Scanning Orchestrator
Operations for the Scanning Orchestrator service collection.
| Language | Last Update |
|---|---|
| Python | v1.6.6 |
| PowerShell | |
| Go | v0.22.0 |
| TypeScript | v0.7.0 |
| Rust | |
| Ruby | v1.4.0 |
Table of Contents
Section titled “Table of Contents”| Operation | Description |
|---|---|
create-schedulescreate_schedules | Create scanning schedules |
delete-schedulesdelete_schedules | Delete scanning schedules |
get-combined-schedulesget_combined_schedules | Get combined scanning schedules |
get-schedulesget_schedules | Get scanning schedules |
get-service-typesget_service_types | Get allowed service types |
search-schedulessearch_schedules | Search scanning schedules |
trigger-scan-by-scheduletrigger_scan_by_schedule | Trigger scan by schedule IDs |
update-schedulesupdate_schedules | Update scanning schedules |
create-schedules
Section titled “create-schedules”Create scanning schedules
Method POST
Route /agentless-scanning/entities/schedules/v1
Scope Agentless scanning configuration: WRITE
PEP 8
create_schedulesParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
resources body · array
The resources value.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
resources = [ { "account_ids": [ "string" ], "all_accounts": True, "all_regions": True, "cadence": { "unit": "string", "value": 0 }, "cloud_group_ids": [ "string" ], "dspm_scanning_config": { "classification_scan_mode": "string", "scan_type": "string" }, "enable": True, "name": "string", "provider_type": "string", "scan_product": "string", "selected_regions": [ "string" ], "service_names": [ "string" ] }]
response = falcon.create_schedules(resources=resources)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = { "resources": [ { "account_ids": ["string"], "all_accounts": boolean, "all_regions": boolean, "cadence": { "unit": {}, "value": integer }, "cloud_group_ids": ["string"], "dspm_scanning_config": { "classification_scan_mode": {}, "scan_type": {} }, "enable": boolean, "name": "string", "provider_type": {}, "scan_product": {}, "selected_regions": ["string"], "service_names": ["string"] } ]}
response = falcon.command("create_schedules", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.CreateSchedules( &scanning_orchestrator.CreateSchedulesParams{ Body: &models.TypesCreateSchedulesRequest{ Resources: []*models.TypesScheduleRuleInput{ { AccountIds: []string{"string"}, AllAccounts: boolean, AllRegions: boolean, Cadence: &models.CadenceCadence{}, CloudGroupIds: []string{"string"}, DspmScanningConfig: &models.TypesDSPMScanningConfig{}, Enable: boolean, Name: "string", ProviderType: models.TypesProviderType("string"), ScanProduct: models.ScanProductsScanProduct("string"), SelectedRegions: []string{"string"}, ServiceNames: []string{"string"}, }, }, }, Authorization: "string", Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.createSchedules( "string", // authorization { // body resources: [{ accountIds: [], allAccounts: boolean, allRegions: boolean, cadence: { unit: "Week", value: integer }, cloudGroupIds: [], dspmScanningConfig: { classificationScanMode: "standard", scanType: "quick" }, enable: boolean, name: "string", providerType: "aws", scanProduct: "dspm_scanning", selectedRegions: [], serviceNames: [] }] });
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
body = Falcon::TypesCreateSchedulesRequest.new( resources: [{ account_ids: [], all_accounts: boolean, all_regions: boolean, cadence: { unit: {}, value: integer }, cloud_group_ids: [], dspm_scanning_config: { classification_scan_mode: {}, scan_type: {} }, enable: boolean, name: 'string', provider_type: {}, scan_product: {}, selected_regions: [], service_names: [] }])
response = api.create_schedules('string', body)
puts responseResponses
[ { "account_ids": [], "all_accounts": false, "all_regions": false, "cadence": {}, "cloud_group_ids": [], "enabled": false, "last_run": "string", "name": "string", "provider_type": {}, "scan_config": {}, "scan_product": {}, "schedule_id": "string", "selected_regions": [], "service_names": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}delete-schedules
Section titled “delete-schedules”Delete scanning schedules
Method DELETE
