Supported CEL Macros๐
Note
The terms Alerts and Investigations have recently been changed to Detections and Cases in Taegis XDR. You may still see references to the old terms while we continue to work towards platform convergence of Sophos and Taegis technologies. For more information, see Taegis Terminology Updates.
The Secureworksยฎ Taegisโข XDR Automations platform can use Googleโs Common Expression Language (CEL) to enable embedding logic and data manipulation within connectors, playbook inputs, playbook triggers, and templates.
XDR supports a number of Googleโs Common Expression Language (CEL) macros that allow you to manipulate and evaluate data. Many macros are built-in, but some have been custom built to address common problems.
In these examples, the following data structure is used:
{
"plant": {
"type": "tree",
"name": "white oak",
"uses": [
"lumber",
"firewood",
"furniture"
],
"traits": {
"produces_fruit": yes,
"genus": "Quercus",
"height": 100,
"extinct": false,
"related_to": [
{
"name": "chestnut",
"genus": "Castanea"
},
{
"name": "beech",
"genus": "Fagus"
}
]
},
"locations": [
"usa",
"europe",
"new york",
"New York",
"new york ",
"usa",
"worldwide",
"eu"
]
}
}
Available macros๐
? (optional operator)๐
? is an optional operator for safe navigation, safe indexing, and conditional inclusion in CEL expressions.
The ? operator provides the following capabilities:
- Safe field navigation (
obj.?field): Access fields without errors. - Safe map indexing (
map[?key]): Access map values safely. - Safe list indexing (
list[?index]): Access list elements safely. - Optional map fields (
{?key: value}): Conditionally include map fields. - Optional list elements (
[?element]): Conditionally include list elements.
After the first ? operator, subsequent accesses are automatically safe (viral chaining): obj.?field.subfield == obj.?field.?subfield.
Notes๐
- The
?operator returns optional values that need.orValue()or.hasValue(). - Safe navigation never throws errors on missing fields, keys, or indices.
- Optional field/element syntax requires optional-typed values.
- Use with
optional.of(),optional.none(), oroptional.ofNonZeroValue().
Examples๐
{'name': 'John'}.?name.orValue('Unknown')
{'name': 'John'}.?name.orValue('Unknown')
Output: 'John'
Safe field navigation.
{}.?name.orValue('Unknown')
{}.?name.orValue('Unknown')
Output: 'Unknown'
Field missing returns optional.none().
{'a': 1, 'b': 2}[?'a'].orValue(0)
{'a': 1, 'b': 2}[?'a'].orValue(0)
Output: 1
Safe map indexing.
{'a': 1}[?'c'].orValue(0)
{'a': 1}[?'c'].orValue(0)
Output: 0
Missing key returns optional.none().
[1, 2, 3][?0].orValue(0)
[1, 2, 3][?0].orValue(0)
Output: 1
Safe list indexing.
[1, 2, 3][?10].orValue(0)
[1, 2, 3][?10].orValue(0)
Output: 0
Out-of-bounds index returns optional.none().
{?'key': optional.of(5)}.size()
{?'key': optional.of(5)}.size()
Output: 1
Optional map field is included.
{?'key': optional.none()}.size()
{?'key': optional.none()}.size()
Output: 0
Optional map field is omitted.
[1, ?optional.of(2), 3].size()
[1, ?optional.of(2), 3].size()
Output: 3
Optional list element is included.
[1, ?optional.none(), 3].size()
[1, ?optional.none(), 3].size()
Output: 2
Optional list element is omitted.
abs๐
Returns the absolute value of the provided argument.
Input and output๐
Examples๐
abs(-1.0)
abs(-1.0)
Output: 1.0
abs(1.0)
abs(1.0)
Output: 1.0
alertAttackTechniqueIds๐
Parses an alert record and returns the attack technique IDs value.
Input and output๐
Examples๐
alertAttackTechniqueIds(inputs)
alertAttackTechniqueIds(inputs)
Output: ["T1096", "T1214"]
alertConfidence๐
Parses an alert record and returns the confidence value.
Input and output๐
Examples๐
alertConfidence(inputs)
alertConfidence(inputs)
Output: 0.5
alertCreatedAtNanos๐
Parses an alert record and returns the nanoseconds value of the time the alert was created.
Input and output๐
Examples๐
alertCreatedAtNanos(inputs)
alertCreatedAtNanos(inputs)
Output: 796357058
alertCreatedAtSeconds๐
Parses an alert record and returns the created_at value as a measure of seconds from epoch.
Input and output๐
Examples๐
alertCreatedAtSeconds(inputs)
alertCreatedAtSeconds(inputs)
Output: 1636029855
alertDescription๐
Parses an alert record and returns the description value.
Input and output๐
Examples๐
alertDescription(inputs)
alertDescription(inputs)
Output: "This is a sample Taegis Watchlist Alert"
alertDestinationIPs๐
Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled destinationIPAddress (case insensitive).
Input and output๐
Examples๐
alertDestinationIPs(inputs)
alertDestinationIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
alertDetectorId๐
Parses an alert record and returns the detector ID value.
Input and output๐
Examples๐
alertDetectorId(inputs)
alertDetectorId(inputs)
Output: "app:event-filter"
alertDetectorName๐
Parses an alert record and returns the detector name value.
Input and output๐
Examples๐
alertDetectorName(inputs)
alertDetectorName(inputs)
Output: "Taegis Watchlist"
alertDomains๐
Parses an alert record and returns a unique list of domain name values from the alert entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).
Input and output๐
Examples๐
alertDomains(inputs)
alertDomains(inputs)
Output: ["example.com", "a.example.com"]
alertEnrichment๐
Parses an alert record and the enrichment data and returns the first value matching the path provided.
Input and output๐
Examples๐
alertEnrichment(inputs, 'rare_program_rare_ip.programs')
alertEnrichment(inputs, 'rare_program_rare_ip.programs')
Output: ["foo.exe", "bar.exe"]
alertEnrichment(inputs, 'doesnotexist')
alertEnrichment(inputs, 'doesnotexist')
Output: []
alertEntities๐
Parses an alert record and returns the entities value.
Input and output๐
Examples๐
alertEntities(inputs)
alertEntities(inputs)
Output: ["hostname:abc", "sensorId:12345", "fileName:c:\windows\syswow64\cmd.exe"]
alertEntity๐
Parses an alert record and returns the entity values that match the provided entity name (case insensitive).
Input and output๐
Examples๐
alertEntity(inputs, 'username')
alertEntity(inputs, 'username')
Output: ["sample_user","another_sample_user"]
alertEventIds๐
Parses an alert record and returns a list of event ID values.
Input and output๐
Examples๐
alertEventIds(inputs)
alertEventIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
alertGroupKey๐
Parses an alert record and returns the group_key value.
Input and output๐
Examples๐
alertGroupKey(inputs)
alertGroupKey(inputs)
Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"
alertHostnames๐
Parses an alert record and returns a unique list of values from the alert entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).
Input and output๐
Examples๐
alertHostnames(inputs)
alertHostnames(inputs)
Output: ["sample_hostname", "another_sample_hostname"]
alertIPs๐
Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled ipAddress (case insensitive).
Input and output๐
Examples๐
alertIPs(inputs)
alertIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
alertId๐
Parses an alert record and returns the ID or UUID.
Input and output๐
Examples๐
alertId(inputs)
alertId(inputs)
Output: "alert://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"
alertInvestigationIds๐
Parses an alert record and returns a list of investigation IDs associated with the alert.
Input and output๐
Examples๐
alertInvestigationIds(inputs)
alertInvestigationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
alertMitreAttackInfo๐
Parses an alert record and returns a list of mitre_attack_info values.
Input and output๐
Examples๐
alertMitreAttackInfo(inputs)
alertMitreAttackInfo(inputs)
Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]
alertObservationIds๐
Parses an alert record and returns a list of observation ID values.
Input and output๐
Examples๐
alertObservationIds(inputs)
alertObservationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
alertReferences๐
Parses an alert record and returns a list of references associated with the alert.
Input and output๐
Examples๐
alertReferences(inputs)
alertReferences(inputs)
Output: [{"description": "External Alert Ref","url": "https://example.com/alert/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]
alertResolution๐
Parses an alert record and returns the resolution value.
Input and output๐
Examples๐
alertResolution(inputs)
alertResolution(inputs)
Output: "open"
alertResolutionReason๐
Parses an alert record and returns the resolution reason value.
Input and output๐
Examples๐
alertResolutionReason(inputs)
alertResolutionReason(inputs)
Output: "Valid activity for this user."
alertRuleId๐
Parses an alert record and returns the rule ID.
Input and output๐
Examples๐
alertRuleId(inputs)
alertRuleId(inputs)
Output: "267658fe-65f1-4145-8753-d45fbf9ed6d3"
alertSensorIds๐
Parses an alert record and returns a list of sensor ID values.
Input and output๐
Examples๐
alertSensorIds(inputs)
alertSensorIds(inputs)
Output: ["12345", "1234-12345-123"]
alertSensorTypes๐
Parses an alert record and returns a list of unique sensor type values (in uppercase).
Input and output๐
Examples๐
alertSensorTypes(inputs)
alertSensorTypes(inputs)
Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]
alertSeverity๐
Parses an alert record and returns the severity value.
Input and output๐
Examples๐
alertSeverity(inputs)
alertSeverity(inputs)
Output: 0.75
alertSeverityNice๐
Parses an alert record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).
Input and output๐
Examples๐
alertSeverityNice(inputs)
alertSeverityNice(inputs)
Output: "High"
alertSourceIPs๐
Parses an alert record and returns a unique list of IP address values from the alert entities field where the entity is labeled sourceIPAddress (case insensitive).
Input and output๐
Examples๐
alertSourceIPs(inputs)
alertSourceIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
alertStatus๐
Parses an alert record and returns the status value.
Input and output๐
Examples๐
alertStatus(inputs)
alertStatus(inputs)
Output: "open"
alertTags๐
Parses an alert record and returns a list of tags.
Input and output๐
Examples๐
alertTags(inputs)
alertTags(inputs)
Output: ["alertRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]
alertTenantId๐
Parses an alert record and returns the tenant ID.
Input and output๐
Examples๐
alertTenantId(inputs)
alertTenantId(inputs)
Output: "12345"
alertThirdPartyDetail๐
Parses an alert record and the third-party detail data and returns the first value matching the path provided.
Input and output๐
Examples๐
alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')
alertThirdPartyDetail(inputs, 'userStates.0.aadUserId')
Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]
alertTitle๐
Parses an alert record and returns the title value.
Input and output๐
Examples๐
alertTitle(inputs)
alertTitle(inputs)
Output: "Taegis Watchlist Alert"
alertUpdatedAtNanos๐
Parses an alert record and returns the nanoseconds value of the time the alert was modified.
Input and output๐
Examples๐
alertUpdatedAtNanos(inputs)
alertUpdatedAtNanos(inputs)
Output: 796357058
alertUpdatedAtSeconds๐
Parses an alert record and returns the updated_at value as a measure of seconds from epoch.
Input and output๐
Examples๐
alertUpdatedAtSeconds(inputs)
alertUpdatedAtSeconds(inputs)
Output: 1697207995554
alertUsernames๐
Parses an alert record and returns a unique list of lowercase username values from the alert entities field where the entity is labeled username (case insensitive).
Input and output๐
Examples๐
alertUsernames(inputs)
alertUsernames(inputs)
Output: ["sample_user", "another_sample_user"]
all๐
Iterates on a list or map and validates that a condition is true for all elements in the list.
Input and output๐
Examples๐
[1,2,3,4].all(x, x > 0)
[1,2,3,4].all(x, x > 0)
Output: true
[1,2,3,0].all(x, x > 0)
[1,2,3,0].all(x, x > 0)
Output: false
append๐
Adds elements to an existing list.
Input and output๐
Examples๐
append([1, 2, 3], 4)
append([1, 2, 3], 4)
Output: [1, 2, 3, 4]
append([], "newElement")
append([], "newElement")
Output: ["newElement"]
assetTags๐
Returns a list of asset tag key/value pairs from an asset. By default, returns both keys and values. Optionally returns only keys or values.
Input and output๐
Examples๐
assetTags(inputs)
assetTags(inputs)
Output: ["t1:v1", "t2:v2"]
assetTags(inputs, "keys")
assetTags(inputs, "keys")
Output: ["t1", "t2"]
assetTags(inputs, "values")
assetTags(inputs, "values")
Output: ["v1", "v2"]
base64.decode๐
Decodes a base64-encoded string to bytes.
Input and output๐
Decodes a base64-encoded string back to its original byte sequence.
Returns empty bytes for empty input.
The input must be a valid base64-encoded string.
Use cases๐
Decode encoded credentials.
base64.decode('dXNlcm5hbWU6cGFzc3dvcmQ=')
Output: b'username:password'
Decode Basic Authentication credentials.
Convert to string.
string(base64.decode('aGVsbG8='))
Output: "hello"
Decode and convert bytes to a string.
Decode API responses.
string(base64.decode(api_response.encoded_data))
Decode base64-encoded API response data.
Validate encoding.
base64.decode(base64.encode(b'test'))
Output: b'test'
Verify round-trip encoding and decoding.
Process encoded input.
string(base64.decode(input.encoded_value))
Decode user-provided base64 input.
Empty input handling.
base64.decode('')
Output: b''
Empty string produces empty bytes.
Chain with string operations.
string(base64.decode('aGVsbG8=')).upperAscii()
Output: "HELLO"
Decode, convert to a string, then uppercase.
Working with JSON.
string(base64.decode('eyJrZXkiOiJ2YWx1ZSJ9'))
Output: '{"key":"value"}'
Decode base64-encoded JSON.
Error handling๐
- Invalid base64 strings will cause an error.
- Padding characters (
=) are handled automatically. - Whitespace in input may cause decoding errors.
Notes๐
- Input must be a valid base64-encoded string.
- Output is always a bytes type.
- Use
string()conversion to get a string from bytes. - Uses standard base64 decoding (RFC 4648).
- This coexists with the custom
decodeBase64()function.
Common patterns๐
Decode and use as string:
Most common pattern: decode and convert to a string.
Decode and process:
Decode, check size, then convert or return a default value.
Round trip validation:
Validate that encoding and decoding work correctly.
Examples๐
base64.decode('aGVsbG8=')
base64.decode('aGVsbG8=')
Output: b'hello'
base64.decode('aGVsbG8gd29ybGQ=')
base64.decode('aGVsbG8gd29ybGQ=')
Output: b'hello world'
base64.decode('dGVzdDEyMw==')
base64.decode('dGVzdDEyMw==')
Output: b'test123'
base64.decode('')
base64.decode('')
Output: b''
base64.encode๐
Encodes bytes to a base64-encoded string.
Input and output๐
Encodes a byte sequence to a base64-encoded string using standard base64 encoding.
Returns an empty string for empty input.
The output is a URL-safe base64 string.
Use cases๐
Encode text for transmission.
base64.encode(b'username:password')
Output: "dXNlcm5hbWU6cGFzc3dvcmQ="
Encode credentials for Basic Authentication.
Encode binary data.
base64.encode(file_content)
Convert binary file content to a text representation.
Data serialization.
base64.encode(b'{"key": "value"}')
Encode JSON data for URL parameters.
Safe string encoding.
base64.encode(b'data with special chars: !@#$%')
Encode strings containing special characters.
Round-trip encoding.
string(base64.decode(base64.encode(b'test')))
Output: "test"
Verify that encoding and decoding work correctly.
Working with string conversion.
base64.encode(bytes(input.text))
Convert a string to bytes, then encode.
Empty input handling.
base64.encode(b'')
Output: ""
Empty bytes produce an empty string.
Notes๐
- Input must be a bytes type. Use
b'...'syntax orbytes()conversion. - Output is always a string.
- Uses standard base64 encoding (RFC 4648).
- Padding characters (
=) are included as needed. - This coexists with the custom
encodeBase64()function.
Examples๐
base64.encode(b'hello')
base64.encode(b'hello')
Output: "aGVsbG8="
base64.encode(b'hello world')
base64.encode(b'hello world')
Output: "aGVsbG8gd29ybGQ="
base64.encode(b'test123')
base64.encode(b'test123')
Output: "dGVzdDEyMw=="
base64.encode(b'')
base64.encode(b'')
Output: ""
caseArchivedAt๐
Parses a case record and returns the date and time it was archived.
Input and output๐
Examples๐
caseArchivedAt(inputs)
caseArchivedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseAssetEvidence๐
Parses a case record and returns the list of asset evidence objects.
Input and output๐
Examples๐
caseAssetEvidence(inputs)
caseAssetEvidence(inputs)
Output: [, ...]
caseAssigneeId๐
Parses a case record and returns the ID of the assignee.
Input and output๐
Examples๐
caseAssigneeId(inputs)
caseAssigneeId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseChangeAfter๐
Returns an optional containing the after value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.
Input and output๐
Examples๐
caseChangeAfter(inputs, 'severity').orValue(0)
caseChangeAfter(inputs, 'severity').orValue(0)
Output: 6
caseChangeAfter(inputs, 'severity').hasValue()
caseChangeAfter(inputs, 'severity').hasValue()
Output: true
caseChangeAfter(inputs, 'nonexistent').orValue(0)
caseChangeAfter(inputs, 'nonexistent').orValue(0)
Output: 0
caseChangeAfter(inputs, 'nonexistent').hasValue()
caseChangeAfter(inputs, 'nonexistent').hasValue()
Output: false
caseChangeBefore๐
Returns an optional containing the before value for a field from delta.changes. Use .orValue() to provide a default or .hasValue() to check presence.
Input and output๐
Examples๐
caseChangeBefore(inputs, 'severity').orValue(0)
caseChangeBefore(inputs, 'severity').orValue(0)
Output: 4
caseChangeBefore(inputs, 'severity').hasValue()
caseChangeBefore(inputs, 'severity').hasValue()
Output: true
caseChangeBefore(inputs, 'nonexistent').orValue(0)
caseChangeBefore(inputs, 'nonexistent').orValue(0)
Output: 0
caseChangeBefore(inputs, 'nonexistent').hasValue()
caseChangeBefore(inputs, 'nonexistent').hasValue()
Output: false
caseChanges๐
Returns the delta.changes map from a case record. Each key is a field name, and each value is a map with before and after entries.
