Skip to content

Get FalconIoaRule

bk-cs edited this page Dec 29, 2022 · 22 revisions

Get-FalconIoaRule

SYNOPSIS

Search for custom Indicator of Attack rules

DESCRIPTION

Requires 'Custom IOA Rules: Read'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Id String[] X X Rule identifier
Filter String Falcon Query Language expression to limit results

created_on
description
enabled
modified_on
name
platform
rules.action_label
rules.name
rules.description
rules.pattern_severity
rules.ruletype_name
rules.enabled
Query String Perform a generic substring search across available fields
Sort String rules.created_by.asc
rules.created_by.desc
rules.created_on.asc
rules.created_on.desc
rules.current_version.action_label.asc
rules.current_version.action_label.desc
rules.current_version.description.asc
rules.current_version.description.desc
rules.current_version.modified_by.asc
rules.current_version.modified_by.desc
rules.current_version.modified_on.asc
rules.current_version.modified_on.desc
rules.current_version.name.asc
rules.current_version.name.desc
rules.current_version.pattern_severity.asc
rules.current_version.pattern_severity.desc
rules.enabled.asc
rules.enabled.desc
rules.ruletype_name.asc
rules.ruletype_name.desc
Property and direction to sort results
Limit Int32 1 500 Maximum number of results per request
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconIoaRule [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIoaRule -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

SDK Reference

falconpy

query_rulesMixin0
get_rules_get

USAGE

Find custom IOA rules

Get-FalconIoaRule [-Detailed]

Find a custom IOA rule identifier by name within a rule group

Get-FalconIoaRule -Filter "id:'<id>'+rules.name:'BugRule'" [-Detailed] [-All]

2022-12-12: PSFalcon v2.2.3

Clone this wiki locally