Closed harrim4n closed 1 year ago
A scheduled search is created within the Falcon console to run for a specific period of time (i.e. "allow search to run between these dates", designated by search_window_start
to search_window_end
). The search frequency defines how often the search executes within that range (every 7 days/24 hours/5 minutes etc.).
Invoke-FalconScheduledReport
(which calls POST /reports/entities/scheduled-reports/execution/v1
) runs the search using the corresponding identifier and the predefined search criteria--it doesn't decide the range of the search.
If I'm understanding correctly, you're saying that when a search is executed, it's run from now until X time
, and you'd like it to be from X time until now
?
Not quite, it's not run from now until X time
, but instead it uses the search period of when the search that would be executed next according to the preset schedule. That could (at worst, if the scheduled search just ran) be from now until X time
and from X time until now
(at best, if the scheduled search is just about the be started).
The problem with this is that on average 50% of the search window is in the future - where there obviously are no events to be found. And in the worst case, the entire search window is in the future.
Ideally, it would be possible to provide a custom search window when calling the API endpoint. To stick to your nomenclature, I would expect the invoked search to run from X time until now
, where x
is either supplied manually or at least defaults to the predefined search period.
Thanks for the clarification. It sounds like you want to create an IDEA (feature request) from within your Falcon console for this specific API to update the API request to include a search range when initiating it. I don't have control over these APIs personally, and ideas from customers can attract votes and get added more quickly.
Describe the bug When invoking a scheduled report, the report uses the schedule / search period of the next upcoming report. This means that if a report is to be run next in 6 days and has a period of 7 days, it will search 1 day in the past and 6 days in the future.
To Reproduce
Invoke-FalconScheduledReport
for new reportExpected behavior I would expect the scheduled report to run with an end time of "now" - at the time of invocation. Ideally, it would be possible to "manually" specify a start time / search window, but it should at least search the configured time period in the past - not (partially) in the future.
Environment (please complete the following information):
Transcript content