Edit FalconNgsParser - CrowdStrike/psfalcon GitHub Wiki

Edit-FalconNgsParser

SYNOPSIS

Modify Falcon NGSIEM parsers

DESCRIPTION

Requires 'NGSIEM Parsers: Write'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String Parser identifier X
Repository String Repository name parsers-repository X
Script String Parser script to transform input into events X
TestCase Object[] An example event and output X
FieldToRemoveParsing String[] X
FieldToTag String[] Event fields to tag during parsing X

SYNTAX

Edit-FalconNgsParser [-Id] <String> [-Repository] <String> [-Script] <String> [-TestCase] <Object[]> [[-FieldToRemoveParsing] <String[]>] [[-FieldToTag] <String[]>] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

PATCH /ngsiem-content/entities/parsers/v1

USAGE

2025-08-05: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️