Skip to content

Get FalconCorrelationRule

bk-cs edited this page Dec 19, 2024 · 1 revision

Get-FalconCorrelationRule

SYNOPSIS

Search for Falcon NGSIEM correlation rules

DESCRIPTION

Requires 'Correlation Rules: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Correlation rule identifier X X
Filter String Falcon Query Language expression to limit results
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results created_on|asc
created_on|desc
last_updated_on|asc
last_updated_on|desc
Limit Int32 Maximum number of results per request [default: 100]
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconCorrelationRule [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconCorrelationRule -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconCorrelationRule [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] -Detailed [-All] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /correlation-rules/combined/rules/v1
GET /correlation-rules/entities/rules/v1
GET /correlation-rules/queries/rules/v1

falconpy

queries_rules_get_v1
entities_rules_get_v1
combined_rules_get_v1

USAGE

2024-12-19: PSFalcon v2.2.8

Clone this wiki locally