View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Get RTR Command Status

Retrieve the status and output of a Real-Time Response command via GET /real-time-response/entities/command/v1, returning stdout, stderr and completion status. Provide the cloud_request_id returned by Run RTR Command. Requires an RTR entitlement. See the documentation.
  • Action
  • Read only
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Get RTR Command Status from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-get-rtr-command-status",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    cloudRequestId: "Cloud Request ID",
    sequenceId: 10,
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Get RTR Command Status inputs
Property Type Description
cloudRequestId Cloud Request ID string
The cloud_request_id returned by Run RTR Command.
Required
sequenceId Sequence ID integer
Sequence ID for paging through a long command result. Default: 0.
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-get-rtr-command-status
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
Yes
Destructive
No
Open world
Yes