Google Vault - Search Mail

This is a playbook for performing Google Vault search in Mail accounts and display the results.

Google Vault · 10 tasks · 17 inputs · 16 outputs

Details

IDGoogle-Vault-Search-Mail
From Version5.0.0
Tasks10

README

Performs a Google Vault search in Drive accounts and display the results.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • GenericPolling

Integrations

This playbook does not use any integrations.

Scripts

  • PrintErrorEntry

Commands

  • gvault-download-results
  • gvault-get-drive-results
  • gvault-export-status
  • gvault-create-export-drive

Playbook Inputs


Name Description Default Value Required
matterID The ID of the matter. - Required
exportName The name of the exported file. - Required
dataScope The choice of Search scope. All Data Optional
searchMethod The choice of Search method. The default is: “Specific Accounts”, this requires the emails argument. “Organizational Unit”, this requires ou argument. “Team Drive”. Specific Accounts Optional
emails Whether the search method is set to “Specific Accounts” (separated by comma). - Optional
ou Whether the search method is set to “Specific Accounts” (separated by comma). - Optional
teamDrive Whether the search method is set to “Team Drives”. - Optional
includeTeamDrives Include/Exclude team drives. true Optional
timeFrame The search time frame. For example, “1 min ago”,”2 weeks ago”,”3 months ago”. - Optional
startTime The UTC start time. For example, 2018-10-16T12:59:02.584000Z. - Optional
endTime The UTC end time. For example, 2018-10-16T12:59:02.584000Z. - Optional
terms Add specific terms for the search (subject:example). - Optional
exportPST The export format. true Optional
exportMBOX The export format. false Optional
pollInterval The interval to check export status (in minutes). For big data inquires increase both pollInterval and pollTimeout 2 Optional
pollTimeout The timeout to terminate the poll (in minutes). For big data inquires increase both pollTimeout and pollInterval. 30 Optional
maxResultForDisplay The maximal number of result to be displayed. 30 Optional
downloadFile Whether the export file will be downloaded into the War Room. If set to “Ture” this will occur. false Optional

Playbook Outputs


Path Description Type
GoogleVault.Matter.Export.MatterID The matter ID. string
GoogleVault.Matter.Export.ExportID The export ID. string
GoogleVault.Matter.Export.Name The export’s name. string
GoogleVault.Matter.Export.CreateTime The export’s creation time. string
GoogleVault.Matter.Export.Results.Title The title of the file. string
GoogleVault.Matter.Export.Results.Author The author of the file. string
GoogleVault.Matter.Export.Results.Others The other users related to the file. string
GoogleVault.Matter.Export.Results.Viewers The viewers of the file. string
GoogleVault.Matter.Export.Results.DateModified The date the file was modified. string
GoogleVault.Matter.Export.Results.DateCreated The date the file was created. string
GoogleVault.Matter.Export.Results.DocType The type of the file (extension). string
GoogleVault.Matter.Export.Results.MD5 The MD5 hash of the file (SHA1). string
GoogleVault.Matter.Export.Status The export status. Can be, “COMPLETED”, “FAILED”, or “IN_PROGRESS”. string
GoogleVault.Matter.Export.BucketName The bucket holder name for this export. string
GoogleVault.Matter.Export.DownloadID The ID to be used by the download-export command. string
GoogleVault.Matter.Export.ViewID The ID to be used by the get-X-results command (X=drive/mail/groups). string
GoogleVault.Matter The matter object. unknown

Playbook Image


GVault_Search_Mail

Inputs

  • matterID — matterID
  • exportName — Export Name
  • dataScope — Choice of Search scope
  • searchMethod — Choice of Search method
  • emails — If the search method is set to Specific Accounts (separated by comma)
  • ou — The organizational unit (specify only if the search method is set to Organizational Unit)
  • includeDrafts — Include/Exclude drafts in the search
  • timeFrame — Search time frame. E.g: "1 min ago","2 weeks ago","3 months ago"
  • startTime — UTC start time (2018-10-16T12:59:02.584000Z)
  • endTime — UTC end time (2018-10-16T12:59:02.584000Z)
  • terms — Add specific terms for the search (subject:example)
  • exportPST — Export format
  • exportMBOX — Export format
  • pollInterval — Interval to check export status (minutes)
  • pollTimeout — Timeout to terminate the poll (minutes)
  • maxResultForDisplay — The maximal number of result to be displayed
  • downloadFile — If set to true the export file created will be downloaded into the War Room

