← All XDRInternals commands

POWERSHELL COMMAND

New-XdrEndpointConfigurationCustomCollectionRule

Creates a new custom collection rule for Microsoft Defender for Endpoint from a YAML file.

View source ↗

Creates custom collection rules for Microsoft Defender for Endpoint by importing YAML files. The YAML files should follow the schema format used by Get-XdrEndpointConfigurationCustomCollectionRule. Each file is validated before submission to ensure proper schema structure.

More information about the schema can be found here: https://github.com/FalconForceTeam/TelemetryCollectionManager

Syntax

New-XdrEndpointConfigurationCustomCollectionRule [-FilePath] <string[]> [[-Enabled] <bool>] [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-FilePath

Property Value
Type String[]
Required Yes
Position 1
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

Path to one or more YAML files containing custom collection rule definitions. Supports wildcards for batch processing.

-Enabled

Property Value
Type Boolean
Required No
Position 2
Pipeline input No
Default False

Specifies whether the created rule(s) should be enabled. Default is $false.

-BypassCache

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses any existing cache entries when creating the rule. Will slow down processing if multiple rules are created in succession.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The cmdlet is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before creating each rule.

Examples

New-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\FileMonitoring.yaml"
Creates a single custom collection rule from the specified YAML file.
New-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\*.yaml"
Creates custom collection rules from all YAML files in the specified directory.
Get-ChildItem "C:\Rules" -Filter "*.yaml" |
    New-XdrEndpointConfigurationCustomCollectionRule
Creates custom collection rules from all YAML files using pipeline input.

Output

Type: Object

Returns the created custom collection rule object(s) from the API.

View source