New FalconNgsCase - CrowdStrike/psfalcon GitHub Wiki
Create a Falcon NGSIEM case
Requires 'Cases: Write'.
Name | Type | Description | Min | Max | Allowed | Pipeline | PipelineByName |
---|---|---|---|---|---|---|---|
Name | String | Case name | X | ||||
Severity | String | Case severity | X | ||||
Description | String | Case description | X | ||||
Status | String | Case status |
new in_progress reopened closed
|
X | |||
Evidence | Object | Object containing evidence properties ('alerts', 'events', 'leads') | X | ||||
Tag | String[] | Case tags | X | ||||
AssignedUuid | String | User identifier for case assignment | X | ||||
Template | Object | Object containing case template properties ('id') | X |
New-FalconNgsCase [-Name] <String> [-Severity] <String> [[-Description] <String>] [[-Status] <String>] [[-Evidence] <Object>] [[-Tag] <String[]>] [[-AssignedUuid] <String>] [[-Template] <Object>] [-WhatIf] [-Confirm] [<CommonParameters>]
PUT /cases/entities/cases/v2
2025-08-25: PSFalcon v2.2.9