Skip to content

Filtering detections by Status #431

Answered by bk-cs
matwmatw asked this question in Q&A
Discussion options

You must be logged in to vote

With the switchover to Raptor, "detections" became "alerts" (despite still being called "detections" in the Falcon UI). While Get-FalconDetection still works and still shows endpoint detections, eventually it will be deprecated and Get-FalconAlert will be your only option.

Have you tried using Get-FalconAlert? I just tested closing a detection in my environment through the Falcon UI and noticed that the corresponding detection displayed by Get-FalconDetection did not update, while the corresponding "alert" did.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@matwmatw
Comment options

Answer selected by matwmatw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants