Send FalconNgsSavedQuery - CrowdStrike/psfalcon GitHub Wiki

Send-FalconNgsSavedQuery

SYNOPSIS

Create a Falcon NGSIEM saved query from a YAML template

DESCRIPTION

Requires 'NGSIEM Saved Queries: Write'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Domain String Repository or view all
falcon
third-party
X
Path String Path to YAML template X

SYNTAX

Send-FalconNgsSavedQuery [-Domain] <String> [-Path] <String> [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

POST /ngsiem-content/entities/savedqueries-template/v1

USAGE

2025-08-05: PSFalcon v2.2.9

⚠️ **GitHub.com Fallback** ⚠️