdentityExternalCreatedAt(inputs)

Output: "2024-01-15T10:30:00Z"

findingIdentityExternalId

Parses an identity finding record and returns the external ID from the identity data.

Input and output

findingIdentityExternalId(map) -> string

Examples

findingIdentityExternalId(inputs)
findingIdentityExternalId(inputs)

Output: "ext-12345-abcd"

findingIdentityExternalUpdatedAt

Parses an identity finding record and returns the external update timestamp from the identity data.

Input and output

findingIdentityExternalUpdatedAt(map) -> string

Examples

findingIdentityExternalUpdatedAt(inputs)
findingIdentityExternalUpdatedAt(inputs)

Output: "2024-01-20T15:45:00Z"

findingIdentityField

Parses a finding and returns the value of the specified identity field.

Input and output

findingIdentityField(map, string) -> bool

Examples

findingIdentityField(inputs, 'status')
findingIdentityField(inputs, 'status')

Output: "ACTIVE"

findingIdentityField(inputs, 'nonexistent_field')
findingIdentityField(inputs, 'nonexistent_field')

Output:

findingIdentityGivenName

Parses an identity finding record and returns the given name from the identity data.

Input and output

findingIdentityGivenName(map) -> string

Examples

findingIdentityGivenName(inputs)
findingIdentityGivenName(inputs)

Output: "John"

findingIdentityHasMfa

Parses an identity finding record and returns whether MFA is enabled from the identity data.

Input and output

findingIdentityHasMfa(map) -> bool

Examples

findingIdentityHasMfa(inputs)
findingIdentityHasMfa(inputs)

Output: true

findingIdentityHasPasswordlessMfa

Parses an identity finding record and returns whether passwordless MFA is enabled from the identity data.

Input and output

findingIdentityHasPasswordlessMfa(map) -> bool

Examples

findingIdentityHasPasswordlessMfa(inputs)
findingIdentityHasPasswordlessMfa(inputs)

Output: false

findingIdentityHireDate

Parses an identity finding record and returns the hire date from the identity data.

Input and output

findingIdentityHireDate(map) -> string

Examples

findingIdentityHireDate(inputs)
findingIdentityHireDate(inputs)

Output: "2023-06-01"

findingIdentityIsAdmin

Parses an identity finding record and returns whether the identity has admin privileges.

Input and output

findingIdentityIsAdmin(map) -> bool

Examples

findingIdentityIsAdmin(inputs)
findingIdentityIsAdmin(inputs)

Output: false

findingIdentityIsGuest

Parses an identity finding record and returns whether the identity is a guest user.

Input and output

findingIdentityIsGuest(map) -> bool

Examples

findingIdentityIsGuest(inputs)
findingIdentityIsGuest(inputs)

Output: false

findingIdentityLastActiveAt

Parses an identity finding record and returns the last active timestamp from the identity data.

Input and output

findingIdentityLastActiveAt(map) -> string

Examples

findingIdentityLastActiveAt(inputs)
findingIdentityLastActiveAt(inputs)

Output: "2024-09-01T14:30:00Z"

findingIdentityLastPasswordChangeAt

Parses an identity finding record and returns the last password change timestamp from the identity data.

Input and output

findingIdentityLastPasswordChangeAt(map) -> string

Examples

findingIdentityLastPasswordChangeAt(inputs)
findingIdentityLastPasswordChangeAt(inputs)

Output: "2024-08-15T09:00:00Z"

findingIdentityLeaveDate

Parses an identity finding record and returns the leave date from the identity data.

Input and output

findingIdentityLeaveDate(map) -> string

Examples

findingIdentityLeaveDate(inputs)
findingIdentityLeaveDate(inputs)

Output: "2025-01-31"

findingIdentityLocation

Parses an identity finding record and returns the location from the identity data.

Input and output

findingIdentityLocation(map) -> string

Examples

findingIdentityLocation(inputs)
findingIdentityLocation(inputs)

Output: "New York Office"

findingIdentityManager

Parses an identity finding record and returns the manager from the identity data.

Input and output

findingIdentityManager(map) -> string

Examples

findingIdentityManager(inputs)
findingIdentityManager(inputs)

Output: "Jane Smith"

findingIdentityMfaMethods

Parses an identity finding record and returns the MFA methods from the identity data.

Input and output

findingIdentityMfaMethods(map) -> list

Examples

findingIdentityMfaMethods(inputs)
findingIdentityMfaMethods(inputs)

Output: ["SMS", "Authenticator App"]

findingIdentityOfficeLocation

Parses an identity finding record and returns the office location from the identity data.

Input and output

findingIdentityOfficeLocation(map) -> string

Examples

findingIdentityOfficeLocation(inputs)
findingIdentityOfficeLocation(inputs)

Output: "Building A, Floor 5"

findingIdentityOfficeZipCode

Parses an identity finding record and returns the office zip code from the identity data.

Input and output

findingIdentityOfficeZipCode(map) -> string

Examples

findingIdentityOfficeZipCode(inputs)
findingIdentityOfficeZipCode(inputs)

Output: "10001"

findingIdentityPhoneNumbers

Parses an identity finding record and returns the phone numbers from the identity data.

Input and output

findingIdentityPhoneNumbers(map) -> list

Examples

findingIdentityPhoneNumbers(inputs)
findingIdentityPhoneNumbers(inputs)

Output: ["+1-555-0123", "+1-555-0124"]

findingIdentityPrimaryDomain

Parses an identity finding record and returns the primary domain from the identity data.

Input and output

findingIdentityPrimaryDomain(map) -> string

Examples

findingIdentityPrimaryDomain(inputs)
findingIdentityPrimaryDomain(inputs)

Output: "example.com"

findingIdentityPrimaryEntityId

Parses an identity finding record and returns the primary entity ID from the identity data.

Input and output

findingIdentityPrimaryEntityId(map) -> string

Examples

findingIdentityPrimaryEntityId(inputs)
findingIdentityPrimaryEntityId(inputs)

Output: "entity-12345-abcd"

findingIdentityPrimaryMfaMethod

Parses an identity finding record and returns the primary MFA method from the identity data.

Input and output

findingIdentityPrimaryMfaMethod(map) -> string

Examples

findingIdentityPrimaryMfaMethod(inputs)
findingIdentityPrimaryMfaMethod(inputs)

Output: "Authenticator App"

findingIdentityPrimaryUsername

Parses an identity finding record and returns the primary username from the identity data.

Input and output

findingIdentityPrimaryUsername(map) -> string

Examples

findingIdentityPrimaryUsername(inputs)
findingIdentityPrimaryUsername(inputs)

Output: "john.doe"

findingIdentityProperties

Parses an identity finding record and returns the properties map from the identity data.

Input and output

findingIdentityProperties(map) -> map

Examples

findingIdentityProperties(inputs)
findingIdentityProperties(inputs)

Output: {"customAttribute1": "value1", "customAttribute2": "value2"}

findingIdentityProviderId

Parses an identity finding record and returns the provider ID from the identity data.

Input and output

findingIdentityProviderId(map) -> string

Examples

findingIdentityProviderId(inputs)
findingIdentityProviderId(inputs)

Output: "provider-azure-ad-12345"

findingIdentityRaw

Parses an identity finding record and returns the raw identity data.

Input and output

findingIdentityRaw(map) -> map

Examples

findingIdentityRaw(inputs)
findingIdentityRaw(inputs)

Output: {"id": "user-123", "displayName": "John Doe", "mail": "john.doe@example.com"}

findingIdentityRegion

Parses an identity finding record and returns the region from the identity data.

Input and output

findingIdentityRegion(map) -> string

Examples

findingIdentityRegion(inputs)
findingIdentityRegion(inputs)

Output: "North America"

findingIdentityStatus

Parses an identity finding record and returns the status from the identity data.

Input and output

findingIdentityStatus(map) -> string

Examples

findingIdentityStatus(inputs)
findingIdentityStatus(inputs)

Output: "ACTIVE"

findingIdentitySurname

Parses an identity finding record and returns the surname from the identity data.

Input and output

findingIdentitySurname(map) -> string

Examples

findingIdentitySurname(inputs)
findingIdentitySurname(inputs)

Output: "Doe"

findingIdentityTenant

Parses an identity finding record and returns the tenant from the identity data.

Input and output

findingIdentityTenant(map) -> int

Examples

findingIdentityTenant(inputs)
findingIdentityTenant(inputs)

Output: 12345

findingIdentityTitle

Parses an identity finding record and returns the job title from the identity data.

Input and output

findingIdentityTitle(map) -> string

Examples

findingIdentityTitle(inputs)
findingIdentityTitle(inputs)

Output: "Software Engineer"

findingIdentityUpdatedAt

Parses an identity finding record and returns the update timestamp from the identity data.

Input and output

findingIdentityUpdatedAt(map) -> string

Examples

findingIdentityUpdatedAt(inputs)
findingIdentityUpdatedAt(inputs)

Output: "2024-09-01T12:00:00Z"

findingIdentityUsageLocation

Parses an identity finding record and returns the usage location from the identity data.

Input and output

findingIdentityUsageLocation(map) -> string

Examples

findingIdentityUsageLocation(inputs)
findingIdentityUsageLocation(inputs)

Output: "US"

findingIdentityUsernames

Parses an identity finding record and returns the usernames from the identity data.

Input and output

findingIdentityUsernames(map) -> list

Examples

findingIdentityUsernames(inputs)
findingIdentityUsernames(inputs)

Output: ["john.doe", "jdoe", "john.doe@example.com"]

findingIdentityZipCode

Parses an identity finding record and returns the zip code from the identity data.

Input and output

findingIdentityZipCode(map) -> string

Examples

findingIdentityZipCode(inputs)
findingIdentityZipCode(inputs)

Output: "10001"

findingLastModified

Parses an identity finding record and returns the last modified timestamp.

Input and output

findingLastModified(map) -> string

Examples

findingLastModified(inputs)
findingLastModified(inputs)

Output: "2025-04-28T16:57:49.591956Z"

findingLastSeen

Parses an identity finding record and returns the last seen timestamp.

Input and output

findingLastSeen(map) -> string

Examples

findingLastSeen(inputs)
findingLastSeen(inputs)

Output: "2025-04-22T16:57:49.591956Z"

findingOtherReferences

Parses an identity finding record and returns the other references list. An optional second argument returns a list of specific entries.

Input and output

findingOtherReferences(map) -> list
findingOtherReferences(map, string) -> list

Examples

findingOtherReferences(inputs)
findingOtherReferences(inputs)

Output: [{"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}]

findingOtherReferences(inputs, 'type')
findingOtherReferences(inputs, 'type')

Output: ["microsoft.graph.application"]

findingOtherReferences(inputs, 'id')
findingOtherReferences(inputs, 'id')

Output: ["7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingOtherReferences(inputs, 'logicalType')
findingOtherReferences(inputs, 'logicalType')

Output: ["UNKNOWN"]

findingOtherReferences(inputs, 'derivedType')
findingOtherReferences(inputs, 'derivedType')

Output: ["APP"]

findingOtherReferences(inputs, 'displayName')
findingOtherReferences(inputs, 'displayName')

Output: ["soanceawebapp"]

findingOtherReferences(inputs, 'externalLink')
findingOtherReferences(inputs, 'externalLink')

Output: ["https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]

findingPrimaryReference

Parses an identity finding record and returns the primary reference map. An optional second argument returns a specific entry.

Input and output

findingPrimaryReference(map) -> map
findingPrimaryReference(map, string) -> string

Examples

findingPrimaryReference(inputs)
findingPrimaryReference(inputs)

Output: {"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/%23view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}

findingPrimaryReference(inputs, 'type')
findingPrimaryReference(inputs, 'type')

Output: "microsoft.graph.servicePrincipal"

findingPrimaryReference(inputs, 'id')
findingPrimaryReference(inputs, 'id')

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingPrimaryReference(inputs, 'logicalType')
findingPrimaryReference(inputs, 'logicalType')

Output: "IDENTITY_SERVICE_PRINCIPAL"

findingPrimaryReference(inputs, 'derivedType')
findingPrimaryReference(inputs, 'derivedType')

Output: "APP"

findingPrimaryReference(inputs, 'displayName')
findingPrimaryReference(inputs, 'displayName')

Output: "soanceawebapp"

findingPrimaryReference(inputs, 'externalLink')
findingPrimaryReference(inputs, 'externalLink')

Output: "https://portal.azure.com/%23view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/e98c0bf1-f226-4465-940f-696a79e7bdc6/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"

findingResult

Parses an identity finding record and returns the result.

Input and output

findingResult(map) -> string

Examples

findingResult(inputs)
findingResult(inputs)

Output: "{\"replyUrls\":[\"https://soanceawebapp.azurewebsites.net/.auth/login/aad/callback\"]}"

findingSeverity

Parses an identity finding record and returns the severity label (INFO, LOW, MEDIUM, HIGH, CRITICAL).

An optional second argument of true returns the severity as a double (0.0-1.0).

Input and output

findingSeverity(map) -> string
findingSeverity(map, bool) -> double

Examples

findingSeverity(inputs)
findingSeverity(inputs)

Output: "CRITICAL"

findingSeverity(inputs, true)
findingSeverity(inputs, true)

Output: "0.800000011920929"

findingSource

Parses an identity finding record and returns the source map. An optional second argument returns a specific entry.

Input and output

findingSource(map) -> map
findingSource(map, string) -> any

Examples

findingSource(inputs)
findingSource(inputs)

Output: {'id':'63258f26-1d39-4d69-9e85-e409244d9c97','resolved':{...},'type':'IDENTITY_PROVIDER'}

findingSource(inputs, 'type')
findingSource(inputs, 'type')

Output: "IDENTITY_PROVIDER"

findingSource(inputs, 'id')
findingSource(inputs, 'id')

Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"

findingSource(inputs, 'resolved')
findingSource(inputs, 'resolved')

Output: {'createdAt':'2025-02-03T08:32:21.80852Z','disabledAt':null,'expiration':'2026-06-06T05:00:03Z',...}

findingStatus

Parses an identity finding record and returns the status.

Input and output

findingStatus(map) -> string

Examples

findingStatus(inputs)
findingStatus(inputs)

Output: "OPEN"

findingStatusComments

Parses an identity finding record and returns the status comments.

Input and output

findingStatusComments(map) -> string

Examples

findingStatusComments(inputs)
findingStatusComments(inputs)

Output: "issue resolved"

findingTenantId

Parses an identity finding record and returns the tenant ID.

Input and output

findingTenantId(map) -> string

Examples

findingTenantId(inputs)
findingTenantId(inputs)

Output: "12345"

findingsStatusCommentsUserId

Parses an identity finding record and returns the user ID that added the status comments.

Input and output

findingsStatusCommentsUserId(map) -> string

Examples

findingsStatusCommentsUserId(inputs)
findingsStatusCommentsUserId(inputs)

Output: "3f59db3b-6b9c-4fb8-a26d-4c53fb334b4e"

first (optional element)

Returns an optional containing the first element of a list, or optional.none() if the list is empty.

Input and output

list.first() -> optional(T)

Returns an optional containing the first element of a list. If the list is empty, returns optional.none().

Use cases

Safe head access.
[1, 2, 3].first().orValue(0)

Get the first element or return a default value.

Check if empty.
items.first().hasValue()

Check whether the list has elements.

Process the first item.
tasks.first().optMap(t, t.priority)

Get the priority of the first task.

Conditional access.
results.first().orValue('No results')

Safely access the first result or return a message.

Chained processing.
data.filter(x, x > 0).first().orValue(-1)

Filter the data, then get the first result.

Validation.
!items.first().hasValue() ? 'Empty list' : 'Has items'

Check whether the list is empty.

Notes

  • Returns optional(T), where T is the element type.
  • Safely returns optional.none() for empty lists.
  • Is more expressive than list[?0].
  • Use .orValue() to provide a default.
  • Doesn't modify the original list.

Examples

[1, 2, 3].first().orValue(0)
[1, 2, 3].first().orValue(0)

Output: 1

Get the first element.

[].first().hasValue()
[].first().hasValue()

Output: false

Check an empty list.

[].first().orValue(99)
[].first().orValue(99)

Output: 99

Use the default value for an empty list.

['a', 'b', 'c'].first().value()
['a', 'b', 'c'].first().value()

Output: 'a'

Extract the first string.

first (list elements)

Returns the first N elements of a list.

Input and output

first(list, int) -> list

Examples

first(["a", "c", "b"], 1)
first(["a", "c", "b"], 1)

Output: ["a"]

flatten

Returns a list where all nested lists are combined into a single top-level list.

Input and output

flatten(list) -> list

Examples

flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])

Output: ["row1col1", "row1col2", "row2col1", "row2col2"]

format (string)

Formats the string using printf-style formatting with the provided arguments.

Input and output

string.format(list) -> string

Formats the string using printf-style format specifiers with values from the list.

Common format specifiers:

  • %s: String.
  • %d: Integer.
  • %f: Floating-point number.
  • %%: Literal percent sign.

Examples

'Hello %s'.format(['World'])
'Hello %s'.format(['World'])

Output: "Hello World"

'Value: %d, Name: %s'.format([42, 'test'])
'Value: %d, Name: %s'.format([42, 'test'])

Output: "Value: 42, Name: test"

'Pi: %.2f'.format([3.14159])
'Pi: %.2f'.format([3.14159])

Output: "Pi: 3.14"

format (timestamp)

Returns the string representation of the timestamp using the provided format. See Constants for a list of supported formats.

Input and output

format(timestamp, string) -> string

Examples

"1/1/2012".toTimestamp().format("layout")
"1/1/2012".toTimestamp().format("layout")

Output: 2012-01-01T00:00:00Z

"1/1/2012".toTimestamp().format("dateonly")
"1/1/2012".toTimestamp().format("dateonly")

Output: 2012-01-01

"1/1/2012".toTimestamp().format("Mon")
"1/1/2012".toTimestamp().format("Mon")

Output: Sun

generateString

Returns a randomly generated string with the length specified in the first argument and the characters or alphabet provided in the second argument.

Input and output

generateString(int, string) -> string

Examples

generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")

Output: aPsd2

groupBy

Returns a list of map elements grouped by one or more paths and a corresponding count of each grouping.

The first argument is the list to group. The second argument is a list of paths to group by. The optional third argument sorts the list in ascending (asc) or descending (desc) order. The default is ascending.

Input and output

groupBy(list, list, string) -> list

Examples

groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")

Output: [{"amap.host": "test1", "amap.title": "test", "count": 1}, {"amap.host": "test", "amap.title": "test", "count": 2}]

has

Validates that a key exists, is defined, and has a non-null value.

This macro also supports checking a map for one or more paths. An optional third argument specifies the separator used in the paths.

Input and output

has(map, string) -> bool

Examples

has(inputs, "key")
has(inputs, "key")

Output: true

hasValue

Returns true if the optional contains a value. Otherwise, returns false.

Input and output

optional(T).hasValue() -> bool

Checks whether an optional contains a value.

Use cases

Check before access.
obj.?field.hasValue() ? obj.field : 'default'

Safely check for a value before accessing it.

Validate input.
input.?userId.hasValue()

Check whether the field exists.

Use guard clauses.
!optional.none().hasValue()

Output: true

Verify that an optional is empty.

Optional chaining.
data[?'key'].hasValue() && data['key'] > 10

Check that a value exists before comparing it.

Filter present values.
items.filter(i, i.?metadata.hasValue())

Keep only items that have metadata.

Notes

  • Returns a Boolean value (true or false).
  • Is safe to call on any optional.
  • Use before calling .value() to avoid errors.
  • Is commonly used with conditional expressions.
  • Provides an alternative to checking for errors.

Examples

optional.of(42).hasValue()
optional.of(42).hasValue()

Output: true

The optional has a value.

optional.none().hasValue()
optional.none().hasValue()

Output: false

The optional has no value.

{'a': 1}[?'a'].hasValue()
{'a': 1}[?'a'].hasValue()

Output: true

The key exists.

{'a': 1}[?'b'].hasValue()
{'a': 1}[?'b'].hasValue()

Output: false

The key is missing.

[1, 2, 3][?0].hasValue()
[1, 2, 3][?0].hasValue()

Output: true

The index exists.

[1, 2, 3][?10].hasValue()
[1, 2, 3][?10].hasValue()

Output: false

The index is out of bounds.

hostnames

Parses an alert, entity, or asset and returns the hostnames found.

Input and output

hostnames(map) -> list

Examples

hostnames(inputs)
hostnames(inputs)

Output: ["alert_hostname", "entity_hostname", "asset_hostname"]

indexOf

Returns the index of the first occurrence of a substring.

Input and output

string.indexOf(string) -> int
string.indexOf(string, int) -> int

Returns the zero-based index of the first occurrence of the substring.

Returns -1 if the substring isn't found.

The optional second argument specifies the starting position for the search.

Examples

'hello world'.indexOf('world')
'hello world'.indexOf('world')

Output: 6

'hello world'.indexOf('o')
'hello world'.indexOf('o')

Output: 4

'hello world'.indexOf('o', 5)
'hello world'.indexOf('o', 5)

Output: 7

'hello world'.indexOf('xyz')
'hello world'.indexOf('xyz')

Output: -1

ipInNetwork

Returns true if the first argument IP address is in one or more of the second argument IP network ranges.

The second argument is represented as a list of networks in CIDR notation.

