Velociraptor icon

Velociraptor

Interact with Velociraptor DFIR platform via gRPC API

Get Flow Results

AI-generated

Summary

Retrieve and return the results of a completed collection flow executed on a specified Velociraptor client.

Inputs

  • Client ID (required) — The Velociraptor client ID to retrieve flow results from, e.g., C.1234567890abcdef.
  • Flow ID (required) — The Flow ID of the completed collection flow, e.g., F.C123456.
  • Artifact Source — Optional artifact source path to filter results by (e.g., ArtifactName/SourceName). Leave blank to retrieve all artifact sources from the flow.

Output shape

a list of JSON objects, each representing flow results grouped by artifact source, containing the artifact name, source path, count of results, and the array of result rows. If no results are found, returns a JSON object with a message indicating no results.

If 'Artifact Source' is blank, results from all sources in the specified flow are returned. If an artifact name is provided without a slash, all matching sources for that artifact are returned. Handles multiple artifact sources by querying them sequentially and aggregating results. Errors indicate failure to retrieve or parse flow data.

Links

Discussion