Chainsaw: summarise a result
chainsaw_result_summarySummarize stored hunt results without paging by aggregating counts and grouping by event fields, enabling pivots for deeper searches.
Instructions
Aggregate a stored result without paging through it.
Use the default overview to understand a hunt, then group by specific event fields (users, processes, source IPs, logon IDs) to build pivots for chainsaw_search.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| top | No | Values per grouping. | |
| where | No | Filters applied before counting; same matching rules as chainsaw_result_page's where. | |
| handle | Yes | Result handle returned by a hunt, search, dump or analysis tool. | |
| group_by | No | Field paths or shorthand names to count by, e.g. ['rule', 'computer'] or ['document.data.Event.EventData.TargetUserName']. Omit for the standard overview (rules, levels, hosts, channels, event IDs, hours). |