Get FalconCompleteCase - CrowdStrike/psfalcon GitHub Wiki

Get-FalconCompleteCase

SYNOPSIS

Search for Falcon Complete cases

DESCRIPTION

Requires 'Message Center: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Case identifier X X
Filter String Falcon Query Language expression to limit results
Sort String Property and direction to sort results case.created_time.asc
case.created_time.desc
case.id.asc
case.id.desc
case.last_modified_time.asc
case.last_modified_time.desc
case.status.asc
case.status.desc
case.type.asc
case.type.desc
Limit Int32 Maximum number of results per request 1 500
Offset String Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconCompleteCase [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <String>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconCompleteCase -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /message-center/queries/cases/v1
POST /message-center/entities/cases/GET/v1

falconpy

QueryCasesIdsByFilter
GetCaseEntitiesByIDs

USAGE

Getting a list of case IDs

Get-FalconCompleteCase -Limit 10 -Sort case.id.desc

Viewing the details of multiple cases

Get-FalconCompleteCase -Id <id>, <id>

2023-04-25: PSFalcon v2.2.5

⚠️ **GitHub.com Fallback** ⚠️