POWERSHELL COMMAND
New-XdrEndpointConfigurationCustomCollectionRule
Creates a new custom collection rule for Microsoft Defender for Endpoint from a YAML file.
Creates custom collection rules for Microsoft Defender for Endpoint by importing YAML files. The YAML files should follow the schema format used by Get-XdrEndpointConfigurationCustomCollectionRule. Each file is validated before submission to ensure proper schema structure.
More information about the schema can be found here: https://github.com/FalconForceTeam/TelemetryCollectionManager
Syntax
New-XdrEndpointConfigurationCustomCollectionRule [-FilePath] <string[]> [[-Enabled] <bool>] [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-FilePath
| Property | Value |
|---|---|
| Type | String[] |
| Required | Yes |
| Position | 1 |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
Path to one or more YAML files containing custom collection rule definitions. Supports wildcards for batch processing.
-Enabled
| Property | Value |
|---|---|
| Type | Boolean |
| Required | No |
| Position | 2 |
| Pipeline input | No |
| Default | False |
Specifies whether the created rule(s) should be enabled. Default is $false.
-BypassCache
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses any existing cache entries when creating the rule. Will slow down processing if multiple rules are created in succession.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before creating each rule.
Examples
New-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\FileMonitoring.yaml"
Creates a single custom collection rule from the specified YAML file.
New-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\*.yaml"
Creates custom collection rules from all YAML files in the specified directory.
Get-ChildItem "C:\Rules" -Filter "*.yaml" |
New-XdrEndpointConfigurationCustomCollectionRule
Creates custom collection rules from all YAML files using pipeline input.
Output
Type: Object
Returns the created custom collection rule object(s) from the API.