Input and output๐
Examples๐
caseChanges(inputs)
caseChanges(inputs)
Output: {"severity": {"before": 4, "after": 6}, "title": {"before": "Original Case Title", "after": "Updated Case Title"}}
caseCloseReason๐
Parses a case record and returns the reason it was closed.
Input and output๐
Examples๐
caseCloseReason(inputs)
caseCloseReason(inputs)
Output: "reason for closing"
caseClosedAt๐
Parses a case record and returns the date and time it was closed (RFC3339), or an empty string when unset.
Input and output๐
Examples๐
caseClosedAt(inputs)
caseClosedAt(inputs)
Output: "2026-03-09T11:57:04.205591Z"
caseComment๐
Parses a case record and returns the comment associated with it.
Input and output๐
Examples๐
caseComment(inputs)
caseComment(inputs)
Output: "This is a sample comment for the case."
caseCommentAuthorId๐
Parses a case record and returns the ID of the author of the comment.
Input and output๐
Examples๐
caseCommentAuthorId(inputs)
caseCommentAuthorId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseCommentCreatedAt๐
Parses a case record and returns the date and time the comment was created.
Input and output๐
Examples๐
caseCommentCreatedAt(inputs)
caseCommentCreatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseCommentMentions๐
Parses a case record and returns a list of mentions in the comment.
Input and output๐
Examples๐
caseCommentMentions(inputs)
caseCommentMentions(inputs)
Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]
caseCommentOperation๐
Parses a case record and returns the operation type of the comment.
Input and output๐
Examples๐
caseCommentOperation(inputs)
caseCommentOperation(inputs)
Output: "create"
caseContributorIds๐
Parses a case record and returns a list of contributor IDs.
Input and output๐
Examples๐
caseContributorIds(inputs)
caseContributorIds(inputs)
Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]
caseCreatedAt๐
Parses a case record and returns the date and time it was created.
Input and output๐
Examples๐
caseCreatedAt(inputs)
caseCreatedAt(inputs)
Output: "2024-06-20T17:57:45.592464Z"
caseCreatedById๐
Parses a case record and returns the ID of the user that created it.
Input and output๐
Examples๐
caseCreatedById(inputs)
caseCreatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
caseCreatedByPartner๐
Parses a case record and returns true if it was created by a parent of the tenant.
Input and output๐
Examples๐
caseCreatedByPartner(inputs)
caseCreatedByPartner(inputs)
Output: false
caseDetectionEvidence๐
Parses a case record and returns the list of detection evidence objects.
Input and output๐
Examples๐
caseDetectionEvidence(inputs)
caseDetectionEvidence(inputs)
Output: [{id, isGenesis}, ...]
caseEventEvidence๐
Parses a case record and returns the list of event evidence objects.
Input and output๐
Examples๐
caseEventEvidence(inputs)
caseEventEvidence(inputs)
Output: [, ...]
caseFieldChanged๐
Parses a case record and returns true if the provided field was modified.
Input and output๐
Examples๐
caseFieldChanged(inputs, 'priority')
caseFieldChanged(inputs, 'priority')
Output: true
caseFieldChanged(inputs, 'nonexistent_field')
caseFieldChanged(inputs, 'nonexistent_field')
Output: false
caseFileId๐
Parses a case record and returns the file ID from delta.file (File Added events).
Input and output๐
Examples๐
caseFileId(inputs)
caseFileId(inputs)
Output: "f1e2d3c4-b5a6-7890-1234-567890abcdef"
caseFileName๐
Parses a case record and returns the file name from delta.file (File Added events).
Input and output๐
Examples๐
caseFileName(inputs)
caseFileName(inputs)
Output: "evidence.pdf"
caseFileSize๐
Parses a case record and returns the file size from delta.file (File Added events).
Input and output๐
Examples๐
caseFileSize(inputs)
caseFileSize(inputs)
Output: 102400
caseFileStatus๐
Parses a case record and returns the file lifecycle status from delta.file (File Added/Deleted events).
Input and output๐
Examples๐
caseFileStatus(inputs)
caseFileStatus(inputs)
Output: "SCHEDULED"
caseFileUploadedById๐
Parses a case record and returns the user ID that uploaded the file from delta.file (File Added/Deleted events).
Input and output๐
Examples๐
caseFileUploadedById(inputs)
caseFileUploadedById(inputs)
Output: "auth0user123"
caseId๐
Parses a case record and returns the ID.
Input and output๐
Examples๐
caseId(inputs)
caseId(inputs)
Output: "a251201f-9a26-4cd5-81f6-20509999933d"
caseIncidentAdvisorId๐
Parses a case record and returns the incident advisor ID.
Input and output๐
Examples๐
caseIncidentAdvisorId(inputs)
caseIncidentAdvisorId(inputs)
Output: "adv-123"
caseKeyFindings๐
Parses a case record and returns the key findings content.
With an optional second argument, returns a specific field from the keyFindings object (for example, documentType or documentVersion).
Input and output๐
Examples๐
caseKeyFindings(inputs)
caseKeyFindings(inputs)
Output: "Sample Case Key Findings"
caseKeyFindings(inputs, 'documentType')
caseKeyFindings(inputs, 'documentType')
Output: "DOCUMENT_TYPE_MARKDOWN"
caseKeyFindings(inputs, 'documentVersion')
caseKeyFindings(inputs, 'documentVersion')
Output: "1"
caseLinkCreatedAt๐
Returns the link creation timestamp from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkCreatedAt(inputs)
caseLinkCreatedAt(inputs)
Output: "2026-04-30T18:53:00.483028Z"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkCreatedAt(l))
Output: ["2026-04-30T18:53:00.483028Z"]
caseLinkIsInternal๐
Returns whether the link is internal from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkIsInternal(inputs)
caseLinkIsInternal(inputs)
Output: false
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkIsInternal(l))
Output: [false]
caseLinkReference๐
Returns the link reference from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkReference(inputs)
caseLinkReference(inputs)
Output: "EXT-12345"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkReference(l))
Output: ["EXT-12345"]
caseLinkTitle๐
Returns the link title from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkTitle(inputs)
caseLinkTitle(inputs)
Output: "External Ticket"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkTitle(l))
Output: ["External Ticket"]
caseLinkType๐
Returns the link type from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkType(inputs)
caseLinkType(inputs)
Output: "External"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
caseLinks(inputs).filter(l, caseLinkType(l) == 'External')
Output: []
caseLinkUrl๐
Returns the link URL from a case-change event (delta.link) or a bare link record.
Input and output๐
Examples๐
caseLinkUrl(inputs)
caseLinkUrl(inputs)
Output: "https://example.com/tickets/EXT-12345"
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
caseLinks(inputs).filter(l, caseLinkType(l) == 'External').map(l, caseLinkUrl(l))
Output: ["https://example.com/tickets/EXT-12345"]
caseLinks๐
Parses a case record and returns the full list of link objects.
Input and output๐
Examples๐
caseLinks(inputs)
caseLinks(inputs)
Output: [, ]
caseLinksReference๐
Parses a case record and returns the list of reference strings from all links.
Input and output๐
Examples๐
caseLinksReference(inputs)
caseLinksReference(inputs)
Output: ["EXT-12345", "JIRA-456"]
caseLinksTitle๐
Parses a case record and returns the list of title strings from all links.
Input and output๐
Examples๐
caseLinksTitle(inputs)
caseLinksTitle(inputs)
Output: ["External Ticket", "Jira Ticket"]
caseLinksType๐
Parses a case record and returns the list of type strings from all links (for example, External or Jira).
Input and output๐
Examples๐
caseLinksType(inputs)
caseLinksType(inputs)
Output: ["External", "Jira"]
caseLinksUrl๐
Parses a case record and returns the list of URL strings from all links.
Input and output๐
Examples๐
caseLinksUrl(inputs)
caseLinksUrl(inputs)
Output: ["https://example.com/tickets/EXT-12345", "https://jira.example.com/..."]
caseManagedBy๐
Parses a case record and returns the managed-by value (PROVIDER, CUSTOMER, UNKNOWN).
Input and output๐
Examples๐
caseManagedBy(inputs)
caseManagedBy(inputs)
Output: "CUSTOMER"
casePrimaryStatusId๐
Parses a case record and returns the primary status ID.
Input and output๐
Examples๐
casePrimaryStatusId(inputs)
casePrimaryStatusId(inputs)
Output: "8dafe9bc-cbf6-4b27-aff4-8959682f859c"
casePrimaryStatusName๐
Parses a case record and returns the primary status name.
Input and output๐
Examples๐
casePrimaryStatusName(inputs)
casePrimaryStatusName(inputs)
Output: "draft"
casePrimaryStatusTitle๐
Parses a case record and returns the primary status title.
Input and output๐
Examples๐
casePrimaryStatusTitle(inputs)
casePrimaryStatusTitle(inputs)
Output: "Draft"
casePrimaryVerdictId๐
Parses a case record and returns the primary verdict ID.
Input and output๐
Examples๐
casePrimaryVerdictId(inputs)
casePrimaryVerdictId(inputs)
Output: "pv-1"
casePrimaryVerdictName๐
Parses a case record and returns the primary verdict name.
Input and output๐
Examples๐
casePrimaryVerdictName(inputs)
casePrimaryVerdictName(inputs)
Output: "confirmed"
casePrimaryVerdictTitle๐
Parses a case record and returns the primary verdict title.
Input and output๐
Examples๐
casePrimaryVerdictTitle(inputs)
casePrimaryVerdictTitle(inputs)
Output: "Confirmed"
casePriority๐
Parses a case record and returns the priority of the case as a word (Low, Medium, High, Critical).
An optional second argument of true returns the priority as an integer (1-4).
Input and output๐
Examples๐
casePriority(inputs)
casePriority(inputs)
Output: "High"
casePriority(inputs, true)
casePriority(inputs, true)
Output: 3
caseProcessingStatus๐
Parses a case record and returns the processing status map.
Input and output๐
Examples๐
caseProcessingStatus(inputs)
caseProcessingStatus(inputs)
Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}
caseRiskScore๐
Parses a case record and returns the risk score.
Input and output๐
Examples๐
caseRiskScore(inputs)
caseRiskScore(inputs)
Output: 7.2
caseRuleId๐
Parses a case record and returns the auto case rule ID that created it.
Input and output๐
Examples๐
caseRuleId(inputs)
caseRuleId(inputs)
Output: "12345"
caseSearchEvidence๐
Parses a case record and returns the list of search evidence objects.
Input and output๐
Examples๐
caseSearchEvidence(inputs)
caseSearchEvidence(inputs)
Output: [, ...]
caseSecondaryStatusId๐
Parses a case record and returns the secondary status ID.
Input and output๐
Examples๐
caseSecondaryStatusId(inputs)
caseSecondaryStatusId(inputs)
Output: "ss-1"
caseSecondaryStatusName๐
Parses a case record and returns the secondary status name.
Input and output๐
Examples๐
caseSecondaryStatusName(inputs)
caseSecondaryStatusName(inputs)
Output: "under_review"
caseSecondaryStatusReason๐
Parses a case record and returns the list of secondary status reasons.
Input and output๐
Examples๐
caseSecondaryStatusReason(inputs)
caseSecondaryStatusReason(inputs)
Output: ["reason1", "reason2"]
caseSecondaryStatusTitle๐
Parses a case record and returns the secondary status title.
Input and output๐
Examples๐
caseSecondaryStatusTitle(inputs)
caseSecondaryStatusTitle(inputs)
Output: "Under Review"
caseSecondaryVerdictId๐
Parses a case record and returns the secondary verdict ID.
Input and output๐
Examples๐
caseSecondaryVerdictId(inputs)
caseSecondaryVerdictId(inputs)
Output: "sv-1"
caseSecondaryVerdictName๐
Parses a case record and returns the secondary verdict name.
Input and output๐
Examples๐
caseSecondaryVerdictName(inputs)
caseSecondaryVerdictName(inputs)
Output: "malicious"
caseSecondaryVerdictTitle๐
Parses a case record and returns the secondary verdict title.
Input and output๐
Examples๐
caseSecondaryVerdictTitle(inputs)
caseSecondaryVerdictTitle(inputs)
Output: "Malicious"
caseSeverity๐
Parses a case record and returns the severity as a word (Informational, Low, Medium, High, Critical).
For inputs.case, uses severity values 2, 4, 6, 8, and 10. For V1/V2 records, uses priority values 1-4.
An optional second argument of false returns the raw numeric value.
Input and output๐
Examples๐
caseSeverity(inputs)
caseSeverity(inputs)
Output: "Medium"
caseSeverity(inputs, false)
caseSeverity(inputs, false)
Output: 6
caseShortId๐
Parses a case record and returns the short ID.
Input and output๐
Examples๐
caseShortId(inputs)
caseShortId(inputs)
Output: "INV41773"
caseSourceId๐
Parses a case record and returns the source ID.
Input and output๐
Examples๐
caseSourceId(inputs)
caseSourceId(inputs)
Output: "src-auto-001"
caseSourceName๐
Parses a case record and returns the source name.
Input and output๐
Examples๐
caseSourceName(inputs)
caseSourceName(inputs)
Output: "auto_case_rule"
caseSourceTitle๐
Parses a case record and returns the source display title.
Input and output๐
Examples๐
caseSourceTitle(inputs)
caseSourceTitle(inputs)
Output: "Auto-Generated"
caseStatus๐
Parses a case record and returns the status.
Input and output๐
Examples๐
caseStatus(inputs)
caseStatus(inputs)
Output: "OPEN"
caseStatus(inputs, 'v1')
caseStatus(inputs, 'v1')
Output: "Open"
caseTags๐
Parses a case record and returns the list of tags.
Input and output๐
Examples๐
caseTags(inputs)
caseTags(inputs)
Output: ["automation", "playbook"]
caseTenantId๐
Parses a case record and returns the ID of the tenant.
Input and output๐
Examples๐
caseTenantId(inputs)
caseTenantId(inputs)
Output: "12345"
caseThirdPartyId๐
Parses a case record and returns the ID of a third-party record associated with it.
Input and output๐
Examples๐
caseThirdPartyId(inputs)
caseThirdPartyId(inputs)
Output: "bdf9f35a8383121055c9e330ceaad3b8"
caseThirdPartyType๐
Parses a case record and returns the type of a third-party record associated with it.
Input and output๐
Examples๐
caseThirdPartyType(inputs)
caseThirdPartyType(inputs)
Output: "SNOW"
caseTitle๐
Parses a case record and returns the title.
Input and output๐
Examples๐
caseTitle(inputs)
caseTitle(inputs)
Output: "Taegis Watchlist Case"
caseType๐
Parses a case record and returns the type.
An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.
Input and output๐
Examples๐
caseType(inputs)
caseType(inputs)
Output: "SECURITY_INVESTIGATION"
caseType(inputs, 'v1')
caseType(inputs, 'v1')
Output: "Security Investigation"
caseTypeId๐
Parses a case record and returns the raw type ID from the structured type object.
Returns an empty string when the type is absent or not an object.
Input and output๐
Examples๐
caseTypeId(inputs)
caseTypeId(inputs)
Output: "00000006-0000-4000-a000-000000000001"
caseTypeTitle๐
Parses a case record and returns the type display title from the structured type object.
Returns an empty string when the type is absent or not an object.
Input and output๐
Examples๐
caseTypeTitle(inputs)
caseTypeTitle(inputs)
Output: "Investigation"
caseUpdatedAt๐
Parses a case record and returns the date and time of the last update.
Input and output๐
Examples๐
caseUpdatedAt(inputs)
caseUpdatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
caseUpdatedById๐
Parses a case record and returns the ID of the user that last updated it.
Input and output๐
Examples๐
caseUpdatedById(inputs)
caseUpdatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
cel.bind๐
Creates a local variable binding within an expression to avoid recomputing expensive operations.
Input and output๐
Creates a local variable that can be referenced within the expression.
The variable is only available in the scope of the third argument (expression).
This is useful for:
- Avoiding repeated computation of expensive operations.
- Making complex expressions more readable.
- Creating intermediate values for cleaner logic.
The variable name is provided as an identifier (not a string).
The value can be any CEL expression.
The expression is evaluated with the variable in scope.
Use cases๐
Avoid repeated computation.
cel.bind(name, inputs.user.name.uppercase(), name + ' - ' + string(name.size()))
Avoid repeating expensive operations and improve readability.
Simplify complex conditions.
cel.bind(withTax, inputs.price * 1.2, withTax > 100 ? withTax * 0.9 : withTax)
Calculate an intermediate value and reuse it.
Chain multiple bindings.
cel.bind(x, 5, cel.bind(y, x * 2, cel.bind(z, y + 3, x + y + z)))
Output: 26
Create nested variable bindings.
Work with lists.
cel.bind(nums, [1, 2, 3, 4, 5], cel.bind(doubled, nums.map(n, n * 2), doubled.filter(n, n > 5)))
Output: [6, 8, 10]
Double all values, then filter the result.
Complex object access.
cel.bind(user, inputs.users[0], user.name + ' (' + user.email + ')')
Access an object once and reuse it multiple times.
Examples๐
cel.bind(x, 10, x * x)
cel.bind(x, 10, x * x)
Output: 100
cel.bind(user, 'John', 'Hello ' + user)
cel.bind(user, 'John', 'Hello ' + user)
Output: "Hello John"
cel.bind(list, [1,2,3], list.size() + list[0])
cel.bind(list, [1,2,3], list.size() + list[0])
Output: 4
charAt๐
Returns the character at the specified index in the string.
Input and output๐
Returns the character (as a single-character string) at the specified zero-based index.
Returns an empty string if the index is out of bounds.
Examples๐
'hello'.charAt(0)
'hello'.charAt(0)
Output: "h"
'hello'.charAt(4)
'hello'.charAt(4)
Output: "o"
collect๐
Returns a list of map values that match the provided path argument.
Input and output๐
Examples๐
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
[{\"a\": \"value1\"}, {\"b\": \"value2\"}, {\"a\": \"value3\"}].collect('a')
Output: ["value1", "value3"]
contains๐
Returns true if any element in the string or list matches the provided string or list (case-sensitive).
An optional second argument of true causes the match to ignore case.