Input and output

ipInNetwork(string, list) -> bool

Examples

ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])

Output: true

ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])

Output: false

ipsv4

Parses an alert or entity and returns a list of IPv4 addresses if found.

Input and output

ipsv4(map) -> list

Examples

ipsv4(inputs)
ipsv4(inputs)

Output: ["127.0.0.111", "4.3.2.1", "1.2.3.4", "9.8.7.6", "6.7.8.9"]

isCaseClosed

Parses a case record and returns whether the case is closed.

Input and output

isCaseClosed(map) -> bool

Examples

isCaseClosed(inputs)
isCaseClosed(inputs)

Output: false

isCaseVisibleToCustomers

Parses a case record and returns whether the case is visible to customers.

Input and output

isCaseVisibleToCustomers(map) -> bool

Examples

isCaseVisibleToCustomers(inputs)
isCaseVisibleToCustomers(inputs)

Output: true

isDomain

Returns true if the provided string argument represents a valid domain.

Input and output

isDomain(string) -> bool

Examples

isDomain("example.com")
isDomain("example.com")

Output: true

isDomain("not_a_domain")
isDomain("not_a_domain")

Output: false

isEmail

Returns true if the provided string argument represents a valid email address.

Input and output

isEmail(string) -> bool

Examples

isEmail("sara@example.com")
isEmail("sara@example.com")

Output: true

isEmail("not_an_email")
isEmail("not_an_email")

Output: false

isIP

Returns true if the provided string argument represents a valid IPv4 address.

Input and output

isIP(string) -> bool

Examples

isIP("127.0.0.1")
isIP("127.0.0.1")

Output: true

isIP("not_an_ip")
isIP("not_an_ip")

Output: false

isPrivateIP

Returns true if the provided string argument represents a private (RFC-1918), link-local, or loopback IPv4 address.

Input and output

isPrivateIP(string) -> bool

Examples

isPrivateIP("192.168.1.1")
isPrivateIP("192.168.1.1")

Output: true

isPrivateIP("8.8.8.8")
isPrivateIP("8.8.8.8")

Output: false

isURL

Returns true if the provided string argument represents a valid Uniform Resource Locator (URL).

Input and output

isURL(string) -> bool
isURL(list) -> bool

Examples

isURL("https://example.com")
isURL("https://example.com")

Output: true

isURL("not_a_url")
isURL("not_a_url")

Output: false

isUUID

Returns true if the provided string argument represents a valid Universally Unique Identifier (UUID).

Input and output

isUUID(string) -> bool

Examples

isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")

Output: true

isUUID("not_a_uuid")
isUUID("not_a_uuid")

Output: false

join

Combines the elements of a list into a string using the provided separator.

The default separator is a comma character.

Input and output

join(list) -> string
join(list, string) -> string

Examples

join(["a", 1, true])
join(["a", 1, true])

Output: "a,1,true"

join(["a", 1, true], ".")
join(["a", 1, true], ".")

Output: "a.1.true"

keys

Returns a list of top-level keys from a map.

Input and output

keys(map) -> list

Examples

keys({"foo": "bar", "a": "b"})
keys({"foo": "bar", "a": "b"})

Output: ["foo", "a"]

last (list elements)

Returns the last N elements of a list.

Input and output

last(list, int) -> list

Examples

last(["a", "c", "b"], 2)
last(["a", "c", "b"], 2)

Output: ["c", "b"]

last (optional element)

Returns an optional containing the last element of a list, or optional.none() if the list is empty.

Input and output

list.last() -> optional(T)

Returns an optional containing the last element of a list.

If the list is empty, returns optional.none().

Use cases

Safe tail access.
[1, 2, 3].last().orValue(0)

Get the last element or return a default value.

Most recent item.
events.last().optMap(e, e.timestamp)

Get the timestamp of the latest event.

Check if empty.
items.last().hasValue()

Check whether the list has elements.

Latest value.
history.last().orValue('No history')

Get the most recent value or a default message.

End of sequence.
sequence.last().orValue(-1) > threshold

Check the last value against a threshold.

Validation.
results.last().hasValue() ? 'Complete' : 'Empty'

Check the state of the list.

Notes

  • Returns optional(T), where T is the element type.
  • Safely returns optional.none() for empty lists.
  • Is more expressive than list[?list.size()-1].
  • Use .orValue() to provide a default.
  • Doesn't modify the original list.

Examples

[1, 2, 3].last().orValue(0)
[1, 2, 3].last().orValue(0)

Output: 3

Get the last element.

[].last().hasValue()
[].last().hasValue()

Output: false

Check an empty list.

[].last().orValue(99)
[].last().orValue(99)

Output: 99

Use the default value for an empty list.

['a', 'b', 'c'].last().value()
['a', 'b', 'c'].last().value()

Output: 'c'

Extract the last string.

lastIndexOf

Returns the index of the last occurrence of a substring.

Input and output

string.lastIndexOf(string) -> int
string.lastIndexOf(string, int) -> int

Returns the zero-based index of the last occurrence of the substring.

Returns -1 if the substring isn't found.

The optional second argument specifies the ending position for the search.

Examples

'hello world'.lastIndexOf('o')
'hello world'.lastIndexOf('o')

Output: 7

'hello world'.lastIndexOf('l')
'hello world'.lastIndexOf('l')

Output: 9

'hello world'.lastIndexOf('o', 6)
'hello world'.lastIndexOf('o', 6)

Output: 4

'hello world'.lastIndexOf('xyz')
'hello world'.lastIndexOf('xyz')

Output: -1

list

Converts input to a list.

Input and output

list(any) -> list

Examples

list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

Output: [1, 3]

lists.range

Generates a list of sequential integers from 0 to n-1.

Input and output

lists.range(int) -> list

Generates a list of integers from 0 (inclusive) to n (exclusive).

Returns [0, 1, 2, ..., n-1].

Returns an empty list for values less than or equal to 0.

Use cases

Generate index list.
lists.range(items.size())

Get indices for a list.

Iterate N times.
lists.range(5).map(i, processItem(i))

Execute a function five times with an index.

Create test data.
lists.range(100)

Generate 100 sequential numbers.

Batch processing.
lists.range(totalItems / batchSize).map(i, processBatch(i))

Process items in batches.

Pagination.
lists.range(totalPages)

Generate page numbers.

Fill an array.
lists.range(10).map(i, 'item-' + string(i))

Output: ['item-0', 'item-1', ..., 'item-9']

Create a list of strings.

lowerAscii

Converts all ASCII characters in the string to lowercase.

Input and output

string.lowerAscii() -> string

Converts all ASCII uppercase letters (A-Z) to lowercase (a-z).

Non-ASCII characters are left unchanged.

Examples

'HELLO World'.lowerAscii()
'HELLO World'.lowerAscii()

Output: "hello world"

'ABC123XYZ'.lowerAscii()
'ABC123XYZ'.lowerAscii()

Output: "abc123xyz"

'Café'.lowerAscii()
'Café'.lowerAscii()

Output: "café"

map

Converts input to a map.

Input and output

map(list) -> map

Examples

map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))

Output: {"1": {"a": 1, "b": 2}, "3": {"a": 3, "b": 4}}

matchGroup

Returns a list of strings from the provided regex capture group or groups.

Input and output

matchGroup(string, string) -> list

Examples

"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")

Output: ["https://www.example.com", "https://", "www.example.com"]

math.abs

Returns the absolute value of a number.

Input and output

math.abs(double) -> double
math.abs(int) -> int
math.abs(uint) -> uint

Returns the absolute (non-negative) value of the input number.

Works with int, uint, and double types.

Examples

math.abs(-5)
math.abs(-5)

Output: 5

math.abs(5)
math.abs(5)

Output: 5

math.abs(-3.14)
math.abs(-3.14)

Output: 3.14

math.abs(0)
math.abs(0)

Output: 0

math.bitAnd

Performs a bitwise AND operation on two integers.

Input and output

math.bitAnd(int, int) -> int
math.bitAnd(uint, uint) -> uint

Returns the bitwise AND of two integers.

Each bit in the result is 1 only if both corresponding bits in the operands are 1.

Examples

math.bitAnd(5, 3)
math.bitAnd(5, 3)

Output: 1 (0101 & 0011 = 0001)

math.bitAnd(12, 10)
math.bitAnd(12, 10)

Output: 8 (1100 & 1010 = 1000)

math.bitAnd(15, 15)
math.bitAnd(15, 15)

Output: 15

math.bitAnd(7, 0)
math.bitAnd(7, 0)

Output: 0

math.bitNot

Performs a bitwise NOT (complement) operation on an integer.

Input and output

math.bitNot(int) -> int
math.bitNot(uint) -> uint

Returns the bitwise complement of the integer.

Each bit is flipped: 0 becomes 1, and 1 becomes 0.

Examples

math.bitNot(0)
math.bitNot(0)

Output: -1

math.bitNot(-1)
math.bitNot(-1)

Output: 0

math.bitNot(5)
math.bitNot(5)

Output: -6

math.bitNot(10)
math.bitNot(10)

Output: -11

math.bitOr

Performs a bitwise OR operation on two integers.

Input and output

math.bitOr(int, int) -> int
math.bitOr(uint, uint) -> uint

Returns the bitwise OR of two integers.

Each bit in the result is 1 if either corresponding bit in the operands is 1.

Examples

math.bitOr(5, 3)
math.bitOr(5, 3)

Output: 7 (0101 0011 = 0111)

math.bitOr(8, 4)
math.bitOr(8, 4)

Output: 12 (1000 0100 = 1100)

math.bitOr(0, 15)
math.bitOr(0, 15)

Output: 15

math.bitOr(7, 0)
math.bitOr(7, 0)

Output: 7

math.bitShiftLeft

Shifts the bits of an integer to the left by the specified number of positions.

Input and output

math.bitShiftLeft(int, int) -> int
math.bitShiftLeft(uint, uint) -> uint

Shifts all bits to the left by the specified number of positions.

Zeros are shifted in from the right. This is equivalent to multiplying by 2^n.

Examples

math.bitShiftLeft(5, 1)
math.bitShiftLeft(5, 1)

Output: 10 (0101 << 1 = 1010)

math.bitShiftLeft(5, 2)
math.bitShiftLeft(5, 2)

Output: 20 (0101 << 2 = 10100)

math.bitShiftLeft(1, 3)
math.bitShiftLeft(1, 3)

Output: 8

math.bitShiftLeft(3, 4)
math.bitShiftLeft(3, 4)

Output: 48

math.bitShiftRight

Shifts the bits of an integer to the right by the specified number of positions.

Input and output

math.bitShiftRight(int, int) -> int
math.bitShiftRight(uint, uint) -> uint

Shifts all bits to the right by the specified number of positions.

For unsigned integers, zeros are shifted in from the left.

For signed integers, the sign bit is preserved. This is equivalent to dividing by 2^n.

