POWERSHELL COMMAND
Set-XdrEndpointConfigurationCustomCollectionRule
Updates an existing custom collection rule for Microsoft Defender for Endpoint.
Updates custom collection rules for Microsoft Defender for Endpoint by importing YAML files or PSObjects. The YAML files should follow the schema format used by Get-XdrEndpointConfigurationCustomCollectionRule. Each rule is validated before submission to ensure proper schema structure and that the rule exists.
More information about the schema can be found here: https://github.com/FalconForceTeam/TelemetryCollectionManager
Syntax
Set-XdrEndpointConfigurationCustomCollectionRule -InputObject <Object> [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]
Set-XdrEndpointConfigurationCustomCollectionRule -FilePath <string[]> -RuleId <string> [-BypassCache] [-WhatIf] [-Confirm] [<CommonParameters>]
Parameters
-FilePath
| Property | Value |
|---|---|
| Type | String[] |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue, ByPropertyName) |
| Default | Not documented |
Path to one or more YAML files containing custom collection rule definitions. Supports wildcards for batch processing. When using YAML files, the RuleId parameter must be provided.
-RuleId
| Property | Value |
|---|---|
| Type | String |
| Required | Yes |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
The GUID of the rule to update. Required when using FilePath parameter. This ensures you’re updating the correct rule when using YAML files.
-InputObject
| Property | Value |
|---|---|
| Type | Object |
| Required | Yes |
| Position | named |
| Pipeline input | true (ByValue) |
| Default | Not documented |
PSObject containing the rule to update. The object must include a ruleId property. Typically obtained from Get-XdrEndpointConfigurationCustomCollectionRule.
-BypassCache
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | False |
Bypasses any existing cache entries when updating the rule. Will slow down processing if multiple rules are updated in succession.
-WhatIf
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Shows what would happen if the cmdlet runs. The cmdlet is not run.
-Confirm
| Property | Value |
|---|---|
| Type | SwitchParameter |
| Required | No |
| Position | named |
| Pipeline input | No |
| Default | Not documented |
Prompts for confirmation before creating each rule.
Examples
Set-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\FileMonitoring.yaml" -RuleId "12345678-1234-1234-1234-123456789012"
Updates a single custom collection rule from the specified YAML file.
Set-XdrEndpointConfigurationCustomCollectionRule -FilePath "C:\Rules\*.yaml" -RuleId "12345678-1234-1234-1234-123456789012"
Updates custom collection rules from all YAML files in the specified directory.
Get-XdrEndpointConfigurationCustomCollectionRule |
Where-Object { $_.ruleName -eq "My Rule" } |
Set-XdrEndpointConfigurationCustomCollectionRule
Updates a rule by passing a PSObject from Get cmdlet through the pipeline.
$rule = Get-XdrEndpointConfigurationCustomCollectionRule | Where-Object { $_.ruleName -eq "My Rule" }
$rule.isEnabled = $false
Set-XdrEndpointConfigurationCustomCollectionRule -InputObject $rule
Gets a rule, modifies it, and updates it.
Output
Type: Object
Returns the updated custom collection rule object(s) from the API.