Route /agentless-scanning/entities/schedules/v1
Scope Agentless scanning configuration: WRITE
PEP 8
delete_schedulesParameters
Section titled “Parameters”ids query · string or list of strings
Schedule IDs to delete
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.delete_schedules(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("delete_schedules", ids=id_list)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.DeleteSchedules( &scanning_orchestrator.DeleteSchedulesParams{ Ids: []string{"ID1", "ID2", "ID3"}, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.deleteSchedules( "string", // authorization ["ID1", "ID2", "ID3"] // ids);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
response = api.delete_schedules('string', ['ID1', 'ID2', 'ID3'])
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}get-combined-schedules
Section titled “get-combined-schedules”Get combined scanning schedules
Method GET
Route /agentless-scanning/combined/schedules/v1
Scope Agentless scanning configuration: READ
PEP 8
get_combined_schedulesParameters
Section titled “Parameters”limit query · integer
Number of results to return
offset query · integer
Starting offset for pagination
sort query · string
Sort field and direction. Available fields:
Available values (5)
scan_product | provider_type | enabled |
name | created_at |
filter query · string
FQL filter expression. Available fields:
Available values (5)
scan_product | provider_type | enabled |
name | created_at |
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_combined_schedules(limit=integer, offset=integer, sort="string", filter="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("get_combined_schedules", limit=integer, offset=integer, sort="string", filter="string")print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
limit := int64(0) offset := int64(0) sort := "string" filter := "string"
response, err := client.ScanningOrchestrator.GetCombinedSchedules( &scanning_orchestrator.GetCombinedSchedulesParams{ Limit: &limit, Offset: &offset, Sort: &sort, Filter: &filter, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.getCombinedSchedules( "string", // authorization integer, // limit integer, // offset "string", // sort "string" // filter);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
response = api.get_combined_schedules('string')
puts responseResponses
[ { "account_ids": [], "all_accounts": false, "all_regions": false, "cadence": {}, "cloud_group_ids": [], "enabled": false, "last_run": "string", "name": "string", "provider_type": {}, "scan_config": {}, "scan_product": {}, "schedule_id": "string", "selected_regions": [], "service_names": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}get-schedules
Section titled “get-schedules”Get scanning schedules
Method GET
Route /agentless-scanning/entities/schedules/v1
Scope Agentless scanning configuration: READ
PEP 8
get_schedulesParameters
Section titled “Parameters”ids query · string or list of strings
Schedule IDs to retrieve
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_schedules(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.command("get_schedules", ids=id_list)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.GetSchedules( &scanning_orchestrator.GetSchedulesParams{ Ids: []string{"ID1", "ID2", "ID3"}, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.getSchedules( "string", // authorization ["ID1", "ID2", "ID3"] // ids);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
response = api.get_schedules('string', ['ID1', 'ID2', 'ID3'])
puts responseResponses
[ { "account_ids": [], "all_accounts": false, "all_regions": false, "cadence": {}, "cloud_group_ids": [], "enabled": false, "last_run": "string", "name": "string", "provider_type": {}, "scan_config": {}, "scan_product": {}, "schedule_id": "string", "selected_regions": [], "service_names": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}get-service-types
Section titled “get-service-types”Get allowed service types
Method GET
Route /agentless-scanning/entities/supported-service-types/v1
Scope Agentless scanning configuration: READ
PEP 8
get_service_typesParameters
Section titled “Parameters”scan_product query · string
Scan product filter
