Skip to content

Get FalconReconNotification

bk-cs edited this page Sep 22, 2022 · 21 revisions

Get-FalconReconNotification

SYNOPSIS

Search for Falcon X Recon notifications

DESCRIPTION

Requires 'Monitoring Rules (Falcon X Recon): Read'.

PARAMETERS

Name Type Min Max Pattern Allowed Pipeline PipelineByName Description
Id String[] ^\w{76}$ True True Notification identifier
Filter String False False Falcon Query Language expression to limit results
Query String False False Perform a generic substring search across available fields
Sort String `created_date asc<BR>created_date desc<BR>updated_date asc<BR>updated_date
Limit Int32 1 500 False False Maximum number of results per request
Offset Int32 False False Position to begin retrieving results
Detailed Switch False False Retrieve detailed information
All Switch False False Repeat requests until all available results are retrieved
Total Switch False False Display total result count instead of results
Intel Switch False False Include raw intelligence content
Translate Switch False False Translate to English
Combined Switch False False Include raw intelligence content and translate to English

SYNTAX

Get-FalconReconNotification [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset 
<Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Combined [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Translate [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> -Intel [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconReconNotification -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

Generated 20220922 using PSFalcon v2.2.3

Clone this wiki locally