Search security events
castle_search_eventsQuery the security event stream — logins, registrations, transactions and their risk verdicts. Read-only despite being a POST: Castle takes the query in the body. Castle: POST /v1/events/query.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| page | No | 1-based page number. | |
| columns | No | Only return these event fields. | |
| filters | Yes | Castle query filters, ANDed together. Each is {field, op, value} — e.g. {"field":"user.email","op":"$eq","value":"a@example.com"}. Operators: $eq, $neq, $in, $nin, $like, $nlike, $contains, $ncontains, $starts_with, $nstarts_with, $ends_with, $nends_with, $matches, $nmatches, $ip_range, $nip_range, $relative_range (value {gt,gteq,lt,lteq} in seconds ago), $range, $exists. Call castle_get_events_schema first to see the available field names. | |
| query_type | No | Return matching records, just a count, or both. Defaults to records. | |
| results_size | No | Results per page, 1-100. |