Get FalconWorkflow - CrowdStrike/psfalcon GitHub Wiki

Get-FalconWorkflow

SYNOPSIS

Search for Falcon Fusion workflows

DESCRIPTION

Requires 'Workflow: Read'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Id String[] Workflow execution identifier X X
Filter String Falcon Query Language expression to limit results

activities
activity_id
change_log
description
enabled
id
input_field_types
last_modified_by_email
last_modified_by_timestamp
name
template.id
trigger
trigger.id
trigger.type
version

Execution:
activity_names
cid
completed_timestamp
customer_name
definition_id
definition_name
definition_version
id
last_modified_by_email
source_event_id
source_event_url
started_timestamp
status
step
trigger_name
ui_status
Sort String Property and direction to sort results
Limit Int32 Maximum number of results per request 1 500
Offset String Position to begin retrieving results
Execution Switch Retrieve information about workflow executions
All Switch Repeat requests until all available results are retrieved
Total Switch Display total result count instead of results

SYNTAX

Get-FalconWorkflow [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <String>] [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconWorkflow -Id <String[]> -Execution [-WhatIf] [-Confirm] [<CommonParameters>]
Get-FalconWorkflow [[-Filter] <String>] [[-Sort] <String>] [[-Limit] <Int32>] [-Offset <String>] -Execution [-All] [-Total] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

GET /workflows/combined/definitions/v1
GET /workflows/combined/executions/v1
GET /workflows/entities/execution-results/v1

falconpy

WorkflowDefinitionsCombined
WorkflowExecutionResults
WorkflowExecutionsCombined

USAGE

2024-09-03: PSFalcon v2.2.7

⚠️ **GitHub.com Fallback** ⚠️