GuardianCases
Query anomaly detection cases via the Guardian API.
Select
The connector uses the Talkdesk API to process WHERE clause conditions built with the following columns and operators. The rest of the filter is executed client-side within the connector.
| Column | Supported Operators |
| Id | =, IN, IS, IS_NOT, NOT_IN |
| EventId | =, IN, IS, IS_NOT, NOT_IN |
| UserId | =, IN, IS, IS_NOT, NOT_IN |
| IngestTimestamp | =, IS, IS_NOT, <, <=, >, >= |
| CaseType | =, CONTAINS, LIKE, IS, IS_NOT |
| Specification | =, CONTAINS, LIKE, IS, IS_NOT |
| Source | =, IN, IS, IS_NOT, NOT_IN |
| HitsNumber | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| UserProb | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| UserConf | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| PopProb | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| PopConf | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
For example, the following query is processed server-side:
SELECT * FROM GuardianCases WHERE Id = 'value'
The connector pushes the ORDER BY clause to the Talkdesk API for the following columns. Sorting on any other column is performed client-side within the connector.
- IngestTimestamp supports the following sort directions: ASC, DESC.
For example, the following query is sorted server-side:
SELECT * FROM GuardianCases ORDER BY IngestTimestamp ASC
Columns
| Name | Type | References | Description |
| Id [KEY] | String | The unique identifier of the anomaly case. | |
| EventId | String | The identifier of the event that triggered the anomaly. | |
| UserId | String |
Users.Id | The identifier of the user that triggered the anomaly. |
| IngestTimestamp | Datetime | The ingestion timestamp of the anomaly. | |
| CaseType | String | The case type identifier (e.g. country_code). | |
| Specification | String | The specification of the case (e.g. inbound calls). | |
| Source | String | The anomaly source. Allowed values: DATABRICKS, ELASTICSEARCH. | |
| Hits | String | JSON array of anomalous values. | |
| HitsNumber | Integer | The number of anomalous values. | |
| Baseline | Integer | The baseline of the current case. | |
| UserProb | Double | The probability of hits for the user. | |
| UserConf | Double | The confidence in the anomaly regarding the user baseline. | |
| PopProb | Double | The probability of hits for the peers. | |
| PopConf | Double | The confidence in the anomaly regarding the peer baseline. | |
| UserBaseline | String | JSON array of user baseline values. | |
| PopBaseline | String | JSON array of peer baseline values. |