View as Markdown
CrowdStrike Falcon icon

CrowdStrike Falcon TRIGGER

New Alert

Emit new event for each CrowdStrike Falcon alert created since the last run. Polls GET /alerts/queries/alerts/v1 (GetQueriesAlertsV2) for alert IDs newer than the stored created_timestamp checkpoint, then hydrates them via POST /alerts/entities/alerts/v1 (PostEntitiesAlertsV2, body field composite_ids). Use the optional FQL filter to narrow to specific alert products (e.g. legacy endpoint detections, now surfaced through the Alerts API). See the documentation.
  • Trigger
  • Polling
  • OAuth
  • Webhook delivery

IMPLEMENTATION

Deploy this event source

Connect the user's CrowdStrike Falcon account, configure the source, and choose the webhook where your backend receives events.

import { PipedreamClient } from "@pipedream/sdk"

const pd = new PipedreamClient({
  projectId: process.env.PIPEDREAM_PROJECT_ID!,
  clientId: process.env.PIPEDREAM_CLIENT_ID!,
  clientSecret: process.env.PIPEDREAM_CLIENT_SECRET!,
  projectEnvironment: "production",
})

const deployed = await pd.triggers.deploy({
  id: "crowdstrike_falcon-new-alert",
  externalUserId: "{external_user_id}", // any stable ID for this user in your system
  configuredProps: {
    crowdstrike_falcon: { authProvisionId: "apn_xxxxxxx" },
    timer: { "intervalSeconds": 900 },
    fqlFilter: "FQL Filter",
  },
  webhookUrl: "https://example.com/webhooks/crowdstrike-falcon",
})

console.log(deployed.id)

MCP exposes on-demand actions. Event sources are deployed through the Connect SDK or API because they continue listening after the initial request.

SCHEMA

Configuration

These inputs define which events the source watches. Dynamic options are loaded from the connected account.

New Alert configuration
Property Type Description
timer Timer $.interface.timer
Required
fqlFilter FQL Filter string
Optional FQL filter appended to the created_timestamp checkpoint filter. Example: product:'epp' to emit only endpoint-detection alerts. Combine terms with +.
Optional

01

Connect

Your user authorizes CrowdStrike Falcon through Pipedream managed auth.

02

Deploy

Your backend deploys this source with that user's own configuration.

03

Webhook delivery

Every event is sent to the HTTP endpoint you choose when you deploy the source — after each poll.

OR

On-demand retrieval

No webhook required. Your app or agent can fetch recent events from the trigger events API.

Registry key
crowdstrike_falcon-new-alert
Version
0.0.1
App
CrowdStrike Falcon
Authentication
OAuth
Delivery
Polling source
Output
Events emitted by CrowdStrike Falcon.