STELLAR CYBER · DATA EXPORT
Query once. Export safely at scale.
Choose data, time, query, output and destination. Safe defaults handle the rest; advanced tuning is available when needed.
Stellar Cyber
Choose the credential type you were issued. Credentials stay in this session and are exchanged for a short-lived JWT.
Root Scope uses account email + All-Access Token. JWT refresh is automatic during long exports.
Query
Paste a query you wrote yourself or generated with any AI tool.
Select one or more Stellar Cyber data types. Internal index names are mapped automatically.
aella-ser-*
Use Elasticsearch DSL or paste a Stellar Cyber Lucene query. The selected time range is managed automatically.
Examples: event_status:New · event_name:"Login Failure" AND srcip:10.0.0.*
Request
—/connect/api/data/{select-data-source}/_search—Query
Statistics
Export Plan
Preview
Preview before starting a large export.
| Run Preview to inspect data |
|---|
| No data loaded yet. |
Output
Choose CSV or JSON. Advanced mode adds field, limit, compression and file-splitting controls.
Parts are split on record boundaries, so a file may slightly exceed the target size. Browser downloads with multiple parts are bundled into one ZIP.
Destination
Choose a direct browser download, S3-compatible object storage, or SFTP.
Adaptive export settings
Adaptive slices use half-open time ranges. Reject overlap blocks matching export pipelines whose requested time windows intersect; adjacent ranges are allowed.
Scheduled Export Optional
Run the current query/output configuration repeatedly to S3 or SFTP.
Schedules require S3/SFTP. Query and credentials are encrypted at rest; scheduled runs always reject matching overlap and continue from the last successful window.
| Name | Cadence | Window | Next | Last status | Actions |
|---|---|---|---|---|---|
| Loading schedules… | |||||
Ready to export
Review the summary, then start the export when all settings are complete.
Credentials stay in memory only; remote-job credentials are discarded after completion.
Export History
Recent jobs persist across exporter restarts without storing credentials or raw queries.
| Created | Status | Sources | Range | Output | Destination | Records / Size | Checkpoint | Action | Result |
|---|---|---|---|---|---|---|---|---|---|
| Loading export history… | |||||||||
Stored metadata excludes API tokens, S3 credentials, SFTP passwords/private keys, and raw query contents. Resume verifies completed split parts by SHA-256; re-enter the original settings and credentials before resuming.