• API
  • Docs

Search endpoints now list their searchable fields grouped by the operators each field accepts, measured against the API, and the docs show the forms a filter error takes.

Which filter operators a search field accepts is set per field, and the field's type does not tell you. The reference now shows it for each field.

  • Fields grouped by operator. On each search endpoint's reference page, Filtering lists the searchable fields grouped by the operators they accept. The groups come from measurement: each operator was sent to each field against the API. Search & Filters explains the groups and links the Filtering section of each search.
  • Fields that could not be measured. website.parent_asset.type in Asset Search, and source_format and network in Compromised Payment Credential Search, take a value from a fixed list. The API's error message does not name the values they accept, and the demo account used for the measurement had no records that use them. These fields are listed under Operators: not measured, on the search and on its exports and bulk actions.
  • gt and lt as a filter type: Vulnerability Search only. Vulnerability Search of the CVE database accepts gt and lt on each of its date and number fields and on id. Every other search with must, should and must_not lists returns 400 for them, so use gte and lte there. The operators do exist elsewhere in the API: the searches with another filter format take gt and lt as keys of a range filter, and Email Breach List, a list endpoint, as the __gt and __lt suffixes.
  • Request templates. Each of these searches, with its exports and bulk actions, shows a Request Template among its examples: a request body with the endpoint's filters, an operator each field accepts and placeholder values, ready to copy. A template is a request only, without a response.
  • Filter errors. An operator that a field does not accept returns 400, and today the message comes back in one of three forms, depending on the endpoint. One of them uses code 30004, which also stands for a state change that is not allowed. An operator the search does not know at all, such as gt outside Vulnerability Search of the CVE database, returns 400 with Select a valid choice. for the filter's type. A value of the wrong type returns 400 with a message of its own. Search & Filters shows each one with the filter behind it, and Errors lists them with the other error codes.
  • The other filter format. Search & Filters now names every search that takes filters as an object with one key per field: the technology searches, the custom discovery rule search, the fraudulent rule search and Report Search.