Skip to content

Get FalconContainerDriftIndicator

bk-cs edited this page Sep 4, 2024 · 3 revisions

Get-FalconContainerDriftIndicator

SYNOPSIS

Search for Falcon Container Security container drift indicators

DESCRIPTION

Requires 'Falcon Container Image: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Falcon Cloud Security drift indicator X X
Filter String Falcon Query Language expression to limit results

cid
cloud_name
command_line
container_id
file_name
file_sha256
host_id
indicator_process_id
namespace
occurred_at
parent_process_id
pod_name
prevented
scheduler_name
severity
worker_node_name
Sort String Property and direction to sort results
Limit Int32 Maximum number of results per request
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconContainerDriftIndicator [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconContainerDriftIndicator -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconContainerDriftIndicator [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] -Detailed [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /container-security/combined/drift-indicators/v1
GET /container-security/entities/drift-indicators/v1
GET /container-security/queries/drift-indicators/v1

falconpy

SearchDriftIndicators
ReadDriftIndicatorEntities
SearchAndReadDriftIndicatorEntities

USAGE

2024-09-03: PSFalcon v2.2.7

Clone this wiki locally