O365 - Security And Compliance - Search Action - Preview Deprecated

Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead. This playbook perform: 1. Creates a new compliance search action - Preview (Base on created compliance search). 2. Waits for the preview action to complete. 3. Retrieves the preview results.

Microsoft Exchange Online · 6 tasks · 3 inputs · 32 outputs

Details

IDO365 - Security And Compliance - Search Action - Preview
From Version5.5.0
Tasks6

README

This playbook perform:

  1. Creates a new compliance search action - Preview (Base on created compliance search).
  2. Waits for the preview action to complete.
  3. Retrieves the preview results.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Waiting for search action to complete

Integrations

  • SecurityAndCompliance

Scripts

This playbook does not use any scripts.

Commands

  • o365-sc-get-search-action
  • o365-sc-new-search-action

Playbook Inputs


Name Description Default Value Required
search_name The name of the compliance search.   Required
polling_interval Search action polling interval. 3 Optional
polling_timeout Search action polling timeout. 45 Optional

Playbook Outputs


Path Description Type
O365.SecurityAndCompliance.ContentSearch.SearchAction.Action Security and compliance search action type. Either “Purge” or “Preview”. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled Whether to include mailboxes other than regular user mailboxes in the compliance search. Boolean
O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled Whether the Azure Batch Framework is enabled for job processing. Boolean
O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId Identity of a Core eDiscovery case which is associated with the compliance search. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName Name of a Core eDiscovery case which is associated with the compliance search. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy Security and compliance search action creator. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime Security and compliance search action creation time. Date
O365.SecurityAndCompliance.ContentSearch.SearchAction.Description Security and compliance search action description. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors Security and compliance search action errors. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId Security and compliance search action job ID estimation. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId Security and compliance search action run ID estimation. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation Security and compliance search action exchange locations to include. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion Security and compliance search action exchange locations to exclude. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity Security and compliance search action identity. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid Whether the security and compliance search action is valid. Boolean
O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime Security and compliance search action job end time. Date
O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId Security and compliance search action job ID. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId Security and compliance search action job run ID. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime Security and compliance search action job start time. Date
O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime Security and compliance search action last modified time. Date
O365.SecurityAndCompliance.ContentSearch.SearchAction.Name Security and compliance search action name. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation Security and compliance search action public folder locations to include. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion Security and compliance search action public folder locations to exclude. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Location Security and compliance search action result location. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Sender Security and compliance search action result mail sender. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Subject Security and compliance search action result subject. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Type Security and compliance search action result type. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Size Security and compliance search action result size. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.ReceivedTime Security and compliance search action result received time. Date
O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.DataLink Security and compliance search action data link. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry Whether to retry if the search action failed. Boolean
O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy Security and compliance search action run by UPN (email address). String
O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId Security and compliance search action run space ID. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName Security and compliance search action search name. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation Security and compliance search action SharePoint locations to include. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion Security and compliance search action SharePoint locations to exclude. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.Status Security and compliance search action status. Either “Started” or “Completed”. String
O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId Security and compliance search action Tenant ID. String

Playbook Image


O365 - Security And Compliance - Search Action - Preview

Known Limitations


  • Each security and compliance command creates a PSSession (PowerShell session). The security and compliance PowerShell limits the number of concurrent sessions to 3. Since this affects the behavior of multiple playbooks running concurrently it we recommend that you retry failed tasks when using the integration commands in playbooks.
  • In order to handle sessions limits, A retry mechanism is applied which will retry for 10 time with 30 sec breaks. (The retry isn’t applied on the generic polling as it’s not supported yet)

Inputs

  • search_name — The name of the compliance search.
  • polling_interval — Search action polling interval.
  • polling_timeout — Search action polling timeout.

