New FalconNgsParser - CrowdStrike/psfalcon GitHub Wiki

New-FalconNgsParser

SYNOPSIS

Create a Falcon NGSIEM parser

DESCRIPTION

Requires 'NGSIEM Parsers: Write'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Name String Parser name X
Repository String Repository name parsers-repository X
Script String Parser script to transform input into events X
TestCase Object[] An example event and output X
FieldToRemove String[] Event fields to remove before parsing X
FieldToTag String[] Event fields to tag during parsing X

SYNTAX

New-FalconNgsParser [-Name] <String> [-Repository] <String> [-Script] <String> [-TestCase] <Object[]> [[-FieldToRemove] <String[]>] [[-FieldToTag] <String[]>] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

POST /ngsiem-content/entities/parsers/v1

USAGE

2025-08-05: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️