Knowledge Article
Identity Security Cloud Common Search Queries
Author
neil_mcglennon
SailPoint
This document aims to provide a quick set of commonly-used example search queries. This should not only give you a good reference of syntax and features, but also how to easily find what you are looking for.
For additional information on building search queries, refer to the Search-related topics in the Identity Security Cloud Admin Help:
https://documentation.sailpoint.com/saas/help/search/index.html
Common Identity Searches
Find all identities with username of 'neil.mcglennon'
Note: This is useful for doing authentication troubleshooting.
attributes.uid:"neil.mcglennon"
Find all identities with a custom attribute, department, is 'Inventory'.
Note: department is not an out-of-the-box identity attribute. Your attributes may vary.
attributes.department:"Inventory"
Find all identities with no email, last name, or username attribute.
Note: This is useful for fixing identity exceptions.
(NOT _exists_:attributes.lastname) OR (NOT _exists_:attributes.email) OR (NOT _exists_:attributes.uid)
Find all identities with no lifecycle state assigned.
NOT _exists_:attributes.cloudLifecycleState
Find all identities with email that ends with a certain domain (@acme.com):
attributes.email:"*@acme.com"
Find all identities with a last name which starts with A through M (uses regex).
Note: Elasticsearch Regex Syntax
attributes.lastname:/[a-m].*/
Find all identities which were created within a specified time range (e.g. in the past week timeframe):
created:[now-1w TO now]
Note: Elasticsearch uses 'now' as a keyword for current time and date. It also supports date math with the following:
- y (year)
- M (month)
- w (week)
- d (day)
- h (hour)
- m (minute)
- s (second)
It also supports operations:
- - (subtraction)
- + (addition)
- / (round)
So if you say now-1d that is yesterday, and now+1w is next week.
Find all identities which have more than 100 accounts:
Note: This detects identities with a lot of accounts, which are good for troubleshooting object slowness.
accountCount:>100
Find identities that have errors:
processingState:ERROR
Find identities which were recently changed:
modified:>2025-04-19
Find identities which were recently created:
created:>2025-03-01 AND created:<2025-03-30
created:[2025-03-01 TO 2025-03-30]
Find all identities with a specific start date or end dates:
attributes.startDate:[2018-08-01 TO 2018-10-01]
attributes.endDate:[2018-09-01 TO 2018-09-30]
Find common identities which share manager by display name:
manager.displayName:"Bill Lumbergh"
Find common identities which share manager by manager ID:
manager.id:2c9180845d1edece015d27a96c973e0d
Find identities with Directory accounts which are disabled.
@accounts(source.name'Directory' AND disabled:true)
Find identities with a certain IdentityNow invitation status:
Note: IdentityNow has three invitation statuses, UNREGISTERED, PENDING, and REGISTERED. Choose the right one which works for you.
attributes.cloudStatus:UNREGISTERED
attributes.cloudStatus:PENDING
attributes.cloudStatus:REGISTERED
Find identities which have manually correlated accounts on a certain source:
@accounts(source.name:'Directory' AND manuallyCorrelated:true)
Find entitlements that are marked as privileged:
privileged:true
Find entitlements marked with a specific privilege level:
privilegeLevel.direct:high
privilegeLevel.direct:medium
privilegeLevel.direct:low
Note: privileged:true and privilegeLevel.direct:high return the same results
Find identities with privileged accounts (on any source):
@accounts(privileged:true)
Note: this concept can be applied to searching for identities with access to privileged entitlements
@access(privileged:true)
Find identities with locked accounts (on any source):
@accounts(locked:true)
Find identities with disabled accounts (on any source):
@accounts(disabled:true)
Find identities with accounts from a source (e.g. Employees) which were created in the past month:
@accounts(source.name:Employees AND created:[2017-03-01 TO 2017-03-30])
Find identities with AD accounts that have had a password set within a certain time period (using AD passwordLastSet timestamp):
@accounts( source.name:"Active Directory" AND passwordLastSet:[2024-08-01 TO 2025-09-01])
Find all identities on a specific identity profile:
identityProfile.name:HR
Find all identities who work in London:
attributes.location:London
Find all identities who work in London who started this year:
attributes.location:London AND created:[2024-01-01 TO now]
Find a manager's direct reports:
manager.name:brandy.smith
Note: this syntax will also work with manager.id: or manager.displayName:
Find identities with a specific role:
@access(type:ROLE AND name:Inventory*)
Find inactive identities with active accounts:
attributes.cloudLifecycleState:inactive AND @accounts(disabled:false)
Find out whether privileged access was revoked for previous contingent workers:
identityProfile.name:contractors AND attributes.cloudLifecycleState:inactive AND @access(value:EXCHANGESERVER*)
Find identities who haven't finished registering in Identity Security Cloud:
attributes.cloudStatus:PENDING OR attributes.cloudStatus:UNREGISTERED
Find identities from the Sales department who have Webex accounts who don't have a particular entitlement:
attributes.department:Sales AND @accounts(source.name:webex) AND NOT @access(value:"MeetingType 220")
Find identities that don't have a manager:
NOT _exists_:manager.name
Note: this syntax will also work as manager.id or manager.displayName
Find all the identities with certain elevated user levels within Identity Security Cloud:
@access(value:(ORG_ADMIN OR HELPDESK OR DASHBOARD OR CERT_ADMIN) AND type:ENTITLEMENT AND source.name:IdentityNow)
Find all the identities with Admin-level access in Identity Security Cloud:
@access(value:ORG_ADMIN AND type:ENTITLEMENT AND source.name:IdentityNow)
Find all identities that have a lifecycle state of terminated in IdentityNow with accounts on Active Directory that are still enabled:
attributes.cloudLifecycleState:Inactive AND @accounts(source.name:"Active Directory" AND disabled:false)
Find identities that are active in IdentityNow but who have disabled Active Directory accounts:
attributes.cloudLifecycleState:Active AND @accounts(source.name:"Active Directory" AND disabled:true)
Find all active identities that have anything listed in their personal email field:
attributes.cloudLifecycleState:active AND _exists_:attributes.personalEmail