Add FalconNgsCaseEvidence - CrowdStrike/psfalcon GitHub Wiki

Add-FalconNgsCaseEvidence

SYNOPSIS

Add alerts or events to a Falcon NGSIEM case

DESCRIPTION

Requires 'Cases: Write'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
AlertId String[] Alert identifier
EventId String[] Event identifier
Id String Case identifier X X

SYNTAX

Add-FalconNgsCaseEvidence [-AlertId] <String[]> [-Id] <String> [-WhatIf] [-Confirm] [<CommonParameters>]
Add-FalconNgsCaseEvidence [-EventId] <String[]> [-Id] <String> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

POST /cases/entities/alert-evidence/v1
POST /cases/entities/event-evidence/v1

falconpy

entities_alert_evidence_post_v1
entities_event_evidence_post_v1

USAGE

2025-08-25: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️