Overview
The Configuration Management API allows you to export your entire Falcon configuration as a portable archive and import it into another CID or restore it to the same CID. This is useful for:- Backup and disaster recovery - Regular configuration backups
- Multi-CID deployments - Replicate configurations across environments
- Configuration migration - Move policies and settings between test and production
- Audit and compliance - Document configuration state at specific points in time
Export-FalconConfig
Create a ZIP archive containing Falcon configuration files including groups, policies, exclusions, rules, and scripts.Syntax
Parameters
Selected items to export from your current CID. If not specified, all available items are exported.Valid values:
ContentPolicyDeviceControlPolicyFileVantagePolicyFileVantageRuleGroupFirewallGroupFirewallLocationFirewallPolicyHostGroupIoaExclusionIoaGroupIocMlExclusionPreventionPolicyResponsePolicyScriptSensorUpdatePolicySvExclusion
ItemsOverwrite an existing export file when present.
Examples
Export Process
The export process:- Retrieves all selected items from your Falcon environment
- Identifies dependencies (e.g., Host Groups assigned to policies)
- Automatically includes dependent items in the export
- Saves each item type as a JSON file
- Creates a ZIP archive named
FalconConfig_<timestamp>.zip - Removes temporary JSON files
Returns
Archive file information including full path, file size, and last write time.The export automatically includes dependencies. For example, exporting Prevention Policies will also export assigned Host Groups and IOA Rule Groups.
Import-FalconConfig
Import items from a FalconConfig archive into your Falcon environment.Syntax
Parameters
Path to the FalconConfig archive (.zip file) to import.
Import only selected items from the archive. If not specified, all items in the archive are imported.Valid values: Same as Export-FalconConfig
Assign existing host groups with identical names to imported items. Without this switch, imported policies will not be assigned to any groups.Aliases:
ForceModify default policies to match the import. Use
All for all possible values or specify individual policy types.Valid values:AllContentPolicyDeviceControlPolicyPreventionPolicyResponsePolicySensorUpdatePolicy
Modify existing items to match the import. Use
All for all possible values or specify individual item types.Valid values: Same as Export-FalconConfig (including All)Examples
Import Behavior
Default Behavior (No Switches)
Default Behavior (No Switches)
- Creates new items that don’t exist
- Ignores items that already exist
- Does not modify any existing items
- Does not assign imported policies to host groups
With -AssignExisting
With -AssignExisting
- Creates new items
- Matches host groups by name
- Assigns imported policies to matched host groups
- Still does not modify existing items
With -ModifyDefault
With -ModifyDefault
- Creates new items
- Modifies specified default policies to match import
- Useful for standardizing default policy settings
With -ModifyExisting
With -ModifyExisting
- Creates new items
- Modifies specified existing items to match import
- Updates policies, groups, exclusions, etc.
- Use with caution in production environments
Import Results
The import process generates a CSV file with detailed results:Common Workflows
Backup Configuration
Migrate Configuration Between CIDs
Clone Production to Test
Scheduled Backup
Selective Policy Update
Disaster Recovery
What Gets Exported
The export includes all user-created configurations:Policies
- Prevention Policies (with settings and IOA rule groups)
- Response Policies (with settings)
- Sensor Update Policies (with settings and schedules)
- Device Control Policies (with classes and exceptions)
- Firewall Policies (with settings and rule groups)
- File Vantage Policies (with rule groups and exclusions)
- Content Update Policies
Groups and Rules
- Host Groups (with assignment rules)
- IOA Rule Groups (with custom rules)
- Firewall Groups (with rules)
- File Vantage Rule Groups (with rules)
Exclusions and Indicators
- IOA Exclusions
- ML Exclusions
- Sensor Visibility Exclusions
- Indicators of Compromise (IOCs)
Other Items
- Firewall Locations
- RTR Scripts
Permissions Required
Export Permissions
For each item type being exported, you need Read permission:- Hosts: Read (for Host Groups)
- Prevention Policies: Read
- Response Policies: Read
- Sensor Update Policies: Read
- Device Control Policies: Read
- Firewall Management: Read
- IOA Rules: Read
- Custom IOA Rules: Read
- IOC Management: Read
- Real Time Response Admin: Read (for Scripts)
- File Vantage: Read
Import Permissions
For each item type being imported, you need Read and Write permissions:- Hosts: Read, Write
- Prevention Policies: Write
- Response Policies: Write
- Sensor Update Policies: Write
- Device Control Policies: Write
- Firewall Management: Write
- IOA Rules: Write
- Custom IOA Rules: Write
- IOC Management: Write
- Real Time Response Admin: Write
- File Vantage: Write
In Flight Control environments, Sensor Download: Read permission is also required for CID comparison.
Best Practices
Regular Backups
Schedule automated backups before making major configuration changes. Keep backups for at least 6 months.
Test Before Production
Always test imports in a test environment before applying to production. Verify all changes in the results CSV.
Version Control
Store configuration archives in version control or secure backup storage with timestamps and change descriptions.
Document Changes
Maintain a log of configuration imports/exports, including purpose, date, and who performed the operation.
Troubleshooting
Export Issues
Export fails with permission error
Export fails with permission error
Ensure your API credentials have Read permission for all item types being exported. Use
-Select to export only items you have access to.Archive file is empty or very small
Archive file is empty or very small
Check if you have any user-created configurations. Default policies and system items may be filtered out. Use
-Detailed to see what’s being exported.Export hangs or times out
Export hangs or times out
Large environments may take several minutes. Try exporting specific item types separately using
-Select.Import Issues
Import creates duplicates
Import creates duplicates
Without
-ModifyExisting, the import creates new items rather than updating existing ones. Use -ModifyExisting to update items with matching names.Policies not assigned to host groups
Policies not assigned to host groups
Use the
-AssignExisting switch to automatically assign imported policies to host groups with matching names.Some items failed to import
Some items failed to import
Review the results CSV for failed items. Common causes include permission issues, naming conflicts, or missing dependencies.
Related Commands
Get-FalconConfig- View current configurationCompare-FalconConfig- Compare configurations between CIDsRequest-FalconToken- Authenticate to switch between CIDs