Skip to content

Edit FalconReconRule

bk-CS edited this page Oct 11, 2022 · 21 revisions

Edit-FalconReconRule

SYNOPSIS

Modify a Falcon X Recon monitoring rule

DESCRIPTION

Requires 'Monitoring Rules (Falcon X Recon): Write'.

PARAMETERS

Name Type Min Max Allowed Pipeline PipelineByName Description
Array Object[] X An array of monitoring rules to modify in a single request
Id String Monitoring rule identifier
Name String Monitoring rule name
Filter String Monitoring rule filter
Priority String high
medium
low
Monitoring rule priority
Permission String private
public
Permission level [public: 'All Intel users', private: 'Recon Admins']

SYNTAX

Edit-FalconReconRule [-Id] <String> [-Name] <String> [-Filter] <String> [-Priority] <String> [-Permission] <String> [-WhatIf] [-Confirm] [<CommonParameters>]
Edit-FalconReconRule -Array <Object[]> [-WhatIf] [-Confirm] [<CommonParameters>]

USAGE

Updating a monitoring rule

Edit-FalconReconRule -Id <id> -Name psfalcon_example_updated -Priority medium

Updating multiple monitoring rules in a single request

$Array = @(
    @{
        id = <id>
        priority = "high"
    },
    @{
        id = <id>
        priority = "high"
    }
)
Edit-FalconReconRule -Array $Array

2022-10-10: PSFalcon v2.2.3

Clone this wiki locally