Outputs

  • GoogleVault.Matter.Export.MatterID — Matter ID
  • GoogleVault.Matter.Export.ExportID — Export ID
  • GoogleVault.Matter.Export.Name — Export's name
  • GoogleVault.Matter.Export.CreateTime — Export's creation time
  • GoogleVault.Matter.Export.Results.CC — CC of the mail
  • GoogleVault.Matter.Export.Results.BCC — BCC of the mail
  • GoogleVault.Matter.Export.Results.DateSent — The date the email was sent
  • GoogleVault.Matter.Export.Results.From — The sender of the email
  • GoogleVault.Matter.Export.Results.Subject — The subject of the email
  • GoogleVault.Matter.Export.Results.DateReceived — The date the email was received
  • GoogleVault.Matter.Export.Results.To — The address the email was sent to
  • GoogleVault.Matter.Export.Status — Export Status (COMPLETED,FAILED,IN_PROGRESS)
  • GoogleVault.Matter.Export.BucketName — Bucket holder name for this export
  • GoogleVault.Matter.Export.DownloadID — ID to be used by the download-export command
  • GoogleVault.Matter.Export.ViewID — ID to be used by the get-X-results command (X=drive/mail/groups)
  • GoogleVault.Matter — Matter object

Commands used

gvault-create-export-mail gvault-download-results gvault-export-status gvault-get-mail-results