Input and output๐
contains(string, string) -> bool
contains(string, string, bool) -> bool
contains(string, list) -> bool
contains(string, list, bool) -> bool
contains(list, string) -> bool
contains(list, string, bool) -> bool
contains(list, list) -> bool
contains(list, list, bool) -> bool
Examples๐
"apple".contains("app")
"apple".contains("app")
Output: true
"apple".contains("APP", true)
"apple".contains("APP", true)
Output: true
"apple".contains(["app"])
"apple".contains(["app"])
Output: true
"apple".contains(["APP"], true)
"apple".contains(["APP"], true)
Output: true
["apple", "banana"].contains("app")
["apple", "banana"].contains("app")
Output: true
["apple", "banana"].contains("APP", true)
["apple", "banana"].contains("APP", true)
Output: true
["apple", "banana"].contains(["app"])
["apple", "banana"].contains(["app"])
Output: true
["apple", "banana"].contains(["APP"], true)
["apple", "banana"].contains(["APP"], true)
Output: true
count๐
Returns a count of the list elements that match the provided string argument, or the keys in a map that match it.
Input and output๐
Examples๐
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
count([{"a": "value1"}, {"b": "value2"}, {"a": "value3"}], "a")
Output: 2
createShareLink๐
Returns a Taegis Sharelink for an alert, investigation, or asset.
Input and output๐
Examples๐
createShareLink(inputs)
createShareLink(inputs)
Output: "https://ctpx.secureworks.com/share/14f-ca9d-ad47-34db-2243b945ce2112f"
decodeBase64๐
Returns a decoded base64 input string.
Input and output๐
Examples๐
decodeBase64("aGVsbG8gd29ybGQ=")
decodeBase64("aGVsbG8gd29ybGQ=")
Output: "hello world"
decodeJSON๐
Returns a JSON object after decoding the input string.
Input and output๐
Examples๐
decodeJSON('{"key": "value"}')
decodeJSON('{"key": "value"}')
Output: {"key":"value"}
decodeYAML๐
Decodes YAML input to any data type.
Input and output๐
Examples๐
decodeYAML("key: value")
decodeYAML("key: value")
Output: {"key":"value"}
detectionAttackTechniqueIds๐
Parses a detection record and returns the attack technique IDs value.
Input and output๐
Examples๐
detectionAttackTechniqueIds(inputs)
detectionAttackTechniqueIds(inputs)
Output: ["T1096", "T1214"]
detectionConfidence๐
Parses a detection record and returns the confidence value.
Input and output๐
Examples๐
detectionConfidence(inputs)
detectionConfidence(inputs)
Output: 0.5
detectionCreatedAtNanos๐
Parses a detection record and returns the nanoseconds value of the time the detection was created.
Input and output๐
Examples๐
detectionCreatedAtNanos(inputs)
detectionCreatedAtNanos(inputs)
Output: 796357058
detectionCreatedAtSeconds๐
Parses a detection record and returns the created_at value as a measure of seconds from epoch.
Input and output๐
Examples๐
detectionCreatedAtSeconds(inputs)
detectionCreatedAtSeconds(inputs)
Output: 1636029855
detectionDescription๐
Parses a detection record and returns the description value.
Input and output๐
Examples๐
detectionDescription(inputs)
detectionDescription(inputs)
Output: "This is a sample Taegis Watchlist Detection"
detectionDestinationIPs๐
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled destinationIPAddress (case insensitive).
Input and output๐
Examples๐
detectionDestinationIPs(inputs)
detectionDestinationIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionDetectorId๐
Parses a detection record and returns the detector ID value.
Input and output๐
Examples๐
detectionDetectorId(inputs)
detectionDetectorId(inputs)
Output: "app:event-filter"
detectionDetectorName๐
Parses a detection record and returns the detector name value.
Input and output๐
Examples๐
detectionDetectorName(inputs)
detectionDetectorName(inputs)
Output: "Taegis Watchlist"
detectionDomains๐
Parses a detection record and returns a unique list of domain name values from the detection entities field where the entity is labeled ipdomain, topprivateipdomain, domainname, authdomainname, sourceauthdomainname, or targetauthdomainname (case insensitive).
Input and output๐
Examples๐
detectionDomains(inputs)
detectionDomains(inputs)
Output: ["example.com", "a.example.com"]
detectionEnrichment๐
Parses a detection record and the enrichment data and returns the first value matching the path provided.
Input and output๐
Examples๐
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
detectionEnrichment(inputs, 'rare_program_rare_ip.programs')
Output: ["foo.exe", "bar.exe"]
detectionEnrichment(inputs, 'doesnotexist')
detectionEnrichment(inputs, 'doesnotexist')
Output: []
detectionEntities๐
Parses a detection record and returns the entities value.
Input and output๐
Examples๐
detectionEntities(inputs)
detectionEntities(inputs)
Output: ["hostname:abc", "sensorId:12345", "fileName:c:\windows\syswow64\cmd.exe"]
detectionEntity๐
Parses a detection record and returns the entity values that match the provided entity name (case insensitive).
Input and output๐
Examples๐
detectionEntity(inputs, 'username')
detectionEntity(inputs, 'username')
Output: ["sample_user", "another_sample_user"]
detectionEventIds๐
Parses a detection record and returns a list of event ID values.
Input and output๐
Examples๐
detectionEventIds(inputs)
detectionEventIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionGroupKey๐
Parses a detection record and returns the group_key value.
Input and output๐
Examples๐
detectionGroupKey(inputs)
detectionGroupKey(inputs)
Output: "12345:app:event-filter:80c0809b-153f-4b81-bb7c-52fcb83c7127"
detectionHostnames๐
Parses a detection record and returns a unique list of values from the detection entities field where the entity is labeled hostname, sourcehostname, desthostname, workstationname, or computername (case insensitive).
Input and output๐
Examples๐
detectionHostnames(inputs)
detectionHostnames(inputs)
Output: ["sample_hostname", "another_sample_hostname"]
detectionIPs๐
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled ipAddress (case insensitive).
Input and output๐
Examples๐
detectionIPs(inputs)
detectionIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionId๐
Parses a detection record and returns the ID or UUID.
Input and output๐
Examples๐
detectionId(inputs)
detectionId(inputs)
Output: "detection://priv:endpoint-redcloak:12345:1678899090095:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"
detectionInvestigationIds๐
Parses a detection record and returns a list of investigation IDs associated with the detection.
Input and output๐
Examples๐
detectionInvestigationIds(inputs)
detectionInvestigationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionMitreAttackInfo๐
Parses a detection record and returns a list of mitre_attack_info values.
Input and output๐
Examples๐
detectionMitreAttackInfo(inputs)
detectionMitreAttackInfo(inputs)
Output: [{"description":"Adversaries may attempt...","technique":"Process Discovery","technique_id":"T1057"}]
detectionObservationIds๐
Parses a detection record and returns a list of observation ID values.
Input and output๐
Examples๐
detectionObservationIds(inputs)
detectionObservationIds(inputs)
Output: ["29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "aef81a33-fe5c-43fe-b589-c5ff8c3cce1c"]
detectionReferences๐
Parses a detection record and returns a list of references associated with the detection.
Input and output๐
Examples๐
detectionReferences(inputs)
detectionReferences(inputs)
Output: [{"description": "External Detection Ref", "url": "https://example.com/detection/29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae"}]
detectionResolution๐
Parses a detection record and returns the resolution value.
Input and output๐
Examples๐
detectionResolution(inputs)
detectionResolution(inputs)
Output: "open"
detectionResolutionReason๐
Parses a detection record and returns the resolution reason value.
Input and output๐
Examples๐
detectionResolutionReason(inputs)
detectionResolutionReason(inputs)
Output: "Valid activity for this user."
detectionRuleId๐
Parses a detection record and returns the rule ID.
Input and output๐
Examples๐
detectionRuleId(inputs)
detectionRuleId(inputs)
Output* "267658fe-65f1-4145-8753-d45fbf9ed6d3"
detectionSensorIds๐
Parses a detection record and returns a list of sensor ID values.
Input and output๐
Examples๐
detectionSensorIds(inputs)
detectionSensorIds(inputs)
Output: ["12345", "1234-12345-123"]
detectionSensorTypes๐
Parses a detection record and returns a list of unique sensor type values (in uppercase).
Input and output๐
Examples๐
detectionSensorTypes(inputs)
detectionSensorTypes(inputs)
Output: ["ENDPOINT_REDCLOAK", "ENDPOINT_TAEGIS"]
detectionSeverity๐
Parses a detection record and returns the severity value.
Input and output๐
Examples๐
detectionSeverity(inputs)
detectionSeverity(inputs)
Output: 0.75
detectionSeverityNice๐
Parses a detection record and returns the human-friendly severity value as a word (Informational, Low, Medium, High, Critical).
Input and output๐
Examples๐
detectionSeverityNice(inputs)
detectionSeverityNice(inputs)
Output: "High"
detectionSourceEntities๐
Returns the list of source entities from a detection's source_entities field.
Input and output๐
Examples๐
detectionSourceEntities(inputs)
detectionSourceEntities(inputs)
Output: [{"id": "...", "display_name": "...", "perspective": "SOURCE", ...}]
detectionSourceEntityProperties๐
Filters source_entities by property_type and returns values for the specified property keys.
Input and output๐
Examples๐
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
detectionSourceEntityProperties(inputs, "EntityUser", ["user_name", "original_user_name"])
Output: ["jdoe", "jdoe"]
detectionSourceIPs๐
Parses a detection record and returns a unique list of IP address values from the detection entities field where the entity is labeled sourceIPAddress (case insensitive).
Input and output๐
Examples๐
detectionSourceIPs(inputs)
detectionSourceIPs(inputs)
Output: ["192.168.0.1", "192.168.0.2"]
detectionStatus๐
Parses a detection record and returns the status value.
Input and output๐
Examples๐
detectionStatus(inputs)
detectionStatus(inputs)
Output: "open"
detectionTags๐
Parses a detection record and returns a list of tags.
Input and output๐
Examples๐
detectionTags(inputs)
detectionTags(inputs)
Output: ["detectionRule:29ab783f-d3b5-4d4e-8025-9d36f4e1d2ae", "compactor:handler"]
detectionTargetEntities๐
Returns the list of target entities from a detection's target_entities field.
Input and output๐
Examples๐
detectionTargetEntities(inputs)
detectionTargetEntities(inputs)
Output: [{"id": "...", "display_name": "...", "perspective": "TARGET", ...}]
detectionTargetEntityProperties๐
Filters target_entities by property_type and returns values for the specified property keys.
Input and output๐
Examples๐
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
detectionTargetEntityProperties(inputs, "EntityFileHash", ["hash_value"])
Output: ["abc123def456"]
detectionTenantId๐
Parses a detection record and returns the tenant ID.
Input and output๐
Examples๐
detectionTenantId(inputs)
detectionTenantId(inputs)
Output: "12345"
detectionThirdPartyDetail๐
Parses a detection record and the third-party detail data and returns the first value matching the path provided.
Input and output๐
Examples๐
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
detectionThirdPartyDetail(inputs, 'userStates.0.aadUserId')
Output: ["F86DBD0D-6571-44A0-BAE1-43B83CF430AD"]
detectionTitle๐
Parses a detection record and returns the title value.
Input and output๐
Examples๐
detectionTitle(inputs)
detectionTitle(inputs)
Output: "Taegis Watchlist Detection"
detectionUpdatedAtNanos๐
Parses a detection record and returns the nanoseconds value of the time the detection was modified.
Input and output๐
Examples๐
detectionUpdatedAtNanos(inputs)
detectionUpdatedAtNanos(inputs)
Output: 796357058
detectionUpdatedAtSeconds๐
Parses a detection record and returns the updated_at value as a measure of seconds from epoch.
Input and output๐
Examples๐
detectionUpdatedAtSeconds(inputs)
detectionUpdatedAtSeconds(inputs)
Output: 1697207995554
detectionUsernames๐
Parses a detection record and returns a unique list of lowercase username values from the detection entities field where the entity is labeled username (case insensitive).
Input and output๐
Examples๐
detectionUsernames(inputs)
detectionUsernames(inputs)
Output: ["sample_user", "another_sample_user"]
distinct๐
Removes duplicate elements from a list, preserving the first occurrence of each element.
Input and output๐
Returns a new list containing only unique elements from the original list.
The first occurrence of each element is preserved in the order encountered.
Duplicates are removed.
Use cases๐
Remove duplicates from user input.
user_tags.distinct()
Clean up duplicate tags.
Get unique values.
results.map(r, r.category).distinct()
Get all unique categories from the results.
Deduplicate IDs.
id_list.distinct()
Ensure that there are no duplicate IDs.
Clean data.
inputs.values.distinct()
Remove duplicates.
Use set-like operations.
list1.distinct().size() == list1.size()
Check whether a list has no duplicates.
Combine with a filter.
items.filter(i, i.active).map(i, i.id).distinct()
Get the unique IDs of active items.
Preserve order.
[3, 1, 2, 1, 3].distinct()
Output: [3, 1, 2]
Preserve the order of the first occurrence of each element.
Notes๐
- Preserves the order of the first occurrence.
- Works with any comparable type.
- Empty lists remain empty.
- Doesn't sort the output.
Examples๐
[1, 2, 2, 3, 3, 3].distinct()
[1, 2, 2, 3, 3, 3].distinct()
Output: [1, 2, 3]
Remove duplicate numbers.
['b', 'b', 'c', 'a', 'c'].distinct()
['b', 'b', 'c', 'a', 'c'].distinct()
Output: ['b', 'c', 'a']
Remove duplicate strings and preserve their order.
[1, 2, 3].distinct()
[1, 2, 3].distinct()
Output: [1, 2, 3]
The list is already unique.
[1, 1, 1].distinct()
[1, 1, 1].distinct()
Output: [1]
Remove all duplicate elements.
[].distinct()
[].distinct()
Output: []
An empty list remains empty.
domains๐
Returns true if the provided username argument is in one or more of the provided domains.
Input and output๐
Examples๐
domains(inputs)
domains(inputs)
Output: ["example.com","foo.com"]
encodeBase64๐
Returns an encoded string input as a base64 string.
Input and output๐
Examples๐
encodeBase64("hello world")
encodeBase64("hello world")
Output: "aGVsbG8gd29ybGQ="
encodeJSON๐
Returns an encoded string input as a JSON string.
Input and output๐
Examples๐
encodeJSON({"key":"value"})
encodeJSON({"key":"value"})
Output: "{\"key\":\"value\"}"
encodeYAML๐
Encodes any value as a YAML string.
Input and output๐
Examples๐
encodeYAML({"key":"value"})
encodeYAML({"key":"value"})
Output: "key: value\n"
entityValue๐
Parses an entity record and returns a list of values for the provided entity property.
Input and output๐
Examples๐
entityValue(inputs, "username")
entityValue(inputs, "username")
Output: ["john"]
entityValue(inputs, "nonexistent")
entityValue(inputs, "nonexistent")
Output: []
entityValues๐
Parses an entity record and returns a list of values associated with the entity.
Input and output๐
Examples๐
entityValues(inputs)
entityValues(inputs)
Output: ["example.com", "john@example.com", "john"]
exists๐
Iterates on a list or map and validates that a condition is true for at least one of the elements.
Input and output๐
Examples๐
[1, 2, 3].exists(i, i % 2 != 0)
[1, 2, 3].exists(i, i % 2 != 0)
Output: true
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
{"x": "foo", "y": "bar"}.exists(key, key.startsWith("z"))
Output: false
exists_one๐
Iterates on a list or map and validates that a condition is true for exactly one of the elements.
Input and output๐
Examples๐
[1, 2, 2].exists_one(i, i < 2)
[1, 2, 2].exists_one(i, i < 2)
Output: true
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
{"a": "hello", "aa": "hellohello"}.exists_one(k, k.startsWith("a"))
Output: false
filehashes๐
Returns a list of file hashes from an alert or entity if found.
Input and output๐
Examples๐
filehashes(inputs)
filehashes(inputs)
Output: ["445362b51bf855f62f9af7bb8362c8b27c7bc1ceb1dc88fd41a72de19b779969", "2e5a8590cf6848968fc23de3fa1e25f1", "9785001b0dcf755eddb8af294a373c0b87b2498660f724e76c4d53f9c217c7a3"]
filter๐
Iterates on a list and returns the elements that match the provided criteria.
Input and output๐
Examples๐
["a", "ab", "c"].filter(x, x.contains("a"))
["a", "ab", "c"].filter(x, x.contains("a"))
Output: ["a", "ab"]
["a", "ab", "c"].filter(x, x.contains("d"))
["a", "ab", "c"].filter(x, x.contains("d"))
Output: []
findingCheck๐
Parses an identity finding record and returns the check map, or returns a specific entry when a second argument is provided.
Input and output๐
Examples๐
findingCheck(inputs)
findingCheck(inputs)
Output: {'autoResolutionDisabled':false,'category':'CONFIGURATION', ... }
findingCheck(inputs, "module")
findingCheck(inputs, "module")
Output: "IDENTITY"
findingCheck(inputs, "id")
findingCheck(inputs, "id")
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingCheck(inputs, "title")
findingCheck(inputs, "title")
Output: "Application shall not have unclaimed DNS names that are susceptible to takeover"
findingCheck(inputs, "description")
findingCheck(inputs, "description")
Output: "Threat actors can exploit vulnerabilities in Microsoft Entra ID applications by registering unclaimed subdomains, also known as dangling Fully Qualified Domain Names (FQDNs)."
findingCheck(inputs, "enabled")
findingCheck(inputs, "enabled")
Output: true
findingClosedAt๐
Parses an identity finding record and returns the closed-at timestamp.
Input and output๐
Examples๐
findingClosedAt(inputs)
findingClosedAt(inputs)
Output: "2025-04-28T16:57:49.591956Z"
findingConfidenceScore๐
Parses an identity finding record and returns the confidence score.
Input and output๐
Examples๐
findingConfidenceScore(inputs)
findingConfidenceScore(inputs)
Output: "1.0"
findingFieldChanged๐
Parses a finding record and returns true if the provided field was modified.
Input and output๐
Examples๐
findingFieldChanged(inputs, 'status')
findingFieldChanged(inputs, 'status')
Output: true
findingFieldChanged(inputs, 'nonexistent_field')
findingFieldChanged(inputs, 'nonexistent_field')
Output: false
findingFirstSeen๐
Parses an identity finding record and returns the first-seen timestamp.
Input and output๐
Examples๐
findingFirstSeen(inputs)
findingFirstSeen(inputs)
Output: "2025-03-12T16:57:49.591956Z"
findingId๐
Parses an identity finding record and returns the ID.
