Replies: 1 comment 1 reply
-
@Skyw3lker - This was covered in some degree back in a release note published on Sept 19, 2023. |
Beta Was this translation helpful? Give feedback.
-
@Skyw3lker - This was covered in some degree back in a release note published on Sept 19, 2023. |
Beta Was this translation helpful? Give feedback.
-
I'm writing to report a discrepancy between the Detects Advisor API and the recently updated web interface for viewing detections.
Issue:
The web interface now offers two options for viewing detections:
However, the Detects Advisor API continues to return results associated with the "Deprecated" page. This inconsistency creates confusion and makes it difficult to access the data displayed in the new "Updated" web interface view via FalconPy.
Desired Behavior:
It would be ideal if the Detects Advisor API could be updated to provide results that are compatible with the new "Endpoint detections (Updated)" format on the web interface, when using it with the -d option to dump results in json file. This would ensure seamless integration and a consistent user experience.
https://falconpy.io/Service-Collections/Detects.html
https://github.com/CrowdStrike/falconpy/blob/main/samples/detects/README.md#dumping-results-to-a-file
Possible Solutions:
API Update: Modify the Detects Advisor API to return data in the format expected by the new "Endpoint detections (Updated)" web interface.
Documentation Update: If the API cannot be updated immediately, consider revising the documentation to clearly explain the difference between the API results and the updated web interface view. This will help users understand the potential discrepancies and guide them towards the correct approach for accessing the desired data.
Update:
Sorry for the confusion, but I think "Endpoint detections",
can be retrived via falcon.get_aggregate_alerts_v2
https://falconpy.io/Service-Collections/Alerts.html#postaggregatesalertsv2
but still I've tried the provided code sample but I'm getting error code 500
response = falcon.GetQueriesAlertsV2(offset=integer,
limit=integer,
include_hidden=boolean,
sort="string",
filter="string",
q="string"
)
print(response)
So, Simply How to retrieve all the detection fron Endpoint detections (Updated) Page to a json file via python3 code ?!
Beta Was this translation helpful? Give feedback.
All reactions