client_id and client_secret are keyword arguments that contain your CrowdStrike API credentials. Please note that all examples below do not hard code these values. (These values are ingested as strings.)
CrowdStrike does not recommend hard coding API credentials or customer identifiers within source code.
Filter drift indicators using a query in Falcon Query Language (FQL). Supported filters: cid,cloud_name,command_line,container_id,file_name,file_sha256,host_id,indicator_process_id,namespace,occurred_at,parent_process_id,pod_name,prevented,scheduler_name,severity,worker_node_name
limit
query
integer
The upper-bound on the number of records to retrieve.
parameters
query
dictionary
Full query string parameters payload in JSON format.
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.get_drift_indicators_by_date(filter="string", limit=integer)
print(response)
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.GetDriftIndicatorsValuesByDate(filter="string", limit=integer)
print(response)
Filter images using a query in Falcon Query Language (FQL). Supported filters: cid,cloud_name,command_line,container_id,file_name,file_sha256,host_id,indicator_process_id,namespace,occurred_at,parent_process_id,pod_name,prevented,scheduler_name,severity,worker_node_name
parameters
query
dictionary
Full query string parameters payload in JSON format.
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.read_drift_indicator_counts(filter="string")
print(response)
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.ReadDriftIndicatorsCount(filter="string")
print(response)
from falconpy import APIHarnessV2
# Do not hardcode API credentials!
falcon = APIHarnessV2(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.command("ReadDriftIndicatorsCount", filter="string")
print(response)
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3'# Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.read_drift_indicators(ids=id_list)
print(response)
from falconpy import DriftIndicators
# Do not hardcode API credentials!
falcon = DriftIndicators(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3'# Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.ReadDriftIndicatorEntities(ids=id_list)
print(response)
from falconpy import APIHarnessV2
# Do not hardcode API credentials!
falcon = APIHarnessV2(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3'# Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("ReadDriftIndicatorEntities", ids=id_list)
print(response)