Edit FalconDetection - CrowdStrike/psfalcon GitHub Wiki
Modify detections
Requires 'Detections: Write'.
| Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName | 
|---|---|---|---|---|---|---|---|
| Comment | String | Detection comment | |||||
| ShowInUi | Boolean | Visible within the Falcon UI [default: $true] | |||||
| Status | String | Detection status | 
newin_progresstrue_positivefalse_positiveclosedreopened
 | 
X | |||
| AssignedToUuid | String | User identifier for assignment | X | ||||
| Id | String[] | Detection identifier | X | X | 
Edit-FalconDetection [[-Comment] <String>] [[-ShowInUi] <Boolean>] [[-Status] <String>] [[-AssignedToUuid] <String>] [-Id] <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]PATCH /detects/entities/detects/v2
NOTE: Edit-FalconDetection will automatically group requests in batches of 1,000 detections (the API limit).
Edit-FalconDetection -Id <id>, <id> -Status newWARNING: Hiding detections is not reversible!
Edit-FalconDetection -Id <id>, <id> -ShowInUi $falseSee Hide detections involving a specific file.
2023-04-25: PSFalcon v2.2.5
