# Host Status Changed — CrowdStrike Falcon

> Emit new event for each host matching a user-supplied FQL filter that has not been emitted in a prior run. Polls GET /devices/combined/devices/v1 (returns full device records including status/containment status and sensor-health fields)…

- Key: `crowdstrike_falcon-host-status-changed`
- Type: Trigger (Polling)
- Version: 0.0.1
- App: CrowdStrike Falcon (`crowdstrike_falcon`) — https://pipedream.com/apps/crowdstrike-falcon.md
- This page (HTML): https://pipedream.com/apps/crowdstrike-falcon/triggers/host-status-changed
- Source: https://github.com/PipedreamHQ/pipedream/blob/master/components/crowdstrike_falcon/sources/host-status-changed/host-status-changed.mjs

## Description

Emit new event for each host matching a user-supplied FQL filter that has not been emitted in a prior run. Polls GET /devices/combined/devices/v1 (returns full device records including `status`/containment status and sensor-health fields) and deduplicates on a `deviceId-modified_timestamp` composite so only genuinely changed hosts emit. Covers both sensor-health and containment-status scenarios via the filter prop. [See the documentation](https://developer.crowdstrike.com/api-reference/collections/hosts/#combineddevicesbyfilter).

## Props

| Prop | Type | Required | Description |
|---|---|---|---|
| `timer` | `$.interface.timer` | Yes | Timer |
| `fqlFilter` | `string` | No | FQL filter selecting the hosts to watch. Examples: status:'containment_pending' (containment change), reduced_functionality_mode:'yes' (degraded sensor health). Combine terms with +. |

## Returns

Events emitted by CrowdStrike Falcon.

## Run it

**TypeScript**

```ts
import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "crowdstrike_falcon-host-status-changed",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    timer: { "intervalSeconds": 900 },
    fqlFilter: "FQL Filter",
  },
  webhookUrl: "https://example.com/webhooks/crowdstrike-falcon",
})

console.log(deployed.id)
```

**cURL**

```bash
curl -X POST https://api.pipedream.com/v1/connect/{project_id}/triggers/deploy \
  -H "Content-Type: application/json" \
  -H "X-PD-Environment: production" \
  -H "Authorization: Bearer {access_token}" \
  -d '{
    "external_user_id": "{external_user_id}",
    "id": "crowdstrike_falcon-host-status-changed",
    "webhook_url": "https://example.com/webhooks/crowdstrike-falcon",
    "configured_props": {
      "crowdstrike_falcon": { "authProvisionId": "apn_xxxxxxx" },
      "timer": { "intervalSeconds": 900 },
      "fqlFilter": "FQL Filter"
    }
  }'
```

**MCP**

MCP servers expose CrowdStrike Falcon actions as on-demand tools.

Host Status Changed is an event source, so your application deploys it with the Connect SDK or API and then either receives each event at a webhook URL or retrieves events on demand with the trigger events API.

## Event delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source. Or: no webhook required — your app or agent can fetch recent events from the [trigger events API](https://pipedream.com/docs/connect/api-reference/list-trigger-events.md) instead.

---

- App: https://pipedream.com/apps/crowdstrike-falcon.md · All apps: https://pipedream.com/apps