Available values (2)
dspm_scanning | vulnerability_scanning |
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.get_service_types(scan_product="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("get_service_types", scan_product="string")print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.GetServiceTypes( &scanning_orchestrator.GetServiceTypesParams{ ScanProduct: "string", Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.getServiceTypes( "string", // authorization "dspm_scanning" // scanProduct);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
response = api.get_service_types('string', 'string')
puts responseResponses
[ { "name": "string", "provider_type": {} }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}search-schedules
Section titled “search-schedules”Search scanning schedules
Method GET
Route /agentless-scanning/queries/schedules/v1
Scope Agentless scanning configuration: READ
PEP 8
search_schedulesParameters
Section titled “Parameters”limit query · integer
Number of results to return
offset query · integer
Starting offset for pagination
sort query · string
Sort field and direction. Available fields:
Available values (5)
scan_product | provider_type | enabled |
name | created_at |
filter query · string
FQL filter expression. Available fields:
Available values (5)
scan_product | provider_type | enabled |
name | created_at |
parameters query · dictionary
Full query string parameters payload in JSON format. Not required when using other keywords.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.search_schedules(limit=integer, offset=integer, sort="string", filter="string")print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
response = falcon.command("search_schedules", limit=integer, offset=integer, sort="string", filter="string")print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
limit := int64(0) offset := int64(0) sort := "string" filter := "string"
response, err := client.ScanningOrchestrator.SearchSchedules( &scanning_orchestrator.SearchSchedulesParams{ Limit: &limit, Offset: &offset, Sort: &sort, Filter: &filter, Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.searchSchedules( "string", // authorization integer, // limit integer, // offset "string", // sort "string" // filter);
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
response = api.search_schedules('string')
puts responseResponses
{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}trigger-scan-by-schedule
Section titled “trigger-scan-by-schedule”Trigger scan by schedule IDs
Method POST
Route /agentless-scanning/entities/scan-by-schedule/v1
Scope Agentless scanning configuration: WRITE
PEP 8
trigger_scan_by_scheduleParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
ids body · array
The ids value.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.trigger_scan_by_schedule(ids=id_list)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = { "ids": ["string"]}
response = falcon.command("trigger_scan_by_schedule", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.TriggerScanBySchedule( &scanning_orchestrator.TriggerScanByScheduleParams{ Body: &models.MsaspecIdsRequest{ Ids: []string{"string"}, }, Authorization: "string", Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.triggerScanBySchedule( "string", // authorization { // body ids: [] });
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
body = Falcon::MsaspecIdsRequest.new( ids: [])
response = api.trigger_scan_by_schedule('string', body)
puts responseResponses
[ { "account_ids": [], "all_accounts": false, "all_regions": false, "cadence": {}, "cloud_group_ids": [], "enabled": false, "last_run": "string", "name": "string", "provider_type": {}, "scan_config": {}, "scan_product": {}, "schedule_id": "string", "selected_regions": [], "service_names": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}update-schedules
Section titled “update-schedules”Update scanning schedules
Method PATCH
Route /agentless-scanning/entities/schedules/v1
Scope Agentless scanning configuration: WRITE
PEP 8
update_schedulesParameters
Section titled “Parameters”body body · dictionary
Full body payload as JSON formatted dictionary.
resources body · array
The resources value.
