Google Vault - Search Groups

This is a playbook for performing Google Vault search in Groups and display the results.

Google Vault · 10 tasks · 14 inputs · 16 outputs

Details

IDGoogle-Vault-Search-Groups
From Version5.0.0
Tasks10

README

Performs a Google Vault search in Drive accounts and display the results.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • GenericPolling

Integrations

This playbook does not use any integrations.

Scripts

  • PrintErrorEntry

Commands

  • gvault-download-results
  • gvault-get-drive-results
  • gvault-export-status
  • gvault-create-export-drive

Playbook Inputs


Name Description Default Value Required
matterID The ID of the matter. - Required
exportName The name of the exported file. - Required
dataScope The choice of the search scope. All Data Optional
searchMethod The choice of Search method. The default is, “Specific Accounts”, this requires emails argument. “Organizational Unit” this requires ou argument. ‘Team Drive’ Specific Accounts Optional
emails Whether the search method is set to Specific Accounts (separated by comma). - Optional
ou Whether the search method is set to Specific Accounts (separated by comma). - Optional
teamDrive Whether the search method is set to team drives. - Optional
includeTeamDrives Include/Exclude team drives. true Optional
timeFrame The search time frame. For example, “1 min ago”,”2 weeks ago”,”3 months ago”. - Optional
startTime The UTC start time. For example, 2018-10-16T12:59:02.584000Z. - Optional
endTime The UTC end time. For example, 2018-10-16T12:59:02.584000Z. - Optional
terms Add specific terms for the search (subject:example). - Optional
exportPST The export format. true Optional
exportMBOX The export format. false Optional
pollInterval The interval to check export status (in minutes). For big data inquires increase both pollInterval and pollTimeout 2 Optional
pollTimeout The timeout to terminate the poll (in minutes). For big data inquires increase both pollTimeout and pollInterval 30 Optional
maxResultForDisplay The maximal number of result to be displayed. 30 Optional
downloadFile Whether the created file will be downloaded into the War Room. If set to “True” this will occur. false Optional

Playbook Outputs


Path Description Type
GoogleVault.Matter.Export.MatterID The matter ID. string
GoogleVault.Matter.Export.ExportID The export ID. string
GoogleVault.Matter.Export.Name The export’s name. string
GoogleVault.Matter.Export.CreateTime The export’s creation time. string
GoogleVault.Matter.Export.Results.Title The title of the file. string
GoogleVault.Matter.Export.Results.Author The author of the file. string
GoogleVault.Matter.Export.Results.Others The other users related to the file. string
GoogleVault.Matter.Export.Results.Viewers The viewers of the file. string
GoogleVault.Matter.Export.Results.DateModified The date the file was modified. string
GoogleVault.Matter.Export.Results.DateCreated The date the file was created. string
GoogleVault.Matter.Export.Results.DocType The type of the file (extension). string
GoogleVault.Matter.Export.Results.MD5 The MD5 hash of the file (SHA1). string
GoogleVault.Matter.Export.Status The export status. Can be, “COMPLETED”, “FAILED”, “IN_PROGRESS”. string
GoogleVault.Matter.Export.BucketName The bucket holder name for the export. string
GoogleVault.Matter.Export.DownloadID The ID to be used by the download-export command. string
GoogleVault.Matter.Export.ViewID The ID to be used by the get-X-results command (X=drive/mail/groups). string
GoogleVault.Matter The matter object. unknown

Playbook Image


GVault_Search_Groups

Inputs

  • matterID — matterID
  • exportName — Export Name
  • dataScope — Choice of Search scope
  • groups — Enter one or more Groups separated by commas. You can search up to 50 Groups.
  • timeFrame — Search time frame. E.g: "1 min ago","2 weeks ago","3 months ago"
  • startTime — UTC start time (2018-10-16T12:59:02.584000Z)
  • endTime — UTC end time (2018-10-16T12:59:02.584000Z)
  • terms — Add specific terms for the search (subject:example)
  • exportPST — Export format
  • exportMBOX — Export format
  • pollInterval — Interval to check export status (minutes)
  • pollTimeout — Timeout to terminate the poll (minutes)
  • maxResultForDisplay — The maximal number of result to be displayed
  • downloadFile — If set to true the export file created will be downloaded into the War Room

Outputs

  • GoogleVault.Matter.Export.MatterID — Matter ID
  • GoogleVault.Matter.Export.ExportID — Export ID
  • GoogleVault.Matter.Export.Name — Export's name
  • GoogleVault.Matter.Export.CreateTime — Export's creation time
  • GoogleVault.Matter.Export.Results.CC — CC of the message
  • GoogleVault.Matter.Export.Results.BCC — BCC of the message
  • GoogleVault.Matter.Export.Results.DateSent — The date the message
  • GoogleVault.Matter.Export.Results.From — The sender of the message
  • GoogleVault.Matter.Export.Results.Subject — The subject of the message
  • GoogleVault.Matter.Export.Results.DateReceived — The date the message was received
  • GoogleVault.Matter.Export.Results.To — The address the message was sent to
  • GoogleVault.Matter.Export.Status — Export Status (COMPLETED,FAILED,IN_PROGRESS)
  • GoogleVault.Matter.Export.BucketName — Bucket holder name for this export
  • GoogleVault.Matter.Export.DownloadID — ID to be used by the download-export command
  • GoogleVault.Matter.Export.ViewID — ID to be used by the get-X-results command (X=drive/mail/groups)
  • GoogleVault.Matter — Matter object

