View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon ACTION

Search Hosts

Search CrowdStrike Falcon hosts and return full device records via GET /devices/combined/devices/v1, including status (containment status), reduced_functionality_mode and other sensor-health fields. Use Get Host to retrieve a specific device by ID. See the documentation.
  • Action
  • Read only
  • OAuth
  • SDK
  • MCP

IMPLEMENTATION

Call this tool

Connect a user's CrowdStrike Falcon account once, then configure and run Search Hosts from your backend or agent.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const result = await pd.actions.run({
  id: "crowdstrike_falcon-search-hosts",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    fqlFilter: "FQL Filter",
    limit: 10,
  },
})

console.log(result)

SCHEMA

Inputs

Pipedream supplies the connected account. Your application provides the operation-specific values below. Dynamic inputs are resolved against that user's account.

Search Hosts inputs
Property Type Description
fqlFilter FQL Filter string
Optional FQL filter. Example: platform_name:'Windows'+status:'normal'. Combine terms with +.
Optional
limit Limit integer
Maximum number of device records to return (1-1000). Default: 100.
Optional
offset Offset integer
Offset for pagination. Default: 0.
Optional
sort Sort string
Optional sort in field.direction form, e.g. hostname.asc or status.desc.
Optional
fields Fields string
The fields to return, comma delimited.
Optional

REFERENCE

Tool details

Behavior hints are published with the component in the Pipedream registry and surface as MCP tool annotations, so an agent can reason about a tool before it calls it.

Registry key
crowdstrike_falcon-search-hosts
Version
0.0.2
App
CrowdStrike Falcon
Authentication
OAuth
Read-only
Yes
Destructive
No
Open world
Yes