O365 - Security And Compliance - Search Action - Preview Deprecated
Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead. This playbook perform: 1. Creates a new compliance search action - Preview (Base on created compliance search). 2. Waits for the preview action to complete. 3. Retrieves the preview results.
Microsoft Exchange Online · 6 tasks · 3 inputs · 32 outputs
Details
| ID | O365 - Security And Compliance - Search Action - Preview |
|---|---|
| From Version | 5.5.0 |
| Tasks | 6 |
README
This playbook perform:
- Creates a new compliance search action - Preview (Base on created compliance search).
- Waits for the preview action to complete.
- Retrieves the preview results.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
- Waiting for search action to complete
Integrations
- SecurityAndCompliance
Scripts
This playbook does not use any scripts.
Commands
- o365-sc-get-search-action
- o365-sc-new-search-action
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| search_name | The name of the compliance search. | Required | |
| polling_interval | Search action polling interval. | 3 | Optional |
| polling_timeout | Search action polling timeout. | 45 | Optional |
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Action | Security and compliance search action type. Either “Purge” or “Preview”. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled | Whether to include mailboxes other than regular user mailboxes in the compliance search. | Boolean |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled | Whether the Azure Batch Framework is enabled for job processing. | Boolean |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId | Identity of a Core eDiscovery case which is associated with the compliance search. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName | Name of a Core eDiscovery case which is associated with the compliance search. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy | Security and compliance search action creator. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime | Security and compliance search action creation time. | Date |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Description | Security and compliance search action description. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors | Security and compliance search action errors. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId | Security and compliance search action job ID estimation. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId | Security and compliance search action run ID estimation. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation | Security and compliance search action exchange locations to include. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion | Security and compliance search action exchange locations to exclude. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity | Security and compliance search action identity. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid | Whether the security and compliance search action is valid. | Boolean |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime | Security and compliance search action job end time. | Date |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId | Security and compliance search action job ID. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId | Security and compliance search action job run ID. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime | Security and compliance search action job start time. | Date |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime | Security and compliance search action last modified time. | Date |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Name | Security and compliance search action name. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation | Security and compliance search action public folder locations to include. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion | Security and compliance search action public folder locations to exclude. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Location | Security and compliance search action result location. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Sender | Security and compliance search action result mail sender. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Subject | Security and compliance search action result subject. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Type | Security and compliance search action result type. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.Size | Security and compliance search action result size. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.ReceivedTime | Security and compliance search action result received time. | Date |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Results.DataLink | Security and compliance search action data link. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry | Whether to retry if the search action failed. | Boolean |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy | Security and compliance search action run by UPN (email address). | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId | Security and compliance search action run space ID. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName | Security and compliance search action search name. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation | Security and compliance search action SharePoint locations to include. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion | Security and compliance search action SharePoint locations to exclude. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.Status | Security and compliance search action status. Either “Started” or “Completed”. | String |
| O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId | Security and compliance search action Tenant ID. | String |
Playbook Image

Known Limitations
- Each security and compliance command creates a PSSession (PowerShell session). The security and compliance PowerShell limits the number of concurrent sessions to 3. Since this affects the behavior of multiple playbooks running concurrently it we recommend that you retry failed tasks when using the integration commands in playbooks.
- In order to handle sessions limits, A retry mechanism is applied which will retry for 10 time with 30 sec breaks. (The retry isn’t applied on the generic polling as it’s not supported yet)
Inputs
search_name— The name of the compliance search.polling_interval— Search action polling interval.polling_timeout— Search action polling timeout.
