Knowledge Article

Identity Security Cloud Common Search Queries

Author

  • neil_mcglennon

    SailPoint

This document aims to provide a quick set of commonly-used example search queries. This should not only give you a good reference of syntax and features, but also how to easily find what you are looking for.

For additional information on building search queries, refer to the Search-related topics in the Identity Security Cloud Admin Help:

https://documentation.sailpoint.com/saas/help/search/index.html

Common Identity Searches

Find all identities with username of 'neil.mcglennon'

Note: This is useful for doing authentication troubleshooting.

attributes.uid:"neil.mcglennon"

Find all identities with a custom attribute, department, is 'Inventory'.

Note: department is not an out-of-the-box identity attribute. Your attributes may vary.

attributes.department:"Inventory"

Find all identities with no email, last name, or username attribute.

Note: This is useful for fixing identity exceptions.

(NOT _exists_:attributes.lastname) OR (NOT _exists_:attributes.email) OR (NOT _exists_:attributes.uid)

Find all identities with no lifecycle state assigned.

NOT _exists_:attributes.cloudLifecycleState

Find all identities with email that ends with a certain domain (@acme.com):

attributes.email:"*@acme.com"

Find all identities with a last name which starts with A through M (uses regex).

Note: Elasticsearch Regex Syntax

attributes.lastname:/[a-m].*/

Find all identities which were created within a specified time range (e.g. in the past week timeframe):

created:[now-1w TO now]

Note: Elasticsearch uses 'now' as a keyword for current time and date. It also supports date math with the following:

  • y (year)
  • M (month)
  • w (week)
  • d (day)
  • h (hour)
  • m (minute)
  • s (second)

It also supports operations: 

  • - (subtraction)
  • + (addition)
  • / (round)

 So if you say now-1d that is yesterday, and now+1w is next week.

Find all identities which have more than 100 accounts:

Note: This detects identities with a lot of accounts, which are good for troubleshooting object slowness.

accountCount:>100

Find identities that have errors:

processingState:ERROR

Find identities which were recently changed:

modified:>2025-04-19

Find identities which were recently created:

created:>2025-03-01 AND created:<2025-03-30

created:[2025-03-01 TO 2025-03-30]

Find all identities with a specific start date or end dates:

attributes.startDate:[2018-08-01 TO 2018-10-01]

attributes.endDate:[2018-09-01 TO 2018-09-30]

Find common identities which share manager by display name:

manager.displayName:"Bill Lumbergh"

Find common identities which share manager by manager ID:

manager.id:2c9180845d1edece015d27a96c973e0d

Find identities with Directory accounts which are disabled.

@accounts(source.name'Directory' AND disabled:true)​

Find identities with a certain IdentityNow invitation status:

Note: IdentityNow has three invitation statuses, UNREGISTERED, PENDING, and REGISTERED. Choose the right one which works for you.

attributes.cloudStatus:UNREGISTERED

attributes.cloudStatus:PENDING

attributes.cloudStatus:REGISTERED

Find identities which have manually correlated accounts on a certain source:

@accounts(source.name:'Directory' AND manuallyCorrelated:true)

Find entitlements that are marked as privileged:

privileged:true

Find entitlements marked with a specific privilege level:

privilegeLevel.direct:high
privilegeLevel.direct:medium
privilegeLevel.direct:low

Note: privileged:true and privilegeLevel.direct:high return the same results

Find identities with privileged accounts (on any source):

@accounts(privileged:true)​

Note: this concept can be applied to searching for identities with access to privileged entitlements

@access(privileged:true)

Find identities with locked accounts (on any source):

@accounts(locked:true)

Find identities with disabled accounts (on any source):

@accounts(disabled:true)

Find identities with accounts from a source (e.g. Employees) which were created in the past month:

@accounts(source.name:Employees AND created:[2017-03-01 TO 2017-03-30])

Find identities with AD accounts that have had a password set within a certain time period (using AD passwordLastSet timestamp):

@accounts( source.name:"Active Directory" AND passwordLastSet:[2024-08-01 TO 2025-09-01])

Find all identities on a specific identity profile:

identityProfile.name:HR

Find all identities who work in London:

attributes.location:London

Find all identities who work in London who started this year:

attributes.location:London AND created:[2024-01-01 TO now]

Find a manager's direct reports:

manager.name:brandy.smith

Note: this syntax will also work with manager.id: or manager.displayName:

Find identities with a specific role:

@access(type:ROLE AND name:Inventory*)

Find inactive identities with active accounts:

attributes.cloudLifecycleState:inactive AND @accounts(disabled:false)

Find out whether privileged access was revoked for previous contingent workers:

identityProfile.name:contractors AND attributes.cloudLifecycleState:inactive AND @access(value:EXCHANGESERVER*)

Find identities who haven't finished registering in Identity Security Cloud:

attributes.cloudStatus:PENDING OR attributes.cloudStatus:UNREGISTERED

Find identities from the Sales department who have Webex accounts who don't have a particular entitlement:

attributes.department:Sales AND @accounts(source.name:webex) AND NOT @access(value:"MeetingType 220")

Find identities that don't have a manager:

NOT _exists_:manager.name

Note: this syntax will also work as manager.id or manager.displayName

Find all the identities with certain elevated user levels within Identity Security Cloud:

@access(value:(ORG_ADMIN OR HELPDESK OR DASHBOARD OR CERT_ADMIN) AND type:ENTITLEMENT AND source.name:IdentityNow)

Find all the identities with Admin-level access in Identity Security Cloud:

@access(value:ORG_ADMIN AND type:ENTITLEMENT AND source.name:IdentityNow)

Find all identities that have a lifecycle state of terminated in IdentityNow with accounts on Active Directory that are still enabled:

attributes.cloudLifecycleState:Inactive AND @accounts(source.name:"Active Directory" AND disabled:false)

Find identities that are active in IdentityNow but who have disabled Active Directory accounts:

attributes.cloudLifecycleState:Active AND @accounts(source.name:"Active Directory" AND disabled:true)

Find all active identities that have anything listed in their personal email field:

attributes.cloudLifecycleState:active AND _exists_:attributes.personalEmail