Flowchart

yes yes Start Start Create Mail Export - gvault-create-export-mail Create Mail Export gvault-create-export-mail GenericPolling - GenericPolling GenericPolling GenericPolling Get Mail results - gvault-get-mail-results Get Mail results gvault-get-mail-results Done Done Check downloadFile Check downloadFile Get Export status to context - gvault-export-status Get Export status to context gvault-export-status Download Export file - gvault-download-results Download Export file gvault-download-results Check if status COMPLETED Check if status COMPLETED Polling Timeout - PrintErrorEntry Polling Timeout PrintErrorEntry
id: Google-Vault-Search-Mail
version: -1
fromversion: 5.0.0
name: Google Vault - Search Mail
description: This is a playbook for performing Google Vault search in Mail accounts and display the results.
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: 14cac14a-3745-46d2-8ef6-da411a06da52
    type: start
    task:
      id: 14cac14a-3745-46d2-8ef6-da411a06da52
      version: -1
      name: ""
      description: ''
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 210
        }
      }
    note: false
  "1":
    id: "1"
    taskid: e3690834-b9f7-4574-8106-e70ec6cec8c6
    type: regular
    task:
      id: e3690834-b9f7-4574-8106-e70ec6cec8c6
      version: -1
      name: 'Create Mail Export '
      description: Creates a Google Vault export in order to perform search actions on emails.
      script: '|||gvault-create-export-mail'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "2"
    scriptarguments:
      dataScope:
        simple: ${inputs.dataScope}
      emails:
        complex:
          root: inputs.emails
      endTime:
        complex:
          root: inputs.endTime
      exportMBOX:
        simple: ${inputs.exportMBOX}
      exportName:
        complex:
          root: inputs.exportName
      exportPST:
        simple: ${inputs.exportPST}
      includeDrafts:
        simple: ${inputs.includeDrafts}
      matterID:
        complex:
          root: inputs.matterID
      ou:
        complex:
          root: inputs.ou
      searchMethod:
        simple: ${inputs.searchMethod}
      startTime:
        complex:
          root: inputs.startTime
      terms:
        complex:
          root: inputs.terms
      timeFrame:
        complex:
          root: inputs.timeFrame
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 370
        }
      }
    note: false
  "2":
    id: "2"
    taskid: db065150-defd-4197-85cd-001dcbcd8d5f
    type: playbook
    task:
      id: db065150-defd-4197-85cd-001dcbcd8d5f
      version: -1
      name: GenericPolling
      description: |-
        Use as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continually running the command in Step #2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      playbookName: GenericPolling
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "16"
    scriptarguments:
      Ids:
        simple: ${GoogleVault.Matter.MatterID}#${GoogleVault.Matter.Export.[0].ExportID}
      Interval:
        complex:
          root: inputs.pollInterval
      PollingCommandArgName:
        simple: queryIDS
      PollingCommandName:
        simple: gvault-export-status
      Timeout:
        complex:
          root: inputs.pollTimeout
      dt:
        simple: GoogleVault.Matter.Export(val.Status != 'COMPLETED')=val.MatterID + '#' + val.ExportID
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
    view: |-
      {
        "position": {
          "x": 50,
          "y": 545
        }
      }
    note: false
  "3":
    id: "3"
    taskid: 84cab8e3-4c98-4931-83fa-5c13d0c55e05
    type: regular
    task:
      id: 84cab8e3-4c98-4931-83fa-5c13d0c55e05
      version: -1
      name: Get Mail results
      description: Get the results of a given mail export
      script: '|||gvault-get-mail-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "15"
    scriptarguments:
      bucketName:
        complex:
          root: GoogleVault
          accessor: Matter.Export.BucketName
      maxResult:
        complex:
          root: inputs.maxResultForDisplay
      viewID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ViewID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1120
        }
      }
    note: false
  "5":
    id: "5"
    taskid: 9ed8fed0-adb4-4d5a-8de3-4390979be049
    type: title
    task:
      id: 9ed8fed0-adb4-4d5a-8de3-4390979be049
      version: -1
      name: Done
      description: ''
      type: title
      iscommand: false
      brand: ""
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 780,
          "y": 1760
        }
      }
    note: false
  "15":
    id: "15"
    taskid: 3f8f4650-cc6f-4dde-85cf-52875002b5a1
    type: condition
    task:
      id: 3f8f4650-cc6f-4dde-85cf-52875002b5a1
      version: -1
      name: Check downloadFile
      description: ''
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "5"
      "yes":
      - "17"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              simple: inputs.downloadFile
            iscontext: true
          right:
            value:
              simple: "true"
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1320
        }
      }
    note: false
  "16":
    id: "16"
    taskid: 9b8234da-1a70-499b-86c8-6de0665449f9
    type: regular
    task:
      id: 9b8234da-1a70-499b-86c8-6de0665449f9
      version: -1
      name: Get Export status to context
      description: ''
      script: '|||gvault-export-status'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "18"
    scriptarguments:
      exportID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ExportID
      exportIDS:
        complex:
          root: GoogleVault
          accessor: Matter.Export.ExportID
      matterId:
        complex:
          root: GoogleVault
          accessor: Matter.Export.MatterID
      queryIDS: {}
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 730
        }
      }
    note: false
  "17":
    id: "17"
    taskid: 52069817-50f6-4267-80f4-7e4c94431f52
    type: regular
    task:
      id: 52069817-50f6-4267-80f4-7e4c94431f52
      version: -1
      name: Download Export file
      description: ''
      script: '|||gvault-download-results'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      bucketName:
        complex:
          root: GoogleVault
          accessor: Matter.Export.BucketName
      downloadID:
        complex:
          root: GoogleVault
          accessor: Matter.Export.DownloadID
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 1550
        }
      }
    note: false
  "18":
    id: "18"
    taskid: f04a7a20-83ae-4198-86e0-22c079cef34b
    type: condition
    task:
      id: f04a7a20-83ae-4198-86e0-22c079cef34b
      version: -1
      name: Check if status COMPLETED
      description: ''
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "19"
      "yes":
      - "3"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: GoogleVault
                accessor: Matter.Export.Status
            iscontext: true
          right:
            value:
              simple: COMPLETED
    view: |-
      {
        "position": {
          "x": 50,
          "y": 920
        }
      }
    note: false
  "19":
    id: "19"
    taskid: de226b27-9336-4659-823e-079c17b7873b
    type: regular
    task:
      id: de226b27-9336-4659-823e-079c17b7873b
      version: -1
      name: Polling Timeout
      description: ''
      scriptName: PrintErrorEntry
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "5"
    scriptarguments:
      message:
        simple: 'Polling time out: Your search is taking a bit more time. To see your results please run playbook ''Google Vault - Display Results'' with a grater ''PollIntarval'' and ''PollTimeout'' using this ExportID: ${GoogleVault.Matter.Export.ExportID} and MatterID: ${GoogleVault.Matter.Export.MatterID}'
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 550,
          "y": 1110
        }
      }
    note: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 1615,
        "width": 1110,
        "x": 50,
        "y": 210
      }
    }
  }
inputs:
- key: matterID
  value: {}
  required: true
  description: |2-

