Velociraptor icon

Velociraptor

Interact with Velociraptor DFIR platform via gRPC API

Execute VQL

AI-generated

Summary

Execute a Velocity Query Language (VQL) query on the connected Velociraptor server and return the resulting data rows.

Inputs

  • VQL Query (required) — The VQL query string to execute on the Velociraptor server, e.g. 'SELECT * FROM clients() LIMIT 10'.

Output shape

a list of JSON objects representing the rows returned by the VQL query

Each item in the output array corresponds to one row returned by the VQL query. The exact structure depends on the query executed. Errors in query execution result in node operation errors.

Examples

Example 1: Retrieve client information

Set 'VQL Query' to 'SELECT * FROM clients() LIMIT 10' to get up to 10 client records from Velociraptor.

Links

Discussion