Input and output๐
Examples๐
findingId(inputs)
findingId(inputs)
Output: "f1234567-89ab-cdef-0123-456789abcdef"
findingIdentityCity๐
Parses an identity finding record and returns the city from the identity data.
Input and output๐
Examples๐
findingIdentityCity(inputs)
findingIdentityCity(inputs)
Output: "New York"
findingIdentityCompanyName๐
Parses an identity finding record and returns the company name from the identity data.
Input and output๐
Examples๐
findingIdentityCompanyName(inputs)
findingIdentityCompanyName(inputs)
Output: "Example Corp"
findingIdentityCountry๐
Parses an identity finding record and returns the country from the identity data.
Input and output๐
Examples๐
findingIdentityCountry(inputs)
findingIdentityCountry(inputs)
Output: "United States"
findingIdentityCreatedAt๐
Parses an identity finding record and returns the creation timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityCreatedAt(inputs)
findingIdentityCreatedAt(inputs)
Output: "2024-01-15T10:30:00Z"
findingIdentityDepartment๐
Parses an identity finding record and returns the department from the identity data.
Input and output๐
Examples๐
findingIdentityDepartment(inputs)
findingIdentityDepartment(inputs)
Output: "Engineering"
findingIdentityDisplayName๐
Parses an identity finding record and returns the display name from the identity data.
Input and output๐
Examples๐
findingIdentityDisplayName(inputs)
findingIdentityDisplayName(inputs)
Output: "John Doe"
findingIdentityEmails๐
Parses an identity finding record and returns the email addresses from the identity data.
Input and output๐
Examples๐
findingIdentityEmails(inputs)
findingIdentityEmails(inputs)
Output: ["john.doe@example.com", "j.doe@example.com"]
findingIdentityEmployeeId๐
Parses an identity finding record and returns the employee ID from the identity data.
Input and output๐
Examples๐
findingIdentityEmployeeId(inputs)
findingIdentityEmployeeId(inputs)
Output: "EMP12345"
findingIdentityEmployeeType๐
Parses an identity finding record and returns the employee type from the identity data.
Input and output๐
Examples๐
findingIdentityEmployeeType(inputs)
findingIdentityEmployeeType(inputs)
Output: "Full-time"
findingIdentityExternalCreatedAt๐
Parses an identity finding record and returns the external creation timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityExternalCreatedAt(inputs)
findingIdentityExternalCreatedAt(inputs)
Output: "2024-01-15T10:30:00Z"
findingIdentityExternalId๐
Parses an identity finding record and returns the external ID from the identity data.
Input and output๐
Examples๐
findingIdentityExternalId(inputs)
findingIdentityExternalId(inputs)
Output: "ext-12345-abcd"
findingIdentityExternalUpdatedAt๐
Parses an identity finding record and returns the external update timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityExternalUpdatedAt(inputs)
findingIdentityExternalUpdatedAt(inputs)
Output: "2024-01-20T15:45:00Z"
findingIdentityField๐
Parses a finding and returns the value of the specified identity field.
Input and output๐
Examples๐
findingIdentityField(inputs, 'status')
findingIdentityField(inputs, 'status')
Output: "ACTIVE"
findingIdentityField(inputs, 'nonexistent_field')
findingIdentityField(inputs, 'nonexistent_field')
Output:
findingIdentityGivenName๐
Parses an identity finding record and returns the given name from the identity data.
Input and output๐
Examples๐
findingIdentityGivenName(inputs)
findingIdentityGivenName(inputs)
Output: "John"
findingIdentityHasMfa๐
Parses an identity finding record and returns whether MFA is enabled from the identity data.
Input and output๐
Examples๐
findingIdentityHasMfa(inputs)
findingIdentityHasMfa(inputs)
Output: true
findingIdentityHasPasswordlessMfa๐
Parses an identity finding record and returns whether passwordless MFA is enabled from the identity data.
Input and output๐
Examples๐
findingIdentityHasPasswordlessMfa(inputs)
findingIdentityHasPasswordlessMfa(inputs)
Output: false
findingIdentityHireDate๐
Parses an identity finding record and returns the hire date from the identity data.
Input and output๐
Examples๐
findingIdentityHireDate(inputs)
findingIdentityHireDate(inputs)
Output: "2023-06-01"
findingIdentityIsAdmin๐
Parses an identity finding record and returns whether the identity has admin privileges.
Input and output๐
Examples๐
findingIdentityIsAdmin(inputs)
findingIdentityIsAdmin(inputs)
Output: false
findingIdentityIsGuest๐
Parses an identity finding record and returns whether the identity is a guest user.
Input and output๐
Examples๐
findingIdentityIsGuest(inputs)
findingIdentityIsGuest(inputs)
Output: false
findingIdentityLastActiveAt๐
Parses an identity finding record and returns the last active timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityLastActiveAt(inputs)
findingIdentityLastActiveAt(inputs)
Output: "2024-09-01T14:30:00Z"
findingIdentityLastPasswordChangeAt๐
Parses an identity finding record and returns the last password change timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityLastPasswordChangeAt(inputs)
findingIdentityLastPasswordChangeAt(inputs)
Output: "2024-08-15T09:00:00Z"
findingIdentityLeaveDate๐
Parses an identity finding record and returns the leave date from the identity data.
Input and output๐
Examples๐
findingIdentityLeaveDate(inputs)
findingIdentityLeaveDate(inputs)
Output: "2025-01-31"
findingIdentityLocation๐
Parses an identity finding record and returns the location from the identity data.
Input and output๐
Examples๐
findingIdentityLocation(inputs)
findingIdentityLocation(inputs)
Output: "New York Office"
findingIdentityManager๐
Parses an identity finding record and returns the manager from the identity data.
Input and output๐
Examples๐
findingIdentityManager(inputs)
findingIdentityManager(inputs)
Output: "Jane Smith"
findingIdentityMfaMethods๐
Parses an identity finding record and returns the MFA methods from the identity data.
Input and output๐
Examples๐
findingIdentityMfaMethods(inputs)
findingIdentityMfaMethods(inputs)
Output: ["SMS", "Authenticator App"]
findingIdentityOfficeLocation๐
Parses an identity finding record and returns the office location from the identity data.
Input and output๐
Examples๐
findingIdentityOfficeLocation(inputs)
findingIdentityOfficeLocation(inputs)
Output: "Building A, Floor 5"
findingIdentityOfficeZipCode๐
Parses an identity finding record and returns the office zip code from the identity data.
Input and output๐
Examples๐
findingIdentityOfficeZipCode(inputs)
findingIdentityOfficeZipCode(inputs)
Output: "10001"
findingIdentityPhoneNumbers๐
Parses an identity finding record and returns the phone numbers from the identity data.
Input and output๐
Examples๐
findingIdentityPhoneNumbers(inputs)
findingIdentityPhoneNumbers(inputs)
Output: ["+1-555-0123", "+1-555-0124"]
findingIdentityPrimaryDomain๐
Parses an identity finding record and returns the primary domain from the identity data.
Input and output๐
Examples๐
findingIdentityPrimaryDomain(inputs)
findingIdentityPrimaryDomain(inputs)
Output: "example.com"
findingIdentityPrimaryEntityId๐
Parses an identity finding record and returns the primary entity ID from the identity data.
Input and output๐
Examples๐
findingIdentityPrimaryEntityId(inputs)
findingIdentityPrimaryEntityId(inputs)
Output: "entity-12345-abcd"
findingIdentityPrimaryMfaMethod๐
Parses an identity finding record and returns the primary MFA method from the identity data.
Input and output๐
Examples๐
findingIdentityPrimaryMfaMethod(inputs)
findingIdentityPrimaryMfaMethod(inputs)
Output: "Authenticator App"
findingIdentityPrimaryUsername๐
Parses an identity finding record and returns the primary username from the identity data.
Input and output๐
Examples๐
findingIdentityPrimaryUsername(inputs)
findingIdentityPrimaryUsername(inputs)
Output: "john.doe"
findingIdentityProperties๐
Parses an identity finding record and returns the properties map from the identity data.
Input and output๐
Examples๐
findingIdentityProperties(inputs)
findingIdentityProperties(inputs)
Output: {"customAttribute1": "value1", "customAttribute2": "value2"}
findingIdentityProviderId๐
Parses an identity finding record and returns the provider ID from the identity data.
Input and output๐
Examples๐
findingIdentityProviderId(inputs)
findingIdentityProviderId(inputs)
Output: "provider-azure-ad-12345"
findingIdentityRaw๐
Parses an identity finding record and returns the raw identity data.
Input and output๐
Examples๐
findingIdentityRaw(inputs)
findingIdentityRaw(inputs)
Output: {"id": "user-123", "displayName": "John Doe", "mail": "john.doe@example.com"}
findingIdentityRegion๐
Parses an identity finding record and returns the region from the identity data.
Input and output๐
Examples๐
findingIdentityRegion(inputs)
findingIdentityRegion(inputs)
Output: "North America"
findingIdentityStatus๐
Parses an identity finding record and returns the status from the identity data.
Input and output๐
Examples๐
findingIdentityStatus(inputs)
findingIdentityStatus(inputs)
Output: "ACTIVE"
findingIdentitySurname๐
Parses an identity finding record and returns the surname from the identity data.
Input and output๐
Examples๐
findingIdentitySurname(inputs)
findingIdentitySurname(inputs)
Output: "Doe"
findingIdentityTenant๐
Parses an identity finding record and returns the tenant from the identity data.
Input and output๐
Examples๐
findingIdentityTenant(inputs)
findingIdentityTenant(inputs)
Output: 12345
findingIdentityTitle๐
Parses an identity finding record and returns the job title from the identity data.
Input and output๐
Examples๐
findingIdentityTitle(inputs)
findingIdentityTitle(inputs)
Output: "Software Engineer"
findingIdentityUpdatedAt๐
Parses an identity finding record and returns the update timestamp from the identity data.
Input and output๐
Examples๐
findingIdentityUpdatedAt(inputs)
findingIdentityUpdatedAt(inputs)
Output: "2024-09-01T12:00:00Z"
findingIdentityUsageLocation๐
Parses an identity finding record and returns the usage location from the identity data.
Input and output๐
Examples๐
findingIdentityUsageLocation(inputs)
findingIdentityUsageLocation(inputs)
Output: "US"
findingIdentityUsernames๐
Parses an identity finding record and returns the usernames from the identity data.
Input and output๐
Examples๐
findingIdentityUsernames(inputs)
findingIdentityUsernames(inputs)
Output: ["john.doe", "jdoe", "john.doe@example.com"]
findingIdentityZipCode๐
Parses an identity finding record and returns the zip code from the identity data.
Input and output๐
Examples๐
findingIdentityZipCode(inputs)
findingIdentityZipCode(inputs)
Output: "10001"
findingLastModified๐
Parses an identity finding record and returns the last modified timestamp.
Input and output๐
Examples๐
findingLastModified(inputs)
findingLastModified(inputs)
Output: "2025-04-28T16:57:49.591956Z"
findingLastSeen๐
Parses an identity finding record and returns the last seen timestamp.
Input and output๐
Examples๐
findingLastSeen(inputs)
findingLastSeen(inputs)
Output: "2025-04-22T16:57:49.591956Z"
findingOtherReferences๐
Parses an identity finding record and returns the other references list. An optional second argument returns a list of specific entries.
Input and output๐
Examples๐
findingOtherReferences(inputs)
findingOtherReferences(inputs)
Output: [{"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}]
findingOtherReferences(inputs, 'type')
findingOtherReferences(inputs, 'type')
Output: ["microsoft.graph.application"]
findingOtherReferences(inputs, 'id')
findingOtherReferences(inputs, 'id')
Output: ["7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]
findingOtherReferences(inputs, 'logicalType')
findingOtherReferences(inputs, 'logicalType')
Output: ["UNKNOWN"]
findingOtherReferences(inputs, 'derivedType')
findingOtherReferences(inputs, 'derivedType')
Output: ["APP"]
findingOtherReferences(inputs, 'displayName')
findingOtherReferences(inputs, 'displayName')
Output: ["soanceawebapp"]
findingOtherReferences(inputs, 'externalLink')
findingOtherReferences(inputs, 'externalLink')
Output: ["https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"]
findingPrimaryReference๐
Parses an identity finding record and returns the primary reference map. An optional second argument returns a specific entry.
Input and output๐
Examples๐
findingPrimaryReference(inputs)
findingPrimaryReference(inputs)
Output: {"type":"microsoft.graph.servicePrincipal","id":"e98c0bf1-f226-4465-940f-696a79e7bdc6","logicalType":"IDENTITY_SERVICE_PRINCIPAL","derivedType":"APP","displayName":"soanceawebapp","externalLink":"https://portal.azure.com/#view/Microsoft_AAD_RegisteredApps/ApplicationMenuBlade/~/Overview/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"}
findingPrimaryReference(inputs, 'type')
findingPrimaryReference(inputs, 'type')
Output: "microsoft.graph.servicePrincipal"
findingPrimaryReference(inputs, 'id')
findingPrimaryReference(inputs, 'id')
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingPrimaryReference(inputs, 'logicalType')
findingPrimaryReference(inputs, 'logicalType')
Output: "IDENTITY_SERVICE_PRINCIPAL"
findingPrimaryReference(inputs, 'derivedType')
findingPrimaryReference(inputs, 'derivedType')
Output: "APP"
findingPrimaryReference(inputs, 'displayName')
findingPrimaryReference(inputs, 'displayName')
Output: "soanceawebapp"
findingPrimaryReference(inputs, 'externalLink')
findingPrimaryReference(inputs, 'externalLink')
Output: "https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/e98c0bf1-f226-4465-940f-696a79e7bdc6/appId/7fcde2b0-9fda-472a-8be3-3666f92f7aa1"
findingResult๐
Parses an identity finding record and returns the result.
Input and output๐
Examples๐
findingResult(inputs)
findingResult(inputs)
Output: "{\"replyUrls\":[\"https://soanceawebapp.azurewebsites.net/.auth/login/aad/callback\"]}"
findingSeverity๐
Parses an identity finding record and returns the severity label (INFO, LOW, MEDIUM, HIGH, CRITICAL).
An optional second argument of true returns the severity as a double (0.0-1.0).
Input and output๐
Examples๐
findingSeverity(inputs)
findingSeverity(inputs)
Output: "CRITICAL"
findingSeverity(inputs, true)
findingSeverity(inputs, true)
Output: "0.800000011920929"
findingSource๐
Parses an identity finding record and returns the source map. An optional second argument returns a specific entry.
Input and output๐
Examples๐
findingSource(inputs)
findingSource(inputs)
Output: {'id':'63258f26-1d39-4d69-9e85-e409244d9c97','resolved':{...},'type':'IDENTITY_PROVIDER'}
findingSource(inputs, 'type')
findingSource(inputs, 'type')
Output: "IDENTITY_PROVIDER"
findingSource(inputs, 'id')
findingSource(inputs, 'id')
Output: "e98c0bf1-f226-4465-940f-696a79e7bdc6"
findingSource(inputs, 'resolved')
findingSource(inputs, 'resolved')
Output: {'createdAt':'2025-02-03T08:32:21.80852Z','disabledAt':null,'expiration':'2026-06-06T05:00:03Z',...}
findingStatus๐
Parses an identity finding record and returns the status.
Input and output๐
Examples๐
findingStatus(inputs)
findingStatus(inputs)
Output: "OPEN"
findingStatusComments๐
Parses an identity finding record and returns the status comments.
Input and output๐
Examples๐
findingStatusComments(inputs)
findingStatusComments(inputs)
Output: "issue resolved"
findingTenantId๐
Parses an identity finding record and returns the tenant ID.
Input and output๐
Examples๐
findingTenantId(inputs)
findingTenantId(inputs)
Output: "12345"
findingsStatusCommentsUserId๐
Parses an identity finding record and returns the user ID that added the status comments.
Input and output๐
Examples๐
findingsStatusCommentsUserId(inputs)
findingsStatusCommentsUserId(inputs)
Output: "3f59db3b-6b9c-4fb8-a26d-4c53fb334b4e"
first (optional element)๐
Returns an optional containing the first element of a list, or optional.none() if the list is empty.
Input and output๐
Returns an optional containing the first element of a list. If the list is empty, returns optional.none().
Use cases๐
Safe head access.
[1, 2, 3].first().orValue(0)
Get the first element or return a default value.
Check if empty.
items.first().hasValue()
Check whether the list has elements.
Process the first item.
tasks.first().optMap(t, t.priority)
Get the priority of the first task.
Conditional access.
results.first().orValue('No results')
Safely access the first result or return a message.
Chained processing.
data.filter(x, x > 0).first().orValue(-1)
Filter the data, then get the first result.
Validation.
!items.first().hasValue() ? 'Empty list' : 'Has items'
Check whether the list is empty.
Notes๐
- Returns
optional(T), whereTis the element type. - Safely returns
optional.none()for empty lists. - Is more expressive than
list[?0]. - Use
.orValue()to provide a default. - Doesn't modify the original list.
Examples๐
[1, 2, 3].first().orValue(0)
[1, 2, 3].first().orValue(0)
Output: 1
Get the first element.
[].first().hasValue()
[].first().hasValue()
Output: false
Check an empty list.
[].first().orValue(99)
[].first().orValue(99)
Output: 99
Use the default value for an empty list.
['a', 'b', 'c'].first().value()
['a', 'b', 'c'].first().value()
Output: 'a'
Extract the first string.
first (list elements)๐
Returns the first N elements of a list.
Input and output๐
Examples๐
first(["a", "c", "b"], 1)
first(["a", "c", "b"], 1)
Output: ["a"]
flatten๐
Returns a list where all nested lists are combined into a single top-level list.
Input and output๐
Examples๐
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
flatten([["row1col1", "row1col2"], ["row2col1", "row2col2"]])
Output: ["row1col1", "row1col2", "row2col1", "row2col2"]
format (string)๐
Formats the string using printf-style formatting with the provided arguments.
Input and output๐
Formats the string using printf-style format specifiers with values from the list.
Common format specifiers:
%s: String.%d: Integer.%f: Floating-point number.%%: Literal percent sign.
Examples๐
'Hello %s'.format(['World'])
'Hello %s'.format(['World'])
Output: "Hello World"
'Value: %d, Name: %s'.format([42, 'test'])
'Value: %d, Name: %s'.format([42, 'test'])
Output: "Value: 42, Name: test"
'Pi: %.2f'.format([3.14159])
'Pi: %.2f'.format([3.14159])
Output: "Pi: 3.14"
format (timestamp)๐
Returns the string representation of the timestamp using the provided format. See Constants for a list of supported formats.
Input and output๐
Examples๐
"1/1/2012".toTimestamp().format("layout")
"1/1/2012".toTimestamp().format("layout")
Output: 2012-01-01T00:00:00Z
"1/1/2012".toTimestamp().format("dateonly")
"1/1/2012".toTimestamp().format("dateonly")
Output: 2012-01-01
"1/1/2012".toTimestamp().format("Mon")
"1/1/2012".toTimestamp().format("Mon")
Output: Sun
generateString๐
Returns a randomly generated string with the length specified in the first argument and the characters or alphabet provided in the second argument.
Input and output๐
Examples๐
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
generateString(5, "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890")
Output: aPsd2
groupBy๐
Returns a list of map elements grouped by one or more paths and a corresponding count of each grouping.
The first argument is the list to group. The second argument is a list of paths to group by. The optional third argument sorts the list in ascending (asc) or descending (desc) order. The default is ascending.
Input and output๐
Examples๐
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
groupBy([{"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test", "title": "test"}}, {"amap": {"host": "test1", "title": "test"}}], ["amap.host", "amap.title"], "asc")
Output: [{"amap.host": "test1", "amap.title": "test", "count": 1}, {"amap.host": "test", "amap.title": "test", "count": 2}]
has๐
Validates that a key exists, is defined, and has a non-null value.
This macro also supports checking a map for one or more paths. An optional third argument specifies the separator used in the paths.
Input and output๐
Examples๐
has(inputs, "key")
has(inputs, "key")
Output: true
hasValue๐
Returns true if the optional contains a value. Otherwise, returns false.
Input and output๐
Checks whether an optional contains a value.
Use cases๐
Check before access.
obj.?field.hasValue() ? obj.field : 'default'
Safely check for a value before accessing it.
Validate input.
input.?userId.hasValue()
Check whether the field exists.
Use guard clauses.
!optional.none().hasValue()
Output: true
Verify that an optional is empty.
Optional chaining.
data[?'key'].hasValue() && data['key'] > 10
Check that a value exists before comparing it.
Filter present values.
items.filter(i, i.?metadata.hasValue())
Keep only items that have metadata.
Notes๐
- Returns a Boolean value (
trueorfalse). - Is safe to call on any optional.
- Use before calling
.value()to avoid errors. - Is commonly used with conditional expressions.
- Provides an alternative to checking for errors.
Examples๐
optional.of(42).hasValue()
optional.of(42).hasValue()
Output: true
The optional has a value.
optional.none().hasValue()
optional.none().hasValue()
Output: false
The optional has no value.
{'a': 1}[?'a'].hasValue()
{'a': 1}[?'a'].hasValue()
Output: true
The key exists.
{'a': 1}[?'b'].hasValue()
{'a': 1}[?'b'].hasValue()
Output: false
The key is missing.
[1, 2, 3][?0].hasValue()
[1, 2, 3][?0].hasValue()
Output: true
The index exists.
[1, 2, 3][?10].hasValue()
[1, 2, 3][?10].hasValue()
Output: false
The index is out of bounds.
hostnames๐
Parses an alert, entity, or asset and returns the hostnames found.
Input and output๐
Examples๐
hostnames(inputs)
hostnames(inputs)
Output: ["alert_hostname", "entity_hostname", "asset_hostname"]
indexOf๐
Returns the index of the first occurrence of a substring.
Input and output๐
Returns the zero-based index of the first occurrence of the substring.
Returns -1 if the substring isn't found.
The optional second argument specifies the starting position for the search.
Examples๐
'hello world'.indexOf('world')
'hello world'.indexOf('world')
Output: 6
'hello world'.indexOf('o')
'hello world'.indexOf('o')
Output: 4
'hello world'.indexOf('o', 5)
'hello world'.indexOf('o', 5)
Output: 7
'hello world'.indexOf('xyz')
'hello world'.indexOf('xyz')
Output: -1
investigationArchivedAt๐
Parses an investigation record and returns the date and time it was archived.
Input and output๐
Examples๐
investigationArchivedAt(inputs)
investigationArchivedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
investigationAssigneeId๐
Parses an investigation record and returns the ID of the assignee.
Input and output๐
Examples๐
investigationAssigneeId(inputs)
investigationAssigneeId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
investigationCloseReason๐
Parses an investigation record and returns the reason it was closed.
Input and output๐
Examples๐
investigationCloseReason(inputs)
investigationCloseReason(inputs)
Output: "reason for closing"
investigationComment๐
Parses an investigation record and returns the comment associated with it.
Input and output๐
Examples๐
investigationComment(inputs)
investigationComment(inputs)
Output: "This is a sample comment for the investigation."
investigationCommentAuthorId๐
Parses an investigation record and returns the ID of the author of the comment.
Input and output๐
Examples๐
investigationCommentAuthorId(inputs)
investigationCommentAuthorId(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
investigationCommentCreatedAt๐
Parses an investigation record and returns the date and time the comment was created.
Input and output๐
Examples๐
investigationCommentCreatedAt(inputs)
investigationCommentCreatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
investigationCommentMentions๐
Parses an investigation record and returns a list of mentions in the comment.
Input and output๐
Examples๐
investigationCommentMentions(inputs)
investigationCommentMentions(inputs)
Output: ["@secureworks", "@dac1ed31-111-4809-9cc9-9f99b6e"]
investigationCommentOperation๐
Parses an investigation record and returns the operation type of the comment.
Input and output๐
Examples๐
investigationCommentOperation(inputs)
investigationCommentOperation(inputs)
Output: "create"
investigationContributorIds๐
Parses an investigation record and returns a list of contributor IDs.
Input and output๐
Examples๐
investigationContributorIds(inputs)
investigationContributorIds(inputs)
Output: ["dac1ed31-111-4809-9cc9-9f99b6e", "ff0197b0@clients"]
investigationCreatedAt๐
Parses an investigation record and returns the date and time it was created.
Input and output๐
Examples๐
investigationCreatedAt(inputs)
investigationCreatedAt(inputs)
Output: "2024-06-20T17:57:45.592464Z"
investigationCreatedById๐
Parses an investigation record and returns the ID of the user that created it.
Input and output๐
Examples๐
investigationCreatedById(inputs)
investigationCreatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
investigationCreatedByPartner๐
Parses an investigation record and returns true if it was created by a parent of the tenant.
Input and output๐
Examples๐
investigationCreatedByPartner(inputs)
investigationCreatedByPartner(inputs)
Output: false
investigationFieldChanged๐
Parses an investigation record and returns true if the provided field was modified.
Input and output๐
Examples๐
investigationFieldChanged(inputs, 'priority')
investigationFieldChanged(inputs, 'priority')
Output: true
investigationFieldChanged(inputs, 'nonexistent_field')
investigationFieldChanged(inputs, 'nonexistent_field')
Output: false
investigationId๐
Parses an investigation record and returns the ID.
Input and output๐
Examples๐
investigationId(inputs)
investigationId(inputs)
Output: "a251201f-9a26-4cd5-81f6-20509999933d"
investigationKeyFindings๐
Parses an investigation record and returns the key findings.
Input and output๐
Examples๐
investigationKeyFindings(inputs)
investigationKeyFindings(inputs)
Output: "Sample Investigation Key Findings"
investigationPriority๐
Parses an investigation record and returns the priority as a word (Low, Medium, High, or Critical).
An optional second argument of true returns the priority as an integer (1-4).
Input and output๐
Examples๐
investigationPriority(inputs)
investigationPriority(inputs)
Output: "High"
investigationPriority(inputs, true)
investigationPriority(inputs, true)
Output: 3
investigationProcessingStatus๐
Parses an investigation record and returns the processing status map.
Input and output๐
Examples๐
investigationProcessingStatus(inputs)
investigationProcessingStatus(inputs)
Output: {"alerts": "SUCCESS", "assets": "SUCCESS", "events": "SUCCESS"}
investigationRuleId๐
Parses an investigation record and returns the auto investigation rule ID that created it.
Input and output๐
Examples๐
investigationRuleId(inputs)
investigationRuleId(inputs)
Output: "12345"
investigationStatus๐
Parses an investigation record and returns the status.
Input and output๐
Examples๐
investigationStatus(inputs)
investigationStatus(inputs)
Output: "OPEN"
investigationStatus(inputs, "v1")
investigationStatus(inputs, "v1")
Output: "Open"
investigationTenantId๐
Parses an investigation record and returns the ID of the tenant.
Input and output๐
Examples๐
investigationTenantId(inputs)
investigationTenantId(inputs)
Output: "12345"
investigationThirdPartyId๐
Parses an investigation record and returns the ID of a third-party record associated with it.
Input and output๐
Examples๐
investigationThirdPartyId(inputs)
investigationThirdPartyId(inputs)
Output: "bdf9f35a8383121055c9e330ceaad3b8"
investigationThirdPartyType๐
Parses an investigation record and returns the type of a third-party record associated with it.
Input and output๐
Examples๐
investigationThirdPartyType(inputs)
investigationThirdPartyType(inputs)
Output: "SNOW"
investigationTitle๐
Parses an investigation record and returns the title.
Input and output๐
Examples๐
investigationTitle(inputs)
investigationTitle(inputs)
Output: "Taegis Watchlist Investigation"
investigationType๐
Parses an investigation record and returns the type.
An optional second argument of 'v1' or 'v2' converts the type. The default is 'v2'.
Input and output๐
Examples๐
investigationType(inputs)
investigationType(inputs)
Output: "SECURITY_INVESTIGATION"
investigationType(inputs, 'v1')
investigationType(inputs, 'v1')
Output: "Security Investigation"
investigationUpdatedAt๐
Parses an investigation record and returns the date and time of the last update.
Input and output๐
Examples๐
investigationUpdatedAt(inputs)
investigationUpdatedAt(inputs)
Output: "2024-06-20T17:57:46.700164Z"
investigationUpdatedById๐
Parses an investigation record and returns the ID of the user that last updated it.
Input and output๐
Examples๐
investigationUpdatedById(inputs)
investigationUpdatedById(inputs)
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
ipInNetwork๐
Returns true if the first argument IP address is in one or more of the second argument IP network ranges.
The second argument is represented as a list of networks in CIDR notation.
Input and output๐
Examples๐
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
ipInNetwork("10.1.1.1", ["10.0.0.0/8"])
Output: true
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
ipInNetwork("192.168.1.1", ["10.0.0.0/8"])
Output: false
ipsv4๐
Parses an alert or entity and returns a list of IPv4 addresses if found.
Input and output๐
Examples๐
ipsv4(inputs)
ipsv4(inputs)
Output: ["127.0.0.111", "4.3.2.1", "1.2.3.4", "9.8.7.6", "6.7.8.9"]
isCaseClosed๐
Parses a case record and returns whether the case is closed.
Input and output๐
Examples๐
isCaseClosed(inputs)
isCaseClosed(inputs)
Output: false
isCaseVisibleToCustomers๐
Parses a case record and returns whether the case is visible to customers.
Input and output๐
Examples๐
isCaseVisibleToCustomers(inputs)
isCaseVisibleToCustomers(inputs)
Output: true
isDomain๐
Returns true if the provided string argument represents a valid domain.
Input and output๐
Examples๐
isDomain("example.com")
isDomain("example.com")
Output: true
isDomain("not_a_domain")
isDomain("not_a_domain")
Output: false
isEmail๐
Returns true if the provided string argument represents a valid email address.
Input and output๐
Examples๐
isEmail("sara@example.com")
isEmail("sara@example.com")
Output: true
isEmail("not_an_email")
isEmail("not_an_email")
Output: false
isIP๐
Returns true if the provided string argument represents a valid IPv4 address.
Input and output๐
Examples๐
isIP("127.0.0.1")
isIP("127.0.0.1")
Output: true
isIP("not_an_ip")
isIP("not_an_ip")
Output: false
isPrivateIP๐
Returns true if the provided string argument represents a private (RFC-1918), link-local, or loopback IPv4 address.
Input and output๐
Examples๐
isPrivateIP("192.168.1.1")
isPrivateIP("192.168.1.1")
Output: true
isPrivateIP("8.8.8.8")
isPrivateIP("8.8.8.8")
Output: false
isURL๐
Returns true if the provided string argument represents a valid Uniform Resource Locator (URL).
Input and output๐
Examples๐
isURL("https://example.com")
isURL("https://example.com")
Output: true
isURL("not_a_url")
isURL("not_a_url")
Output: false
isUUID๐
Returns true if the provided string argument represents a valid Universally Unique Identifier (UUID).
Input and output๐
Examples๐
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
isUUID("ce53ce61-0745-4b9b-ad16-568a022b6002")
Output: true
isUUID("not_a_uuid")
isUUID("not_a_uuid")
Output: false
join๐
Combines the elements of a list into a string using the provided separator.
The default separator is a comma character.
Input and output๐
Examples๐
join(["a", 1, true])
join(["a", 1, true])
Output: "a,1,true"
join(["a", 1, true], ".")
join(["a", 1, true], ".")
Output: "a.1.true"
keys๐
Returns a list of top-level keys from a map.
Input and output๐
Examples๐
keys({"foo": "bar", "a": "b"})
keys({"foo": "bar", "a": "b"})
Output: ["foo", "a"]
last (list elements)๐
Returns the last N elements of a list.
Input and output๐
Examples๐
last(["a", "c", "b"], 2)
last(["a", "c", "b"], 2)
Output: ["c", "b"]
last (optional element)๐
Returns an optional containing the last element of a list, or optional.none() if the list is empty.
Input and output๐
Returns an optional containing the last element of a list.
If the list is empty, returns optional.none().
Use cases๐
Safe tail access.
[1, 2, 3].last().orValue(0)
Get the last element or return a default value.
Most recent item.
events.last().optMap(e, e.timestamp)
Get the timestamp of the latest event.
Check if empty.
items.last().hasValue()
Check whether the list has elements.
Latest value.
history.last().orValue('No history')
Get the most recent value or a default message.
End of sequence.
sequence.last().orValue(-1) > threshold
Check the last value against a threshold.
Validation.
results.last().hasValue() ? 'Complete' : 'Empty'
Check the state of the list.
Notes๐
- Returns
optional(T), whereTis the element type. - Safely returns
optional.none()for empty lists. - Is more expressive than
list[?list.size()-1]. - Use
.orValue()to provide a default. - Doesn't modify the original list.
Examples๐
[1, 2, 3].last().orValue(0)
[1, 2, 3].last().orValue(0)
Output: 3
Get the last element.
[].last().hasValue()
[].last().hasValue()
Output: false
Check an empty list.
[].last().orValue(99)
[].last().orValue(99)
Output: 99
Use the default value for an empty list.
['a', 'b', 'c'].last().value()
['a', 'b', 'c'].last().value()
Output: 'c'
Extract the last string.
lastIndexOf๐
Returns the index of the last occurrence of a substring.
Input and output๐
Returns the zero-based index of the last occurrence of the substring.
Returns -1 if the substring isn't found.
The optional second argument specifies the ending position for the search.
Examples๐
'hello world'.lastIndexOf('o')
'hello world'.lastIndexOf('o')
Output: 7
'hello world'.lastIndexOf('l')
'hello world'.lastIndexOf('l')
Output: 9
'hello world'.lastIndexOf('o', 6)
'hello world'.lastIndexOf('o', 6)
Output: 4
'hello world'.lastIndexOf('xyz')
'hello world'.lastIndexOf('xyz')
Output: -1
list๐
Converts input to a list.
Input and output๐
Examples๐
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
list([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
Output: [1, 3]
lists.range๐
Generates a list of sequential integers from 0 to n-1.
Input and output๐
Generates a list of integers from 0 (inclusive) to n (exclusive).
Returns [0, 1, 2, ..., n-1].
Returns an empty list for values less than or equal to 0.
Use cases๐
Generate index list.
lists.range(items.size())
Get indices for a list.
Iterate N times.
lists.range(5).map(i, processItem(i))
Execute a function five times with an index.
Create test data.
lists.range(100)
Generate 100 sequential numbers.
Batch processing.
lists.range(totalItems / batchSize).map(i, processBatch(i))
Process items in batches.
Pagination.
lists.range(totalPages)
Generate page numbers.
Fill an array.
lists.range(10).map(i, 'item-' + string(i))
Output: ['item-0', 'item-1', ..., 'item-9']
Create a list of strings.
lowerAscii๐
Converts all ASCII characters in the string to lowercase.
Input and output๐
Converts all ASCII uppercase letters (A-Z) to lowercase (a-z).
Non-ASCII characters are left unchanged.
Examples๐
'HELLO World'.lowerAscii()
'HELLO World'.lowerAscii()
Output: "hello world"
'ABC123XYZ'.lowerAscii()
'ABC123XYZ'.lowerAscii()
Output: "abc123xyz"
'Cafรฉ'.lowerAscii()
'Cafรฉ'.lowerAscii()
Output: "cafรฉ"
map๐
Converts input to a map.
Input and output๐
Examples๐
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
map([{"a": 1, "b": 2}, {"a": 3, "b": 4}].map(x, x.a))
Output: {"1": {"a": 1, "b": 2}, "3": {"a": 3, "b": 4}}
matchGroup๐
Returns a list of strings from the provided regex capture group or groups.
Input and output๐
Examples๐
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
"https://www.example.com".matchGroup("([^:]+:\\/\\/)?([\\w]+[\\.\\w+]+)")
Output: ["https://www.example.com", "https://", "www.example.com"]
math.abs๐
Returns the absolute value of a number.
Input and output๐
Returns the absolute (non-negative) value of the input number.
Works with int, uint, and double types.
Examples๐
math.abs(-5)
math.abs(-5)
Output: 5
math.abs(5)
math.abs(5)
Output: 5
math.abs(-3.14)
math.abs(-3.14)
Output: 3.14
math.abs(0)
math.abs(0)
Output: 0
math.bitAnd๐
Performs a bitwise AND operation on two integers.
Input and output๐
Returns the bitwise AND of two integers.
Each bit in the result is 1 only if both corresponding bits in the operands are 1.
