-
Notifications
You must be signed in to change notification settings - Fork 63
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[ BUG ] Get-FalconQueue
no longer reporting queued sessions
#294
Comments
Possibly related to CrowdStrike/caracara#78 where an invalid filter uses "1" instead of "True" for the FQL query listing queued sessions; psfalcon does the same.
side note : queued operations not being visible nor doable in the web UI is really surprising. btw ; beware, your filter is using commands_queued=1 as a factor to figure out if sessions are offline or not. I couldn't find proper documentation, but it seems "offline_queued" is the proper bit describing if a session is offline ; the following combinations were found on my side ; I'm really not sure what "commands_queued" implies related to the overall session nature.
|
@59e5aaf4 thank you for the tip! It does seem that something changed in the RTR sessions API causing no values to return when using If you'd like to fix your local copy, you can modify the Filter = "(deleted_at:null+commands_queued:1),(created_at:>'last $Days days'+commands_queued:1)" To... Filter = "(deleted_at:null+commands_queued:true),(created_at:>'last $Days days'+commands_queued:true)" NOTE: Edited issue to clarify that the problem isn't that queuing is failing--it's that you can't view queued sessions due to the API change that caused |
Get-FalconQueue
no longer reporting queued sessions
Hi all, can confirm this has given me visibility of the offline queue. |
Leaving open for people to fix before release. |
Describe the bug
Despite a hefty list of offline hosts within Falcon; these are not added to the offline queue in PSFalcon when issuing a FalconDeploy command.
To Reproduce
Expected behavior
A list of hosts that are offline but in the Offline Queue.
Environment (please complete the following information):
Additional context
Trying to deploy ForensicFalcon out to estate. Many offline hosts offline and are not added to Offline Queue. User conducting the commands has RTR permissions.
Transcript content
Attached below
PowerShell_transcript.txt
The text was updated successfully, but these errors were encountered: