Skip to content

Get FalconCloudIoaEvent

bk-cs edited this page Sep 3, 2024 · 1 revision

Get-FalconCloudIoaEvent

SYNOPSIS

Retrieve Falcon Cloud Security Indicator of Attack events

DESCRIPTION

Requires 'CSPM registration: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
PolicyId Int32 Policy identifier X
CloudPlatform String Cloud platform aws
azure
gcp
AwsAccountId String AWS account identifier X
AzureSubscriptionId String Azure subscription identifier X
AzureTenantId String Azure tenant identifier X
UserId String[] User identifier
State String Event state
Limit Int32 Maximum number of results per request 1 500
Offset Int32 Position to begin retrieving results
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconCloudIoaEvent [-PolicyId] <Int32> [[-CloudPlatform] <String>] [[-AwsAccountId] <String>] [[-AzureSubscriptionId] <String>] [[-AzureTenantId] <String>] [[-UserId] <String[]>] [[-State] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /ioa/entities/events/v1

USAGE

2024-09-03: PSFalcon v2.2.7

Clone this wiki locally