Examples๐
math.bitAnd(5, 3)
math.bitAnd(5, 3)
Output: 1 (0101 & 0011 = 0001)
math.bitAnd(12, 10)
math.bitAnd(12, 10)
Output: 8 (1100 & 1010 = 1000)
math.bitAnd(15, 15)
math.bitAnd(15, 15)
Output: 15
math.bitAnd(7, 0)
math.bitAnd(7, 0)
Output: 0
math.bitNot๐
Performs a bitwise NOT (complement) operation on an integer.
Input and output๐
Returns the bitwise complement of the integer.
Each bit is flipped: 0 becomes 1, and 1 becomes 0.
Examples๐
math.bitNot(0)
math.bitNot(0)
Output: -1
math.bitNot(-1)
math.bitNot(-1)
Output: 0
math.bitNot(5)
math.bitNot(5)
Output: -6
math.bitNot(10)
math.bitNot(10)
Output: -11
math.bitOr๐
Performs a bitwise OR operation on two integers.
Input and output๐
Returns the bitwise OR of two integers.
Each bit in the result is 1 if either corresponding bit in the operands is 1.
Examples๐
math.bitOr(5, 3)
math.bitOr(5, 3)
Output: 7 (0101 0011 = 0111)
math.bitOr(8, 4)
math.bitOr(8, 4)
Output: 12 (1000 0100 = 1100)
math.bitOr(0, 15)
math.bitOr(0, 15)
Output: 15
math.bitOr(7, 0)
math.bitOr(7, 0)
Output: 7
math.bitShiftLeft๐
Shifts the bits of an integer to the left by the specified number of positions.
Input and output๐
Shifts all bits to the left by the specified number of positions.
Zeros are shifted in from the right. This is equivalent to multiplying by 2^n.
Examples๐
math.bitShiftLeft(5, 1)
math.bitShiftLeft(5, 1)
Output: 10 (0101 << 1 = 1010)
math.bitShiftLeft(5, 2)
math.bitShiftLeft(5, 2)
Output: 20 (0101 << 2 = 10100)
math.bitShiftLeft(1, 3)
math.bitShiftLeft(1, 3)
Output: 8
math.bitShiftLeft(3, 4)
math.bitShiftLeft(3, 4)
Output: 48
math.bitShiftRight๐
Shifts the bits of an integer to the right by the specified number of positions.
Input and output๐
Shifts all bits to the right by the specified number of positions.
For unsigned integers, zeros are shifted in from the left.
For signed integers, the sign bit is preserved. This is equivalent to dividing by 2^n.
Examples๐
math.bitShiftRight(10, 1)
math.bitShiftRight(10, 1)
Output: 5 (1010 >> 1 = 0101)
math.bitShiftRight(20, 2)
math.bitShiftRight(20, 2)
Output: 5 (10100 >> 2 = 0101)
math.bitShiftRight(8, 3)
math.bitShiftRight(8, 3)
Output: 1
math.bitShiftRight(48, 4)
math.bitShiftRight(48, 4)
Output: 3
math.bitXor๐
Performs a bitwise XOR (exclusive OR) operation on two integers.
Input and output๐
Returns the bitwise XOR of two integers.
Each bit in the result is 1 if the corresponding bits in the operands are different.
Examples๐
math.bitXor(5, 3)
math.bitXor(5, 3)
Output: 6 (0101 ^ 0011 = 0110)
math.bitXor(12, 10)
math.bitXor(12, 10)
Output: 6 (1100 ^ 1010 = 0110)
math.bitXor(15, 15)
math.bitXor(15, 15)
Output: 0
math.bitXor(7, 0)
math.bitXor(7, 0)
Output: 7
math.ceil๐
Rounds a number up to the nearest integer (towards positive infinity).
Input and output๐
Returns the smallest integer value greater than or equal to the input.
Always rounds up, even for negative numbers.
Examples๐
math.ceil(1.2)
math.ceil(1.2)
Output: 2.0
math.ceil(1.9)
math.ceil(1.9)
Output: 2.0
math.ceil(-1.2)
math.ceil(-1.2)
Output: -1.0
math.ceil(5.0)
math.ceil(5.0)
Output: 5.0
math.floor๐
Rounds a number down to the nearest integer (towards negative infinity).
Input and output๐
Returns the largest integer value less than or equal to the input.
Always rounds down, even for negative numbers.
Examples๐
math.floor(1.2)
math.floor(1.2)
Output: 1.0
math.floor(1.9)
math.floor(1.9)
Output: 1.0
math.floor(-1.2)
math.floor(-1.2)
Output: -2.0
math.floor(5.0)
math.floor(5.0)
Output: 5.0
math.greatest๐
Returns the maximum value from the provided arguments.
Input and output๐
Returns the largest value among all provided arguments.
Accepts a variable number of arguments (int, uint, or double).
All arguments must be of comparable numeric types.
Examples๐
math.greatest(1, 5, 3, 9, 2)
math.greatest(1, 5, 3, 9, 2)
Output: 9
math.greatest(-10, -5, -20)
math.greatest(-10, -5, -20)
Output: -5
math.greatest(1.5, 2.3, 0.9)
math.greatest(1.5, 2.3, 0.9)
Output: 2.3
math.greatest(42)
math.greatest(42)
Output: 42
math.isFinite๐
Checks if a value is a finite number (not NaN or infinity).
Input and output๐
Returns true if the value is a finite number (not NaN or infinity).
Returns false for NaN, positive infinity, or negative infinity.
Examples๐
math.isFinite(3.14)
math.isFinite(3.14)
Output: true
math.isFinite(1.0 / 0.0)
math.isFinite(1.0 / 0.0)
Output: false
math.isFinite(0.0 / 0.0)
math.isFinite(0.0 / 0.0)
Output: false
math.isFinite(-100.5)
math.isFinite(-100.5)
Output: true
math.isInf๐
Checks if a value is positive or negative infinity.
Input and output๐
Returns true if the value is infinity.
Examples๐
math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)
Output: true
math.isInf(-1.0 / 0.0)
math.isInf(-1.0 / 0.0)
Output: true
math.isInf(1.0 / 0.0)
math.isInf(1.0 / 0.0)
Output: true
math.isInf(3.14)
math.isInf(3.14)
Output: false
math.isNaN๐
Checks if a value is NaN (Not a Number).
Input and output๐
Returns true if the value is NaN. Otherwise, returns false.
Only applies to floating-point values.
Examples๐
math.isNaN(0.0 / 0.0)
math.isNaN(0.0 / 0.0)
Output: true
math.isNaN(1.0)
math.isNaN(1.0)
Output: false
math.isNaN(math.sqrt(-1.0))
math.isNaN(math.sqrt(-1.0))
Output: true
math.isNaN(3.14)
math.isNaN(3.14)
Output: false
math.least๐
Returns the minimum value from the provided arguments.
Input and output๐
Returns the smallest value among all provided arguments.
Accepts a variable number of arguments (int, uint, or double).
All arguments must be of comparable numeric types.
Examples๐
math.least(1, 5, 3, 9, 2)
math.least(1, 5, 3, 9, 2)
Output: 1
math.least(-10, -5, -20)
math.least(-10, -5, -20)
Output: -20
math.least(1.5, 2.3, 0.9)
math.least(1.5, 2.3, 0.9)
Output: 0.9
math.least(42)
math.least(42)
Output: 42
math.round๐
Rounds a number to the nearest integer (half away from zero).
Input and output๐
Returns the nearest integer value, rounding half values away from zero.
For positive numbers, 0.5 rounds up. For negative numbers, -0.5 rounds down.
Examples๐
math.round(1.4)
math.round(1.4)
Output: 1.0
math.round(1.5)
math.round(1.5)
Output: 2.0
math.round(-1.5)
math.round(-1.5)
Output: -2.0
math.round(5.0)
math.round(5.0)
Output: 5.0
math.sign๐
Returns the sign of a number: -1 for negative, 0 for zero, and 1 for positive.
Input and output๐
Returns:
-1if the number is negative.0if the number is zero.1if the number is positive.
Examples๐
math.sign(-5)
math.sign(-5)
Output: -1
math.sign(0)
math.sign(0)
Output: 0
math.sign(5)
math.sign(5)
Output: 1
math.sign(-3.14)
math.sign(-3.14)
Output: -1.0
math.sqrt๐
Returns the square root of a number.
Input and output๐
Returns the square root of the input number.
Returns NaN for negative inputs.
Examples๐
math.sqrt(9.0)
math.sqrt(9.0)
Output: 3.0
math.sqrt(16)
math.sqrt(16)
Output: 4.0
math.sqrt(2.0)
math.sqrt(2.0)
Output: 1.414...
math.sqrt(0.0)
math.sqrt(0.0)
Output: 0.0
math.trunc๐
Truncates a number to its integer part (towards zero).
Input and output๐
Returns the integer part of the number by removing the fractional part.
Rounds towards zero for both positive and negative numbers.
Examples๐
math.trunc(1.9)
math.trunc(1.9)
Output: 1.0
math.trunc(-1.9)
math.trunc(-1.9)
Output: -1.0
math.trunc(5.0)
math.trunc(5.0)
Output: 5.0
math.trunc(3.14159)
math.trunc(3.14159)
Output: 3.0
md5sum๐
Returns the computed MD5 digest for the provided string.
Input and output๐
Examples๐
md5sum("Hello").toHex()
md5sum("Hello").toHex()
Output: "8b1a9953c4611296a827abf8c47804d7"
merge๐
Adds elements to an existing map.
Input and output๐
Examples๐
merge({"key1": "val1"}, {"key2": "val2"})
merge({"key1": "val1"}, {"key2": "val2"})
Output: {"key1": "val1", "key2": "val2"}
now๐
Returns the current local time as a timestamp.
Input and output๐
Examples๐
now()
now()
Output: "2025-04-29T12:34:56.789Z"
nowUnixMilli๐
Returns the current time as the number of milliseconds since epoch.
Input and output๐
Examples๐
nowUnixMilli()
nowUnixMilli()
Output: 1742395914211
optFlatMap๐
Transforms the optional's value with a function that returns an optional, flattening the result.
Input and output๐
Applies a transformation that returns an optional.
Unlike optMap, this doesn't nest optionals. If the original optional is empty or the transformation returns optional.none(), the result is optional.none().
Use cases๐
Chained optional access.
optional.of([1, 2, 3]).optFlatMap(l, l[?0])
Get the first element as an optional.
Conditional transformation.
optional.of(value).optFlatMap(v, v > 0 ? optional.of(v * 2) : optional.none())
Transform only if the condition is met.
Safe nested access.
optional.of(user).optFlatMap(u, u.?email)
Access a nested optional value safely.
Zero-value filtering.
optional.of(input).optFlatMap(i, optional.ofNonZeroValue(i.trim()))
Filter empty strings after trimming.
Multiple optional sources.
optional.of(config).optFlatMap(c, c[?'setting'])
Perform an optional map lookup within an optional object.
Notes๐
- Variable binding syntax:
optFlatMap(var, expression returning optional). - Prevents nested optionals such as
optional(optional(T)). - Useful when the transformation itself returns an optional.
- Empty optionals pass through unchanged as
optional.none(). - The transformation only runs when the optional contains a value.
Examples๐
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
optional.of([1, 2, 3]).optFlatMap(l, l[?0]).orValue(0)
Output: 1
optional.of([]).optFlatMap(l, l[?0]).orValue(0)
optional.of([]).optFlatMap(l, l[?0]).orValue(0)
Output: 0
optional.none().optFlatMap(l, l[?0]).orValue(0)
optional.none().optFlatMap(l, l[?0]).orValue(0)
Output: 0
optMap๐
Transforms the optional's value if present, returning a new optional with the transformed value.
Input and output๐
Applies a transformation to the optional's value if present.
The transformation returns a new value that is wrapped in an optional.
If the optional is empty, returns optional.none().
Use cases๐
Transform a value.
optional.of(5).optMap(x, x * 2)
Output: optional(10)
Double the value.
String manipulation.
optional.of('hello').optMap(s, s.upperAscii())
Output: optional('HELLO')
Transform to uppercase.
Property access.
optional.of(user).optMap(u, u.email)
Extract a property from a wrapped object.
Complex calculation.
optional.of([1, 2, 3]).optMap(l, l.size())
Output: optional(3)
Get the size of a list.
Chained transformations.
optional.of(10).optMap(x, x * 2).optMap(x, x + 1).orValue(0)
Output: 21
Chain multiple transformations.
Filter with map.
optional.of([1, 2, 3, 4, 5]).optMap(l, l.filter(x, x > 2))
Transform and filter data.
Safe navigation.
data.?user.optMap(u, u.name).orValue('Anonymous')
Safe nested access with transformation.
Notes๐
- Variable binding syntax:
optMap(var, expression using var). - Returns
optional(R)whereRis the result type. - Empty optionals pass through unchanged.
- Use
.orValue()to extract the final result. - Compare with
.optFlatMap()when the transformation returns an optional.
Examples๐
optional.of(5).optMap(x, x * 2).orValue(0)
optional.of(5).optMap(x, x * 2).orValue(0)
Output: 10
optional.none().optMap(x, x * 2).orValue(0)
optional.none().optMap(x, x * 2).orValue(0)
Output: 0
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
optional.of('hello').optMap(s, s.upperAscii()).orValue('NONE')
Output: 'HELLO'
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
optional.of([1, 2, 3]).optMap(l, l.size()).orValue(0)
Output: 3
optional.none๐
Creates an empty optional value with no content.
Input and output๐
Creates an empty optional value that contains no value.
Use cases๐
Represent a missing value.
optional.none()
Explicit absence of a value.
Use as a default in a conditional.
hasError ? optional.none() : optional.of(result)
Return an empty optional when an error occurs.
Chain with .or().
optional.none().or(optional.of(5))
Fall back to another optional.
Check emptiness.
optional.none().hasValue()
Output: false
Check whether an optional is empty.
Provide a default.
optional.none().orValue('default')
Extract a value with a fallback.
Notes๐
- Represents the absence of a value (similar to
null). .hasValue()returnsfalseforoptional.none().- Calling
.value()onoptional.none()causes an error. - Use
.orValue()to provide a default value. - Use
.or()to chain with other optionals.
Examples๐
optional.none().hasValue()
optional.none().hasValue()
Output: false
optional.none().orValue(42)
optional.none().orValue(42)
Output: 42
optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)
Output: 5
optional.of๐
Creates an optional value containing the given value.
Input and output๐
Creates an optional value that contains the given value.
Any value is considered valid, including zero values.
Use cases๐
Wrap a known value.
optional.of(42)
Create an optional containing 42.
Wrap zero or empty values.
optional.of(0)
Create an optional containing 0.
Wrap an empty string.
optional.of('')
Create an optional containing an empty string.
Chain transformations.
optional.of(5).optMap(x, x * 2)
Transform the wrapped value.
Conditional wrapping.
hasValue ? optional.of(value) : optional.none()
Wrap a value conditionally.
Default value pattern.
optional.of(userInput).orValue('default')
Wrap input with a fallback.
Notes๐
- Accepts any value, including zero values such as
0,'',[], or{}. - Returns
optional(T)whereTis the value type. - Compare with
optional.ofNonZeroValue(), which rejects zero values. - Use
.hasValue()to check whether a value exists. - Use
.orValue()to extract a value with a fallback.
Examples๐
optional.of(42)
optional.of(42)
Output: optional(42)
optional.of('hello')
optional.of('hello')
Output: optional('hello')
optional.of([1, 2, 3])
optional.of([1, 2, 3])
Output: optional([1, 2, 3])
optional.of(0).hasValue()
optional.of(0).hasValue()
Output: true
optional.ofNonZeroValue๐
Creates an optional containing the value only if it's non-zero. Otherwise, returns optional.none().
Input and output๐
Creates an optional containing the given value only if it's not a zero or empty value.
Zero values such as 0, '', [], {}, and null result in optional.none().
Use cases๐
Filter zero values.
optional.ofNonZeroValue(userInput)
Only wrap non-empty input.
Validate non-empty values.
optional.ofNonZeroValue('').hasValue()
Output: false
Check whether a string is non-empty.
Skip empty lists.
optional.ofNonZeroValue([]).orValue([1, 2, 3])
Use a default value for an empty list.
Conditional processing.
optional.ofNonZeroValue(score).optMap(s, s * 100)
Only process non-zero scores.
Null safety.
optional.ofNonZeroValue(null).orValue('N/A')
Handle null values safely.
Notes๐
Zero values by type:
- Numeric:
0,0.0 - String:
'' - List:
[] - Map:
{} - Boolean:
false - Bytes:
b'' - Null:
null
Additional notes:
- Returns
optional.none()for zero values. - Use when you want to treat empty or zero values as absent.
- Compare with
optional.of(), which accepts all values. - Useful for validation and filtering.
Examples๐
optional.ofNonZeroValue(42).hasValue()
optional.ofNonZeroValue(42).hasValue()
Output: true
Non-zero numeric value.
optional.ofNonZeroValue(0).hasValue()
optional.ofNonZeroValue(0).hasValue()
Output: false
Zero is rejected.
optional.ofNonZeroValue('').hasValue()
optional.ofNonZeroValue('').hasValue()
Output: false
Empty string is rejected.
optional.ofNonZeroValue('hello').hasValue()
optional.ofNonZeroValue('hello').hasValue()
Output: true
Non-empty string is accepted.
or๐
Returns the first optional if it has a value. Otherwise, returns the second optional.
Input and output๐
Chains optional values.
If the left optional has a value, it is returned. Otherwise, the right optional is returned.
Evaluation is short-circuited.
Use cases๐
Fallback chain.
optional.none().or(optional.of(5))
Use an alternative optional value.
Multiple sources.
cache[?key].or(database[?key]).or(optional.of(default))
Try cache, then database, then a default value.
Coalesce pattern.
primary.or(secondary).or(tertiary).orValue(fallback)
Chain multiple optional sources.
Safe navigation chain.
obj.?field1.or(obj.?field2).orValue('none')
Try multiple fields in priority order.
Priority-based selection.
premium.?feature.or(basic.?feature)
Prefer a premium feature and fall back to a basic feature.
Notes๐
- Returns
optional(T), notT. - Use
.orValue()at the end to extract the final value. - Short-circuits evaluation when the first optional has a value.
- Useful for chaining multiple optional sources.
- Compare with
.orValue(), which returns a concrete value.