Examples

math.bitShiftRight(10, 1)
math.bitShiftRight(10, 1)

Output: 5 (1010 >> 1 = 0101)

math.bitShiftRight(20, 2)
math.bitShiftRight(20, 2)

Output: 5 (10100 >> 2 = 0101)

math.bitShiftRight(8, 3)
math.bitShiftRight(8, 3)

Output: 1

math.bitShiftRight(48, 4)
math.bitShiftRight(48, 4)

Output: 3

math.bitXor

Performs a bitwise XOR (exclusive OR) operation on two integers.

Input and output

math.bitXor(int, int) -> int
math.bitXor(uint, uint) -> uint

Returns the bitwise XOR of two integers.

Each bit in the result is 1 if the corresponding bits in the operands are different.

Examples

math.bitXor(5, 3)
math.bitXor(5, 3)

Output: 6 (0101 ^ 0011 = 0110)

math.bitXor(12, 10)
math.bitXor(12, 10)

Output: 6 (1100 ^ 1010 = 0110)

math.bitXor(15, 15)
math.bitXor(15, 15)

Output: 0

math.bitXor(7, 0)
math.bitXor(7, 0)

Output: 7

math.ceil

Rounds a number up to the nearest integer (towards positive infinity).

Input and output

math.ceil(double) -> double

Returns the smallest integer value greater than or equal to the input.

Always rounds up, even for negative numbers.

Examples

math.ceil(1.2)
math.ceil(1.2)

Output: 2.0

math.ceil(1.9)
math.ceil(1.9)

Output: 2.0

math.ceil(-1.2)
math.ceil(-1.2)

Output: -1.0

math.ceil(5.0)
math.ceil(5.0)

Output: 5.0

math.floor

Rounds a number down to the nearest integer (towards negative infinity).

Input and output

math.floor(double) -> double

Returns the largest integer value less than or equal to the input.

Always rounds down, even for negative numbers.

Examples

math.floor(1.2)
math.floor(1.2)

Output: 1.0

math.floor(1.9)
math.floor(1.9)

Output: 1.0

math.floor(-1.2)
math.floor(-1.2)

Output: -2.0

math.floor(5.0)
math.floor(5.0)

Output: 5.0

math.greatest

Returns the maximum value from the provided arguments.

Input and output

math.greatest(...) -> number

Returns the largest value among all provided arguments.

Accepts a variable number of arguments (int, uint, or double).

All arguments must be of comparable numeric types.

Examples

math.greatest(1, 5, 3, 9, 2)
math.greatest(1, 5, 3, 9, 2)

Output: 9

math.greatest(-10, -5, -20)
math.greatest(-10, -5, -20)

Output: -5

math.greatest(1.5, 2.3, 0.9)
math.greatest(1.5, 2.3, 0.9)

Output: 2.3

math.greatest(42)
math.greatest(42)

Output: 42

math.isFinite

Checks if a value is a finite number (not NaN or infinity).

Input and output

math.isFinite(double) -> bool

Returns true if the value is a finite number (not NaN or infinity).

Returns false for NaN, positive infinity, or negative infinity.

Examples

math.isFinite(3.14)
math.isFinite(3.14)

Output: true

math.isFinite(1.0 / 0.0)
math.isFinite(1.0 / 0.0)

Output: false

math.isFinite(0.0 / 0.0)
math.isFinite(0.0 / 0.0)

Output: false

math.isFinite(-100.5)
math.isFinite(-100.5)

Output: true

math.isInf

Checks if a value is positive or negative infinity.

Input and output

math.isInf(double) -> bool

Returns true if the value is infinity.

Examples

math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)

Output: true

math.isInf(-1.0 / 0.0)
math.isInf(-1.0 / 0.0)

Output: true

math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)

Output: true

math.isInf(3.14)
math.isInf(3.14)

Output: false

math.isNaN

Checks if a value is NaN (Not a Number).

Input and output

math.isNaN(double) -> bool

Returns true if the value is NaN. Otherwise, returns false.

Only applies to floating-point values.

Examples

math.isNaN(0.0 / 0.0)
math.isNaN(0.0 / 0.0)

Output: true

math.isNaN(1.0)
math.isNaN(1.0)

Output: false

math.isNaN(math.sqrt(-1.0))
math.isNaN(math.sqrt(-1.0))

Output: true

math.isNaN(3.14)
math.isNaN(3.14)

Output: false

math.least

Returns the minimum value from the provided arguments.

Input and output

math.least(...) -> number

Returns the smallest value among all provided arguments.

Accepts a variable number of arguments (int, uint, or double).

All arguments must be of comparable numeric types.

Examples

math.least(1, 5, 3, 9, 2)
math.least(1, 5, 3, 9, 2)

Output: 1

math.least(-10, -5, -20)
math.least(-10, -5, -20)

Output: -20

math.least(1.5, 2.3, 0.9)
math.least(1.5, 2.3, 0.9)

Output: 0.9

math.least(42)
math.least(42)

Output: 42

math.round

Rounds a number to the nearest integer (half away from zero).

Input and output

math.round(double) -> double

Returns the nearest integer value, rounding half values away from zero.

For positive numbers, 0.5 rounds up. For negative numbers, -0.5 rounds down.

Examples

math.round(1.4)
math.round(1.4)

Output: 1.0

math.round(1.5)
math.round(1.5)

Output: 2.0

math.round(-1.5)
math.round(-1.5)

Output: -2.0

math.round(5.0)
math.round(5.0)

Output: 5.0

math.sign

Returns the sign of a number: -1 for negative, 0 for zero, and 1 for positive.

Input and output

math.sign(double) -> double
math.sign(int) -> int

Returns:

  • -1 if the number is negative.
  • 0 if the number is zero.
  • 1 if the number is positive.

Examples

math.sign(-5)
math.sign(-5)

Output: -1

math.sign(0)
math.sign(0)

Output: 0

math.sign(5)
math.sign(5)

Output: 1

math.sign(-3.14)
math.sign(-3.14)

Output: -1.0

math.sqrt

Returns the square root of a number.

Input and output

math.sqrt(int) -> double
math.sqrt(double) -> double

Returns the square root of the input number.

Returns NaN for negative inputs.

Examples

math.sqrt(9.0)
math.sqrt(9.0)

Output: 3.0

math.sqrt(16)
math.sqrt(16)

Output: 4.0

math.sqrt(2.0)
math.sqrt(2.0)

Output: 1.414...

math.sqrt(0.0)
math.sqrt(0.0)

Output: 0.0

math.trunc

Truncates a number to its integer part (towards zero).

Input and output

math.trunc(double) -> double

Returns the integer part of the number by removing the fractional part.

Rounds towards zero for both positive and negative numbers.

Examples

math.trunc(1.9)
math.trunc(1.9)

Output: 1.0

math.trunc(-1.9)
math.trunc(-1.9)

Output: -1.0

math.trunc(5.0)
math.trunc(5.0)

Output: 5.0

math.trunc(3.14159)
math.trunc(3.14159)

Output: 3.0

md5sum

Returns the computed MD5 digest for the provided string.

Input and output

md5sum(string) -> bytes

Examples

md5sum("Hello").toHex()
md5sum("Hello").toHex()

Output: "8b1a9953c4611296a827abf8c47804d7"

merge

Adds elements to an existing map.

Input and output

merge(map, map) -> map

Examples

merge({"key1": "val1"}, {"key2": "val2"})
merge({"key1": "val1"}, {"key2": "val2"})

Output: {"key1": "val1", "key2": "val2"}

now

Returns the current local time as a timestamp.

Input and output

now() -> timestamp

Examples

now()
now()

Output: "2025-04-29T12:34:56.789Z"

nowUnixMilli

Returns the current time as the number of milliseconds since epoch.

Input and output

nowUnixMilli() -> int

Examples

nowUnixMilli()
nowUnixMilli()

Output: 1742395914211

optFlatMap

Transforms the optional's value with a function that returns an optional, flattening the result.

Input and output

optional(T).optFlatMap(var, expr) -> optional(R)

Applies a transformation that returns an optional.

Unlike optMap, this doesn't nest optionals. If the original optional is empty or the transformation returns optional.none(), the result is optional.none().

Use cases

Chained optional access.
optional.of([1, 2, 3]).optFlatMap(l, l[?0])

Get the first element as an optional.

Conditional transformation.
optional.of(value).optFlatMap(v, v > 0 ? optional.of(v * 2) : optional.none())

Transform only if the condition is met.

Safe nested access.
optional.of(user).optFlatMap(u, u.?email)

Access a nested optional value safely.

Zero-value filtering.
optional.of(input).optFlatMap(i, optional.ofNonZeroValue(i.trim()))

Filter empty strings after trimming.

Multiple optional sources.
optional.of(config).optFlatMap(c, c[?'setting'])

Perform an optional map lookup within an optional object.

Notes

  • Variable binding syntax: optFlatMap(var, expression returning optional).
  • Prevents nested optionals such as optional(optional(T)).
  • Useful when the transformation itself returns an optional.
  • Empty optionals pass through unchanged as optional.none().
  • The transformation only runs when the optional contains a value.

Examples

optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)

Output: 1

optional.of([]).optFlatMap(l, l[?0]).orValue(0)
optional.of([]).optFlatMap(l, l[?0]).orValue(0)

Output: 0

optional.none().optFlatMap(l, l[?0]).orValue(0)
optional.none().optFlatMap(l, l[?0]).orValue(0)

Output: 0

optMap

Transforms the optional's value if present, returning a new optional with the transformed value.

Input and output

optional(T).optMap(var, expr) -> optional(R)

Applies a transformation to the optional's value if present.

The transformation returns a new value that is wrapped in an optional.

If the optional is empty, returns optional.none().

Use cases

Transform a value.
optional.of(5).optMap(x, x * 2)

Output: optional(10)

Double the value.

String manipulation.
optional.of('hello').optMap(s, s.upperAscii())

Output: optional('HELLO')

Transform to uppercase.

Property access.
optional.of(user).optMap(u, u.email)

Extract a property from a wrapped object.

Complex calculation.
optional.of([1, 2, 3]).optMap(l, l.size())

Output: optional(3)

Get the size of a list.

Chained transformations.
optional.of(10).optMap(x, x * 2).optMap(x, x + 1).orValue(0)

Output: 21

Chain multiple transformations.

Filter with map.
optional.of([1, 2, 3, 4, 5]).optMap(l, l.filter(x, x > 2))

Transform and filter data.

Safe navigation.
data.?user.optMap(u, u.name).orValue('Anonymous')

Safe nested access with transformation.

Notes

  • Variable binding syntax: optMap(var, expression using var).
  • Returns optional(R) where R is the result type.
  • Empty optionals pass through unchanged.
  • Use .orValue() to extract the final result.
  • Compare with .optFlatMap() when the transformation returns an optional.

