Chainsaw: group detections by event
chainsaw_result_eventsPage through unique source-qualified events from a result handle, keeping every associated rule match, so agents can review detections without loading raw logs.
Instructions
Page unique source-qualified events, retaining every associated rule match.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Event groups to return. | |
| fields | No | Dotted paths or shorthand names to project inside each group's event. Omit for whole events. | |
| handle | Yes | Result handle returned by a hunt, search, dump or analysis tool. | |
| offset | No | First event-group offset to return (not a detection-row offset). | |
| max_bytes | No | Encoded response byte budget (256-131072). |