View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Search Alerts

Search CrowdStrike Falcon alerts and return their IDs via GET /alerts/queries/alerts/v2. Detections are now delivered through the Alerts API (the legacy /detects/* collection was decommissioned), so filter on the alert product to retrieve endpoint detections. Use Get Alert to hydrate the returned IDs into full records. See the documentation.
  • Action
  • Read only
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Search Alerts from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-search-alerts",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    fqlFilter: "FQL Filter",
    limit: 10,
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Search Alerts inputs
Property Type Description
fqlFilter FQL Filter string
Optional FQL filter. Example: status:'new'+severity:'High'. Combine terms with +.
Optional
limit Limit integer
Maximum number of alert IDs to return (1-1000). Default: 100.
Optional
offset Offset integer
Offset for pagination. Default: 0.
Optional
sort Sort string
Optional sort in field|direction form, e.g. created_timestamp|desc. Sortable fields: timestamp, created_timestamp, updated_timestamp, status, severity.
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-search-alerts
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
Yes
Destructive
No
Open world
Yes