View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Get Alert

Retrieve full CrowdStrike Falcon alert records for one or more alert composite IDs via GET /alerts/entities/alerts/v1 (max 1000 per request). Use Search Alerts to find alert IDs first. See the documentation.
  • Action
  • Read only
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Get Alert from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-get-alert",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    alertIds: ["Alert IDs"],
    includeHidden: true,
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Get Alert inputs
Property Type Description
alertIds Alert IDs string[]
Alert composite IDs to retrieve (max 1000). Run Search Alerts to obtain these IDs. Sent as composite_ids in the request body.
Required
includeHidden Include Hidden boolean
Allows previously hidden alerts to be retrieved
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-get-alert
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
Yes
Destructive
No
Open world
Yes