Operator Support per Field
Search endpoints now list their searchable fields grouped by the operators each field accepts, measured against the API, and the docs show the forms a filter error takes.
Which filter operators a search field accepts is set per field, and the field's type does not tell you. The reference now shows it for each field.
- Fields grouped by operator. On each search endpoint's reference page, Filtering lists the searchable fields grouped by the operators they accept. The groups come from measurement: each operator was sent to each field against the API. Search & Filters explains the groups and links the Filtering section of each search.
- Fields that could not be measured.
website.parent_asset.typein Asset Search, andsource_formatandnetworkin Compromised Payment Credential Search, take a value from a fixed list. The API's error message does not name the values they accept, and the demo account used for the measurement had no records that use them. These fields are listed under Operators: not measured, on the search and on its exports and bulk actions. gtandltas a filtertype: Vulnerability Search only. Vulnerability Search of the CVE database acceptsgtandlton each of its date and number fields and onid. Every other search withmust,shouldandmust_notlists returns 400 for them, so usegteandltethere. The operators do exist elsewhere in the API: the searches with another filter format takegtandltas keys of a range filter, and Email Breach List, a list endpoint, as the__gtand__ltsuffixes.- Request templates. Each of these searches, with its exports and bulk actions, shows a Request Template among its examples: a request body with the endpoint's filters, an operator each field accepts and placeholder values, ready to copy. A template is a request only, without a response.
- Filter errors. An operator that a field does not accept returns 400, and today the message comes
back in one of three forms, depending on the endpoint. One of them uses code
30004, which also stands for a state change that is not allowed. An operator the search does not know at all, such asgtoutside Vulnerability Search of the CVE database, returns 400 withSelect a valid choice.for the filter'stype. A value of the wrong type returns 400 with a message of its own. Search & Filters shows each one with the filter behind it, and Errors lists them with the other error codes. - The other filter format. Search & Filters
now names every search that takes
filtersas an object with one key per field: the technology searches, the custom discovery rule search, the fraudulent rule search and Report Search.