Examples

optional.of(5).optMap(x, x * 2).orValue(0)
optional.of(5).optMap(x, x * 2).orValue(0)

Output: 10

optional.none().optMap(x, x * 2).orValue(0)
optional.none().optMap(x, x * 2).orValue(0)

Output: 0

optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')

Output: 'HELLO'

optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)

Output: 3

optional.none

Creates an empty optional value with no content.

Input and output

optional.none() -> optional

Creates an empty optional value that contains no value.

Use cases

Represent a missing value.
optional.none()

Explicit absence of a value.

Use as a default in a conditional.
hasError ? optional.none() : optional.of(result)

Return an empty optional when an error occurs.

Chain with .or().
optional.none().or(optional.of(5))

Fall back to another optional.

Check emptiness.
optional.none().hasValue()

Output: false

Check whether an optional is empty.

Provide a default.
optional.none().orValue('default')

Extract a value with a fallback.

Notes

  • Represents the absence of a value (similar to null).
  • .hasValue() returns false for optional.none().
  • Calling .value() on optional.none() causes an error.
  • Use .orValue() to provide a default value.
  • Use .or() to chain with other optionals.

Examples

optional.none().hasValue()
optional.none().hasValue()

Output: false

optional.none().orValue(42)
optional.none().orValue(42)

Output: 42

optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)

Output: 5

optional.of

Creates an optional value containing the given value.

Input and output

optional.of(T) -> optional(T)

Creates an optional value that contains the given value.

Any value is considered valid, including zero values.

Use cases

Wrap a known value.
optional.of(42)

Create an optional containing 42.

Wrap zero or empty values.
optional.of(0)

Create an optional containing 0.

Wrap an empty string.
optional.of('')

Create an optional containing an empty string.

Chain transformations.
optional.of(5).optMap(x, x * 2)

Transform the wrapped value.

Conditional wrapping.
hasValue ? optional.of(value) : optional.none()

Wrap a value conditionally.

Default value pattern.
optional.of(userInput).orValue('default')

Wrap input with a fallback.

Notes

  • Accepts any value, including zero values such as 0, '', [], or {}.
  • Returns optional(T) where T is the value type.
  • Compare with optional.ofNonZeroValue(), which rejects zero values.
  • Use .hasValue() to check whether a value exists.
  • Use .orValue() to extract a value with a fallback.

Examples

optional.of(42)
optional.of(42)

Output: optional(42)

optional.of('hello')
optional.of('hello')

Output: optional('hello')

optional.of([1, 2, 3])
optional.of([1, 2, 3])

Output: optional([1, 2, 3])

optional.of(0).hasValue()
optional.of(0).hasValue()

Output: true

optional.ofNonZeroValue

Creates an optional containing the value only if it's non-zero. Otherwise, returns optional.none().

Input and output

optional.ofNonZeroValue(T) -> optional(T)

Creates an optional containing the given value only if it's not a zero or empty value.

Zero values such as 0, '', [], {}, and null result in optional.none().

Use cases

Filter zero values.
optional.ofNonZeroValue(userInput)

Only wrap non-empty input.

Validate non-empty values.
optional.ofNonZeroValue('').hasValue()

Output: false

Check whether a string is non-empty.

Skip empty lists.
optional.ofNonZeroValue([]).orValue([1, 2, 3])

Use a default value for an empty list.

Conditional processing.
optional.ofNonZeroValue(score).optMap(s, s * 100)

Only process non-zero scores.

Null safety.
optional.ofNonZeroValue(null).orValue('N/A')

Handle null values safely.

Notes

Zero values by type:

  • Numeric: 0, 0.0
  • String: ''
  • List: []
  • Map: {}
  • Boolean: false
  • Bytes: b''
  • Null: null

Additional notes:

  • Returns optional.none() for zero values.
  • Use when you want to treat empty or zero values as absent.
  • Compare with optional.of(), which accepts all values.
  • Useful for validation and filtering.

Examples

optional.ofNonZeroValue(42).hasValue()
optional.ofNonZeroValue(42).hasValue()

Output: true

Non-zero numeric value.

optional.ofNonZeroValue(0).hasValue()
optional.ofNonZeroValue(0).hasValue()

Output: false

Zero is rejected.

optional.ofNonZeroValue('').hasValue()
optional.ofNonZeroValue('').hasValue()

Output: false

Empty string is rejected.

optional.ofNonZeroValue('hello').hasValue()
optional.ofNonZeroValue('hello').hasValue()

Output: true

Non-empty string is accepted.

or

Returns the first optional if it has a value. Otherwise, returns the second optional.

Input and output

optional(T).or(optional(T)) -> optional(T)

Chains optional values.

If the left optional has a value, it is returned. Otherwise, the right optional is returned.

Evaluation is short-circuited.

Use cases

Fallback chain.
optional.none().or(optional.of(5))

Use an alternative optional value.

Multiple sources.
cache[?key].or(database[?key]).or(optional.of(default))

Try cache, then database, then a default value.

Coalesce pattern.
primary.or(secondary).or(tertiary).orValue(fallback)

Chain multiple optional sources.

Safe navigation chain.
obj.?field1.or(obj.?field2).orValue('none')

Try multiple fields in priority order.

Priority-based selection.
premium.?feature.or(basic.?feature)

Prefer a premium feature and fall back to a basic feature.

Notes

  • Returns optional(T), not T.
  • Use .orValue() at the end to extract the final value.
  • Short-circuits evaluation when the first optional has a value.
  • Useful for chaining multiple optional sources.
  • Compare with .orValue(), which returns a concrete value.

Examples

optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)

Output: 5

optional.of(3).or(optional.of(5)).orValue(0)
optional.of(3).or(optional.of(5)).orValue(0)

Output: 3

optional.none().or(optional.none()).orValue(10)
optional.none().or(optional.none()).orValue(10)

Output: 10

orValue

Returns the value from the optional if present. Otherwise, returns the provided default value.

Input and output

optional(T).orValue(T) -> T

Extracts the value from an optional if present, otherwise returns the provided default value.

Use cases

Provide a default.
optional.none().orValue(42)

Output: 42

Use a default when the optional is empty.

Safe field access.
obj.?field.orValue('N/A')

Get a field value or return a default.

Safe map access.
config[?'timeout'].orValue(30)

Get a configuration value with a fallback.

Safe list access.
items[?0].orValue('empty')

Get the first item or return a default.

Chain operations.
optional.of(5).orValue(0) * 2

Output: 10

Use the extracted value directly in a calculation.

Nested access.
data.?user.?name.orValue('Anonymous')

Safely access nested fields.

Coalesce pattern.
primary.orValue(secondary.orValue(tertiary))

Chain multiple fallback values.

Notes

  • The default value must match the optional type.
  • Always returns a concrete value.
  • Safe to use anywhere a normal value is expected.
  • More concise than conditional expressions.
  • Compare with .value(), which throws an error for empty optionals.

Examples

optional.of(42).orValue(0)
optional.of(42).orValue(0)

Output: 42

optional.none().orValue(0)
optional.none().orValue(0)

Output: 0

optional.of('hello').orValue('default')
optional.of('hello').orValue('default')

Output: 'hello'

{'a': 1}[?'b'].orValue(0)
{'a': 1}[?'b'].orValue(0)

Output: 0

parseURL

Returns the provided URL string as a URL map structure.

Input and output

parseURL(string) -> map

Examples

parseURL("https://www.example.com")
parseURL("https://www.example.com")

Output: {"Scheme": "https", "Host": "www.example.com", "Path": "", "RawQuery": "", "Fragment": ""}

queryJSON

Returns data from the first argument using the JMESPath query provided in the second argument.

Input and output

queryJSON(map, string) -> any

Examples

queryJSON(inputs.alert2, "metadata.confidence")
queryJSON(inputs.alert2, "metadata.confidence")

Output: 0.5

random

Returns a random value between 0 and .99 (inclusive).

Input and output

random() -> double

Examples

random()
random()

Output: 0.42

regex.extract

Extracts the first match of a regular expression pattern from a string, returning an optional value.

Input and output

regex.extract(string, pattern) -> string

Applies a regular expression pattern to a string and returns the first match wrapped in an optional.

If the pattern contains a capturing group, the captured value is returned.

If the pattern contains no capturing groups, the entire match is returned.

Returns optional.none() if no match is found.

Notes

Pattern syntax:

  • Uses RE2 regular expression syntax.
  • Capturing groups use parentheses ().
  • Backslashes must be escaped in CEL strings.
  • Common patterns include \d, \w, and \s.

Additional notes:

  • Returns an optional value. Use .orValue() or .hasValue().
  • Pattern matching proceeds left-to-right and returns only the first match.
  • Use extractAll() to retrieve all matches.
  • Empty strings and empty patterns are handled gracefully.
  • Invalid regex patterns cause compilation errors.

regex.extractAll

Extracts all matches of a regular expression pattern from a string as a list.

Input and output

regex.extractAll(string, pattern) -> list

Applies a regular expression pattern to a string and returns all matches as a list of strings.

Returns an empty list if no matches are found.

Unlike extract(), this function returns all matches, not just the first one.

Use cases

Extract all numbers.
regex.extractAll('test123foo456bar', '\\d+')

Output: ["123", "456"]

Find all numeric sequences.

Extract all words.
regex.extractAll('hello world test', '\\w+')

Output: ["hello", "world", "test"]

Split text into words.

Parse multiple values.
regex.extractAll('192.168.1.1', '\\d+')

Output: ["192", "168", "1", "1"]

Extract all numeric values from an IP address.

Find all email addresses.
regex.extractAll(text, '\\w+@\\w+\\.\\w+')

Extract all email addresses from a string.

Count matches.
regex.extractAll('test123foo456bar', '\\d+').size()

Output: 2

Count the number of numeric sequences.

Check for matches.
regex.extractAll('no-numbers-here', '\\d+').size() == 0

Output: true

Check whether the pattern matches anything.

Extract and process.
regex.extractAll('1,2,3,4,5', '\\d+').map(x, int(x))

Output: [1, 2, 3, 4, 5]

Extract numbers and convert them to integers.

Filter results.
regex.extractAll('a1 b2 c3', '\\w+').filter(x, x.size() > 1)

Output: ["a1", "b2", "c3"]

Extract tokens and filter by length.

Notes

  • Returns a list instead of an optional value.
  • Returns an empty list when no matches are found.
  • Capturing groups are ignored. Only full matches are returned.
  • Useful for extracting multiple values from a string.
  • More efficient than multiple calls to extract().
  • Preserves left-to-right match order.

