Velociraptor icon

Velociraptor

Interact with Velociraptor DFIR platform via gRPC API

List Clients

AI-generated

Summary

List clients from the Velociraptor DFIR platform, optionally filtered by last-seen time, hostname, label, and OS type.

Inputs

  • Last Seen Within (Seconds) — Return clients seen within this many seconds (set 0 for all clients). Defaults to 3600 seconds.
  • Hostname Filter — Case-insensitive substring or regex filter matched against client hostnames. Leave blank to skip filtering by hostname.
  • Label Filter — Case-insensitive substring or regex filter matched against client labels. Leave blank to skip filtering by label.
  • OS Filter — Case-insensitive substring or regex filter matched against client OS type. Leave blank to skip filtering by OS.

Output shape

a list of client records

Each record contains client_id, hostname, operating system, last seen timestamp (last_seen_at), and labels. The filters are applied in an AND fashion. Results are returned as JSON objects in the node's output.

Examples

Example 1: Filter clients seen within the last hour and with 'windows' in their OS type

Set 'Last Seen Within (Seconds)' to 3600 and 'OS Filter' to 'windows'. Leave other filters blank.

Links

Discussion