GuardianCases
Query anomaly detection cases via the Guardian API.
Select
The add-in uses the Talkdesk API to process WHERE clause conditions built with the following columns and operators. The rest of the filter is executed client-side within the add-in.
| Column | Supported Operators |
| Id | =, IN, IS, IS_NOT, NOT_IN |
| EventId | =, IN, IS, IS_NOT, NOT_IN |
| UserId | =, IN, IS, IS_NOT, NOT_IN |
| IngestTimestamp | =, IS, IS_NOT, <, <=, >, >= |
| CaseType | =, CONTAINS, LIKE, IS, IS_NOT |
| Specification | =, CONTAINS, LIKE, IS, IS_NOT |
| Source | =, IN, IS, IS_NOT, NOT_IN |
| HitsNumber | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| UserProb | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| UserConf | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| PopProb | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
| PopConf | =, IN, IS, IS_NOT, NOT_IN, <, <=, >, >= |
For example, the following query is processed server-side:
SELECT * FROM GuardianCases WHERE Id = 'value'
The add-in pushes the ORDER BY clause to the Talkdesk API for the following columns. Sorting on any other column is performed client-side within the add-in.
- IngestTimestamp supports the following sort directions: ASC, DESC.
For example, the following query is sorted server-side:
SELECT * FROM GuardianCases ORDER BY IngestTimestamp ASC
Columns
| Name | Type | References | Description |
| Id [KEY] | String | The unique identifier of the anomaly case. | |
| EventId | String | The identifier of the event that triggered the anomaly. | |
| UserId | String |
Users.Id | The identifier of the user that triggered the anomaly. |
| IngestTimestamp | Datetime | The ingestion timestamp of the anomaly. | |
| CaseType | String | The case type identifier (e.g. country_code). | |
| Specification | String | The specification of the case (e.g. inbound calls). | |
| Source | String | The anomaly source. Allowed values: DATABRICKS, ELASTICSEARCH. | |
| Hits | String | JSON array of anomalous values. | |
| HitsNumber | Integer | The number of anomalous values. | |
| Baseline | Integer | The baseline of the current case. | |
| UserProb | Double | The probability of hits for the user. | |
| UserConf | Double | The confidence in the anomaly regarding the user baseline. | |
| PopProb | Double | The probability of hits for the peers. | |
| PopConf | Double | The confidence in the anomaly regarding the peer baseline. | |
| UserBaseline | String | JSON array of user baseline values. | |
| PopBaseline | String | JSON array of peer baseline values. |