Skip to content

Get FalconDetection

bk-cs edited this page Sep 22, 2022 · 23 revisions

Get-FalconDetection

SYNOPSIS

Search for detections

DESCRIPTION

Requires 'Detections: Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Id String[] True True Detection identifier
Filter String False False Falcon Query Language expression to limit results
Query String False False Perform a generic substring search across available fields
Sort String adversary_id.asc
adversary_id.desc
devices.hostname.asc
devices.hostname.desc
first_behavior.asc
first_behavior.desc
last_behavior.asc
last_behavior.desc
max_confidence.asc
max_confidence.desc
max_severity.asc
max_severity.desc
False False Property and direction to sort results
Limit Int32 1 5000 False False Maximum number of results per request
Offset Int32 False False Position to begin retrieving results
Detailed Switch False False Retrieve detailed information
All Switch False False Repeat requests until all available results are retrieved
Total Switch False False Display total result count instead of results

SYNTAX

Get-FalconDetection [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] -WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconDetection -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

Generated 20220922 using PSFalcon v2.2.3

Clone this wiki locally