Outputs
O365.SecurityAndCompliance.ContentSearch.SearchAction.Action— Security and compliance search action type. Either "Purge" or "Preview".O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled— Whether to include mailboxes other than regular user mailboxes in the compliance search.O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled— Whether the Azure Batch Framework is enabled for job processing.O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId— Identity of a Core eDiscovery case which is associated with the compliance search.O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName— Name of a Core eDiscovery case which is associated with the compliance search.O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy— Security and compliance search action creator.O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime— Security and compliance search action creation time.O365.SecurityAndCompliance.ContentSearch.SearchAction.Description— Security and compliance search action description.O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors— Security and compliance search action errors.O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId— Security and compliance search action job ID estimation.O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId— Security and compliance search action run ID estimation.O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation— Security and compliance search action exchange locations to include.O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion— Security and compliance search action exchange locations to exclude.O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity— Security and compliance search action identity.O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid— Whether the security and compliance search action is valid.O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime— Security and compliance search action job end time.O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId— Security and compliance search action job ID.O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId— Security and compliance search action job run ID.O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime— Security and compliance search action job start time.O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime— Security and compliance search action last modified time.O365.SecurityAndCompliance.ContentSearch.SearchAction.Name— Security and compliance search action name.O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation— Security and compliance search action public folder locations to include.O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion— Security and compliance search action public folder locations to exclude.O365.SecurityAndCompliance.ContentSearch.SearchAction.Results— Security and compliance search action results.O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry— Whether to retry if the search action failed.O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy— Security and compliance search action run by UPN (email address).O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId— Security and compliance search action run space ID.O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName— Security and compliance search action search name.O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation— Security and compliance search action SharePoint locations to include.O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion— Security and compliance search action SharePoint locations to exclude.O365.SecurityAndCompliance.ContentSearch.SearchAction.Status— Security and compliance search action status. Either "Started" or "Completed".O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId— Security and compliance search action Tenant ID.
Commands used
o365-sc-get-search-action
o365-sc-new-search-action
Flowchart
deprecated: true description: |- Deprecated. Use the Microsoft Graph Security - Search And Delete Emails playbook instead. This playbook perform: 1. Creates a new compliance search action - Preview (Base on created compliance search). 2. Waits for the preview action to complete. 3. Retrieves the preview results. id: O365 - Security And Compliance - Search Action - Preview inputs: - key: search_name value: {} required: true description: The name of the compliance search. playbookInputQuery: - key: polling_interval value: simple: "1" required: false description: Search action polling interval. playbookInputQuery: - key: polling_timeout value: simple: "10" required: false description: Search action polling timeout. playbookInputQuery: name: O365 - Security And Compliance - Search Action - Preview outputs: - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Action description: Security and compliance search action type. Either "Purge" or "Preview". type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.AllowNotFoundExchangeLocationsEnabled description: Whether to include mailboxes other than regular user mailboxes in the compliance search. type: Boolean - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.AzureBatchFrameworkEnabled description: Whether the Azure Batch Framework is enabled for job processing. type: Boolean - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseId description: Identity of a Core eDiscovery case which is associated with the compliance search. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CaseName description: Name of a Core eDiscovery case which is associated with the compliance search. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedBy description: Security and compliance search action creator. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.CreatedTime description: Security and compliance search action creation time. type: Date - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Description description: Security and compliance search action description. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Errors description: Security and compliance search action errors. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchJobId description: Security and compliance search action job ID estimation. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.EstimateSearchRunId description: Security and compliance search action run ID estimation. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocation description: Security and compliance search action exchange locations to include. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.ExchangeLocationExclusion description: Security and compliance search action exchange locations to exclude. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Identity description: Security and compliance search action identity. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.IsValid description: Whether the security and compliance search action is valid. type: Boolean - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobEndTime description: Security and compliance search action job end time. type: Date - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobId description: Security and compliance search action job ID. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobRunId description: Security and compliance search action job run ID. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.JobStartTime description: Security and compliance search action job start time. type: Date - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.LastModifiedTime description: Security and compliance search action last modified time. type: Date - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Name description: Security and compliance search action name. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocation description: Security and compliance search action public folder locations to include. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.PublicFolderLocationExclusion description: Security and compliance search action public folder locations to exclude. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Results description: Security and compliance search action results. type: unknown - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Retry description: Whether to retry if the search action failed. type: Boolean - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.RunBy description: Security and compliance search action run by UPN (email address). type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.RunspaceId description: Security and compliance search action run space ID. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SearchName description: Security and compliance search action search name. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocation description: Security and compliance search action SharePoint locations to include. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.SharePointLocationExclusion description: Security and compliance search action SharePoint locations to exclude. type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.Status description: Security and compliance search action status. Either "Started" or "Completed". type: String - contextPath: O365.SecurityAndCompliance.ContentSearch.SearchAction.TenantId description: Security and compliance search action Tenant ID. type: String starttaskid: "0" tasks: "0": id: "0" taskid: e9df5f91-1e9e-4fa8-87eb-6f0df3714bc1 type: start task: id: e9df5f91-1e9e-4fa8-87eb-6f0df3714bc1 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "6" separatecontext: false view: |- { "position": { "x": 50, "y": 50 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "3": id: "3" taskid: 3465b210-3e8c-4e68-82d8-a71d09b64106 type: playbook task: id: 3465b210-3e8c-4e68-82d8-a71d09b64106 version: -1 name: Waiting for search action to complete description: |- Use this playbook as a sub-playbook to block execution of the master playbook until a remote action is complete. This playbook implements polling by continuously running the command in Step \#2 until the operation completes. The remote action should have the following structure: 1. Initiate the operation. 2. Poll to check if the operation completed. 3. (optional) Get the results of the operation. playbookName: GenericPolling type: playbook iscommand: false brand: "" nexttasks: '#none#': - "7" scriptarguments: Ids: complex: root: O365.SecurityAndCompliance.ContentSearch accessor: SearchAction transformers: - operator: DT args: dt: value: simple: '.=val.SearchStatus!=="NotFound" ? val.Name : val.Name + "_Preview"' Interval: simple: ${inputs.polling_interval} PollingCommandArgName: simple: search_action_name PollingCommandName: simple: o365-sc-get-search-action Timeout: simple: ${inputs.polling_timeout} dt: simple: O365.SecurityAndCompliance.ContentSearch.SearchAction(val.Status && val.Status == "InProgress" || val.Status == "Starting" || val.Status == "Purging").Name separatecontext: true loop: iscommand: false exitCondition: "" wait: 1 max: 100 view: |- { "position": { "x": 50, "y": 370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "4": id: "4" taskid: a3b5cc33-9b80-4aa9-8413-a5ad3567168c type: title task: id: a3b5cc33-9b80-4aa9-8413-a5ad3567168c version: -1 name: Search action completed. type: title iscommand: false brand: "" description: '' separatecontext: false view: |- { "position": { "x": 50, "y": 720 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "6": id: "6" taskid: 1a18141a-1cfd-4843-8fc4-2f1db333e66d type: regular task: id: 1a18141a-1cfd-4843-8fc4-2f1db333e66d version: -1 name: Search action - Preview description: After you create a content search using the !o365-sc-new-search command and run it using the !o365-sc-start-search command, you assign a search action to the search using the !o365-sc-new-search-action command. script: '|||o365-sc-new-search-action' type: regular iscommand: true brand: "" nexttasks: '#none#': - "3" '#error#': - "8" scriptarguments: action: simple: Preview retry-count: simple: "10" search_name: complex: root: inputs.search_name separatecontext: false view: |- { "position": { "x": 50, "y": 195 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerror: true continueonerrortype: errorPath "7": id: "7" taskid: 84d44b24-58e7-49aa-8747-b9f0cbf9bb5f type: regular task: id: 84d44b24-58e7-49aa-8747-b9f0cbf9bb5f version: -1 name: Get preview results description: Get the compliance search action from the Security & Compliance Center. script: '|||o365-sc-get-search-action' type: regular iscommand: true brand: "" nexttasks: '#none#': - "4" scriptarguments: export: simple: "true" results: simple: "true" retry-count: simple: "10" search_action_name: complex: root: O365.SecurityAndCompliance.ContentSearch.SearchAction accessor: Name separatecontext: false view: |- { "position": { "x": 50, "y": 545 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false continueonerrortype: "" "8": id: "8" taskid: 4c31505d-360d-4069-af68-09ad2c63e5b3 type: regular task: id: 4c31505d-360d-4069-af68-09ad2c63e5b3 version: -1 name: Search preview is not supported description: Prints text to war room (Markdown supported) scriptName: Print type: regular iscommand: false brand: "" nexttasks: '#none#': - "4" scriptarguments: value: simple: Email search preview could not be completed. This parameter is functional only in on-premises Exchange. separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 540, "y": 370 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": {}, "paper": { "dimensions": { "height": 730, "width": 870, "x": 50, "y": 50 } } } version: -1 fromversion: 5.5.0 tests: - No tests (deprecated) supportedModules: - agentix - cloud - xsiam - edr - cloud_runtime_security contentitemexportablefields: contentitemfields: {}