Examples

regex.extractAll('test123foo456bar', '\\d+')
regex.extractAll('test123foo456bar', '\\d+')

Output: ["123", "456"]

regex.extractAll('hello world test', '\\w+')
regex.extractAll('hello world test', '\\w+')

Output: ["hello", "world", "test"]

regex.extractAll('192.168.1.1', '\\d+')
regex.extractAll('192.168.1.1', '\\d+')

Output: ["192", "168", "1", "1"]

regex.extractAll('no-numbers-here', '\\d+')
regex.extractAll('no-numbers-here', '\\d+')

Output: []

regex.replace

Replaces occurrences of a regular expression pattern in a string with a replacement string.

Input and output

regex.replace(string, pattern, replacement) -> string
regex.replace(string, pattern, replacement, count) -> string

Replaces non-overlapping substrings matching the regex pattern.

Optionally limits the number of replacements using the count argument.

When count is omitted or negative, all occurrences are replaced.

Use cases

Simple text replacement.
regex.replace('hello world hello', 'hello', 'hi')

Output: "hi world hi"

Replace all occurrences of hello.

Remove all digits.
regex.replace('test123test456', '\\d+', '')

Output: "testtest"

Remove all numeric sequences.

Mask sensitive data.
regex.replace('ID: 12345', '\\d+', 'XXXXX')

Output: "ID: XXXXX"

Replace numbers with a placeholder.

Limited replacements.
regex.replace('banana', 'a', 'x', 1)

Output: "bxnana"

Replace only the first occurrence.

Replace all with negative count.
regex.replace('banana', 'a', 'x', -1)

Output: "bxnxnx"

Negative count means replace all occurrences.

Normalize whitespace.
regex.replace('hello    world  test', '\\s+', ' ')

Output: "hello world test"

Replace multiple spaces with a single space.

Clean special characters.
regex.replace('hello@world#test', '[^a-zA-Z0-9]', '')

Output: "helloworldtest"

Remove non-alphanumeric characters.

Format phone numbers.
regex.replace('1234567890', '(\\d{3})(\\d{3})(\\d{4})', '($1) $2-$3')

Format a phone number using capture groups.

Notes

  • Pattern must be a valid regular expression.
  • Replacement string is treated literally except for capture-group references.
  • When count is 0, the original string is returned unchanged.
  • When count is negative, all matches are replaced.
  • Non-matching patterns return the original string unchanged.
  • Empty patterns match between characters.

Capture group references:

  • Use \1, \2, \3, and so on.
  • Only numeric capture groups are supported.
  • Named capture groups aren't supported in replacement strings.
  • Invalid capture-group references cause runtime errors.

Examples

regex.replace('hello world hello', 'hello', 'hi')
regex.replace('hello world hello', 'hello', 'hi')

Output: "hi world hi"

regex.replace('banana', 'a', 'x')
regex.replace('banana', 'a', 'x')

Output: "bxnxnx"

regex.replace('test123test456', '\\d+', 'NUM')
regex.replace('test123test456', '\\d+', 'NUM')

Output: "testNUMtestNUM"

regex.replace('banana', 'a', 'x', 1)
regex.replace('banana', 'a', 'x', 1)

Output: "bxnana"

regex.replace('foo bar', 'foo', 'hello')
regex.replace('foo bar', 'hello')

Output: "hello bar"

replace

Replaces all occurrences of a substring with another string.

Input and output

string.replace(string, string) -> string
string.replace(string, string, int) -> string

Replaces occurrences of the first substring with the second substring.

An optional third argument limits the number of replacements. Use -1 to replace all occurrences.

Examples

'hello world'.replace('o', 'a')
'hello world'.replace('o', 'a')

Output: "hella warld"

'hello world'.replace('l', 'L')
'hello world'.replace('l', 'L')

Output: "heLLo worLd"

'hello world'.replace('l', 'L', 1)
'hello world'.replace('l', 'L', 1)

Output: "heLlo world"

'hello world'.replace('world', 'universe')
'hello world'.replace('world', 'universe')

Output: "hello universe"

resolvePartnerName

Resolves a Taegis tenant ID and returns the partner name.

Input and output

resolvePartnerName(string) -> string

Examples

resolvePartnerName('12345')
resolvePartnerName('12345')

Output: "Partner Name"

resolveSubjectName

Resolves a Taegis user ID or client ID and returns a name string.

Input and output

resolveSubjectName(string) -> string

Examples

resolveSubjectName('auth0asdf')
resolveSubjectName('auth0asdf')

Output: "GivenName FamilyName"

resolveSubjectName('ff0197b0@clients')
resolveSubjectName('ff0197b0@clients')

Output: "ClientName"

resolveTenantName

Resolves a Taegis tenant ID and returns the tenant name.

Input and output

resolveTenantName(string) -> string

Examples

resolveTenantName('12345')
resolveTenantName('12345')

Output: "Tenant Name"

resolveUser

Resolves a Taegis user by ID, Auth0 ID, or email address and returns the Taegis user ID.

Input and output

resolveUser(string) -> string

Examples

resolveUser('auth0asdf')
resolveUser('auth0asdf')

Output: "dac1ed31-111-4809-9cc9-9f99b6e"

resolveUserName

Resolves a Taegis user ID and returns the username string.

Input and output

resolveUserName(string) -> string

Examples

resolveUserName('auth0asdf')
resolveUserName('auth0asdf')

Output: "GivenName FamilyName"

reverse

Reverses the order of elements in a list.

Input and output

list.reverse() -> list

Returns a new list with elements in reverse order.

The first element becomes the last, and vice versa.

Does not modify the original list.

Use cases

Reverse chronological order.
events.reverse()

Show the most recent events first.

Process in reverse.
steps.reverse().map(s, s.execute())

Execute steps in reverse order.

Palindrome check.
list == list.reverse()

Check whether a list is a palindrome.

Last-to-first processing.
queue.reverse()

Process items in LIFO order.

Reverse and filter.
items.reverse().filter(i, i.priority > 5)

Reverse the list and then filter it.

Reverse twice.
list.reverse().reverse() == list

Output: true

Double reversing returns the original list.

Notes

  • Returns a new list.
  • Works with any list type.
  • Empty and single-element lists are unchanged.
  • Reversing twice returns the original order.

Examples

[1, 2, 3, 4].reverse()
[1, 2, 3, 4].reverse()

Output: [4, 3, 2, 1]

['a', 'b', 'c'].reverse()
['a', 'b', 'c'].reverse()

Output: ['c', 'b', 'a']

[1].reverse()
[1].reverse()

Output: [1]

[].reverse()
[].reverse()

Output: []

[5, 3, 1, 2].reverse()
[5, 3, 1, 2].reverse()

Output: [2, 1, 3, 5]

sets.contains

Checks whether the first list contains all elements from the second list (subset check).

Input and output

sets.contains(list, list) -> bool

Returns true if the first list contains all elements from the second list.

The first list is considered a superset of the second list.

Order doesn't matter.

Duplicates in either list are ignored.

Use cases

Permission checking.
sets.contains(user.roles, ['admin'])

Check whether a user has the required role.

Required tags validation.
sets.contains(resource.tags, ['production', 'critical'])

Validate that a resource contains all required tags.

Feature availability.
sets.contains(subscription.features, ['api_access', 'export'])

Check whether a subscription includes all required features.

Empty list handling.
sets.contains([1, 2, 3], [])

Output: true

An empty list is a subset of any list.

Duplicate handling.
sets.contains([1, 1, 2, 2, 3], [1, 2])

Output: true

Duplicates are ignored.

Examples

sets.contains([1, 2, 3, 4], [2, 3])
sets.contains([1, 2, 3, 4], [2, 3])

Output: true

sets.contains([1, 2, 3], [3, 2, 1])
sets.contains([1, 2, 3], [3, 2, 1])

Output: true

sets.contains([1, 2, 3], [1, 2, 4])
sets.contains([1, 2, 3], [1, 2, 4])

Output: false

sets.contains(['admin', 'user', 'guest'], ['admin'])
sets.contains(['admin', 'user', 'guest'], ['admin'])

Output: true

sets.equivalent

Checks whether two lists contain the same elements, ignoring order and duplicates (set equality).

Input and output

sets.equivalent(list, list) -> bool

Returns true if both lists contain exactly the same elements.

Order doesn't matter.

Duplicates are ignored.

Use cases

Compare user permissions.
sets.equivalent(user1.permissions, user2.permissions)

Check whether two users have identical permissions.

Tag comparison.
sets.equivalent(resource1.tags, resource2.tags)

Compare resource tags.

Validate configuration.
sets.equivalent(actual_settings, expected_settings)

Verify that configuration values match.

Empty lists.
sets.equivalent([], [])

Output: true

Empty lists are equivalent.

String comparison.
sets.equivalent(['a', 'b', 'c'], ['c', 'a', 'b'])

Output: true

Works with any comparable type.

Symmetric operation.
sets.equivalent(list1, list2) == sets.equivalent(list2, list1)

Output: true

Argument order doesn't matter.

Examples

sets.equivalent([1, 2, 3], [3, 2, 1])
sets.equivalent([1, 2, 3], [3, 2, 1])

Output: true

sets.equivalent([1, 2, 3], [1, 2, 3])
sets.equivalent([1, 2, 3], [1, 2, 3])

Output: true

sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])

Output: true

sets.equivalent([1, 2, 3], [1, 2, 4])
sets.equivalent([1, 2, 3], [1, 2, 4])

Output: false

sets.intersects

Checks whether two lists have any common elements (non-empty intersection).

Input and output

sets.intersects(list, list) -> bool

Returns true if the two lists share at least one common element.

Order doesn't matter.

Duplicates are ignored.

Use cases

Role-based access control.
sets.intersects(user.roles, ['admin', 'owner', 'moderator'])

Check whether a user has at least one privileged role.

Tag filtering.
sets.intersects(resource.tags, ['production', 'staging'])

Check whether a resource belongs to a target environment.

Feature flags.
sets.intersects(user.features, ['beta', 'preview'])

Check whether a user has access to beta features.

Category matching.
sets.intersects(product.categories, filter.categories)

Check whether a product belongs to any selected category.

Permission validation.
sets.intersects(user.permissions, required_permissions)

Check whether a user has at least one required permission.

Multiple values check.
sets.intersects([user.status], ['active', 'pending', 'trial'])

Apply OR-style matching across multiple values.

Examples

sets.intersects([1, 2, 3], [3, 4, 5])
sets.intersects([1, 2, 3], [3, 4, 5])

Output: true

sets.intersects([1, 2, 3], [4, 5, 6])
sets.intersects([1, 2, 3], [4, 5, 6])

Output: false

sets.intersects(['admin', 'user'], ['admin', 'owner'])
sets.intersects(['admin', 'user'], ['admin', 'owner'])

Output: true

sets.intersects([1, 2, 3], [1, 2, 3])
sets.intersects([1, 2, 3], [1, 2, 3])

Output: true

sha1sum

Returns the computed SHA-1 digest for the provided string.

Input and output

sha1sum(string) -> bytes

Examples

sha1sum("Hello").toHex()
sha1sum("Hello").toHex()

Output: "f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0"

sha256sum

Returns the computed SHA-256 digest for the provided string.