    matterID
- key: exportName
  value: {}
  required: true
  description: Export Name
- key: dataScope
  value:
    simple: All Data
  required: false
  description: Choice of Search scope
- key: searchMethod
  value:
    simple: All Accounts
  required: false
  description: Choice of Search method
- key: emails
  value: {}
  required: false
  description: If the search method is set to Specific Accounts (separated by comma)
- key: ou
  value: {}
  required: false
  description: The organizational unit (specify only if the search method is set to Organizational Unit)
- key: includeDrafts
  value:
    simple: "true"
  required: false
  description: Include/Exclude drafts in the search
- key: timeFrame
  value: {}
  required: false
  description: 'Search time frame. E.g: "1 min ago","2 weeks ago","3 months ago"'
- key: startTime
  value: {}
  required: false
  description: UTC start time (2018-10-16T12:59:02.584000Z)
- key: endTime
  value: {}
  required: false
  description: UTC end time (2018-10-16T12:59:02.584000Z)
- key: terms
  value: {}
  required: false
  description: Add specific terms for the search (subject:example)
- key: exportPST
  value:
    simple: "true"
  required: false
  description: Export format
- key: exportMBOX
  value:
    simple: "false"
  required: false
  description: Export format
- key: pollInterval
  value:
    simple: "2"
  required: false
  description: Interval to check export status (minutes)
- key: pollTimeout
  value:
    simple: "30"
  required: false
  description: Timeout to terminate the poll (minutes)
- key: maxResultForDisplay
  value:
    simple: "30"
  required: false
  description: The maximal number of result to be displayed
- key: downloadFile
  value:
    simple: "false"
  required: false
  description: If set to true the export file created will be downloaded into the War Room
outputs:
- contextPath: GoogleVault.Matter.Export.MatterID
  description: Matter ID
  type: string
- contextPath: GoogleVault.Matter.Export.ExportID
  description: Export ID
  type: string
- contextPath: GoogleVault.Matter.Export.Name
  description: Export's name
  type: string
- contextPath: GoogleVault.Matter.Export.CreateTime
  description: Export's creation time
  type: string
- contextPath: GoogleVault.Matter.Export.Results.CC
  description: CC of the mail
  type: string
- contextPath: GoogleVault.Matter.Export.Results.BCC
  description: 'BCC of the mail '
  type: string
- contextPath: GoogleVault.Matter.Export.Results.DateSent
  description: The date the email was sent
  type: string
- contextPath: GoogleVault.Matter.Export.Results.From
  description: The sender of the email
  type: string
- contextPath: GoogleVault.Matter.Export.Results.Subject
  description: The subject of the email
  type: string
- contextPath: GoogleVault.Matter.Export.Results.DateReceived
  description: The date the email was received
  type: string
- contextPath: GoogleVault.Matter.Export.Results.To
  description: The address the email was sent to
  type: string
- contextPath: GoogleVault.Matter.Export.Status
  description: Export Status (COMPLETED,FAILED,IN_PROGRESS)
  type: string
- contextPath: GoogleVault.Matter.Export.BucketName
  description: Bucket holder name for this export
  type: string
- contextPath: GoogleVault.Matter.Export.DownloadID
  description: ID to be used by the download-export command
  type: string
- contextPath: GoogleVault.Matter.Export.ViewID
  description: ID to be used by the get-X-results command (X=drive/mail/groups)
  type: string
- contextPath: GoogleVault.Matter
  description: Matter object
  type: unknown
tests:
- Google_Vault-Search_And_Display_Results_test