# Operator Support per Field

Search endpoints now list their searchable fields grouped by the operators each field accepts, measured against the API, and the docs show the forms a filter error takes.

Source: https://docs.deepinfo.com/changelog/operator-support/

---
Date: 2026-09-27 · Tags: API, Docs

Which filter operators a search field accepts is set per field, and the field's type does not tell you.
The reference now shows it for each field.

- **Fields grouped by operator.** On each search endpoint's reference page, **Filtering** lists the
  searchable fields grouped by the operators they accept. The groups come from measurement: each operator
  was sent to each field against the API. [Search & Filters](/getting-started/search-and-filters/#which-operators-a-field-accepts)
  explains the groups and links the **Filtering** section of each search.
- **Fields that could not be measured.** `website.parent_asset.type` in Asset Search, and
  `source_format` and `network` in Compromised Payment Credential Search, take a value from a fixed list.
  The API's error message does not name the values they accept, and the demo account used for the
  measurement had no records that use them. These fields are listed under **Operators: not measured**, on the search and on
  its exports and bulk actions.
- **`gt` and `lt` as a filter `type`: Vulnerability Search only.** [Vulnerability Search](/reference/vulnerability/search/)
  of the CVE database accepts `gt` and `lt` on each of its date and number fields and on `id`. Every other
  search with `must`, `should` and `must_not` lists returns 400 for them, so use `gte` and `lte` there.
  The operators do exist elsewhere in the API: the
  [searches with another filter format](/getting-started/search-and-filters/#searches-with-another-filter-format)
  take `gt` and `lt` as keys of a range filter, and
  [Email Breach List](/reference/cti/email-breach-list/), a
  [list endpoint](/getting-started/search-and-filters/#list-endpoints), as the `__gt` and `__lt` suffixes.
- **Request templates.** Each of these searches, with its exports and bulk actions, shows a
  **Request Template** among its examples: a request body with the endpoint's filters, an operator each
  field accepts and placeholder values, ready to copy. A template is a request only, without a response.
- **Filter errors.** An operator that a field does not accept returns 400, and today the message comes
  back in one of three forms, depending on the endpoint. One of them uses code `30004`, which also stands
  for a state change that is not allowed. An operator the search does not know at all, such as `gt` outside
  Vulnerability Search of the CVE database, returns 400 with `Select a valid choice.` for the filter's `type`. A value of the
  wrong type returns 400 with a message of its own.
  [Search & Filters](/getting-started/search-and-filters/#filter-errors) shows each one with the filter
  behind it, and [Errors](/getting-started/errors/#filter-errors) lists them with the other error codes.
- **The other filter format.** [Search & Filters](/getting-started/search-and-filters/#searches-with-another-filter-format)
  now names every search that takes `filters` as an object with one key per field: the technology
  searches, the custom discovery rule search, the fraudulent rule search and Report Search.
