← All XDRInternals commands

POWERSHELL COMMAND

Set-XdrEndpointConfigurationCustomCollectionRule

Updates an existing custom collection rule for Microsoft Defender for Endpoint.

View source ↗

Updates custom collection rules for Microsoft Defender for Endpoint by importing YAML files or PSObjects. The YAML files should follow the schema format used by Get-XdrEndpointConfigurationCustomCollectionRule. Each rule is validated before submission to ensure proper schema structure and that the rule exists.

More information about the schema can be found here: https://github.com/FalconForceTeam/TelemetryCollectionManager

Syntax

Set-XdrEndpointConfigurationCustomCollectionRule -InputObject <Object> [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]

Set-XdrEndpointConfigurationCustomCollectionRule -FilePath <string[]> -RuleId <string> [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]

Parameters

-FilePath

Property Value
Type String[]
Required Yes
Position named
Pipeline input true (ByValue, ByPropertyName)
Default Not documented

Path to one or more YAML files containing custom collection rule definitions. Supports wildcards for batch processing. When using YAML files, the RuleId parameter must be provided.

-RuleId

Property Value
Type String
Required Yes
Position named
Pipeline input No
Default Not documented

The GUID of the rule to update. Required when using FilePath parameter. This ensures you’re updating the correct rule when using YAML files.

-InputObject

Property Value
Type Object
Required Yes
Position named
Pipeline input true (ByValue)
Default Not documented

PSObject containing the rule to update. The object must include a ruleId property. Typically obtained from Get-XdrEndpointConfigurationCustomCollectionRule.

-BypassCache

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default False

Bypasses any existing cache entries when updating the rule. Will slow down processing if multiple rules are updated in succession.

-WhatIf

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Shows what would happen if the cmdlet runs. The cmdlet is not run.

-Confirm

Property Value
Type SwitchParameter
Required No
Position named
Pipeline input No
Default Not documented

Prompts for confirmation before creating each rule.

Examples

Set-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\FileMonitoring.yaml" -RuleId "12345678-1234-1234-1234-123456789012"
Updates a single custom collection rule from the specified YAML file.
Set-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\*.yaml" -RuleId "12345678-1234-1234-1234-123456789012"
Updates custom collection rules from all YAML files in the specified directory.
Get-XdrEndpointConfigurationCustomCollectionRule |
    Where-Object { $_.ruleName -eq "My Rule" } |
    Set-XdrEndpointConfigurationCustomCollectionRule
Updates a rule by passing a PSObject from Get cmdlet through the pipeline.
$rule = Get-XdrEndpointConfigurationCustomCollectionRule | Where-Object { $_.ruleName -eq "My Rule" }
$rule.isEnabled = $false
Set-XdrEndpointConfigurationCustomCollectionRule -InputObject $rule
Gets a rule, modifies it, and updates it.

Output

Type: Object

Returns the updated custom collection rule object(s) from the API.

View source