Skip to content

Get FalconIoaGroup

bk-cs edited this page Sep 3, 2024 · 23 revisions

Get-FalconIoaGroup

SYNOPSIS

Search for custom Indicator of Attack rule groups

DESCRIPTION

Requires 'Custom IOA rules: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Rule group identifier X X
Filter String Falcon Query Language expression to limit results

created_on
description
enabled
modified_on
name
platform
rules.action_label
rules.name
rules.description
rules.pattern_severity
rules.ruletype_name
rules.enabled
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results created_by.asc
created_by.desc
created_on.asc
created_on.desc
description.asc
description.desc
enabled.asc
enabled.desc
modified_by.asc
modified_by.desc
modified_on.asc
modified_on.desc
name.asc
name.desc
Limit Int32 Maximum number of results per request 1 500
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconIoaGroup [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIoaGroup -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconIoaGroup [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] -Detailed [-All] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /ioarules/entities/rule-groups/v1
GET /ioarules/queries/rule-groups-full/v1
GET /ioarules/queries/rule-groups/v1

falconpy

query_rule_groupsMixin0
get_rule_groupsMixin0
query_rule_groups_full

USAGE

Find custom IOA rule groups

Get-FalconIoaGroup [-Detailed]

Find custom IOA rule groups matching a query

Get-FalconIoaGroup -Filter "name:'updatedRuleGroup'+platform:'mac'" -Detailed

Find custom IOA rule group identifiers matching a query

Get-FalconIoaGroup -Filter "name:'updatedRuleGroup'+platform:'mac'"

2024-09-03: PSFalcon v2.2.7

Clone this wiki locally