Commands used

gvault-create-export-groups gvault-download-results gvault-export-status gvault-get-groups-results

Flowchart

yes yes Start Start Create Group Export - gvault-create-export-groups Create Group Export gvault-create-export-groups GenericPolling - GenericPolling GenericPolling GenericPolling Get Groups results - gvault-get-groups-results Get Groups results gvault-get-groups-results Done Done Check downloadFile Check downloadFile Get Export status to context - gvault-export-status Get Export status to context gvault-export-status Download Export file - gvault-download-results Download Export file gvault-download-results Check if status COMPLETED Check if status COMPLETED Polling Timeout - PrintErrorEntry Polling Timeout PrintErrorEntry
id: Google-Vault-Search-Groups
version: -1
fromversion: 5.0.0
name: Google Vault - Search Groups
description: This is a playbook for performing Google Vault search in Groups and display the results.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 14cac14a-3745-46d2-8ef6-da411a06da52
    type: start
    task:
      id: 14cac14a-3745-46d2-8ef6-da411a06da52
      version: -1
      name: ""
      description: ''
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 200
        }
      }
    note: false
  "1":
    id: "1"
    taskid: 40d47276-5b8c-4a16-8bfc-986b89a39382
    type: regular
    task:
      id: 40d47276-5b8c-4a16-8bfc-986b89a39382
      version: -1
      name: Create Group Export
      description: Creates a Google Vault export in order to perform search actions on emails.
      script: '|||gvault-create-export-groups'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      dataScope:
        simple: ${inputs.dataScope}
      endTime:
        complex:
          root: inputs.endTime
      exportMBOX:
        simple: ${inputs.exportMBOX}
      exportName:
        complex:
          root: inputs.exportName
      exportPST:
        simple: ${inputs.exportPST}
      groups:
        complex:
          root: inputs.groups
      matterID:
        complex:
          root: inputs.matterID
      startTime:
        complex:
          root: inputs.startTime
      terms:
        complex:
          root: inputs.terms
      timeFrame:
        complex:
          root: inputs.timeFrame
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 370
        }
      }
    note: false
  "2":
    id: "2"
    taskid: 2499c394-d9b8-4fc2-8e39-006e6ed21018
    type: playbook
    task:
      id: 2499c394-d9b8-4fc2-8e39-006e6ed21018
      version: -1
      name: GenericPolling
      description: |-
        Use as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continually running the command in Step #2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      playbookName: GenericPolling
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    scriptarguments:
      Ids:
        simple: ${GoogleVault.Matter.MatterID}#${GoogleVault.Matter.Export.[0].ExportID}
      Interval:
        complex:
          root: inputs.pollInterval
      PollingCommandArgName:
        simple: queryIDS
      PollingCommandName:
        simple: gvault-export-status
      Timeout:
        complex:
          root: inputs.pollTimeout
      dt:
        simple: GoogleVault.Matter.Export(val.Status != 'COMPLETED')=val.MatterID + '#' + val.ExportID
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
    view: |-
      {
        "position": {
          "x": 50,
          "y": 550
        }
      }
    note: false
  "3":
    id: "3"
    taskid: 31d85c78-3d02-4ef9-8734-3d41200a8857
    type: regular
    task:
      id: 31d85c78-3d02-4ef9-8734-3d41200a8857
      version: -1
      name: Get Groups results
      description: Get the results of a given mail export
      script: '|||gvault-get-groups-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      bucketName:
        complex:
          root: GoogleVault
          accessor: Matter.Export.BucketName
      maxResult:
        complex:
          root: inputs.maxResultForDisplay
      viewID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ViewID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1120
        }
      }
    note: false
  "5":
    id: "5"
    taskid: 9ed8fed0-adb4-4d5a-8de3-4390979be049
    type: title
    task:
      id: 9ed8fed0-adb4-4d5a-8de3-4390979be049
      version: -1
      name: Done
      description: ''
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 780,
          "y": 1760
        }
      }
    note: false
  "15":
    id: "15"
    taskid: aa748877-64f6-403b-8a28-5a48d7470abf
    type: condition
    task:
      id: aa748877-64f6-403b-8a28-5a48d7470abf
      version: -1
      name: Check downloadFile
      description: ''
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.downloadFile
            iscontext: true
          right:
            value:
              simple: "true"
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1330
        }
      }
    note: false
  "16":
    id: "16"
    taskid: 97311171-052d-4110-8cac-66da6235bd3b
    type: regular
    task:
      id: 97311171-052d-4110-8cac-66da6235bd3b
      version: -1
      name: Get Export status to context
      description: ''
      script: '|||gvault-export-status'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      exportID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ExportID
      exportIDS:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ExportID
      matterId:
        complex:
          root: GoogleVault
          accessor: Matter.Export.MatterID
      queryIDS: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 730
        }
      }
    note: false
  "17":
    id: "17"
    taskid: afc45103-f1da-466f-8950-4b4a4227378e
    type: regular
    task:
      id: afc45103-f1da-466f-8950-4b4a4227378e
      version: -1
      name: Download Export file
      description: ''
      script: '|||gvault-download-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      bucketName:
        complex:
          root: GoogleVault
          accessor: Matter.Export.BucketName
      downloadID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.DownloadID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1550
        }
      }
    note: false
  "18":
    id: "18"
    taskid: 0273f108-4e62-44b6-82aa-bb543619668d
    type: condition
    task:
      id: 0273f108-4e62-44b6-82aa-bb543619668d
      version: -1
      name: Check if status COMPLETED
      description: ''
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "19"
      "yes":
      - "3"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: GoogleVault
                accessor: Matter.Export.Status
            iscontext: true
          right:
            value:
              simple: COMPLETED
    view: |-
      {
        "position": {
          "x": 50,
          "y": 920
        }
      }
    note: false
  "19":
    id: "19"
    taskid: 1fb0571b-bd21-423c-85ae-0f9ca53649f2
    type: regular
    task:
      id: 1fb0571b-bd21-423c-85ae-0f9ca53649f2
      version: -1
      name: Polling Timeout
      description: ''
      scriptName: PrintErrorEntry
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      message:
        simple: 'Polling time out: Your search is taking a bit more time. To see your results please run playbook ''Google Vault - Display Results'' with a grater ''PollIntarval'' and ''PollTimeout'' using this ExportID: ${GoogleVault.Matter.Export.ExportID} and MatterID: ${GoogleVault.Matter.Export.MatterID}'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 1110
        }
      }
    note: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1625,
        "width": 1110,
        "x": 50,
        "y": 200
      }
    }
  }
inputs:
- key: matterID
  value: {}
  required: true
  description: |2-

