Skip to content

Get FalconReconNotification

bk-cs edited this page Sep 3, 2024 · 21 revisions

Get-FalconReconNotification

SYNOPSIS

Search for Falcon Intelligence Recon notifications

DESCRIPTION

Requires 'Monitoring rules (Falcon Intelligence Recon): Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Notification identifier X X
Filter String Falcon Query Language expression to limit results
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results created_date|asc
created_date|desc
updated_date|asc
updated_date|desc
Limit Int32 Maximum number of results per request 1 500
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results
Intel Switch Include raw intelligence content
Translate Switch Translate to English
Combined Switch Include raw intelligence content and translate to English

SYNTAX

Get-FalconReconNotification [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Combined [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Translate [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Intel [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /recon/entities/notifications-detailed-translated/v1
GET /recon/entities/notifications-detailed/v1
GET /recon/entities/notifications-translated/v1
GET /recon/entities/notifications/v1
GET /recon/queries/notifications/v1

falconpy

QueryNotificationsV1
GetNotificationsDetailedTranslatedV1
GetNotificationsTranslatedV1
GetNotificationsDetailedV1
GetNotificationsV1

USAGE

Querying notifications

Get-FalconReconNotification

Get simplified data from notifications

Get-FalconReconNotification [-Detailed]

Get raw intelligence data from notifications

Get-FalconReconNotification -Id <id>, <id> -Intel

Get data from notifications translated into English

Get-FalconReconNotification -Id <id>, <id> -Translate

Get raw intelligence data from notifications translated into English

Get-FalconReconNotification -Id <id>, <id> -Combined

2024-09-03: PSFalcon v2.2.7

Clone this wiki locally