-
Notifications
You must be signed in to change notification settings - Fork 69
Export FalconConfig
Create an archive containing Falcon configuration files
Uses various PSFalcon commands to gather and export groups, policies and exclusions as a collection of Json files within a zip archive. The exported files can be used with 'Import-FalconConfig' to restore configurations to your existing CID or create them in another CID.
Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
---|---|---|---|---|---|---|---|
Select | String[] | Selected items to export from your current CID, or leave unspecified to export all available items |
HostGroup IoaGroup FirewallGroup DeviceControlPolicy FirewallPolicy PreventionPolicy ResponsePolicy SensorUpdatePolicy Ioc IoaExclusion MlExclusion Script SvExclusion
|
||||
Force | Switch | Overwrite an existing file when present |
Export-FalconConfig [[-Select] <String[]>] [-Force] [-WhatIf] [-Confirm] [<CommonParameters>]
The Export-FalconConfig
command gathers configurable items from your Falcon environment and exports them as a
ZIP archive. The following example will create a file called FalconConfig_<FileDateTime>.zip
in your current
directory containing all the available configurations.
Export-FalconConfig
NOTE: Users are not included in the export/import process because they are unique and cannot be duplicated.
Similar to the regular command, a zip file will be created, but in this example it will only include HostGroup
,
FirewallGroup
(including Firewall Rules) and FirewallPolicy
items.
Export-FalconConfig -Select HostGroup, FirewallGroup, FirewallPolicy
See Import-FalconConfig.
2023-04-25: PSFalcon v2.2.5
- Using PSFalcon
-
Commands and Permissions
- Configuration Import/Export
- Container Security
- Detection and Prevention Policies
- Discover for Cloud and Containers
- Discover
- Event Streams
- Falcon Complete Dashboards
- Falcon Complete Message Center
- Falcon Data Replicator
- Falcon Intelligence
- Falcon Intelligence Recon
- Falcon OverWatch Dashboards
- Falcon Sandbox
- FileVantage
- Firewall Management
- Flight Control
- Horizon
- Host and Host Group Management
- Identity Protection
- Image Assessment
- Incident and Detection Monitoring
- Installation Tokens
- Kubernetes Protection
- MalQuery
- Mobile Host Enrollment
- On-Demand Scanning
- Quarantine
- Real-time Response
- Real-time Response Policy
- Scheduled Reports and Searches
- Sensor Download
- Sensor Update Policy
- Spotlight
- Tailored Intelligence
- Third-party ingestion
- USB Device Control Policy
- Users and Roles
- Zero Trust Assessment
- Examples
-
CrowdStrike SDKs
- PSFalcon - PowerShell
- FalconPy - Python 3
- goFalcon - Go
- Rusty Falcon - Rust