Get FalconScanHost - CrowdStrike/psfalcon GitHub Wiki

Get-FalconScanHost

SYNOPSIS

Search for on-demand or scheduled scan metadata for specific hosts

DESCRIPTION

Requires 'On-demand scans (ODS): Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id Object[] Scanned host metadata identifier X X
Filter String Falcon Query Language expression to limit results
Sort String Property and direction to sort results id|asc
id|desc
scan_id|asc
scan_id|desc
host_id|asc
host_id|desc
filecount.scanned|asc
filecount.scanned|desc
filecount.malicious|asc
filecount.malicious|desc
filecount.quarantined|asc
filecount.quarantined|desc
filecount.skipped|asc
filecount.skipped|desc
status|asc
status|desc
severity|asc
severity|desc
started_on|asc
started_on|desc
completed_on|asc
completed_on|desc
last_updated|asc
last_updated|desc
Limit Int32 Maximum number of results per request
Offset Int32 Position to begin retrieving results
Detailed Switch Retrieve detailed information
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconScanHost [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <Int32>] [-Detailed] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconScanHost -Id <Object[]> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /ods/entities/scan-hosts/v1
GET /ods/queries/scan-hosts/v1

falconpy

query_scan_host_metadata
get_scan_host_metadata_by_ids

USAGE

2023-04-25: PSFalcon v2.2.5

⚠️ **GitHub.com Fallback** ⚠️