Skip to content

Sensor Visibility Exclusions

The Sensor Visibility Exclusions service collection provides operations for managing sensor visibility exclusions. Retrieve, create, delete, update, and query exclusions that control which processes are excluded from sensor visibility monitoring.

LanguageLast Update
Pythonv1.4.6
PowerShellv2.2.9
Gov0.20.0
TypeScriptv0.6.0
Rustv0.7.0
Rubyv1.2.0
OperationDescription
getSensorVisibilityExclusionsV1
get_exclusions
Get a set of Sensor Visibility Exclusions by specifying their IDs.
createSVExclusionsV1
create_exclusions
Create a sensor visibility exclusion.
deleteSensorVisibilityExclusionsV1
delete_exclusions
Delete the sensor visibility exclusions by ID.
updateSensorVisibilityExclusionsV1
update_exclusions
Update a sensor visibility exclusion.
querySensorVisibilityExclusionsV1
query_exclusions
Search for sensor visibility exclusions.

Get a set of Sensor Visibility Exclusions by specifying their IDs

GET /policy/entities/sv-exclusions/v1
Scope Sensor Visibility Exclusions: READ Consumes · Produces application/json
PEP 8 get_exclusions
NameTypeData typeDescription
idsquerystring or list of stringsThe IDs of the exclusions to retrieve.
parametersquerydictionaryFull query string parameters payload in JSON format.
from falconpy import SensorVisibilityExclusions
falcon = SensorVisibilityExclusions(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.get_exclusions(ids=id_list)
print(response)

Create the sensor visibility exclusions

POST /policy/entities/sv-exclusions/v1
Scope Sensor Visibility Exclusions: WRITE Consumes · Produces application/json
PEP 8 create_exclusions
NameTypeData typeDescription
bodybodydictionaryFull body payload in JSON format.
commentbodystringString comment describing why the exclusions was created.
groupsbodylist of stringsGroup ID(s) impacted by the exclusion.
valuebodystringValue to match for the exclusion.
from falconpy import SensorVisibilityExclusions
falcon = SensorVisibilityExclusions(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.create_exclusions(comment="string",
groups=["string"],
value="string")
print(response)

Delete the sensor visibility exclusions by id

DELETE /policy/entities/sv-exclusions/v1
Scope Sensor Visibility Exclusions: WRITE Consumes · Produces application/json
PEP 8 delete_exclusions
NameTypeData typeDescription
commentquerystringExplains why this exclusion was deleted.
idsquerystring or list of stringsThe IDs of the exclusions to retrieve.
parametersquerydictionaryFull query string parameters payload in JSON format.
from falconpy import SensorVisibilityExclusions
falcon = SensorVisibilityExclusions(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
id_list = 'ID1,ID2,ID3' # Can also pass a list here: ['ID1', 'ID2', 'ID3']
response = falcon.delete_exclusions(comment="string", ids=id_list)
print(response)

Update the sensor visibility exclusions

PATCH /policy/entities/sv-exclusions/v1
Scope Sensor Visibility Exclusions: WRITE Consumes · Produces application/json
PEP 8 update_exclusions
NameTypeData typeDescription
bodybodydictionaryFull body payload in JSON format.
commentbodystringString comment describing why the exclusions was created.
groupsbodylist of stringsGroup ID(s) impacted by the exclusion.
idbodystringThe ID of the exclusion to update.
is_descendent_processbodybooleanFlag to determine if an exclusion should apply to all descendant processes.
valuebodystringValue to match for the exclusion.
from falconpy import SensorVisibilityExclusions
falcon = SensorVisibilityExclusions(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.update_exclusions(comment="string",
groups=["string"],
id="string",
is_descendant_process="string",
value="string")
print(response)

Search for sensor visibility exclusions.

GET /policy/queries/sv-exclusions/v1
Scope Sensor Visibility Exclusions: READ Consumes · Produces application/json
PEP 8 query_exclusions
NameTypeData typeDescription
filterquerystringThe filter expression that should be used to limit the results. FQL syntax. Available filters: applied_globally, created_by, created_on, last_modified, modified_by, value
limitqueryintegerThe maximum number of records to return. [1-500]
offsetqueryintegerThe offset to start retrieving records from.
parametersquerydictionaryFull query string parameters payload in JSON format.
sortquerystringThe property to sort by. FQL syntax. (e.g. last_behavior|asc) Available sort fields: applied_globally, created_by, created_on, last_modified, modified_by, value
from falconpy import SensorVisibilityExclusions
falcon = SensorVisibilityExclusions(client_id=CLIENT_ID,
client_secret=CLIENT_SECRET
)
response = falcon.query_exclusions(filter="string",
limit="string",
offset="string",
sort="string")
print(response)