Examples๐
optional.none().or(optional.of(5)).orValue(0)
optional.none().or(optional.of(5)).orValue(0)
Output: 5
optional.of(3).or(optional.of(5)).orValue(0)
optional.of(3).or(optional.of(5)).orValue(0)
Output: 3
optional.none().or(optional.none()).orValue(10)
optional.none().or(optional.none()).orValue(10)
Output: 10
orValue๐
Returns the value from the optional if present. Otherwise, returns the provided default value.
Input and output๐
Extracts the value from an optional if present, otherwise returns the provided default value.
Use cases๐
Provide a default.
optional.none().orValue(42)
Output: 42
Use a default when the optional is empty.
Safe field access.
obj.?field.orValue('N/A')
Get a field value or return a default.
Safe map access.
config[?'timeout'].orValue(30)
Get a configuration value with a fallback.
Safe list access.
items[?0].orValue('empty')
Get the first item or return a default.
Chain operations.
optional.of(5).orValue(0) * 2
Output: 10
Use the extracted value directly in a calculation.
Nested access.
data.?user.?name.orValue('Anonymous')
Safely access nested fields.
Coalesce pattern.
primary.orValue(secondary.orValue(tertiary))
Chain multiple fallback values.
Notes๐
- The default value must match the optional type.
- Always returns a concrete value.
- Safe to use anywhere a normal value is expected.
- More concise than conditional expressions.
- Compare with
.value(), which throws an error for empty optionals.
Examples๐
optional.of(42).orValue(0)
optional.of(42).orValue(0)
Output: 42
optional.none().orValue(0)
optional.none().orValue(0)
Output: 0
optional.of('hello').orValue('default')
optional.of('hello').orValue('default')
Output: 'hello'
{'a': 1}[?'b'].orValue(0)
{'a': 1}[?'b'].orValue(0)
Output: 0
parseURL๐
Returns the provided URL string as a URL map structure.
Input and output๐
Examples๐
parseURL("https://www.example.com")
parseURL("https://www.example.com")
Output: {"Scheme": "https", "Host": "www.example.com", "Path": "", "RawQuery": "", "Fragment": ""}
queryJSON๐
Returns data from the first argument using the JMESPath query provided in the second argument.
Input and output๐
Examples๐
queryJSON(inputs.alert2, "metadata.confidence")
queryJSON(inputs.alert2, "metadata.confidence")
Output: 0.5
random๐
Returns a random value between 0 and .99 (inclusive).
Input and output๐
Examples๐
random()
random()
Output: 0.42
regex.extract๐
Extracts the first match of a regular expression pattern from a string, returning an optional value.
Input and output๐
Applies a regular expression pattern to a string and returns the first match wrapped in an optional.
If the pattern contains a capturing group, the captured value is returned.
If the pattern contains no capturing groups, the entire match is returned.
Returns optional.none() if no match is found.
Notes๐
Pattern syntax:
- Uses RE2 regular expression syntax.
- Capturing groups use parentheses
(). - Backslashes must be escaped in CEL strings.
- Common patterns include
\d,\w, and\s.
Additional notes:
- Returns an optional value. Use
.orValue()or.hasValue(). - Pattern matching proceeds left-to-right and returns only the first match.
- Use
extractAll()to retrieve all matches. - Empty strings and empty patterns are handled gracefully.
- Invalid regex patterns cause compilation errors.
regex.extractAll๐
Extracts all matches of a regular expression pattern from a string as a list.
Input and output๐
Applies a regular expression pattern to a string and returns all matches as a list of strings.
Returns an empty list if no matches are found.
Unlike extract(), this function returns all matches, not just the first one.
Use cases๐
Extract all numbers.
regex.extractAll('test123foo456bar', '\\d+')
Output: ["123", "456"]
Find all numeric sequences.
Extract all words.
regex.extractAll('hello world test', '\\w+')
Output: ["hello", "world", "test"]
Split text into words.
Parse multiple values.
regex.extractAll('192.168.1.1', '\\d+')
Output: ["192", "168", "1", "1"]
Extract all numeric values from an IP address.
Find all email addresses.
regex.extractAll(text, '\\w+@\\w+\\.\\w+')
Extract all email addresses from a string.
Count matches.
regex.extractAll('test123foo456bar', '\\d+').size()
Output: 2
Count the number of numeric sequences.
Check for matches.
regex.extractAll('no-numbers-here', '\\d+').size() == 0
Output: true
Check whether the pattern matches anything.
Extract and process.
regex.extractAll('1,2,3,4,5', '\\d+').map(x, int(x))
Output: [1, 2, 3, 4, 5]
Extract numbers and convert them to integers.
Filter results.
regex.extractAll('a1 b2 c3', '\\w+').filter(x, x.size() > 1)
Output: ["a1", "b2", "c3"]
Extract tokens and filter by length.
Notes๐
- Returns a list instead of an optional value.
- Returns an empty list when no matches are found.
- Capturing groups are ignored. Only full matches are returned.
- Useful for extracting multiple values from a string.
- More efficient than multiple calls to
extract(). - Preserves left-to-right match order.
Examples๐
regex.extractAll('test123foo456bar', '\\d+')
regex.extractAll('test123foo456bar', '\\d+')
Output: ["123", "456"]
regex.extractAll('hello world test', '\\w+')
regex.extractAll('hello world test', '\\w+')
Output: ["hello", "world", "test"]
regex.extractAll('192.168.1.1', '\\d+')
regex.extractAll('192.168.1.1', '\\d+')
Output: ["192", "168", "1", "1"]
regex.extractAll('no-numbers-here', '\\d+')
regex.extractAll('no-numbers-here', '\\d+')
Output: []
regex.replace๐
Replaces occurrences of a regular expression pattern in a string with a replacement string.
Input and output๐
regex.replace(string, pattern, replacement) -> string
regex.replace(string, pattern, replacement, count) -> string
Replaces non-overlapping substrings matching the regex pattern.
Optionally limits the number of replacements using the count argument.
When count is omitted or negative, all occurrences are replaced.
Use cases๐
Simple text replacement.
regex.replace('hello world hello', 'hello', 'hi')
Output: "hi world hi"
Replace all occurrences of hello.
Remove all digits.
regex.replace('test123test456', '\\d+', '')
Output: "testtest"
Remove all numeric sequences.
Mask sensitive data.
regex.replace('ID: 12345', '\\d+', 'XXXXX')
Output: "ID: XXXXX"
Replace numbers with a placeholder.
Limited replacements.
regex.replace('banana', 'a', 'x', 1)
Output: "bxnana"
Replace only the first occurrence.
Replace all with negative count.
regex.replace('banana', 'a', 'x', -1)
Output: "bxnxnx"
Negative count means replace all occurrences.
Normalize whitespace.
regex.replace('hello world test', '\\s+', ' ')
Output: "hello world test"
Replace multiple spaces with a single space.
Clean special characters.
regex.replace('hello@world#test', '[^a-zA-Z0-9]', '')
Output: "helloworldtest"
Remove non-alphanumeric characters.
Format phone numbers.
regex.replace('1234567890', '(\\d{3})(\\d{3})(\\d{4})', '($1) $2-$3')
Format a phone number using capture groups.
Notes๐
- Pattern must be a valid regular expression.
- Replacement string is treated literally except for capture-group references.
- When
countis0, the original string is returned unchanged. - When
countis negative, all matches are replaced. - Non-matching patterns return the original string unchanged.
- Empty patterns match between characters.
Capture group references:
- Use
\1,\2,\3, and so on. - Only numeric capture groups are supported.
- Named capture groups aren't supported in replacement strings.
- Invalid capture-group references cause runtime errors.
Examples๐
regex.replace('hello world hello', 'hello', 'hi')
regex.replace('hello world hello', 'hello', 'hi')
Output: "hi world hi"
regex.replace('banana', 'a', 'x')
regex.replace('banana', 'a', 'x')
Output: "bxnxnx"
regex.replace('test123test456', '\\d+', 'NUM')
regex.replace('test123test456', '\\d+', 'NUM')
Output: "testNUMtestNUM"
regex.replace('banana', 'a', 'x', 1)
regex.replace('banana', 'a', 'x', 1)
Output: "bxnana"
regex.replace('foo bar', 'foo', 'hello')
regex.replace('foo bar', 'hello')
Output: "hello bar"
replace๐
Replaces all occurrences of a substring with another string.
Input and output๐
Replaces occurrences of the first substring with the second substring.
An optional third argument limits the number of replacements. Use -1 to replace all occurrences.
Examples๐
'hello world'.replace('o', 'a')
'hello world'.replace('o', 'a')
Output: "hella warld"
'hello world'.replace('l', 'L')
'hello world'.replace('l', 'L')
Output: "heLLo worLd"
'hello world'.replace('l', 'L', 1)
'hello world'.replace('l', 'L', 1)
Output: "heLlo world"
'hello world'.replace('world', 'universe')
'hello world'.replace('world', 'universe')
Output: "hello universe"
resolvePartnerName๐
Resolves a Taegis tenant ID and returns the partner name.
Input and output๐
Examples๐
resolvePartnerName('12345')
resolvePartnerName('12345')
Output: "Partner Name"
resolveSubjectName๐
Resolves a Taegis user ID or client ID and returns a name string.
Input and output๐
Examples๐
resolveSubjectName('auth0asdf')
resolveSubjectName('auth0asdf')
Output: "GivenName FamilyName"
resolveSubjectName('ff0197b0@clients')
resolveSubjectName('ff0197b0@clients')
Output: "ClientName"
resolveTenantName๐
Resolves a Taegis tenant ID and returns the tenant name.
Input and output๐
Examples๐
resolveTenantName('12345')
resolveTenantName('12345')
Output: "Tenant Name"
resolveUser๐
Resolves a Taegis user by ID, Auth0 ID, or email address and returns the Taegis user ID.
Input and output๐
Examples๐
resolveUser('auth0asdf')
resolveUser('auth0asdf')
Output: "dac1ed31-111-4809-9cc9-9f99b6e"
resolveUserName๐
Resolves a Taegis user ID and returns the username string.
Input and output๐
Examples๐
resolveUserName('auth0asdf')
resolveUserName('auth0asdf')
Output: "GivenName FamilyName"
reverse๐
Reverses the order of elements in a list.
Input and output๐
Returns a new list with elements in reverse order.
The first element becomes the last, and vice versa.
Does not modify the original list.
Use cases๐
Reverse chronological order.
events.reverse()
Show the most recent events first.
Process in reverse.
steps.reverse().map(s, s.execute())
Execute steps in reverse order.
Palindrome check.
list == list.reverse()
Check whether a list is a palindrome.
Last-to-first processing.
queue.reverse()
Process items in LIFO order.
Reverse and filter.
items.reverse().filter(i, i.priority > 5)
Reverse the list and then filter it.
Reverse twice.
list.reverse().reverse() == list
Output: true
Double reversing returns the original list.
Notes๐
- Returns a new list.
- Works with any list type.
- Empty and single-element lists are unchanged.
- Reversing twice returns the original order.
Examples๐
[1, 2, 3, 4].reverse()
[1, 2, 3, 4].reverse()
Output: [4, 3, 2, 1]
['a', 'b', 'c'].reverse()
['a', 'b', 'c'].reverse()
Output: ['c', 'b', 'a']
[1].reverse()
[1].reverse()
Output: [1]
[].reverse()
[].reverse()
Output: []
[5, 3, 1, 2].reverse()
[5, 3, 1, 2].reverse()
Output: [2, 1, 3, 5]
sets.contains๐
Checks whether the first list contains all elements from the second list (subset check).
Input and output๐
Returns true if the first list contains all elements from the second list.
The first list is considered a superset of the second list.
Order doesn't matter.
Duplicates in either list are ignored.
Use cases๐
Permission checking.
sets.contains(user.roles, ['admin'])
Check whether a user has the required role.
Required tags validation.
sets.contains(resource.tags, ['production', 'critical'])
Validate that a resource contains all required tags.
Feature availability.
sets.contains(subscription.features, ['api_access', 'export'])
Check whether a subscription includes all required features.
Empty list handling.
sets.contains([1, 2, 3], [])
Output: true
An empty list is a subset of any list.
Duplicate handling.
sets.contains([1, 1, 2, 2, 3], [1, 2])
Output: true
Duplicates are ignored.
Examples๐
sets.contains([1, 2, 3, 4], [2, 3])
sets.contains([1, 2, 3, 4], [2, 3])
Output: true
sets.contains([1, 2, 3], [3, 2, 1])
sets.contains([1, 2, 3], [3, 2, 1])
Output: true
sets.contains([1, 2, 3], [1, 2, 4])
sets.contains([1, 2, 3], [1, 2, 4])
Output: false
sets.contains(['admin', 'user', 'guest'], ['admin'])
sets.contains(['admin', 'user', 'guest'], ['admin'])
Output: true
sets.equivalent๐
Checks whether two lists contain the same elements, ignoring order and duplicates (set equality).
Input and output๐
Returns true if both lists contain exactly the same elements.
Order doesn't matter.
Duplicates are ignored.
Use cases๐
Compare user permissions.
sets.equivalent(user1.permissions, user2.permissions)
Check whether two users have identical permissions.
Tag comparison.
sets.equivalent(resource1.tags, resource2.tags)
Compare resource tags.
Validate configuration.
sets.equivalent(actual_settings, expected_settings)
Verify that configuration values match.
Empty lists.
sets.equivalent([], [])
Output: true
Empty lists are equivalent.
String comparison.
sets.equivalent(['a', 'b', 'c'], ['c', 'a', 'b'])
Output: true
Works with any comparable type.
Symmetric operation.
sets.equivalent(list1, list2) == sets.equivalent(list2, list1)
Output: true
Argument order doesn't matter.
Examples๐
sets.equivalent([1, 2, 3], [3, 2, 1])
sets.equivalent([1, 2, 3], [3, 2, 1])
Output: true
sets.equivalent([1, 2, 3], [1, 2, 3])
sets.equivalent([1, 2, 3], [1, 2, 3])
Output: true
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
sets.equivalent([1, 1, 2, 3], [1, 2, 3, 3])
Output: true
sets.equivalent([1, 2, 3], [1, 2, 4])
sets.equivalent([1, 2, 3], [1, 2, 4])
Output: false
sets.intersects๐
Checks whether two lists have any common elements (non-empty intersection).
Input and output๐
Returns true if the two lists share at least one common element.
Order doesn't matter.
Duplicates are ignored.
Use cases๐
Role-based access control.
sets.intersects(user.roles, ['admin', 'owner', 'moderator'])
Check whether a user has at least one privileged role.
Tag filtering.
sets.intersects(resource.tags, ['production', 'staging'])
Check whether a resource belongs to a target environment.
Feature flags.
sets.intersects(user.features, ['beta', 'preview'])
Check whether a user has access to beta features.
Category matching.
sets.intersects(product.categories, filter.categories)
Check whether a product belongs to any selected category.
Permission validation.
sets.intersects(user.permissions, required_permissions)
Check whether a user has at least one required permission.
Multiple values check.
sets.intersects([user.status], ['active', 'pending', 'trial'])
Apply OR-style matching across multiple values.
Examples๐
sets.intersects([1, 2, 3], [3, 4, 5])
sets.intersects([1, 2, 3], [3, 4, 5])
Output: true
sets.intersects([1, 2, 3], [4, 5, 6])
sets.intersects([1, 2, 3], [4, 5, 6])
Output: false
sets.intersects(['admin', 'user'], ['admin', 'owner'])
sets.intersects(['admin', 'user'], ['admin', 'owner'])
Output: true
sets.intersects([1, 2, 3], [1, 2, 3])
sets.intersects([1, 2, 3], [1, 2, 3])
Output: true
sha1sum๐
Returns the computed SHA-1 digest for the provided string.
Input and output๐
Examples๐
sha1sum("Hello").toHex()
sha1sum("Hello").toHex()
Output: "f7ff9e8b7bb2e09b70935a5d785e0cc5d9d0abf0"
sha256sum๐
Returns the computed SHA-256 digest for the provided string.
Input and output๐
Examples๐
sha256sum("Hello").toHex()
sha256sum("Hello").toHex()
Output: "185f8db32271fe25f561a6fc938b2e264306ec304eda518007d1764826381969"
sha512sum๐
Returns the computed SHA-512 digest for the provided string.
Input and output๐
Examples๐
sha512sum("Hello").toHex()
sha512sum("Hello").toHex()
Output: "3615f80c9d293ed7402687f94b22d58e529b8cc7916f8fac7fddf7fbd5af4cf777d3d795a7a00a16bf7e7f3fb9561ee9baae480da9fe7a18769e71886b03f315"
slice๐
Extracts a portion of a list between two indices.
Input and output๐
Extracts a sub-list from the start index (inclusive) to the end index (exclusive).
Indices are zero-based.
Use cases๐
Pagination.
results.slice(page * pageSize, (page + 1) * pageSize)
Extract a page of results.
Take the first N elements.
list.slice(0, 5)
Get the first five elements.
Skip the first N elements.
list.slice(3, list.size())
Skip the first three elements.
Get a middle section.
list.slice(2, 8)
Extract a middle portion of the list.
Get the last N elements.
list.slice(list.size() - 3, list.size())
Get the last three elements.
sort๐
Returns a copy of the provided list sorted in ascending order.
The sort order can be reversed to descending by specifying "desc" as the second argument.
Input and output๐
Examples๐
sort(["a", "c", "b"])
sort(["a", "c", "b"])
Output: ["a", "b", "c"]
sort([3, 2, 1], "desc")
sort([3, 2, 1], "desc")
Output: [3, 2, 1]
sortBy๐
Sorts a list by a computed key expression, allowing custom sort criteria.
Input and output๐
Sorts the list based on values computed by the key expression for each element.
The variable name is bound to each element during key computation.
Elements are sorted by their computed keys in ascending order.
Use cases๐
Sort by object property.
users.sortBy(u, u.name)
Sort users alphabetically by name.
Sort by age.
users.sortBy(u, u.age)
Sort users by age.
Descending sort.
scores.sortBy(s, -s.value)
Sort scores in descending order.
Sort by computed value.
products.sortBy(p, p.price * (1 - p.discount))
Sort by the final discounted price.
Sort by string length.
words.sortBy(w, w.size())
Sort words by length.
Sort by multiple criteria.
items.sortBy(i, string(i.priority) + i.name)
Sort by priority and then by name.