Input and output

sha256sum(string) -> bytes

Examples

sha256sum("Hello").toHex()
sha256sum("Hello").toHex()

Output: "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"

sha512sum

Returns the computed SHA-512 digest for the provided string.

Input and output

sha512sum(string) -> bytes

Examples

sha512sum("Hello").toHex()
sha512sum("Hello").toHex()

Output: "3615f80c9d293ed7402687f94b22d58e529b8cc7916f8fac7fddf7fbd5af4cf777d3d795a7a00a16bf7e7f3fb9561ee9baae480da9fe7a18769e71886b03f315"

slice

Extracts a portion of a list between two indices.

Input and output

list.slice(int, int) -> list

Extracts a sub-list from the start index (inclusive) to the end index (exclusive).

Indices are zero-based.

Use cases

Pagination.
results.slice(page * pageSize, (page + 1) * pageSize)

Extract a page of results.

Take the first N elements.
list.slice(0, 5)

Get the first five elements.

Skip the first N elements.
list.slice(3, list.size())

Skip the first three elements.

Get a middle section.
list.slice(2, 8)

Extract a middle portion of the list.

Get the last N elements.
list.slice(list.size() - 3, list.size())

Get the last three elements.

sort

Returns a copy of the provided list sorted in ascending order.

The sort order can be reversed to descending by specifying "desc" as the second argument.

Input and output

sort(list) -> list
sort(list, string) -> list

Examples

sort(["a", "c", "b"])
sort(["a", "c", "b"])

Output: ["a", "b", "c"]

sort([3, 2, 1], "desc")
sort([3, 2, 1], "desc")

Output: [3, 2, 1]

sortBy

Sorts a list by a computed key expression, allowing custom sort criteria.

Input and output

list.sortBy(var, key_expression) -> list

Sorts the list based on values computed by the key expression for each element.

The variable name is bound to each element during key computation.

Elements are sorted by their computed keys in ascending order.

Use cases

Sort by object property.
users.sortBy(u, u.name)

Sort users alphabetically by name.

Sort by age.
users.sortBy(u, u.age)

Sort users by age.

Descending sort.
scores.sortBy(s, -s.value)

Sort scores in descending order.

Sort by computed value.
products.sortBy(p, p.price * (1 - p.discount))

Sort by the final discounted price.

Sort by string length.
words.sortBy(w, w.size())

Sort words by length.

Sort by multiple criteria.
items.sortBy(i, string(i.priority) + i.name)

Sort by priority and then by name.

Sort by distance.
locations.sortBy(loc, math.abs(loc.lat - target.lat) + math.abs(loc.lon - target.lon))

Sort locations by Manhattan distance.

Sort by Boolean value.
items.sortBy(i, i.active)

Sort with false values first and true values last.

Case insensitive sorting.
names.sortBy(n, n.lowerAscii())

Sort strings without regard to case.

Sort by nested property.
orders.sortBy(o, o.customer.tier)

Sort by a nested property.

Complex calculations.
tasks.sortBy(t, t.priority * 10 + (t.dueDate - now).getHours())

Sort using a weighted priority and time calculation.

Notes

  • Returns a new sorted list.
  • The original list is unchanged.
  • The key expression is evaluated for each element.
  • Sorting is stable, meaning equal keys keep their relative order.
  • Keys must be comparable.
  • Negate numeric values to perform a descending sort.

Examples

[3, 1, 4, 1, 5, 9].sortBy(x, x)
[3, 1, 4, 1, 5, 9].sortBy(x, x)

Output: [1, 1, 3, 4, 5, 9]

Sort using the value itself as the key.

[3, 1, 4, 1, 5, 9].sortBy(x, -x)
[3, 1, 4, 1, 5, 9].sortBy(x, -x)

Output: [9, 5, 4, 3, 1, 1]

Sort in descending order.

split

Splits a string into a list using the specified delimiter.

Input and output

string.split(string) -> list
string.split(string, int) -> list

Splits the string into a list of substrings using the delimiter.

The optional second argument limits the number of splits. Use -1 for all splits.

Examples

'hello world'.split(' ')
'hello world'.split(' ')

Output: ["hello", "world"]

'a,b,c,d'.split(',')
'a,b,c,d'.split(',')

Output: ["a", "b", "c", "d"]

'a,b,c,d'.split(',', 2)
'a,b,c,d'.split(',', 2)

Output: ["a", "b,c,d"]

'one'.split('')
'one'.split('')

Output: ["o", "n", "e"]

substring

Extracts a portion of a string between two indices.

Input and output

string.substring(int) -> string
string.substring(int, int) -> string

Extracts a substring starting at the first index.

If a second argument is provided, extraction stops before that index.

If only one argument is provided, extraction continues to the end of the string.

Examples

'hello world'.substring(0, 5)
'hello world'.substring(0, 5)

Output: "hello"

'hello world'.substring(6)
'hello world'.substring(6)

Output: "world"

'hello world'.substring(6, 11)
'hello world'.substring(6, 11)

Output: "world"

'hello'.substring(1, 4)
'hello'.substring(1, 4)

Output: "ell"

take

Returns the first x elements of a list, or the elements between a start and end position.

Input and output

take(list, int) -> list
take(list, int, int) -> list

Examples

take(["a", "c", "b"], 1)
take(["a", "c", "b"], 1)

Output: ["a"]

take(["a", "c", "b"], 0, 2)
take(["a", "c", "b"], 0, 2)

Output: ["a", "c"]

tenantAllowResponseActions

Checks whether response actions are allowed for a tenant.

Input and output

tenantAllowResponseActions(map) -> bool

Examples

tenantAllowResponseActions(tenant)
tenantAllowResponseActions(tenant)

Output: true

tenantCentralAccountOrigin

Returns the accountOrigin value from the centralTenant map.

Input and output

tenantCentralAccountOrigin(map) -> string

Examples

tenantCentralAccountOrigin(tenant)
tenantCentralAccountOrigin(tenant)

Output: "taegis"

tenantCentralAccountType

Returns the accountType value from the centralTenant map.

Input and output

tenantCentralAccountType(map) -> string

Examples

tenantCentralAccountType(tenant)
tenantCentralAccountType(tenant)

Output: "tenant"

tenantCentralDataRegion

Returns the dataRegion value from the centralTenant map.

Input and output

tenantCentralDataRegion(map) -> string

Examples

tenantCentralDataRegion(tenant)
tenantCentralDataRegion(tenant)

Output: "us03"

tenantCentralId

Returns the central tenant ID from the centralTenant map.

Input and output

tenantCentralId(map) -> string

Examples

tenantCentralId(tenant)
tenantCentralId(tenant)

Output: "7f8f1dee-98da-4b1b-bb70-1f788254687e"

tenantCentralLastRefresh

Returns the lastRefresh value from the centralTenant map.

Input and output

tenantCentralLastRefresh(map) -> string

Examples

tenantCentralLastRefresh(tenant)
tenantCentralLastRefresh(tenant)

Output: "2025-09-23T17:28:01.113261229Z"

tenantCentralRegion

Returns the region value from the centralTenant map.

Input and output

tenantCentralRegion(map) -> string

Examples

tenantCentralRegion(tenant)
tenantCentralRegion(tenant)

Output: "us-east-2"

tenantCentralXdrOwnership

Returns the xdrOwnership value from the centralTenant map.

Input and output

tenantCentralXdrOwnership(map) -> string

Examples

tenantCentralXdrOwnership(tenant)
tenantCentralXdrOwnership(tenant)

Output: "securityOperations"

tenantDataRetentionMonths

Extracts the data retention period in months from a tenant map.

Input and output

tenantDataRetentionMonths(map) -> int

Examples

tenantDataRetentionMonths(tenant)
tenantDataRetentionMonths(tenant)

Output: 60

tenantDescription

Extracts the tenant description from a tenant map.

Input and output

tenantDescription(map) -> string

Examples

tenantDescription(tenant)
tenantDescription(tenant)

Output: "CTPx Playground"

tenantEnabled

Checks whether a tenant is enabled.

Input and output

tenantEnabled(map) -> bool

Examples

tenantEnabled(tenant)
tenantEnabled(tenant)

Output: true

tenantEnvironments

Returns a list of environment names for a tenant.

Input and output

tenantEnvironments(map) -> list

Examples

tenantEnvironments(tenant)
tenantEnvironments(tenant)

Output: ["pilot", "pilot_1", "pilot_2"]

tenantHasService

Checks whether a tenant has a specific service by name (case insensitive).

Input and output

tenantHasService(map, string) -> bool

Examples

tenantHasService(tenant, "MDR")
tenantHasService(tenant, "MDR")

Output: true

tenantId

Extracts the tenant ID from a tenant map.

Input and output

tenantId(map) -> string

Examples

tenantId(tenant)
tenantId(tenant)

Output: "11772"

tenantIsOrganization

Checks whether a tenant is an organization.

Input and output

tenantIsOrganization(map) -> bool

Examples

tenantIsOrganization(tenant)
tenantIsOrganization(tenant)

Output: false

tenantIsPartner

Checks whether a tenant is a partner.

Input and output

tenantIsPartner(map) -> bool

Examples

tenantIsPartner(tenant)
tenantIsPartner(tenant)

Output: false

tenantIsSophosMDR

Returns true when the tenant's licenseLevel is exactly "MDR".

This macro is equivalent to:

tenant.licenseLevel == 'MDR'

Input and output

tenantIsSophosMDR(map) -> bool

Examples

tenantIsSophosMDR(tenant)
tenantIsSophosMDR(tenant)

Output: true

tenantIsSophosXDR

Returns true when the tenant is an XDR customer.

Equivalent to:

tenantCentralXdrOwnership(tenant) != 'taegis' &&
tenantCentralXdrOwnership(tenant) != '' &&
tenant.licenseLevel != 'MDR'

Input and output

tenantIsSophosXDR(map) -> bool

Examples

tenantIsSophosXDR(tenant)
tenantIsSophosXDR(tenant)

Output: true

tenantLabelValue

Returns the value of a specific label for a tenant.

Input and output

tenantLabelValue(map, string) -> string

Examples

tenantLabelValue(tenant, "testing")
tenantLabelValue(tenant, "testing")

Output: "true"

tenantLabels

Returns a map of label names to values for a tenant.

Input and output

tenantLabels(map) -> map

Examples

tenantLabels(tenant)
tenantLabels(tenant)

Output: {"testing": "true", "Endpoints Licensed": "2000"}

tenantName

Extracts the tenant name from a tenant map.

Input and output

tenantName(map) -> string

Examples

tenantName(tenant)
tenantName(tenant)

Output: "CTPx Playground"

tenantOrganization

Extracts the organization from a tenant map.

