Get FalconNgsCase - CrowdStrike/psfalcon GitHub Wiki

Get-FalconNgsCase

SYNOPSIS

Search for Falcon NGSIEM cases

DESCRIPTION

Requires 'Cases: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Case identifier X X
Filter String Falcon Query Language expression to limit results
Query String Perform a generic substring search across available fields
Sort String Property and direction to sort results assigned_to_name|asc
assigned_to_name|desc
assigned_to_userid|asc
assigned_to_userid|desc
assigned_to_uuid|asc
assigned_to_uuid|desc
cid|asc
cid|desc
created_timestamp|asc
created_timestamp|desc
status|asc
status|desc
tags|asc
tags|desc
updated_timestamp|asc
updated_timestamp|desc
Limit Int32 Maximum number of results per request [default: 100] 1 10000
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconNgsCase [[-Filter] <String>] [[-Query] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconNgsCase -Id <String[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /cases/queries/cases/v1
POST /cases/entities/cases/v2

falconpy

queries_cases_get_v1
entities_cases_post_v2

USAGE

2025-08-13: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️