---
title: "Search Cloud Activities"
method: POST
path: "/api/v2/CloudActivities/search"
tags: ["CloudActivities"]
---

# Search Cloud Activities

`POST /api/v2/CloudActivities/search`

Search cloud activities by invoking the following endpoint:

  > `POST https://YourAccount.lacework.net/api/v2/CloudActivities/search` 

 Optionally specify filters in the request body. For more information about using filters, see the [Simple & Advanced Search section](/api/v2/docs/#tag/OVERVIEW).

 For the `timeFilter` filter, these are the supported time formats:

 * `yyyy-MM-dd` for example, `2021-12-18` 

 * `yyyy-MM-ddTHH` for example, `2021-12-18T08` 

 * `yyyy-MM-ddTHH:mm:ssZ` for example, `2021-12-18T08:00:00Z` 

 * `yyyy-MM-ddTHH:mm:ss.SSSZ` for example, `2021-12-18T08:00:00.000Z`

 The `rlike` and `not_rlike` operators are useful for filtering results. For example, the following expression limits results to the `CreateTags` API:

 > `"filters": [ { "expression": "rlike", "field": "entityMap.API", "value": ".CreateTags." } ]`  

 Here is another example that shows how to limit results to those with the numeric pattern specified as the resource ID:

 > `"filters": [ { "expression": "rlike", "field": "entityMap.Resource",  "value": ".3\.0\.529\.0." } ]` 

 Here are some additional example `body` payloads: 
 * `{ "timeFilter": { "startTime": "2021-12-11T00:00:00Z", "endTime": "2021-12-12T00:00:00Z"},` 
 `"filters": [ { "field": "eventType", "expression": "eq", "value": "NewUser" } ] }` 
 * `{ "timeFilter": { "startTime": "2021-12-11T00:00:00Z", "endTime": "2021-12-12T00:00:00Z"},` 
 `"filters": [ { "field": "eventType", "expression": "eq", "value": "NewUser" },`  
 `{ "field": "eventModel", "expression": "eq", "value": "AwsApiTracker" } ],`  
 `"returns":[ "startTime", "endTime", "eventType", "eventActor", "eventModel" ] }` 

 To use the current time as the end time, exclude the endTime field.

## Headers

- `Authorization` string, required
- `Content-Type` string, required

## Request body

- GETDATAREQUESTBODYTIMEFILTERS
  - `timeFilter` object — The date/time range during which actions occurred.
    - `startTime` string — Returns only recorded actions that occurred after this timestamp.
    - `endTime` string — Returns only recorded actions that occurred before this timestamp. If empty or missing, the current time is used.
  - `filters` object[] — One or more condition statements you can use to refine the data returned by the request. Only records that satisfy filtering conditions are returned. If there are multiple conditions, a record must satisfy all conditions for a match.
    - `expression` 'eq' | 'ne' | 'in' | 'not_in' | 'like' | 'ilike' | 'not_like' | 'not_ilike' | 'not_rlike' | 'rlike' | 'gt' | 'ge' | 'lt' | 'le' | 'between', required — The comparison operator for the filter condition.
    - `field` string, required — The name of the data field to which the condition applies.
    - `value` string — The value that the condition checks for in the specified field. Use this attribute when specifying a single value.
    - `values` string[] — The values that the condition checks for in the specified field. Use this attribute when specifying multiple values.
  - `returns` string[] — Use this attribute to specify which top-level fields of the response schema you want to receive.

## Response `200`

No Error (List of Cloud Activities)

- object
  - `paging` PagingSchema — Details of the response's pagination
    - `rows` number — The number of rows displayed on each page
    - `totalRows` number — The number of rows returned from the query
    - `urls` object — Pagination-related URLs
      - `nextPage` string — The next page's URL
  - `data` CloudActivitiesResponseSchema[]
    - `startTime` string
    - `endTime` string
    - `eventType` string
    - `eventId` number
    - `eventModel` string
    - `eventActor` string
    - `entityMap` object

## Other responses

- `204` — No Data
- `4XX` — Client Error
- `5XX` — Internal Server Error

---

[API](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation.md) · [All operations](https://skmtc.net/lacework/apis/forticnapp-api-2-0-documentation/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/lacework/forticnapp-api-2-0-documentation/revisions/7015f76895f2/schema)