Code Examples
from falconpy import ScanningOrchestrator
falcon = ScanningOrchestrator(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
resources = [ { "asset_filter": { "aws": { "account_ids": [ "string" ], "all_accounts": True, "all_regions": True, "regions": [ "string" ], "service_names": [ "string" ] }, "azure": { "all_locations": True, "all_subscriptions": True, "locations": [ "string" ], "service_names": [ "string" ], "subscription_ids": [ "string" ] }, "cloud_groups": { "cloud_group_ids": [ "string" ], "provider_account_ids": [ "string" ], "service_names": [ "string" ] }, "gcp": { "all_projects": True, "all_regions": True, "project_ids": [ "string" ], "regions": [ "string" ], "service_names": [ "string" ] }, "provider_type": "string", "scan_product": "string" }, "cadence": { "unit": "string", "value": 0 }, "enable": True, "id": "string", "name": "string", "scan_config": { "dspm_scanning_config": { "classification_scan_mode": "string", "scan_type": "string" } } }]
response = falcon.update_schedules(resources=resources)print(response)from falconpy import APIHarnessV2
falcon = APIHarnessV2(client_id=CLIENT_ID, client_secret=CLIENT_SECRET )
body_payload = { "resources": [ { "asset_filter": { "aws": {}, "azure": {}, "cloud_groups": {}, "gcp": {}, "provider_type": {}, "scan_product": {} }, "cadence": { "unit": {}, "value": integer }, "enable": boolean, "id": "string", "name": "string", "scan_config": { "dspm_scanning_config": {} } } ]}
response = falcon.command("update_schedules", body=body_payload)print(response)Examples coming soon.
package main
import ( "context" "fmt" "os"
"github.com/crowdstrike/gofalcon/falcon" "github.com/crowdstrike/gofalcon/falcon/client/scanning_orchestrator" "github.com/crowdstrike/gofalcon/falcon/models")
func main() { client, err := falcon.NewClient(&falcon.ApiConfig{ ClientId: os.Getenv("FALCON_CLIENT_ID"), ClientSecret: os.Getenv("FALCON_CLIENT_SECRET"), Context: context.Background(), }) if err != nil { panic(err) }
response, err := client.ScanningOrchestrator.UpdateSchedules( &scanning_orchestrator.UpdateSchedulesParams{ Body: &models.TypesUpdateSchedulesRequest{ Resources: []*models.TypesUpdateScheduleResource{ { AssetFilter: &models.TypesAssetFilter{}, Cadence: &models.CadenceCadence{}, Enable: boolean, ID: "string", Name: "string", ScanConfig: &models.TypesScanConfig{}, }, }, }, Authorization: "string", Context: context.Background(), }, ) if err != nil { panic(falcon.ErrorExplain(err)) }
fmt.Printf("%+v\n", response.Payload)}import { FalconClient } from "crowdstrike-falcon";
const client = new FalconClient({ cloud: "us-1", clientId: process.env.FALCON_CLIENT_ID!, clientSecret: process.env.FALCON_CLIENT_SECRET!,});
const response = await client.scanningOrchestrator.updateSchedules( "string", // authorization { // body resources: [{ assetFilter: { providerType: "aws", scanProduct: "dspm_scanning" }, cadence: { unit: "Week", value: integer }, enable: boolean, id: "string", name: "string", scanConfig: {} }] });
console.log(response);Examples coming soon.
require "crimson-falcon"
Falcon.configure do |config| config.client_id = ENV["FALCON_CLIENT_ID"] config.client_secret = ENV["FALCON_CLIENT_SECRET"] config.cloud = ENV["FALCON_CLOUD"]end
api = Falcon::ScanningOrchestrator.new
body = Falcon::TypesUpdateSchedulesRequest.new( resources: [{ asset_filter: { aws: {}, azure: {}, cloud_groups: {}, gcp: {}, provider_type: {}, scan_product: {} }, cadence: { unit: {}, value: integer }, enable: boolean, id: 'string', name: 'string', scan_config: { dspm_scanning_config: {} } }])
response = api.update_schedules('string', body)
puts responseResponses
[ { "account_ids": [], "all_accounts": false, "all_regions": false, "cadence": {}, "cloud_group_ids": [], "enabled": false, "last_run": "string", "name": "string", "provider_type": {}, "scan_config": {}, "scan_product": {}, "schedule_id": "string", "selected_regions": [], "service_names": [] }]{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}{ "errors": [ { "code": 0, "id": "string", "message": "string" } ], "meta": { "pagination": { "limit": 0, "offset": 0, "total": 0 }, "powered_by": "string", "query_time": 0.0, "trace_id": "string", "writes": { "resources_affected": 0 } }}