Outputs

  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Action — Security and compliance search action type. Either "Purge" or "Preview".
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled — Whether to include mailboxes other than regular user mailboxes in the compliance search.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled — Whether the Azure Batch Framework is enabled for job processing.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId — Identity of a Core eDiscovery case which is associated with the compliance search.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName — Name of a Core eDiscovery case which is associated with the compliance search.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy — Security and compliance search action creator.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime — Security and compliance search action creation time.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Description — Security and compliance search action description.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors — Security and compliance search action errors.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId — Security and compliance search action job ID estimation.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId — Security and compliance search action run ID estimation.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation — Security and compliance search action exchange locations to include.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion — Security and compliance search action exchange locations to exclude.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity — Security and compliance search action identity.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid — Whether the security and compliance search action is valid.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime — Security and compliance search action job end time.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId — Security and compliance search action job ID.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId — Security and compliance search action job run ID.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime — Security and compliance search action job start time.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime — Security and compliance search action last modified time.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Name — Security and compliance search action name.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation — Security and compliance search action public folder locations to include.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion — Security and compliance search action public folder locations to exclude.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Results — Security and compliance search action results.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry — Whether to retry if the search action failed.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy — Security and compliance search action run by UPN (email address).
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId — Security and compliance search action run space ID.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName — Security and compliance search action search name.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation — Security and compliance search action SharePoint locations to include.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion — Security and compliance search action SharePoint locations to exclude.
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.Status — Security and compliance search action status. Either "Started" or "Completed".
  • O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId — Security and compliance search action Tenant ID.

Commands used

o365-sc-get-search-action o365-sc-new-search-action

Flowchart

#error# Start Start Waiting for search action to complete - GenericPolling Waiting for search action... GenericPolling Search action completed. Search action completed. Search action - Preview - o365-sc-new-search-action Search action - Preview o365-sc-new-search-action Get preview results - o365-sc-get-search-action Get preview results o365-sc-get-search-action Search preview is not supported - Print Search preview is not sup... Print
deprecated: true
description: |-
  Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead.
  This playbook perform:
  1. Creates a new compliance search action - Preview (Base on created compliance search).
  2. Waits for the preview action to complete.
  3. Retrieves the preview results.
id: O365 - Security And Compliance - Search Action - Preview
inputs:
- key: search_name
  value: {}
  required: true
  description: The name of the compliance search.
  playbookInputQuery:
- key: polling_interval
  value:
    simple: "1"
  required: false
  description: Search action polling interval.
  playbookInputQuery:
- key: polling_timeout
  value:
    simple: "10"
  required: false
  description: Search action polling timeout.
  playbookInputQuery:
name: O365 - Security And Compliance - Search Action - Preview
outputs:
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Action
  description: Security and compliance search action type. Either "Purge" or "Preview".
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled
  description: Whether to include mailboxes other than regular user mailboxes in the compliance search.
  type: Boolean
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled
  description: Whether the Azure Batch Framework is enabled for job processing.
  type: Boolean
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId
  description: Identity of a Core eDiscovery case which is associated with the compliance search.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName
  description: Name of a Core eDiscovery case which is associated with the compliance search.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy
  description: Security and compliance search action creator.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime
  description: Security and compliance search action creation time.
  type: Date
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Description
  description: Security and compliance search action description.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors
  description: Security and compliance search action errors.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId
  description: Security and compliance search action job ID estimation.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId
  description: Security and compliance search action run ID estimation.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation
  description: Security and compliance search action exchange locations to include.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion
  description: Security and compliance search action exchange locations to exclude.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity
  description: Security and compliance search action identity.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid
  description: Whether the security and compliance search action is valid.
  type: Boolean
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime
  description: Security and compliance search action job end time.
  type: Date
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId
  description: Security and compliance search action job ID.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId
  description: Security and compliance search action job run ID.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime
  description: Security and compliance search action job start time.
  type: Date
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime
  description: Security and compliance search action last modified time.
  type: Date
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Name
  description: Security and compliance search action name.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation
  description: Security and compliance search action public folder locations to include.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion
  description: Security and compliance search action public folder locations to exclude.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Results
  description: Security and compliance search action results.
  type: unknown
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry
  description: Whether to retry if the search action failed.
  type: Boolean
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy
  description: Security and compliance search action run by UPN (email address).
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId
  description: Security and compliance search action run space ID.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName
  description: Security and compliance search action search name.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation
  description: Security and compliance search action SharePoint locations to include.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion
  description: Security and compliance search action SharePoint locations to exclude.
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Status
  description: Security and compliance search action status. Either "Started" or "Completed".
  type: String
- contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId
  description: Security and compliance search action Tenant ID.
  type: String
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: e9df5f91-1e9e-4fa8-87eb-6f0df3714bc1
    type: start
    task:
      id: e9df5f91-1e9e-4fa8-87eb-6f0df3714bc1
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "6"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 50
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "3":
    id: "3"
    taskid: 3465b210-3e8c-4e68-82d8-a71d09b64106
    type: playbook
    task:
      id: 3465b210-3e8c-4e68-82d8-a71d09b64106
      version: -1
      name: Waiting for search action to complete
      description: |-
        Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete.
        This playbook implements polling by continuously running the command in Step \#2 until the operation completes.
        The remote action should have the following structure:

        1. Initiate the operation.
        2. Poll to check if the operation completed.
        3. (optional) Get the results of the operation.
      playbookName: GenericPolling
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "7"
    scriptarguments:
      Ids:
        complex:
          root: O365.SecurityAndCompliance.ContentSearch
          accessor: SearchAction
          transformers:
          - operator: DT
            args:
              dt:
                value:
                  simple: '.=val.SearchStatus!=="NotFound" ? val.Name : val.Name + "_Preview"'
      Interval:
        simple: ${inputs.polling_interval}
      PollingCommandArgName:
        simple: search_action_name
      PollingCommandName:
        simple: o365-sc-get-search-action
      Timeout:
        simple: ${inputs.polling_timeout}
      dt:
        simple: O365.SecurityAndCompliance.ContentSearch.SearchAction(val.Status && val.Status == "InProgress" || val.Status == "Starting" || val.Status == "Purging").Name
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 50,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "4":
    id: "4"
    taskid: a3b5cc33-9b80-4aa9-8413-a5ad3567168c
    type: title
    task:
      id: a3b5cc33-9b80-4aa9-8413-a5ad3567168c
      version: -1
      name: Search action completed.
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 720
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "6":
    id: "6"
    taskid: 1a18141a-1cfd-4843-8fc4-2f1db333e66d
    type: regular
    task:
      id: 1a18141a-1cfd-4843-8fc4-2f1db333e66d
      version: -1
      name: Search action - Preview
      description: After you create a content search using the !o365-sc-new-search command and run it using the !o365-sc-start-search command, you assign a search action to the search using the !o365-sc-new-search-action command.
      script: '|||o365-sc-new-search-action'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "3"
      '#error#':
      - "8"
    scriptarguments:
      action:
        simple: Preview
      retry-count:
        simple: "10"
      search_name:
        complex:
          root: inputs.search_name
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 195
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerror: true
    continueonerrortype: errorPath
  "7":
    id: "7"
    taskid: 84d44b24-58e7-49aa-8747-b9f0cbf9bb5f
    type: regular
    task:
      id: 84d44b24-58e7-49aa-8747-b9f0cbf9bb5f
      version: -1
      name: Get preview results
      description: Get the compliance search action from the Security & Compliance Center.
      script: '|||o365-sc-get-search-action'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      export:
        simple: "true"
      results:
        simple: "true"
      retry-count:
        simple: "10"
      search_action_name:
        complex:
          root: O365.SecurityAndCompliance.ContentSearch.SearchAction
          accessor: Name
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 50,
          "y": 545
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
    continueonerrortype: ""
  "8":
    id: "8"
    taskid: 4c31505d-360d-4069-af68-09ad2c63e5b3
    type: regular
    task:
      id: 4c31505d-360d-4069-af68-09ad2c63e5b3
      version: -1
      name: Search preview is not supported
      description: Prints text to war room (Markdown supported)
      scriptName: Print
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "4"
    scriptarguments:
      value:
        simple: Email search preview could not be completed. This parameter is functional only in on-premises Exchange.
    separatecontext: false
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 540,
          "y": 370
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {},
    "paper": {
      "dimensions": {
        "height": 730,
        "width": 870,
        "x": 50,
        "y": 50
      }
    }
  }
version: -1
fromversion: 5.5.0
tests:
- No tests (deprecated)
supportedModules:
- agentix
- cloud
- xsiam
- edr
- cloud_runtime_security
contentitemexportablefields:
  contentitemfields: {}