Skip to content

Get FalconIncident

bk-cs edited this page Sep 22, 2022 · 22 revisions

Get-FalconIncident

SYNOPSIS

Search for incidents

DESCRIPTION

Requires 'Incidents: Read'.

PARAMETERS

Name Type Min Max Pattern Allowed Pipeline PipelineByName Description
Id String[] ^inc:[a-fA-F0-9]{32}:[a-fA-F0-9]{32}$ True True Incident identifier
Filter String False False Falcon Query Language expression to limit results
Sort String assigned_to.asc
assigned_to.desc
assigned_to_name.asc
assigned_to_name.desc
end.asc
end.desc
modified_timestamp.asc
modified_timestamp.desc
name.asc
name.desc
sort_score.asc
sort_score.desc
start.asc
start.desc
state.asc
state.desc
status.asc
status.desc
False False Property and direction to sort results
Limit Int32 1 500 False False Maximum number of results per request
Offset Int32 False False Position to begin retrieving results
Detailed Switch False False Retrieve detailed information
All Switch False False Repeat requests until all available results are retrieved
Total Switch False False Display total result count instead of results

SYNTAX

Get-FalconIncident [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] <CommonParameters>]
Get-FalconIncident -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

Generated 20220922 using PSFalcon v2.2.3

Clone this wiki locally