Chainsaw: page a result
chainsaw_result_pageRead a page of stored Chainsaw hunt detections or raw search documents, with optional field projection and filters. Iterate using next_offset to page through large results without loading raw logs.
Instructions
Read a page of rows from a stored result, optionally projected and filtered.
Rows are chainsaw detections (hunt) or raw documents (search, dump). Iterate with next_offset until it is null.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| limit | No | Rows to return. | |
| where | No | Filters, field path or shorthand -> value; all must match. Text matches as a case-insensitive substring, numbers and booleans exactly (event_id: '4624' matches 4624 only). An aggregate hunt row matches when any of its documents matches. Example: {'level': 'critical', 'computer': 'DC01'}. | |
| fields | No | Dotted paths to project, e.g. ['name', 'level', 'document.data.Event.EventData.CommandLine']. Shorthand names from chainsaw_result_fields also work. Omit for whole rows. | |
| handle | Yes | Result handle returned by a hunt, search, dump or analysis tool. | |
| offset | No | First row index to return. | |
| max_bytes | No | Encoded response byte budget. |