Sort by distance.
locations.sortBy(loc, math.abs(loc.lat - target.lat) + math.abs(loc.lon - target.lon))
Sort locations by Manhattan distance.
Sort by Boolean value.
items.sortBy(i, i.active)
Sort with false values first and true values last.
Case insensitive sorting.
names.sortBy(n, n.lowerAscii())
Sort strings without regard to case.
Sort by nested property.
orders.sortBy(o, o.customer.tier)
Sort by a nested property.
Complex calculations.
tasks.sortBy(t, t.priority * 10 + (t.dueDate - now).getHours())
Sort using a weighted priority and time calculation.
Notes๐
- Returns a new sorted list.
- The original list is unchanged.
- The key expression is evaluated for each element.
- Sorting is stable, meaning equal keys keep their relative order.
- Keys must be comparable.
- Negate numeric values to perform a descending sort.
Examples๐
[3, 1, 4, 1, 5, 9].sortBy(x, x)
[3, 1, 4, 1, 5, 9].sortBy(x, x)
Output: [1, 1, 3, 4, 5, 9]
Sort using the value itself as the key.
[3, 1, 4, 1, 5, 9].sortBy(x, -x)
[3, 1, 4, 1, 5, 9].sortBy(x, -x)
Output: [9, 5, 4, 3, 1, 1]
Sort in descending order.
split๐
Splits a string into a list using the specified delimiter.
Input and output๐
Splits the string into a list of substrings using the delimiter.
The optional second argument limits the number of splits. Use -1 for all splits.
Examples๐
'hello world'.split(' ')
'hello world'.split(' ')
Output: ["hello", "world"]
'a,b,c,d'.split(',')
'a,b,c,d'.split(',')
Output: ["a", "b", "c", "d"]
'a,b,c,d'.split(',', 2)
'a,b,c,d'.split(',', 2)
Output: ["a", "b,c,d"]
'one'.split('')
'one'.split('')
Output: ["o", "n", "e"]
substring๐
Extracts a portion of a string between two indices.
Input and output๐
Extracts a substring starting at the first index.
If a second argument is provided, extraction stops before that index.
If only one argument is provided, extraction continues to the end of the string.
Examples๐
'hello world'.substring(0, 5)
'hello world'.substring(0, 5)
Output: "hello"
'hello world'.substring(6)
'hello world'.substring(6)
Output: "world"
'hello world'.substring(6, 11)
'hello world'.substring(6, 11)
Output: "world"
'hello'.substring(1, 4)
'hello'.substring(1, 4)
Output: "ell"
take๐
Returns the first x elements of a list, or the elements between a start and end position.
Input and output๐
Examples๐
take(["a", "c", "b"], 1)
take(["a", "c", "b"], 1)
Output: ["a"]
take(["a", "c", "b"], 0, 2)
take(["a", "c", "b"], 0, 2)
Output: ["a", "c"]
tenantAllowResponseActions๐
Checks whether response actions are allowed for a tenant.
Input and output๐
Examples๐
tenantAllowResponseActions(tenant)
tenantAllowResponseActions(tenant)
Output: true
tenantCentralAccountOrigin๐
Returns the accountOrigin value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralAccountOrigin(tenant)
tenantCentralAccountOrigin(tenant)
Output: "taegis"
tenantCentralAccountType๐
Returns the accountType value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralAccountType(tenant)
tenantCentralAccountType(tenant)
Output: "tenant"
tenantCentralDataRegion๐
Returns the dataRegion value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralDataRegion(tenant)
tenantCentralDataRegion(tenant)
Output: "us03"
tenantCentralId๐
Returns the central tenant ID from the centralTenant map.
Input and output๐
Examples๐
tenantCentralId(tenant)
tenantCentralId(tenant)
Output: "7f8f1dee-98da-4b1b-bb70-1f788254687e"
tenantCentralLastRefresh๐
Returns the lastRefresh value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralLastRefresh(tenant)
tenantCentralLastRefresh(tenant)
Output: "2025-09-23T17:28:01.113261229Z"
tenantCentralRegion๐
Returns the region value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralRegion(tenant)
tenantCentralRegion(tenant)
Output: "us-east-2"
tenantCentralXdrOwnership๐
Returns the xdrOwnership value from the centralTenant map.
Input and output๐
Examples๐
tenantCentralXdrOwnership(tenant)
tenantCentralXdrOwnership(tenant)
Output: "securityOperations"
tenantDataRetentionMonths๐
Extracts the data retention period in months from a tenant map.
Input and output๐
Examples๐
tenantDataRetentionMonths(tenant)
tenantDataRetentionMonths(tenant)
Output: 60
tenantDescription๐
Extracts the tenant description from a tenant map.
Input and output๐
Examples๐
tenantDescription(tenant)
tenantDescription(tenant)
Output: "CTPx Playground"
tenantEnabled๐
Checks whether a tenant is enabled.
Input and output๐
Examples๐
tenantEnabled(tenant)
tenantEnabled(tenant)
Output: true
tenantEnvironments๐
Returns a list of environment names for a tenant.
Input and output๐
Examples๐
tenantEnvironments(tenant)
tenantEnvironments(tenant)
Output: ["pilot", "pilot_1", "pilot_2"]
tenantHasService๐
Checks whether a tenant has a specific service by name (case insensitive).
Input and output๐
Examples๐
tenantHasService(tenant, "MDR")
tenantHasService(tenant, "MDR")
Output: true
tenantId๐
Extracts the tenant ID from a tenant map.
Input and output๐
Examples๐
tenantId(tenant)
tenantId(tenant)
Output: "11772"
tenantIsOrganization๐
Checks whether a tenant is an organization.
Input and output๐
Examples๐
tenantIsOrganization(tenant)
tenantIsOrganization(tenant)
Output: false
tenantIsPartner๐
Checks whether a tenant is a partner.
Input and output๐
Examples๐
tenantIsPartner(tenant)
tenantIsPartner(tenant)
Output: false
tenantIsSophosMDR๐
Returns true when the tenant's licenseLevel is exactly "MDR".
This macro is equivalent to:
Input and output๐
Examples๐
tenantIsSophosMDR(tenant)
tenantIsSophosMDR(tenant)
Output: true
tenantIsSophosXDR๐
Returns true when the tenant is an XDR customer.
Equivalent to:
tenantCentralXdrOwnership(tenant) != 'taegis' &&
tenantCentralXdrOwnership(tenant) != '' &&
tenant.licenseLevel != 'MDR'
Input and output๐
Examples๐
tenantIsSophosXDR(tenant)
tenantIsSophosXDR(tenant)
Output: true
tenantLabelValue๐
Returns the value of a specific label for a tenant.
Input and output๐
Examples๐
tenantLabelValue(tenant, "testing")
tenantLabelValue(tenant, "testing")
Output: "true"
tenantLabels๐
Returns a map of label names to values for a tenant.
Input and output๐
Examples๐
tenantLabels(tenant)
tenantLabels(tenant)
Output: {"testing": "true", "Endpoints Licensed": "2000"}
tenantName๐
Extracts the tenant name from a tenant map.
Input and output๐
Examples๐
tenantName(tenant)
tenantName(tenant)
Output: "CTPx Playground"
tenantOrganization๐
Extracts the organization from a tenant map.
Input and output๐
Examples๐
tenantOrganization(tenant)
tenantOrganization(tenant)
Output: ""
tenantParent๐
Extracts the parent tenant ID from a tenant map.
Input and output๐
Examples๐
tenantParent(tenant)
tenantParent(tenant)
Output: "5000"
tenantParentId๐
Extracts the parent tenant ID from a tenant map.
Input and output๐
Examples๐
tenantParentId(tenant)
tenantParentId(tenant)
Output: "5000"
tenantPartner๐
Extracts the partner tenant ID from a tenant map.
Input and output๐
Examples๐
tenantPartner(tenant)
tenantPartner(tenant)
Output: "5000"
tenantPartnerId๐
Extracts the partner tenant ID from a tenant map.
Input and output๐
Examples๐
tenantPartnerId(tenant)
tenantPartnerId(tenant)
Output: "5000"
tenantServices๐
Returns a list of service names for a tenant.
Input and output๐
Examples๐
tenantServices(tenant)
tenantServices(tenant)
Output: ["Access Point", "Ask an Expert", "Data Retention: 60 mo"]
tenantSupportEnabled๐
Checks whether support is enabled for a tenant.
Input and output๐
Examples๐
tenantSupportEnabled(tenant)
tenantSupportEnabled(tenant)
Output: false
toHTML๐
Returns the provided string as HTML.
Input and output๐
Examples๐
'**bold**'.toHTML()
'**bold**'.toHTML()
Output: "bold"
toHex๐
Returns the hexadecimal string representation of a byte list.
Input and output๐
Examples๐
md5sum("Hello").toHex()
md5sum("Hello").toHex()
Output: "8b1a9953c4611296a827abf8c47804d7"
toLower๐
Returns a copy of the string with all characters converted to lowercase.
Input and output๐
Examples๐
"TEST".toLower()
"TEST".toLower()
Output: "test"
toPreferredTimestamp๐
Returns the user's preferred timestamp format based on the specified timestamp, timezone, and language.
Input and output๐
Examples๐
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
toPreferredTimestamp('2025-01-02T15:04:05Z', 'UTC', 'en')
Output: "Jan 2 2025 15:04 UTC"
toString๐
Returns the provided value of any data type as a string.
Input and output๐
Examples๐
toString(100)
toString(100)
Output: "100"
toTable๐
Returns a string representation of the provided data as a text or Markdown table.
Input and output๐
Examples๐
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
toTable([["row1_column1", "row1_column2"], ["row2_column1", "row2_column2"]], ["header1", "header2"], [], false)
Output: "+------+------+\n HEADER1 HEADER2 \n+------+------+\n row1_column1 row1_column2 \n row2_column1 row2_column2 \n+------+------+"
toTimestamp๐
Returns a timestamp from a date and time string.
Input and output๐
Examples๐
'1/1/2012'.toTimestamp()
'1/1/2012'.toTimestamp()
Output: "2012-01-01T00:00:00Z"
toTitle๐
Returns a copy of the string with the first letter of each word converted to uppercase.
Input and output๐
Examples๐
'hello world'.toTitle()
'hello world'.toTitle()
Output: "Hello World"
toURLQuery๐
Returns a copy of the string with URL special characters converted to escape sequences.
Input and output๐
Examples๐
'hello world'.toURLQuery()
'hello world'.toURLQuery()
Output: "hello+world"
toUpper๐
Returns a copy of the string with all characters converted to uppercase.
Input and output๐
Examples๐
"hello".toUpper()
"hello".toUpper()
Output: "HELLO"
transformList๐
Iterates on a list or map with an index/key and value, transforming each element into a new list.
Input and output๐
list.transformList(index, value, expression) -> list
list.transformList(index, value, condition, expression) -> list
map.transformList(key, value, expression) -> list
map.transformList(key, value, condition, expression) -> list
Provides access to both the index/key and value in the transformation expression.
Optionally supports a filter condition.
Examples๐
[1, 2, 3].transformList(i, v, i * v)
[1, 2, 3].transformList(i, v, i * v)
Output: [0, 2, 6]
[10, 20, 30].transformList(i, v, v + i)
[10, 20, 30].transformList(i, v, v + i)
Output: [10, 21, 32]
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformList(i, v, i % 2 == 0, i * v)
Output: [0, 6]
transformMap๐
Iterates on a list or map with an index/key and value, transforming values while preserving keys.
Input and output๐
list.transformMap(index, value, expression) -> map
list.transformMap(index, value, condition, expression) -> map
map.transformMap(key, value, expression) -> map
map.transformMap(key, value, condition, expression) -> map
Provides access to both the index/key and value in the transformation expression.
Optionally supports a filter condition.
Examples๐
[10, 20, 30].transformMap(i, v, v * 2)
[10, 20, 30].transformMap(i, v, v * 2)
Output: {"0": 20, "1": 40, "2": 60}
[1, 2, 3].transformMap(i, v, i * v)
[1, 2, 3].transformMap(i, v, i * v)
Output: {"0": 0, "1": 2, "2": 6}
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
[1, 2, 3, 4].transformMap(i, v, i % 2 == 0, i * v)
Output: {"0": 0, "2": 6}
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
{'a': 1, 'b': 2}.transformMap(k, v, v * 10)
Output: {"a": 10, "b": 20}
transformMapEntry๐
Iterates on a list or map with an index/key and value, creating custom key-value pairs in a new map.
Input and output๐
list.transformMapEntry(index, value, expression) -> map
list.transformMapEntry(index, value, condition, expression) -> map
map.transformMapEntry(key, value, expression) -> map
map.transformMapEntry(key, value, condition, expression) -> map
The transformation expression must produce a map literal containing a single entry.
Examples๐
[1, 2, 3].transformMapEntry(i, v, {string(v): i})
[1, 2, 3].transformMapEntry(i, v, {string(v): i})
Output: {"1": 0, "2": 1, "3": 2}
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
['a', 'b', 'c'].transformMapEntry(i, v, {v: i})
Output: {"a": 0, "b": 1, "c": 2}
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
[1, 2, 3, 4].transformMapEntry(i, v, i % 2 == 0, {string(v): i})
Output: {"1": 0, "3": 2}
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
{'a': 1, 'b': 2}.transformMapEntry(k, v, {string(v): k})
Output: {"1": "a", "2": "b"}
trim (string or list)๐
Removes leading and trailing whitespace.
Input and output๐
Examples๐
" 1 ".trim()
" 1 ".trim()
Output: "1"
trim([" 1 ", " 2 ", " 3 "])
trim([" 1 ", " 2 ", " 3 "])
Output: ["1", "2", "3"]
trim (string)๐
Removes leading and trailing whitespace from the string.
Input and output๐
Removes spaces, tabs, and newline characters from the beginning and end of the string.
Does not remove whitespace from the middle of the string.
Examples๐
' hello '.trim()
' hello '.trim()
Output: "hello"
'hello world'.trim()
'hello world'.trim()
Output: "hello world"
'\\n\\t test \\n'.trim()
'\\n\\t test \\n'.trim()
Output: "test"
' hello world '.trim()
' hello world '.trim()
Output: "hello world"
unique๐
Returns a copy of the list with duplicate elements removed.
Only elements that are exactly the same (case-sensitive) are removed.
Input and output๐
Examples๐
unique(["a", "b", "a"])
unique(["a", "b", "a"])
Output: ["a", "b"]
unwrapOpt๐
Returns a list containing only the values from optional elements that have values, filtering out optional.none().
Input and output๐
Takes a list of optional values and returns a new list containing only the values from optionals that contain values.
Filters out all optional.none() entries.
Use cases๐
Filter present values.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
Output: [1, 3]
Remove empty optionals.
Safe map access.
keys.map(k, data[?k]).unwrapOpt()
Get values for existing keys only.
Clean results.
items.map(i, i.?value).unwrapOpt()
Extract only values that are present.
Conditional collection.
data.map(x, x > 0 ? optional.of(x) : optional.none()).unwrapOpt()
Collect values that meet a condition.
Compact operation.
optionalList.unwrapOpt()
Remove all optional.none() values.
Safe transformations.
inputs.map(i, parseValue(i)).unwrapOpt()
Keep only successfully parsed values.
Notes๐
- Input:
list(optional(T)) - Output:
list(T) - Includes only optionals where
.hasValue()returnstrue. - Maintains the order of non-empty values.
- Returns an empty list when all optionals are empty.
- Also available as
optional.unwrap(list).
Examples๐
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
[optional.of(1), optional.of(2), optional.of(3)].unwrapOpt()
Output: [1, 2, 3]
All values are present.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()
Output: [1, 3]
Filter out empty optionals.
[optional.none(), optional.none()].unwrapOpt()
[optional.none(), optional.none()].unwrapOpt()
Output: []
All values are empty.
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
[optional.of(1), optional.none(), optional.of(3)].unwrapOpt()[0]
Output: 1
Access the first present value.
upperAscii๐
Converts all ASCII characters in the string to uppercase.
Input and output๐
Converts all ASCII lowercase letters (a-z) to uppercase (A-Z).
Non-ASCII characters are left unchanged.
Examples๐
'hello World'.upperAscii()
'hello World'.upperAscii()
Output: "HELLO WORLD"
'abc123xyz'.upperAscii()
'abc123xyz'.upperAscii()
Output: "ABC123XYZ"
'cafรฉ'.upperAscii()
'cafรฉ'.upperAscii()
Output: "CAFรฉ"
userIds๐
Parses an alert or entity and returns a list of user IDs.
Input and output๐
Examples๐
userIds(inputs)
userIds(inputs)
Output: ["1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]
userInDomain๐
Returns true if the provided username belongs to one or more of the provided domains.
Input and output๐
Examples๐
userInDomain("asdf@example.com", ["example.com"])
userInDomain("asdf@example.com", ["example.com"])
Output: true
userNames๐
Parses an alert or entity and returns a list of usernames.
Input and output๐
Examples๐
userNames(inputs)
userNames(inputs)
Output: ["sample_user", "another_sample_user"]
users๐
Parses an alert or entity and returns a list of usernames and user IDs.
Input and output๐
Examples๐
users(inputs)
users(inputs)
Output: ["sample_user", "another_sample_user", "1234", "dac1ed31-111-4809-9cc9-9f99b6e", "5678"]
value๐
Returns the value from the optional, or raises an error if the optional is empty.
Input and output๐
Extracts the value from an optional.
If the optional is empty (optional.none()), this causes a runtime error.
Use cases๐
Extract a known value.
optional.of(42).value()
Output: 42
Get the value directly.
Extract after validation.
opt.hasValue() ? opt.value() : 'default'
Check before extraction.
Fail fast.
requiredField.value()
Raise an error if the field is missing.
Unwrap a result.
computation().value()
Get the result or fail.
Notes๐
- Calling
.value()onoptional.none()causes an error. - Always check with
.hasValue()first, or use.orValue()instead. - Use only when you're certain the optional contains a value.
- Useful when absence should be treated as an error.
- For optional chaining, use
.orValue(). - Common in fail-fast scenarios.
Examples๐
optional.of(42).value()
optional.of(42).value()
Output: 42
Extract an integer value.
optional.of('text').value()
optional.of('text').value()
Output: 'text'
Extract a string value.
[1, 2, 3].first().value()
[1, 2, 3].first().value()
Output: 1
Extract the first element from a list.