Skip to content

Get FalconAlert

bk-cs edited this page Sep 26, 2024 · 24 revisions

Get-FalconAlert

SYNOPSIS

Search for alerts

DESCRIPTION

Requires 'Alerts: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Alert identifier X X
IncludeHidden Boolean Include hidden alerts when retrieving results by identifier
Filter String Falcon Query Language expression to limit results
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results
Limit Int32 Maximum number of results per request 1 10000
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconAlert [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconAlert -Id <String[]> [[-IncludeHidden] <Boolean>] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /alerts/queries/alerts/v2
POST /alerts/entities/alerts/v2

falconpy

GetQueriesAlertsV2
PostEntitiesAlertsV2

USAGE

Get Identity Alerts

Get-FalconAlert -Filter "data_domains:'Identity'" [-Detailed] [-All]

Get Endpoint Alerts

Get-FalconAlert -Filter "data_domains:'Endpoint'" [-Detailed] [-All]

REFERENCE

Endpoints

GET /alerts/queries/alerts/v2
POST /alerts/entities/alerts/v2

falconpy

GetQueriesAlertsV1
PostEntitiesAlertsV2

USAGE

2024-09-03: PSFalcon v2.2.7

Clone this wiki locally