    matterID
- key: exportName
  value: {}
  required: true
  description: Export Name
- key: dataScope
  value:
    simple: All Data
  required: false
  description: Choice of Search scope
- key: groups
  value: {}
  required: false
  description: Enter one or more Groups separated by commas. You can search up to 50 Groups.
- key: timeFrame
  value: {}
  required: false
  description: 'Search time frame. E.g: "1 min ago","2 weeks ago","3 months ago"'
- key: startTime
  value: {}
  required: false
  description: UTC start time (2018-10-16T12:59:02.584000Z)
- key: endTime
  value: {}
  required: false
  description: UTC end time (2018-10-16T12:59:02.584000Z)
- key: terms
  value: {}
  required: false
  description: Add specific terms for the search (subject:example)
- key: exportPST
  value:
    simple: "true"
  required: false
  description: Export format
- key: exportMBOX
  value:
    simple: "false"
  required: false
  description: Export format
- key: pollInterval
  value:
    simple: "2"
  required: false
  description: Interval to check export status (minutes)
- key: pollTimeout
  value:
    simple: "30"
  required: false
  description: Timeout to terminate the poll (minutes)
- key: maxResultForDisplay
  value:
    simple: "30"
  required: false
  description: The maximal number of result to be displayed
- key: downloadFile
  value:
    simple: "false"
  required: false
  description: If set to true the export file created will be downloaded into the War Room
outputs:
- contextPath: GoogleVault.Matter.Export.MatterID
  description: Matter ID
  type: string
- contextPath: GoogleVault.Matter.Export.ExportID
  description: Export ID
  type: string
- contextPath: GoogleVault.Matter.Export.Name
  description: Export's name
  type: string
- contextPath: GoogleVault.Matter.Export.CreateTime
  description: Export's creation time
  type: string
- contextPath: GoogleVault.Matter.Export.Results.CC
  description: CC of the message
  type: string
- contextPath: GoogleVault.Matter.Export.Results.BCC
  description: BCC of the message
  type: string
- contextPath: GoogleVault.Matter.Export.Results.DateSent
  description: The date the message
  type: string
- contextPath: GoogleVault.Matter.Export.Results.From
  description: The sender of the message
  type: string
- contextPath: GoogleVault.Matter.Export.Results.Subject
  description: The subject of the message
  type: string
- contextPath: GoogleVault.Matter.Export.Results.DateReceived
  description: The date the message was received
  type: string
- contextPath: GoogleVault.Matter.Export.Results.To
  description: The address the message was sent to
  type: string
- contextPath: GoogleVault.Matter.Export.Status
  description: Export Status (COMPLETED,FAILED,IN_PROGRESS)
  type: string
- contextPath: GoogleVault.Matter.Export.BucketName
  description: Bucket holder name for this export
  type: string
- contextPath: GoogleVault.Matter.Export.DownloadID
  description: ID to be used by the download-export command
  type: string
- contextPath: GoogleVault.Matter.Export.ViewID
  description: ID to be used by the get-X-results command (X=drive/mail/groups)
  type: string
- contextPath: GoogleVault.Matter
  description: Matter object
  type: unknown
tests:
- Google_Vault-Search_And_Display_Results_test