View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon TRIGGER

Host Status Changed

Emit new event for each host matching a user-supplied FQL filter that has not been emitted in a prior run. Polls GET /devices/combined/devices/v1 (returns full device records including status/containment status and sensor-health fields) and deduplicates on a deviceId-modified_timestamp composite so only genuinely changed hosts emit. Covers both sensor-health and containment-status scenarios via the filter prop. See the documentation.
  • Trigger
  • Polling
  • OAuth
  • Webhook delivery

IMPLEMENTATION

Deploy this event source

Connect the user's CrowdStrike Falcon account, configure the source, and choose the webhook where your backend receives events.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "crowdstrike_falcon-host-status-changed",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    timer: { "intervalSeconds": 900 },
    fqlFilter: "FQL Filter",
  },
  webhookUrl: "https://example.com/webhooks/crowdstrike-falcon",
})

console.log(deployed.id)

MCP exposes on-demand actions. Event sources are deployed through the Connect SDK or API because they continue listening after the initial request.

SCHEMA

Configuration

These inputs define which events the source watches. Dynamic options are loaded from the connected account.

Host Status Changed configuration
Property Type Description
timer Timer $.interface.timer
Required
fqlFilter FQL Filter string
FQL filter selecting the hosts to watch. Examples: status:'containment_pending' (containment change), reduced_functionality_mode:'yes' (degraded sensor health). Combine terms with +.
Optional

01

Connect

Your user authorizes CrowdStrike Falcon through Pipedream managed auth.

02

Deploy

Your backend deploys this source with that user's own configuration.

03

Webhook delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source — after each poll.

OR

On-demand retrieval

No webhook required. Your app or agent can fetch recent events from the trigger events API.

Registry key
crowdstrike_falcon-host-status-changed
Version
0.0.1
App
CrowdStrike Falcon
Authentication
OAuth
Delivery
Polling source
Output
Events emitted by CrowdStrike Falcon.