Input and output

tenantOrganization(map) -> string

Examples

tenantOrganization(tenant)
tenantOrganization(tenant)

Output: ""

tenantParent

Extracts the parent tenant ID from a tenant map.

Input and output

tenantParent(map) -> string

Examples

tenantParent(tenant)
tenantParent(tenant)

Output: "5000"

tenantParentId

Extracts the parent tenant ID from a tenant map.

Input and output

tenantParentId(map) -> string

Examples

tenantParentId(tenant)
tenantParentId(tenant)

Output: "5000"

tenantPartner

Extracts the partner tenant ID from a tenant map.

Input and output

tenantPartner(map) -> string

Examples

tenantPartner(tenant)
tenantPartner(tenant)

Output: "5000"

tenantPartnerId

Extracts the partner tenant ID from a tenant map.

Input and output

tenantPartnerId(map) -> string

Examples

tenantPartnerId(tenant)
tenantPartnerId(tenant)

Output: "5000"

tenantServices

Returns a list of service names for a tenant.

Input and output

tenantServices(map) -> list

Examples

tenantServices(tenant)
tenantServices(tenant)

Output: ["Access Point", "Ask an Expert", "Data Retention: 60 mo"]

tenantSupportEnabled

Checks whether support is enabled for a tenant.

Input and output

tenantSupportEnabled(map) -> bool

Examples

tenantSupportEnabled(tenant)
tenantSupportEnabled(tenant)

Output: false

toHTML

Returns the provided string as HTML.

Input and output

toHTML(string) -> string

Examples

'**bold**'.toHTML()
'**bold**'.toHTML()

Output: "bold"

toHex

Returns the hexadecimal string representation of a byte list.

Input and output

toHex(bytes) -> string

Examples

md5sum("Hello").toHex()
md5sum("Hello").toHex()

Output: "8b1a9953c4611296a827abf8c47804d7"

toLower

Returns a copy of the string with all characters converted to lowercase.

Input and output

toLower(string) -> string

Examples

"TEST".toLower()
"TEST".toLower()

Output: "test"

toPreferredTimestamp

Returns the user's preferred timestamp format based on the specified timestamp, timezone, and language.

Input and output

toPreferredTimestamp(string, string, string) -> string

Examples

toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')

Output: "Jan 2 2025 15:04 UTC"

toString

Returns the provided value of any data type as a string.

Input and output

toString(any) -> string

Examples

toString(100)
toString(100)

Output: "100"

toTable

Returns a string representation of the provided data as a text or Markdown table.

Input and output

toTable(list, list, list, bool) -> string

Examples

toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)

Output: "+------+------+\\n HEADER1 HEADER2 \\n+------+------+\\n row1_column1 row1_column2 \\n row2_column1 row2_column2 \\n+------+------+"

toTimestamp

Returns a timestamp from a date and time string.

Input and output

toTimestamp(string) -> timestamp

Examples

'1/1/2012'.toTimestamp()
'1/1/2012'.toTimestamp()

Output: "2012-01-01T00:00:00Z"

toTitle

Returns a copy of the string with the first letter of each word converted to uppercase.

Input and output

toTitle(string) -> string

Examples

'hello world'.toTitle()
'hello world'.toTitle()

Output: "Hello World"

toURLQuery

Returns a copy of the string with URL special characters converted to escape sequences.

Input and output

toURLQuery(string) -> string

Examples

'hello world'.toURLQuery()
'hello world'.toURLQuery()

Output: "hello+world"

toUpper

Returns a copy of the string with all characters converted to uppercase.

Input and output

toUpper(string) -> string

Examples

"hello".toUpper()
"hello".toUpper()

Output: "HELLO"

transformList

Iterates on a list or map with an index/key and value, transforming each element into a new list.

Input and output

list.transformList(index, value, expression) -> list
list.transformList(index, value, condition, expression) -> list
map.transformList(key, value, expression) -> list
map.transformList(key, value, condition, expression) -> list

Provides access to both the index/key and value in the transformation expression.

Optionally supports a filter condition.

Examples

[1, 2, 3].transformList(i, v, i * v)
[1, 2, 3].transformList(i, v, i * v)

Output: [0, 2, 6]

[10, 20, 30].transformList(i, v, v + i)
[10, 20, 30].transformList(i, v, v + i)

Output: [10, 21, 32]

[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)

Output: [0, 6]

transformMap

Iterates on a list or map with an index/key and value, transforming values while preserving keys.

Input and output

list.transformMap(index, value, expression) -> map
list.transformMap(index, value, condition, expression) -> map
map.transformMap(key, value, expression) -> map
map.transformMap(key, value, condition, expression) -> map

Provides access to both the index/key and value in the transformation expression.

Optionally supports a filter condition.

Examples

[10, 20, 30].transformMap(i, v, v * 2)
[10, 20, 30].transformMap(i, v, v * 2)

Output: {"0": 20, "1": 40, "2": 60}

[1, 2, 3].transformMap(i, v, i * v)
[1, 2, 3].transformMap(i, v, i * v)

Output: {"0": 0, "1": 2, "2": 6}

[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)

Output: {"0": 0, "2": 6}

{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)

Output: {"a": 10, "b": 20}

transformMapEntry

Iterates on a list or map with an index/key and value, creating custom key-value pairs in a new map.

Input and output

list.transformMapEntry(index, value, expression) -> map
list.transformMapEntry(index, value, condition, expression) -> map
map.transformMapEntry(key, value, expression) -> map
map.transformMapEntry(key, value, condition, expression) -> map

The transformation expression must produce a map literal containing a single entry.

Examples

[1, 2, 3].transformMapEntry(i, v, {string(v): i})
[1, 2, 3].transformMapEntry(i, v, {string(v): i})

Output: {"1": 0, "2": 1, "3": 2}

['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})

Output: {"a": 0, "b": 1, "c": 2}

[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})

Output: {"1": 0, "3": 2}

{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})

Output: {"1": "a", "2": "b"}

trim (string or list)

Removes leading and trailing whitespace.

Input and output

trim(string) -> string
trim(list) -> list

Examples

" 1 ".trim()
" 1 ".trim()

Output: "1"

trim([" 1 ", " 2 ", " 3 "])
trim([" 1 ", " 2 ", " 3 "])

Output: ["1", "2", "3"]

trim (string)

Removes leading and trailing whitespace from the string.

Input and output

string.trim() -> string

Removes spaces, tabs, and newline characters from the beginning and end of the string.

Does not remove whitespace from the middle of the string.

Examples

' hello '.trim()
'  hello  '.trim()

Output: "hello"

'hello world'.trim()
'hello world'.trim()

Output: "hello world"

'\\n\\t test \\n'.trim()
'\\n\\t  test  \\n'.trim()

Output: "test"

' hello world '.trim()
'  hello  world  '.trim()

Output: "hello world"

unique

Returns a copy of the list with duplicate elements removed.

Only elements that are exactly the same (case-sensitive) are removed.

Input and output

unique(list) -> list

Examples

unique(["a", "b", "a"])
unique(["a", "b", "a"])

Output: ["a", "b"]

unwrapOpt

Returns a list containing only the values from optional elements that have values, filtering out optional.none().

Input and output

list(optional(T)).unwrapOpt() -> list(T)

Takes a list of optional values and returns a new list containing only the values from optionals that contain values.

Filters out all optional.none() entries.

Use cases

Filter present values.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

Output: [1, 3]

Remove empty optionals.

Safe map access.
keys.map(k, data[?k]).unwrapOpt()

Get values for existing keys only.

Clean results.
items.map(i, i.?value).unwrapOpt()

Extract only values that are present.

Conditional collection.
data.map(x, x > 0 ? optional.of(x) : optional.none()).unwrapOpt()

Collect values that meet a condition.

Compact operation.
optionalList.unwrapOpt()

Remove all optional.none() values.

Safe transformations.
inputs.map(i, parseValue(i)).unwrapOpt()

Keep only successfully parsed values.

Notes

  • Input: list(optional(T))
  • Output: list(T)
  • Includes only optionals where .hasValue() returns true.
  • Maintains the order of non-empty values.
  • Returns an empty list when all optionals are empty.
  • Also available as optional.unwrap(list).

Examples

[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()

Output: [1, 2, 3]

All values are present.

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()

Output: [1, 3]

Filter out empty optionals.

[optional.none(), optional.none()].unwrapOpt()
[optional.none(), optional.none()].unwrapOpt()

Output: []

All values are empty.

[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]

Output: 1

Access the first present value.

upperAscii

Converts all ASCII characters in the string to uppercase.

Input and output

string.upperAscii() -> string

Converts all ASCII lowercase letters (a-z) to uppercase (A-Z).

Non-ASCII characters are left unchanged.

Examples

'hello World'.upperAscii()
'hello World'.upperAscii()

Output: "HELLO WORLD"

'abc123xyz'.upperAscii()
'abc123xyz'.upperAscii()

Output: "ABC123XYZ"

'café'.upperAscii()
'café'.upperAscii()

Output: "CAFé"

userIds

Parses an alert or entity and returns a list of user IDs.

Input and output

userIds(map) -> list

Examples

userIds(inputs)
userIds(inputs)

Output: ["1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

userInDomain

Returns true if the provided username belongs to one or more of the provided domains.

Input and output

userInDomain(string, list) -> bool

Examples

userInDomain("asdf@example.com", ["example.com"])
userInDomain("asdf@example.com", ["example.com"])

Output: true

userNames

Parses an alert or entity and returns a list of usernames.

Input and output

userNames(map) -> list

Examples

userNames(inputs)
userNames(inputs)

Output: ["sample_user", "another_sample_user"]

users

Parses an alert or entity and returns a list of usernames and user IDs.

Input and output

users(map) -> list

Examples

users(inputs)
users(inputs)

Output: ["sample_user", "another_sample_user", "1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]

value

Returns the value from the optional, or raises an error if the optional is empty.

Input and output

optional(T).value() -> T

Extracts the value from an optional.

If the optional is empty (optional.none()), this causes a runtime error.

Use cases

Extract a known value.
optional.of(42).value()

Output: 42

Get the value directly.

Extract after validation.
opt.hasValue() ? opt.value() : 'default'

Check before extraction.

Fail fast.
requiredField.value()

Raise an error if the field is missing.

Unwrap a result.
computation().value()

Get the result or fail.

Notes

  • Calling .value() on optional.none() causes an error.
  • Always check with .hasValue() first, or use .orValue() instead.
  • Use only when you're certain the optional contains a value.
  • Useful when absence should be treated as an error.
  • For optional chaining, use .orValue().
  • Common in fail-fast scenarios.

Examples

optional.of(42).value()
optional.of(42).value()

Output: 42

Extract an integer value.

optional.of('text').value()
optional.of('text').value()

Output: 'text'

Extract a string value.

[1, 2, 3].first().value()
[1, 2, 3].first().value()

Output: 1

Extract the first element from a list.