| Column Name | Column Data Type |
search_id Required Input Column
The identifier of the search job to get details for. | VARCHAR |
_aws_profile Input Column
The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role. | STRUCT( "type" VARCHAR, "name" VARCHAR, "account_id" VARCHAR, "via_profile_name" VARCHAR, "assumed_role_arn" VARCHAR, "organization" STRUCT( "account_name" VARCHAR, "id" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[], "master_account" STRUCT( "id" VARCHAR, "email" VARCHAR ), "parents" STRUCT( "type" VARCHAR, "id" VARCHAR, "name" VARCHAR, "tags" STRUCT( "key" VARCHAR, "value" VARCHAR )[] )[] ) ) |
Show child fields- _aws_profile.account_id
The AWS account id
- _aws_profile.assumed_role_arn
The ARN of the assumed role
- _aws_profile.name
The unique name of the profile.
- _aws_profile.organization
Information about this profile's membership in the AWS organization. Show child fields- _aws_profile.organization.account_name
The name of account speciifed by the organization
- _aws_profile.organization.id
The organization id
- _aws_profile.organization.master_account
Show child fields- _aws_profile.organization.master_account.email
The organization master account email address
- _aws_profile.organization.master_account.id
The organization master account id
- _aws_profile.organization.parents[]
Show child fields- _aws_profile.organization.parents[].id
The id of the parent
- _aws_profile.organization.parents[].name
The name of the parent
- _aws_profile.organization.parents[].tags[]
Show child fields- _aws_profile.organization.parents[].tags[].key
- _aws_profile.organization.parents[].tags[].value
- _aws_profile.organization.parents[].type
The type of parent can be an organization unit or a root
- _aws_profile.organization.tags[]
Show child fields- _aws_profile.organization.tags[].key
- _aws_profile.organization.tags[].value
- _aws_profile.type
The type of profile, either 'credentials' or 'assumed_role'
- _aws_profile.via_profile_name
This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.
|
archive_id
The identifier of the archive the email search was performed in. | VARCHAR |
filters
The criteria used to filter emails included in the search. | STRUCT( "include" STRUCT( "boolean_expression" STRUCT( "evaluate" STRUCT( "attribute" VARCHAR ), "operator" VARCHAR ), "string_expression" STRUCT( "evaluate" STRUCT( "attribute" VARCHAR ), "operator" VARCHAR, "values" VARCHAR[] ) )[], "unless" STRUCT( "boolean_expression" STRUCT( "evaluate" STRUCT( "attribute" VARCHAR ), "operator" VARCHAR ), "string_expression" STRUCT( "evaluate" STRUCT( "attribute" VARCHAR ), "operator" VARCHAR, "values" VARCHAR[] ) )[] ) |
Show child fields- filters.include[]
Show child fields- filters.include[].boolean_expression
A boolean expression to evaluate against email attributes. Show child fields- filters.include[].boolean_expression.evaluate
The email attribute value to evaluate. Show child fields- filters.include[].boolean_expression.evaluate.attribute
The name of the email attribute to evaluate.
- filters.include[].boolean_expression.operator
The boolean operator to use for evaluation.
- filters.include[].string_expression
A string expression to evaluate against email attributes. Show child fields- filters.include[].string_expression.evaluate
The attribute of the email to evaluate. Show child fields- filters.include[].string_expression.evaluate.attribute
The name of the email attribute to evaluate.
- filters.include[].string_expression.operator
The operator to use when evaluating the string values.
- filters.include[].string_expression.values[]
- filters.unless[]
Show child fields- filters.unless[].boolean_expression
A boolean expression to evaluate against email attributes. Show child fields- filters.unless[].boolean_expression.evaluate
The email attribute value to evaluate. Show child fields- filters.unless[].boolean_expression.evaluate.attribute
The name of the email attribute to evaluate.
- filters.unless[].boolean_expression.operator
The boolean operator to use for evaluation.
- filters.unless[].string_expression
A string expression to evaluate against email attributes. Show child fields- filters.unless[].string_expression.evaluate
The attribute of the email to evaluate. Show child fields- filters.unless[].string_expression.evaluate.attribute
The name of the email attribute to evaluate.
- filters.unless[].string_expression.operator
The operator to use when evaluating the string values.
- filters.unless[].string_expression.values[]
|
from_timestamp
The start timestamp of the range the searched emails cover. | TIMESTAMP_S |
max_results
The maximum number of search results to return. | BIGINT |
status
The current status of the search job. | STRUCT( "completion_timestamp" TIMESTAMP_S, "error_message" VARCHAR, "state" VARCHAR, "submission_timestamp" TIMESTAMP_S ) |
Show child fields- status.completion_timestamp
The timestamp of when the search completed (if finished).
- status.error_message
An error message if the search failed.
- status.state
The current state of the search job.
- status.submission_timestamp
The timestamp of when the search was submitted.
|
to_timestamp
The end timestamp of the range the searched emails cover. | TIMESTAMP_S |