Skip to content

Sensor Visibility Exclusions

Joshua Hiller edited this page Apr 11, 2021 · 23 revisions

CrowdStrike Falcon Twitter URL

Using the Sensor Visibility Exclusions service collection

Uber class support Uber class support

Table of Contents

API Function Description
getSensorVisibilityExclusionsV1 Get a set of Sensor Visibility Exclusions by specifying their IDs
createSVExclusionsV1 Create the sensor visibility exclusions
deleteSensorVisibilityExclusionsV1 Delete the sensor visibility exclusions by id
updateSensorVisibilityExclusionsV1 Update the sensor visibility exclusions
querySensorVisibilityExclusionsV1 Search for sensor visibility exclusions.

getSensorVisibilityExclusionsV1

Get a set of Sensor Visibility Exclusions by specifying their IDs

Content-Type

  • Produces: application/json

Parameters

Required Name Type Datatype Description
ids query array (string) The ids of the exclusions to retrieve

Usage

Uber class example
from falconpy import api_complete as FalconSDK

falcon = FalconSDK.APIHarness(creds={
      'client_id': falcon_client_id,
      'client_secret': falcon_client_secret
   }
)

IDS = 'ID1,ID2,ID3'

response = falcon.command('getSensorVisibilityExclusionsV1', ids=IDS)
print(response)
falcon.deauthenticate()

createSVExclusionsV1

Create the sensor visibility exclusions

Content-Type

  • Produces: application/json

Parameters

Required Name Type Datatype Description
body body string

Usage

Uber class example
from falconpy import api_complete as FalconSDK

falcon = FalconSDK.APIHarness(creds={
      'client_id': falcon_client_id,
      'client_secret': falcon_client_secret
   }
)

BODY = {
    'Body Payload': 'See body description above'
}

response = falcon.command('createSVExclusionsV1', body=BODY)
print(response)
falcon.deauthenticate()

deleteSensorVisibilityExclusionsV1

Delete the sensor visibility exclusions by id

Content-Type

  • Produces: application/json

Parameters

Required Name Type Datatype Description
ids query array (string) The ids of the exclusions to delete
comment query string Explains why this exclusions was deleted

Usage

Uber class example
from falconpy import api_complete as FalconSDK

falcon = FalconSDK.APIHarness(creds={
      'client_id': falcon_client_id,
      'client_secret': falcon_client_secret
   }
)

PARAMS = {
    'comment': 'string'
}

IDS = 'ID1,ID2,ID3'

response = falcon.command('deleteSensorVisibilityExclusionsV1', parameters=PARAMS, ids=IDS)
print(response)
falcon.deauthenticate()

updateSensorVisibilityExclusionsV1

Update the sensor visibility exclusions

Content-Type

  • Produces: application/json

Parameters

Required Name Type Datatype Description
body body string

Usage

Uber class example
from falconpy import api_complete as FalconSDK

falcon = FalconSDK.APIHarness(creds={
      'client_id': falcon_client_id,
      'client_secret': falcon_client_secret
   }
)

BODY = {
    'Body Payload': 'See body description above'
}

response = falcon.command('updateSensorVisibilityExclusionsV1', body=BODY)
print(response)
falcon.deauthenticate()

querySensorVisibilityExclusionsV1

Search for sensor visibility exclusions.

Content-Type

  • Produces: application/json

Parameters

Required Name Type Datatype Description
filter query string The filter expression that should be used to limit the results.
offset query integer The offset to start retrieving records from
limit query integer The maximum records to return. [1-500]
sort query string The sort expression that should be used to sort the results.

Usage

Uber class example
from falconpy import api_complete as FalconSDK

falcon = FalconSDK.APIHarness(creds={
      'client_id': falcon_client_id,
      'client_secret': falcon_client_secret
   }
)

PARAMS = {
    'filter': 'string',
    'offset': integer,
    'limit': integer,
    'sort': 'string'
}

response = falcon.command('querySensorVisibilityExclusionsV1', parameters=PARAMS)
print(response)
falcon.deauthenticate()

CrowdStrike Falcon

Clone this wiki locally