Skip to content

New FalconNgsParser

bk-cs edited this page Sep 2, 2025 · 2 revisions

New-FalconNgsParser

SYNOPSIS

Create a Falcon NGSIEM parser

DESCRIPTION

Requires 'NGSIEM Parsers: Write'.

PARAMETERS

Name Type Description Min Max Allowed Pipeline PipelineByName
Name String Parser name X
Repository String Repository name parsers-repository X
Script String Parser script to transform input into events X
TestCase Object[] An example event and output X
FieldToRemove String[] Event fields to remove before parsing X
FieldToTag String[] Event fields to tag during parsing X

SYNTAX

New-FalconNgsParser [-Name] <String> [-Repository] <String> [-Script] <String> [-TestCase] <Object[]> [[-FieldToRemove] <String[]>] [[-FieldToTag] <String[]>] [-WhatIf] [-Confirm] [<CommonParameters>]

REFERENCE

Endpoints

POST /ngsiem-content/entities/parsers/v1

falconpy

CreateParser

USAGE

2025-09-02: PSFalcon v2.2.9

Clone this wiki locally