O365 - Security And Compliance - Search
Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead. This playbook performs the following steps: 1. Creates a compliance search. 2. Starts a compliance search. 3. Waits for the compliance search to complete. 4. Gets the results of the compliance search as an output. 5. Gets the preview results, if specified.
- Pack
- MicrosoftExchangeOnline
- Tasks
- 15
Inputs
- search_name — The name of the compliance search.
- force — If false, use the existing search without modifying any search parameters. If true, overwrite the existing search. Possible values are: "true" and "false".
- preview — Whether to preview results using the search action. Possible values are: "true" and "false".
- case — The name of a Core eDiscovery case to associate with the new compliance search.
- kql — Text search string or a query that is formatted using the Keyword Query Language (KQL).
- description — Description of the compliance search.
- allow_not_found_exchange_locations — Whether to include mailboxes other than regular user mailboxes in the compliance search. Possible values are: "true" and "false".
- exchange_location — Comma-separated list of mailboxes/distribution groups to include, or use the value "All" to include all.
- exchange_location_exclusion — Comma-separated list of mailboxes/distribution groups to exclude when you use the value "All" for the exchange_location parameter.
- public_folder_location — Comma-separated list of public folders to include, or use the value "All" to include all.
- share_point_location — Comma-separated list of SharePoint online sites to include. You can identify the sites by their URL value, or use the value "All" to include all sites.
- share_point_location_exclusion — Comma-separated list of SharePoint online sites to exclude when you use the value "All" for the share_point_location argument. You can identify the sites by their URL value.
- polling_interval — Compliance search polling interval
- polling_timeout — Compliance search polling timeout.
Outputs
- O365.SecurityAndCompliance.ContentSearch.Search.AllowNotFoundExchangeLocationsEnabled — Whether to include mailboxes other than regular user mailboxes in the compliance search.
- O365.SecurityAndCompliance.ContentSearch.Search.AzureBatchFrameworkEnabled — Whether the Azure Batch Framework is enabled for job processing.
- O365.SecurityAndCompliance.ContentSearch.Search.CaseId — Identity of a Core eDiscovery case which is associated with the compliance search.
- O365.SecurityAndCompliance.ContentSearch.Search.CaseName — Name of a Core eDiscovery case which is associated with the compliance search.
- O365.SecurityAndCompliance.ContentSearch.Search.ContentMatchQuery — Compliance text search string or a query that is formatted using the Keyword Query Language (KQL).
- O365.SecurityAndCompliance.ContentSearch.Search.CreatedBy — Security and compliance search creator.
- O365.SecurityAndCompliance.ContentSearch.Search.CreatedTime — Security and compliance search creation time.
- O365.SecurityAndCompliance.ContentSearch.Search.Description — Security and compliance search description.
- O365.SecurityAndCompliance.ContentSearch.Search.Errors — Security and compliance search errors.
- O365.SecurityAndCompliance.ContentSearch.Search.ExchangeLocation — Security and compliance search exchange locations to include.
- O365.SecurityAndCompliance.ContentSearch.Search.Identity — Security and compliance search identity.
- O365.SecurityAndCompliance.ContentSearch.Search.IsValid — Whether the security and compliance search is valid.
- O365.SecurityAndCompliance.ContentSearch.Search.Items — Number of security and compliance search scanned items.
- O365.SecurityAndCompliance.ContentSearch.Search.JobEndTime — Security and compliance search job end time.
- O365.SecurityAndCompliance.ContentSearch.Search.JobId — Security and compliance search job ID.
- O365.SecurityAndCompliance.ContentSearch.Search.JobRunId — Security and compliance search job run ID.
- O365.SecurityAndCompliance.ContentSearch.Search.JobStartTime — Security and compliance search job run start time.
- O365.SecurityAndCompliance.ContentSearch.Search.LastModifiedTime — Security and compliance search last modification time.
- O365.SecurityAndCompliance.ContentSearch.Search.LogLevel — Security and compliance search Azure log level.
- O365.SecurityAndCompliance.ContentSearch.Search.Name — Security and compliance search name.
- O365.SecurityAndCompliance.ContentSearch.Search.OneDriveLocation — Security and compliance search OneDrive locations to include.
- O365.SecurityAndCompliance.ContentSearch.Search.OneDriveLocationExclusion — Security and compliance search OneDrive locations to exclude.
- O365.SecurityAndCompliance.ContentSearch.Search.PublicFolderLocation — Security and compliance search public folder locations to include.
- O365.SecurityAndCompliance.ContentSearch.Search.PublicFolderLocationExclusion — Security and compliance search public folder locations to exclude.
- O365.SecurityAndCompliance.ContentSearch.Search.RunBy — Security and compliance search last run by UPN (Email representation).
- O365.SecurityAndCompliance.ContentSearch.Search.RunspaceId — Security and compliance search run space ID.
- O365.SecurityAndCompliance.ContentSearch.Search.SharePointLocation — Security and compliance search SharePoint locations to include.
- O365.SecurityAndCompliance.ContentSearch.Search.Size — Security and compliance search bytes results size.
- O365.SecurityAndCompliance.ContentSearch.Search.Status — Security and compliance search status.
- O365.SecurityAndCompliance.ContentSearch.Search.TenantId — Security and compliance search Tenant ID.
- O365.SecurityAndCompliance.ContentSearch.Search.SuccessResults — Security and compliance search results.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Action — Security and compliance search action type. Either "Purge" or "Preview".
- O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled — Whether to include mailboxes other than regular user mailboxes in the compliance search.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled — Whether the Azure Batch Framework is enabled for job processing.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId — Identity of a Core eDiscovery case which is associated with the compliance search.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName — Name of a Core eDiscovery case which is associated with the compliance search.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy — Security and compliance search action creator.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime — Security and compliance search action creation time.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Description — Security and compliance search action description.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors — Security and compliance search action errors.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId — Security and compliance search action job ID estimation.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId — Security and compliance search action run ID estimation.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation — Security and compliance search action exchange locations to include.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion — Security and compliance search action exchange locations to exclude.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity — Security and compliance search action identity.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid — Whether the security and compliance search action is valid.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime — Security and compliance search action job end time.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId — Security and compliance search action job ID.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId — Security and compliance search action job run ID.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime — Security and compliance search action job start time.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime — Security and compliance search action last modified time.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Name — Security and compliance search action name.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation — Security and compliance search action public folder locations to include.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion — Security and compliance search action public folder locations to exclude.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Results — Security and compliance search action results.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry — Whether to retry if the search action failed.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy — Security and compliance search action run by UPN (email address).
- O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId — Security and compliance search action run space ID.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName — Security and compliance search action search name.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation — Security and compliance search action SharePoint locations to include.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion — Security and compliance search action SharePoint locations to exclude.
- O365.SecurityAndCompliance.ContentSearch.SearchAction.Status — Security and compliance search action status. Either "Started" or "Completed".
- O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId — Security and compliance search action Tenant ID.
Commands used
- o365-sc-get-search
- o365-sc-new-search
- o365-sc-remove-search
- o365-sc-start-search